Skip to content

Legal

Privacy policy

What we collect, why, for how long, who helps us, and the rights you have. Written to be read.

Last updated: 2 October 2026

In short

  • We run AskMerra, an AI shopping assistant for online shops. This policy covers people who visit our website, businesses and team members who use the dashboard, and anyone who contacts us.
  • When a shopper chats with the assistant on a shop’s website, the shop is responsible for that data and we only process it on the shop’s instructions. See Shoppers who chat on a shop’s website.
  • We collect only what we need to run the service. We don’t sell data, we don’t show ads, and we don’t use your data or shoppers’ chats to train AI models.
  • Our website uses no analytics and no advertising. Our sign-in, sign-up, password reset and contact forms use Cloudflare Turnstile to keep bots out. Everything we use is strictly necessary, so there is no consent banner, only a short notice about our essential cookies. See the cookie policy.
  • Data is hosted in the EU. A few providers outside the EU, such as the AI model provider, receive data under EU-approved safeguards.
  • You can download your account data and delete your account yourself in the dashboard, or write to [email protected].

Who is responsible

The controller for our website, merchant accounts and messages you send us is:

  • [Company legal name]
  • [Registered address]
  • Registration number: [Registration number]
  • VAT number: [VAT number]

For anything about privacy, write to [email protected]. Data protection officer: [DPO / privacy contact email if appointed].

Our two roles

Controller. We decide how and why personal data is used for our own website, for merchant accounts and for messages you send us. The next three sections cover this.

Processor. When a shop installs the AskMerra widget, the shop decides what happens with its shoppers’ chats. We process those chats only on the shop’s behalf, under our data processing agreement. See Shoppers who chat on a shop’s website.

Visiting our website

When you open a page, your browser sends us technical data such as your IP address, browser type and the page you asked for. We use it only to deliver the page and to keep the site secure.

  • No IP addresses in our logs. Our application logs record the request, not who made it. Counters that protect our forms against abuse use a one-way hash of the IP address and expire within 24 hours.
  • No analytics, ads or tracking. We don’t use analytics tools, advertising pixels, social media plugins or externally hosted fonts. Fonts and images come from our own servers.
  • Bot protection on forms. Our sign-in, sign-up, password reset and contact forms use Cloudflare Turnstile to check that a person, not a bot, is sending them. When you open one of these pages, your browser loads the check from Cloudflare, which receives your IP address, browser details such as the user agent, and technical signals from your device. We receive only a one-time pass, which we confirm with Cloudflare when you send the form. Cloudflare also uses these signals, as an independent controller, to improve its bot detection (see the Turnstile privacy addendum).
  • Cookies: only the ones that are strictly necessary, plus a language cookie when you choose a language. Details are in the cookie policy.

Legal basis: our legitimate interest in running a secure website and keeping automated abuse away from accounts and forms (Art. 6(1)(f) GDPR).

Contact form and emails to us

If you use the contact form or email us, we receive your name, email address, the company and website you give us, the topic and your message. We use them to answer you and, if you ask about our service, to prepare an offer.

Legal basis: steps you ask for before a possible contract (Art. 6(1)(b) GDPR) and our legitimate interest in answering questions (Art. 6(1)(f)). We need your name, email and message to reply; company and website are optional.

We keep these messages for up to 2 years after our last exchange, unless they become part of a customer relationship or we need them to establish or defend a legal claim.

Merchant accounts and the dashboard

When you or your team use AskMerra, we process:

  • Account data: name, email address, password (stored only as an argon2id hash), dashboard language, and your shops and roles.
  • Sign-in and security: if you sign in with Google, your Google account id, name and verified email address, never your Google password. Two-factor settings (the secret is encrypted, recovery codes are stored as hashes). Active sessions with a device description and the time of last activity. An audit log of important actions, such as two-factor changes, team changes and data deletions.
  • Company and billing details: company name, VAT and registration numbers, address, invoice email and phone, plan, usage, prepaid credits and payments. If you ask us to verify a VAT number, we check it with the European Commission’s VIES service. Card details go straight to our payment provider, Stripe, and never reach our servers.
  • Shop content: shop name, domains, catalog, knowledge base, widget settings and team invitations.
  • Service emails: emails you need to use the service, such as address confirmation, sign-in links, password resets, team invitations, chat escalations, security alerts and billing notices. We don’t send newsletters or marketing emails, and our emails contain no tracking pixels.
  • Support: messages you send us and our replies.

Legal bases: performing our contract with you or your company (Art. 6(1)(b) GDPR); legal obligations, for example tax and accounting rules for invoices (Art. 6(1)(c)); and our legitimate interests (Art. 6(1)(f)) in securing accounts, preventing abuse and fraud, and establishing or defending legal claims. If you use AskMerra on behalf of a company, we process your work contact details based on our legitimate interest in managing our relationship with that company.

We need your email address to create an account; without it we can’t provide the service. Company details are used for your invoices.

