Privacy Policy

Transparent data practices and enterprise-grade security for the merchants of the Merch Factory ecosystem.
Last Updated: 13th March 2026
1. Introduction

Merch Factory (“we,” “us,” or “our”) is committed to protecting the privacy of our merchants and their end customers. This Privacy Policy explains our data collection, storage, use, and sharing practices across our website (merchfactory.in), dashboard, and fulfillment services.

2. Information We Collect

We collect information that you provide to us directly and information that is automatically generated during your use of the Services.

a) Account and Profile Information

Name, email address, and phone number collected during sign-up via Firebase Authentication.

b) Brand and Business Information

Brand name, logos, GSTIN, and business address. We also collect bank account or UPI details to facilitate COD payouts and remittances.

c) Customer and Order Information

To fulfill your orders, we collect end-customer details including names, shipping addresses, and phone numbers. This data is used solely for fulfillment and tracking purposes.

d) Payment Information

Payment transactions are processed through specialized, PCI-compliant third-party providers (e.g., Razorpay, PhonePe). We do not store your credit card or sensitive financial credentials on our servers.

e) Design and Content

Image files, designs, and metadata you upload for printing. These are stored securely to allow repeat orders and modifications.

f) Device and Usage Data

IP addresses, browser type, operating system, and usage patterns collected via essential cookies and analytics tools to improve platform performance.

3. How We Use Your Information

We use the collected data for the following essential business purposes:

  • Fulfillment: Sending order data to courier partners for delivery.

  • Payouts: Processing COD remittances to your registered bank/UPI account.

  • Notifications: Sending order status updates via SMS, WhatsApp, or email.

  • Support: Resolving technical queries and logistics escalations.

  • Compliance: Fulfilling tax, legal, and regulatory obligations (e.g., GST reporting).

4. Third-Party Integrations

When you connect your external store (e.g., Shopify, Wix, WooCommerce) to Merch Factory, we access only the data necessary to automate the fulfillment process (customer address, product variant, and order ID). We do not access your store's customer marketing lists or unrelated financial data.

Shopify

Wix

WooCommerce

5. Third-Party Service Providers

We share minimum necessary data with specialized partners to maintain our operations:

  • Cloud Infrastructure: Google Cloud (Firebase) for hosting and database management.

  • Payment Gateways: Razorpay and PhonePe for secure transactions.

  • Logistics Partners: Shiprocket, Bluedart, Delhivery, and others for physical delivery.

  • Hosting: Vercel and Google Cloud for application delivery.

6. Cookies and Tracking

We use “cookies” to maintain your login session and enhance your experience.

  • Essential Cookies: Required for dashboard security and authentication.

  • Analytical Cookies: Helping us understand feature usage through tools like Google Analytics.

7. Data Sharing and Disclosure

We do not sell your personal data to third-party marketing companies. Data is only disclosed:

  • When required by law or legal process.

  • In the event of a merger, acquisition, or sale of assets.

  • To prevent fraud or protect the safety of our users.

8. Data Retention

We retain data as follows:

  • Account Data: Retained for the duration of your active account status.

  • Order History: Stored per Indian tax and financial auditing requirements (typically 7 years).

  • Payment Records: Transaction IDs are retained for history; full financial details stay with the payment gateway.

  • Designs: Stored to enable quick re-orders unless you choose to delete them.

9. Data Security
Enterprise Security Standards

All data transmissions are encrypted via HTTPS/TLS. We utilize robust Firewall rules and secure database architectures provided by Google Cloud (Firebase). Access to sensitive merchant data is strictly restricted to authorized personnel for support purposes only.

10. Your Rights

You have the following rights regarding your data:

  • Access & Portability: You can download your order history from the dashboard.

  • Correction: Brand and account details can be updated via “Settings.”

  • Deletion: You can request account termination. Note that some data (e.g., invoices) must be retained for legal compliance.

11. Children's Privacy

Our Services are not designed for or marketed to individuals under the age of 18. We do not knowingly collect information from minors.

12. Changes to This Policy

We may update this Privacy Policy to reflect changes in our technology or legal requirements. Updates become effective immediately upon posting. We encourage you to review this page periodically.

13. Contact Us

For any questions regarding your data privacy or protection, please reach out:

Data Protection Desk

contact@merchfactory.in

Attn: Privacy Compliance Team