Merco

Legal

Privacy Policy

What we hold, why we hold it, who we share it with, and how you take it with you.

Last updated 30 July 2026

About this policy

This Privacy Policy describes how Merco (“Merco”, “we”, “us”) processes personal data when you use merco.dev and the Merco platform (together, the “Platform”). It applies to suppliers, buyers and the users of compliance workspaces who access the Platform.

Merco is established in Switzerland and processes personal data in line with the Swiss Federal Act on Data Protection (revFADP) and, for data concerning individuals in the European Economic Area, the General Data Protection Regulation (GDPR). We do not collect special categories of personal data (Article 9 GDPR) through the Platform, other than identity documents that may be processed by our identity-verification provider as described below.

This policy does not describe the practices of payment, identity, shipping or other third-party services that have their own terms. Where those services process your data, they do so as controllers or processors in their own right under their own policies, which you should also read.

Controller & contact

Merco is the controller responsible for your personal data. You can reach us at the address and contact details published in the imprint. For data-protection questions and to exercise any right in this policy, contact us through the access form or at [privacy@merco.dev — to be inserted].

Where required by law, Merco will designate a data protection officer and, for individuals located in the EU, an Article 27 GDPR representative in the European Union. Their contact details will be published here when appointed. Until then, the contact route above serves all data-protection enquiries.

What we hold

We process the following categories of personal data, depending on how you use the Platform:

  • Account and identity data: name, email address, username, telephone number, country, role and profile image.
  • Business and trade identifiers: company name, website, VAT or tax identification number (for example CNPJ, CUIT, RUT or NIT), EU EORI number, US CBP Manufacturer Identification (MID), and Textile Exchange or equivalent scheme identifiers.
  • Geolocation data: the location of facilities and, for products subject to the EU Deforestation Regulation, the precise geolocation of plots of land where commodities were produced.
  • Documents: certificates, declarations, customs documents, laboratory reports, invoices, contracts, dossiers and similar files you upload or generate, which may contain names, signatures, identifiers and addresses.
  • Communications: messages exchanged on the Platform, order and quote details, and notifications.
  • Behavioural and preference data: the searches you run, the listings and counterparties you view or save, and similar interaction signals used to operate the marketplace.
  • Identity-verification data: where verification is triggered, government identity documents and a facial image are collected and held by our identity provider (see “Identity verification”); Merco stores only a reference to the result.
  • Technical data: we record your IP address and user agent when you give a legal consent, and we use first-party session cookies to keep you signed in.

Purposes & legal bases

We process personal data for the following purposes, on the legal bases indicated:

  • To provide the service you signed up for — creating and maintaining your account, running orders, escrow, shipments and compliance work. Basis: performance of a contract with you.
  • To meet legal obligations — preparing and retaining due-diligence records and filings under the EU Deforestation Regulation (including the five-year retention it requires), customs and trade requirements, anti-money-laundering and know-your-customer rules, and sanctions screening. Basis: compliance with a legal obligation.
  • To run our compliance and due-diligence work — verifying counterparties and supply chains, screening for sanctions and adverse information, and scoring and ranking suppliers and products. Basis: our legitimate interests in operating a trustworthy, compliant Platform and in protecting against fraud and regulatory risk.
  • To operate, secure and improve the Platform — reliability, abuse prevention, security monitoring and product improvement. Basis: our legitimate interests in operating, protecting and improving the Platform.
  • To send you communications — service notifications, and, where you opt in, marketing. Basis: performance of a contract and our legitimate interests for service messages; your consent for marketing, which you can withdraw at any time.

Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms and limited the processing to what is necessary. You have the right to object to processing based on legitimate interests (see “Your rights”).

Who we share it with

We share personal data only with the categories of recipients needed to operate the Platform:

  • Artificial-intelligence providers. To power compliance analysis, document reading, due-diligence drafting and order assistance, data you provide — including supplier identity, trade identifiers, geolocation, uploaded documents and, for order-assistance features, the content of conversations — may be processed by an AI provider acting as our processor. We use a single live model provider; the identity and location of the provider are listed below.
  • Payment and identity providers. Stripe processes payments, escrow, payouts and identity verification, and holds the associated payment and identity data as a controller or processor under its own terms.
  • Communications providers. A transactional-email provider delivers notifications and messages to your inbox; it receives the recipient address and the content of the message.
  • Search and screening providers. To verify counterparties and screen for sanctions or adverse information, supplier names and identifiers may be submitted to web-search and sanctions-data providers.
  • Mapping, satellite and logistics providers. Location data is sent to mapping and satellite-imagery providers to render maps and verify deforestation status, and shipment references are sent to freight-rate and tracking providers.
  • Hosting, database, storage and infrastructure providers. Vercel (hosting), Neon (database), Vercel Blob (object storage), Upstash (queues and rate limiting) and Render (background processing) host and process Platform data as our processors.
  • Public authorities and registers. Where the law requires or allows it, data is submitted to authorities — for example the due-diligence statement filed with the EU TRACES system — and corporate identifiers may be checked against public business registers.
  • The public ledger. Anchoring data is published to a public blockchain as described under “Blockchain anchoring”.

The current list of processors, the data they receive and the countries in which they operate is set out under “International transfers”. We bind our processors by contract and disclose data only as necessary for the service.

