Privacy Policy

Last updated: April 23, 2026

1. Introduction

This Privacy Policy explains how Envision Media Holdings LLC ("Company", "we", "us", "our") collects, uses, discloses, and protects information in connection with Merlin ("the Software"). By using Merlin, you consent to the data practices described in this policy. If you do not agree, do not use the Software.

2. Information We Collect

2.1 Information You Provide:

2.2 Information Collected Automatically:

3. Information We Do NOT Persist on Our Servers

Outside of the limited categories listed in Section 2 (license records, anonymous Wisdom metrics, error reports), the following categories never reach our long-term storage:

Shopify-specific note: When you install Merlin on a Shopify store, your encrypted Shopify Admin API access token is stored at rest in our Cloudflare D1 database (encrypted with AES-256-GCM, AAD-bound to the shop slug — see Section 8.2 for the full Shopify data flow). Order, product, and customer-summary data fetched from Shopify to render your dashboard is fetched live on each page load and not persisted; we do not maintain a copy of your store catalog or customer list on our servers.

4. How We Use Information

5. Data Storage & Security

6. Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA), United Kingdom, or Switzerland, we process personal data under the following legal bases:

Data Processing Agreement (DPA): Enterprise customers requiring a DPA for GDPR compliance may request one by emailing legal@merlingotme.com.

7. Wisdom (Collective Intelligence)

Merlin's Wisdom system aggregates anonymous performance metrics from all users to provide better advertising recommendations. Participation is enabled by default and you may opt out at any time by setting telemetry: false in your config file. There is no consent prompt during onboarding; this section is the disclosure.

8. Third-Party Services & Data Sharing

Merlin connects to third-party services on your behalf using credentials you explicitly authorize via OAuth or API key entry:

We do not sell, rent, or share your personal information with third parties for their marketing purposes. We share data only as described in this policy: with service providers (Stripe, Cloudflare) who process data on our behalf, and in response to valid legal process.

8.1 Google API Services User Data

Merlin accesses data from your Google account only through OAuth 2.0 scopes that you explicitly authorize on the Google-hosted consent screen at accounts.google.com. The scopes Merlin may request, and the user data each scope authorizes Merlin to access on your behalf, are:

Limited Use. Merlin's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

Retention of Google user data. Data fetched from Google APIs is retained only for the duration required to deliver the feature you requested and to render it in the Merlin UI. Performance snapshots written to your local results/ folder (for example, dashboard JSON files) remain on your machine until you delete them and are never uploaded to our servers. Revoking Merlin's access on the Google side, or disconnecting Google inside Merlin, purges the locally stored Google OAuth tokens from your vault.

Revoking access. You can revoke Merlin's access to your Google account at any time by visiting myaccount.google.com/permissions and removing "Merlin", or by disconnecting Google from inside the Merlin application. Revocation through either path immediately invalidates Merlin's ability to make further Google API calls on your behalf.

8.2 Shopify Admin API Data

Merlin accesses your Shopify store data only through OAuth 2.0 scopes that you explicitly authorize on the Shopify-hosted consent screen at {your-shop}.myshopify.com/admin/oauth/authorize. The web install flow that begins on the Shopify App Store grants Merlin only the read-only scopes required to render your dashboard:

If you also use the Merlin desktop application, additional scopes (write_products, read_content, write_content) may be requested separately when you trigger a feature that requires them (for example, publishing a blog post or updating a product description). Each request goes through Shopify's standard reconsent flow.

Storage and encryption. Your Shopify Admin API access token is stored at rest in our Cloudflare D1 database, encrypted with AES-256-GCM using a per-Worker secret key. The encrypted blob is bound to your shop slug via Authenticated Encryption with Associated Data (AAD), so a leaked ciphertext cannot be replayed under a different shop's identity. The dashboard session cookie that maps your browser to your install record is HttpOnly, Secure, SameSite=Lax, and rotates on a 30-day rolling expiry.

Data flow. When you load merlingotme.com/dash/{your-shop}, our server-side handler decrypts your token, calls the Shopify Admin API /shop.json and /orders.json endpoints (last 30 days, projected fields only), aggregates the result into the dashboard view, and renders the HTML. The fetched order, customer, and product data is held only for the lifetime of the request and discarded as soon as the response is sent. Your Shopify access token is never exposed to your browser; the dashboard makes no JavaScript Admin API calls.

Compliance webhooks. Merlin subscribes to all four Shopify-mandated webhook topics:

Every webhook is HMAC-SHA256 verified using SHOPIFY_CLIENT_SECRET with constant-time comparison. Webhooks lacking the X-Shopify-Hmac-Sha256 header, or carrying an invalid HMAC, are rejected with HTTP 401.

Disconnecting Merlin. Open your Shopify admin → Settings → Apps and sales channels → Merlin → Uninstall. Shopify revokes the access token immediately and fires our app/uninstalled webhook, which soft-deletes our install record. To remove your encrypted token entirely (instead of soft-deleting), email privacy@merlingotme.com with your shop slug.

9. International Data Transfers

Our servers (Cloudflare Workers) operate globally. By using Merlin, you consent to the transfer of anonymized telemetry data to servers that may be located outside your country of residence. All transfers are protected by TLS encryption and Cloudflare's security infrastructure.

10. Your Rights

Depending on your jurisdiction (including GDPR for EU/EEA residents and CCPA for California residents), you may have the right to:

To exercise any of these rights, email privacy@merlingotme.com. We will respond within 30 days (or sooner if required by applicable law).

11. Data Deletion

Local data: Uninstall Merlin and delete the application folder (typically Documents/Merlin) to permanently remove all local data including credentials, brand data, generated content, and conversation history.

Server-side data: Use our self-service data deletion tool to instantly delete all server-side records associated with your Machine ID. This removes: license records, referral data, telemetry pings, and reverse indexes. For Stripe payment records, email privacy@merlingotme.com.

12. Data Retention

13. CCPA Financial Incentive Disclosure

Merlin offers a referral program that provides additional free trial days (7 days per referral, up to 21 days maximum) and an affiliate program that provides recurring monetary commissions per active referred subscriber. These programs constitute "financial incentives" under the California Consumer Privacy Act. The value of the incentive is reasonably related to the value of the data provided (referral attribution). You may opt out of these programs at any time without penalty to your core subscription. Participation requires providing your email address and, for affiliates, Stripe Connect account information.

14. Children's Privacy

Merlin is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child under 18, we will promptly delete it. If you believe a child has provided us with personal information, contact privacy@merlingotme.com.

15. Security Measures

We implement commercially reasonable security measures including: encrypted credential storage (OS-level keychain via Electron safeStorage), HMAC-signed API payloads, TLS 1.3 encryption for all server communications, rate limiting, and access controls. However, no method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.

16. Changes to This Policy

We may update this Privacy Policy from time to time. Changes are effective when posted to this page. If we make material changes, we will notify you via the application or email. Continued use of the Software after changes constitutes acceptance of the updated policy.

17. Contact

For privacy inquiries: privacy@merlingotme.com

For general support: support@merlingotme.com

Envision Media Holdings LLC

← Back to Merlin