Privacy Policy
Last updated: April 19, 2026
1. Introduction
MergeUi ("we", "us", "our") takes your privacy seriously. This Privacy Policy explains what personal data we collect, how and why we use it, with whom we share it, how long we keep it, and the rights you have under the EU General Data Protection Regulation ("GDPR"), the Korean Personal Information Protection Act ("PIPA"), and other applicable privacy laws.
This Policy applies to mergeui.com and all related services (the "Service"). By using the Service, you acknowledge that you have read this Policy. Where required by law, we will also obtain your explicit consent.
2. Data Controller
The data controller responsible for your personal data is:
- Company: [COMPANY_NAME]
- Address: [COMPANY_ADDRESS]
- Privacy contact: privacy@mergeui.com
- General contact: [CONTACT_EMAIL]
3. Personal Data We Collect
| Category | Examples | Source |
|---|---|---|
| Account data | Email address, display name, password hash (if email sign-up), country | You, at sign-up |
| OAuth profile | GitHub or Google user ID, email, display name, profile picture URL | GitHub / Google OAuth |
| Subscription & billing | Plan, subscription status, renewal date, Lemonsqueezy customer ID, invoice history | Lemonsqueezy (we do NOT receive full card numbers) |
| Usage data | Pages visited, features used, download history, template preferences | Your device, our servers |
| Device & log data | IP address, user-agent, browser, OS, approximate location (country/region), timestamps, error logs | Your device, server logs |
| Analytics & cookie data | GA4 client ID, session ID, event data, consent status | Google Analytics 4 (with consent) |
| Marketing data | Newsletter subscription status, email opens/clicks, preferences | Loops (with consent) |
| Support data | Contents of support tickets, feedback submissions | You |
We do not knowingly collect special-category ("sensitive") personal data such as health, religion, or political opinions. Please do not submit such data via support channels.
4. Purposes and Legal Basis
Under GDPR Article 6, we process your personal data on the following legal bases:
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Provide and operate the Service (account creation, authentication, download delivery) | Account, OAuth, usage | Art. 6(1)(b) — Performance of contract |
| Process subscriptions, renewals, and refunds | Billing, subscription | Art. 6(1)(b) — Performance of contract |
| Comply with tax, accounting, and legal obligations | Billing, invoices | Art. 6(1)(c) — Legal obligation |
| Prevent fraud, abuse, and secure the Service | Device, log, usage | Art. 6(1)(f) — Legitimate interest |
| Send transactional emails (receipts, password resets, critical announcements) | Account, billing | Art. 6(1)(b) — Performance of contract |
| Send marketing emails (newsletter, product updates) | Email, preferences | Art. 6(1)(a) — Consent (opt-in) |
| Analytics to improve the Service (GA4 with Consent Mode v2) | Cookie, usage | Art. 6(1)(a) — Consent |
| Respond to support requests and feedback | Support data | Art. 6(1)(b)/(f) — Contract / Legitimate interest |
Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing. See Section 9.
5. Data Retention Periods
| Data category | Retention period | Reason |
|---|---|---|
| Account data | Until account deletion + 30 days (technical backup cycle) | Service provision |
| Subscription & billing records (invoices) | 5 years after last transaction | Korean Commercial Act, tax law |
| Consumer-complaint records | 3 years | Korean e-Commerce Consumer Protection Act |
| Access logs (IP, login) | 3 months | Korean Communications Secrets Protection Act |
| Newsletter subscription | Until unsubscribe | Consent-based |
| Analytics (GA4) | 14 months (default GA4 retention) | Analytics improvement |
| Backups | 30 days rolling | Disaster recovery |
After the retention period expires, we will either permanently delete or irreversibly anonymize the data, except where a longer period is required or permitted by law.
6. Third-Party Service Providers (Data Processors)
We share personal data only with the processors listed below, each under a Data Processing Agreement (DPA) that imposes GDPR-compliant obligations. We do not sell your personal data.
| Provider | Purpose | Data shared | Location |
|---|---|---|---|
| Lemonsqueezy (Merchant of Record) | Payment processing, subscription management, tax & invoicing | Email, name, billing address, card data (collected directly by Lemonsqueezy) | USA |
| Supabase | Database & authentication hosting | Account, subscription, usage data | Region to be confirmed at provisioning (EU or US) |
| Loops | Transactional and marketing email delivery | Email, name, preferences, event data | USA |
| Google Analytics 4 | Aggregated usage analytics (with consent) | Pseudonymous client ID, page views, events, anonymized IP | Global (Google) |
| GitHub / Google | OAuth authentication | OAuth profile fields listed in Section 3 | USA |
| Hosting / CDN (TBD) | Static site and asset delivery | IP address, user-agent, request metadata | Global |
We may also disclose data when required by law, court order, or government request, or to protect the rights, property, or safety of MergeUi, our users, or others.