Shoppers who chat on a shop’s website

The shop that installed the widget is the controller of its shoppers’ chat data. Its own privacy policy, linked in the chat window, explains how it uses your data. AskMerra processes the data only on the shop’s behalf, under our data processing agreement. For the shop, the widget processes:

  • your messages and the assistant’s answers, the products shown and clicked, and your feedback;
  • the page you chat from, your language, and an approximate country derived from network headers (your IP address is never stored; a one-way hash is used briefly against abuse);
  • a random visitor id and a few technical items in your browser’s storage, created only once you open the chat or start typing (see the cookie policy);
  • your name and email address only if you fill in the contact form in the chat, or if the shop chose to link the chat to your customer account.

AI answers. The chat window always tells you that you are talking to an AI assistant. To write an answer, your messages are sent to our AI model provider. Providers may not use them to train their models, and neither do we. The assistant does not make decisions about you that have legal or similarly significant effects.

Purchases after a chat. If you accept analytics in the shop’s cookie banner and place an order within 7 days after chatting, the widget tells the shop: order number, amount and products, linked to your chat. If you didn’t chat, or don’t consent, nothing is sent.

How long. The shop chooses how long chats are kept: 30, 90 or 365 days. After that they are deleted automatically.

Your rights. Please contact the shop first: it decides about your data, and we help it answer. Shops can delete a shopper’s data from their dashboard and can offer a delete button on their own site. If you write to us, we will pass your request on to the shop.

Who receives data

We share personal data only with providers that help us run the service, and only what they need. They act on our instructions under data processing contracts:

RecipientPurposeLocation
[Hosting provider name]Servers, database and backupsEU
Anthropic, PBCAI model that writes chat answers and enriches catalogsUSA
Voyage AIText embeddings for product searchUSA
[Email provider name]Delivery of service emails[Location]
[Mailbox provider name]Our inbox for contact form messages and support emails[Location]
StripePayments, invoices and tax calculation for merchantsEU and USA
Cloudflare, Inc.Bot protection on the sign-in, sign-up, password reset and contact forms (Turnstile)USA

Other recipients, only when relevant: Google, if you choose to sign in with Google; the European Commission (VIES), if you verify a VAT number; our professional advisers, such as accountants and lawyers, who are bound to confidentiality; and public authorities when the law requires it. The sub-processors for shoppers’ chat data are listed in our DPA.

We never sell personal data or share it for advertising.

Transfers outside the EU

Our servers and databases are in the EU. Some providers are based in the USA (see the table above). For these transfers we rely on the EU-U.S. Data Privacy Framework where the provider is certified, and otherwise on the European Commission’s Standard Contractual Clauses, with additional safeguards where needed. You can ask for a copy of the safeguards at [email protected].

How long we keep data

DataHow long
Merchant account, sign-in methods, company detailsUntil you delete your account. Deletion takes effect immediately in our database.
Shop content (catalog, knowledge base, settings)Until the shop is deleted, then purged right away.
Shoppers’ conversationsAs set by the shop: 30, 90 or 365 days.
Sessions30 days after your last activity, or until you sign out or revoke them.
Email links and team invitationsEmail links: 1 day after they expire or are used. Invitations: 30 days after they expire or are accepted.
Audit log12 months.
Contact form messages and support emailsUp to 2 years after our last exchange.
Invoices and accounting recordsAs long as tax and accounting law requires ([statutory retention period]).
BackupsDeleted data disappears from backups within 30 days.
Abuse-protection counters (hashed IP address)Up to 24 hours.

AI and automated decisions

We use AI to write chat answers for shops and to enrich their product data. We don’t make decisions based solely on automated processing that have legal or similarly significant effects on you (Art. 22 GDPR), and we don’t profile shoppers or merchants for marketing. Automatic security checks, such as limits that briefly block too many sign-in attempts, only protect the service.

Cookies and similar technologies

Our website and dashboard use only cookies that are strictly necessary, plus a language cookie when you choose a language. That’s why we don’t ask for consent and only show a short notice about them. The full list, including what the chat widget stores on shops’ websites, is in our cookie policy.

Security

We protect data with encryption in transit, hashed passwords and API keys, encrypted two-factor secrets, strict separation between shops, rate limiting, abuse protection and least-privilege access for our team. Read more on our security page.

If a personal data breach is likely to put your rights at risk, we inform the competent authority and, where required, you, as the GDPR requires.

Your rights

Under the GDPR you have the right to:

  • access your data and get a copy of it;
  • rectify data that is wrong or incomplete;
  • erase your data;
  • restrict how we process it;
  • data portability: receive your data in a machine-readable format;
  • object at any time, on grounds relating to your situation, to processing based on our legitimate interests;
  • withdraw consent at any time where we rely on consent, without affecting what happened before.

Do it yourself: on the Account page of the dashboard you can correct your profile, download your data as a JSON file and delete your account.

Ask us: write to [email protected]. We answer within one month and may first ask you to confirm your identity. Using your rights is free.

Complain: you can lodge a complaint with a data protection authority, in particular in the EU country where you live or work, or where you think the infringement happened. Our lead authority is [Supervisory authority of the country of our registered office]. We would appreciate the chance to sort things out with you first.

Children

AskMerra is a service for businesses and is not directed at children. Shops must not use the assistant to collect data from children.

Changes to this policy

We update this policy when our processing changes; the date at the top shows the current version. If a change affects you, we tell you by email or in the dashboard before it applies. Questions: [email protected] or the contact form.