International transfers

Your data is processed in Switzerland, in the EU and in other countries — including the United States — because several processors we rely on are established there. The following processors may receive personal data and are located outside Switzerland and the EEA:

  • OpenAI (United States) — AI model processing of supplier identity, trade identifiers, geolocation, documents and conversation content.
  • Stripe (United States / EU) — payments, escrow, payouts and identity verification.
  • Resend (United States) — transactional email.
  • Tavily (United States) — web search for verification and screening.
  • Mapbox (United States) — maps and geocoding.
  • Vercel, Vercel Blob, Upstash and Render (United States) — hosting, storage, queues and background processing.
  • Global Forest Watch / Hansen data (United States) and DP World SeaRates (UAE) — satellite verification and freight services.

The database (Neon) is hosted in the EU (Frankfurt). We transfer personal data outside Switzerland and the EEA only where an adequate level of protection is assured: under the Swiss–US and EU–US Data Privacy Framework where a processor is certified under it, or otherwise under the European Commission's Standard Contractual Clauses and their Swiss-law equivalents, supplemented by transfer impact assessments where appropriate. We will provide a copy of the safeguards on request where you are entitled to one.

Automated decisions

Merco uses automated processing to support compliance and marketplace decisions — for example to assess and score supplier compliance, to rank suppliers and products, and to suggest matches in the marketplace. These are tools that support, and do not replace, human judgement.

We do not take decisions producing legal or similarly significant effects concerning you based solely on automated processing, except where necessary to enter into or perform a contract with you, where authorised by law, or where you have consented. Where such automated decision-making takes place, you have the right to obtain human intervention, to express your point of view and to contest the decision. To do so, contact us as set out under “Controller & contact”.

Blockchain anchoring

To create a tamper-evident, independently verifiable record, Merco anchors a digest of compliance decisions and due-diligence documents to a public blockchain (Polygon). The data published is a one-way cryptographic hash of the underlying record, together with a short identifier of the record type.

Because a public blockchain is immutable, anything anchored to it cannot be altered or removed. We therefore publish only digests and minimal identifiers, never the contents of documents or your personal data. Where a feature publishes a record identifier on-chain, that identifier is a non-descriptive reference to a transaction, not your personal data on its own. This means that, for the specific records that have been anchored, the right to erasure is limited by the technical impossibility of removing a public, immutable entry, which we consider to fall within the legal-obligation and legitimate-interest bases described above. All substantive personal data remains in our controlled systems, where your rights apply in full.

Identity verification

When identity verification is required — typically for higher-value transactions — we use Stripe Identity. Stripe collects and verifies your government identity document and a facial image, and holds that data as the controller of the verification process under its own terms. Merco receives and stores only the outcome and a reference to the verification, not the underlying documents.

Cookies

We use only first-party, strictly necessary cookies and similar technologies — to keep you signed in, to maintain your session, to remember your active organisation, and (for administrators) to support a safe impersonation tool. These cookies are essential to the service and cannot be switched off in our systems.

We do not use advertising, analytics, tracking or cross-site cookies, and there is no cookie banner because none is needed. You can clear or block first-party cookies in your browser settings; doing so will sign you out and affect how the Platform works for you. Because we do not profile you with trackers, “do not track” signals do not change our practices.

How long we keep it

We keep personal data only as long as necessary for the purposes set out in this policy and to meet our legal and contractual obligations. In particular:

  • Due-diligence and compliance records are retained for the period required by law — including at least five years for records under the EU Deforestation Regulation — and longer where another legal obligation applies.
  • Account, order, document and communication data is kept for the life of your relationship with the Platform and for the limitation and retention periods that follow it, including tax and accounting requirements.
  • Short-lived operational data — such as security and audit logs, search-intent data and AI-run telemetry — is deleted on a short schedule (typically between 45 and 180 days).

When data is no longer needed, we delete it or anonymise it so that it can no longer be linked to you, subject to any legal retention obligation.

Your rights

Subject to applicable law, you have the right to:

  • Access the personal data we hold about you and receive a copy.
  • Rectify personal data that is inaccurate or incomplete.
  • Erasure of your personal data, subject to legal retention obligations (for example the due-diligence records we are required to keep) and the immutable nature of any anchored record.
  • Restrict or object to processing, in particular processing based on legitimate interests.
  • Data portability — to receive your data in a structured, machine-readable form and, where technically feasible, to have it transmitted to another controller.
  • Not be subject to a decision based solely on automated processing, with the right to human intervention as described above.
  • Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal.

To exercise any of these rights, contact us through the access form or at the privacy address above. We respond within the time the law requires (usually one month, which may be extended for complex requests). Where your records are exportable, you can also obtain them directly from within the Platform.

If you believe we have not handled your data correctly, you have the right to complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, if you are in the EU, to your local data-protection authority.

Security

We protect personal data with measures appropriate to the risk, including encryption of data in transit, access controls limited to authorised personnel, secure password storage and optional two-factor authentication, segregation of roles, logging of sensitive actions, and access controls over uploaded documents. We cannot guarantee absolute security, but we work to meet our obligations and to notify you and the authorities where the law requires it in the event of a personal-data breach.

Children

The Platform is a business service and is not directed at children. We do not knowingly collect personal data from anyone under the age of sixteen. If you believe we have collected personal data from a child, contact us and we will delete it.

Changes

We may update this policy to reflect changes in our practices, the law or the Platform. We will publish the updated policy here with the date above and, where a change is material, we will give you notice. Continued use of the Platform after a change takes effect constitutes acceptance of the updated policy, to the extent permitted by law.

This policy is published by Merco. Operator-specific particulars (entity details, the privacy email address, and the identity of any appointed representative) are shown as fields to be completed on incorporation and should be confirmed by a qualified lawyer before launch. It does not constitute legal advice.

← Merco