7. International Data Transfers
Because we operate a global service and several of our processors are located outside Korea and the EEA (primarily in the United States), your personal data may be transferred to and processed in jurisdictions whose data-protection laws may differ from those of your country.
For transfers from the EEA/UK, we rely on:
- the European Commission's Standard Contractual Clauses (SCCs) as updated in 2021;
- the EU–US Data Privacy Framework (DPF), where the recipient is certified; and
- supplementary safeguards such as encryption in transit and at rest.
For transfers from Korea to overseas processors, we obtain the consents required under PIPA Articles 28-8 and 28-9 and disclose the items, country, and duration of transfer in this Policy.
9. Your Rights under GDPR
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights:
- Right of access (Art. 15) — obtain a copy of the personal data we hold about you.
- Right to rectification (Art. 16) — correct inaccurate or incomplete data.
- Right to erasure / "right to be forgotten" (Art. 17) — request deletion of your data, subject to legal retention obligations.
- Right to restriction of processing (Art. 18) — limit how we use your data.
- Right to data portability (Art. 20) — receive your data in a structured, machine-readable format (JSON/CSV) and transmit it to another controller.
- Right to object (Art. 21) — object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent (Art. 7(3)) — withdraw consent for any consent-based processing at any time.
- Right not to be subject to automated decision-making (Art. 22) — we do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
- Right to lodge a complaint — you may lodge a complaint with your local data-protection supervisory authority. A list of EU authorities is available at edpb.europa.eu.
To exercise any right, email privacy@mergeui.com. We will respond within 30 days (extendable by a further 60 days for complex requests, with prior notice). We may need to verify your identity before fulfilling a request.
10. Your Rights under Korean PIPA
If you are located in the Republic of Korea, you (or your legal representative) have the right to:
- access your personal data (Art. 35);
- request correction or deletion (Art. 36);
- request suspension of processing (Art. 37);
- withdraw consent at any time for consent-based processing.
To exercise these rights, contact privacy@mergeui.com. You may also file a complaint with the Personal Information Protection Commission (PIPC, www.pipc.go.kr, tel. 1833-6972) or the Korea Internet & Security Agency (KISA, privacy.kisa.or.kr, tel. 118).
11. Security Measures
We implement reasonable technical and organizational measures designed to protect your personal data, including:
- TLS 1.2+ encryption for all data in transit;
- encryption at rest for managed database storage (Supabase);
- password hashing with modern algorithms (bcrypt/argon2) — plaintext passwords are never stored;
- principle of least privilege for production access, with logging of administrative actions;
- regular dependency updates and security reviews;
- access tokens scoped per session with short expiry and rotation;
- Data Processing Agreements (DPAs) with all sub-processors.
Despite these measures, no method of transmission or storage is 100% secure. In the event of a personal data breach, we will notify affected users and regulators where required by law (GDPR: within 72 hours; PIPA: as prescribed).
12. Children's Privacy
The Service is not directed to children under the age of 16 (or the age of digital consent in your jurisdiction, if higher). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact privacy@mergeui.com and we will delete the data promptly.
13. Privacy Contact and Representative
- Privacy inquiries: privacy@mergeui.com
- Data Protection Officer: To be appointed. Contact the privacy email above for DPO correspondence.
- EU Representative (Art. 27 GDPR): [EU_REPRESENTATIVE_TBD] — to be appointed if required by the scope of processing.
- UK Representative: [UK_REPRESENTATIVE_TBD] — to be appointed if required.
- Korean Chief Privacy Officer (CPO): [CPO_NAME_TBD], privacy@mergeui.com
14. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or business operations. We will post the updated version with a new "Last updated" date. For material changes, we will provide advance notice by email or a prominent in-product notice at least 30 days before the changes take effect.