This Privacy Policy explains how Merquly (“Merquly,” “we,” “us,” or “our”) collects, uses, discloses, and protects information when you visit merquly.com, create a Merquly account, purchase or use a subscription, install or connect the Merquly AI Search for WooCommerce plugin, use our support tools, or otherwise use our hosted search and AI services (collectively, the “Services”).
Merquly operates from Israel. If you have questions or want to exercise a privacy right, contact us at support@merquly.com.
1. Our roles
For account, billing, licensing, website, and direct support information, Merquly generally acts as the controller or business responsible for deciding why and how that information is processed.
When a WooCommerce merchant connects the plugin and sends product data, selected store content, or shopper search requests to Merquly, the merchant generally determines the purpose of that processing. For that information, Merquly generally acts as the merchant’s processor or service provider. The merchant remains responsible for its own privacy notice, lawful instructions, and any consent required from its shoppers.
2. Information we collect
Account and transaction information
When you register or purchase a plan or search add-on, we may collect your name, email address, account credentials, billing address, company details, tax information, order and subscription history, plan, renewal dates, payment status, and communications with us. Payment-card and similar financial credentials are processed by the payment provider shown at checkout. We ordinarily receive transaction identifiers, payment status, card type or limited card details, and other records needed to manage the purchase, but not the full payment credential.
License and connected-store information
When you connect a store, we process the license key or its cryptographic representation, an installation credential, WordPress and plugin versions, the store domain, site identifier, subscription status, plan limits, synchronization status, indexed item counts, usage totals, and technical diagnostics needed to authenticate and operate the installation.
Product and store content
At the store administrator’s direction, the plugin may send public WooCommerce product information such as product identifiers, names, descriptions, SKUs, prices, availability, categories, tags, attributes, public taxonomies, URLs, and image URLs. It may also send rendered text and source metadata from pages, posts, or supported custom post types that the administrator explicitly selects.
The plugin may synchronize enabled shipping zones and methods, geographic rules, public prices and conditions, currency information, and enabled payment-method names, descriptions, instructions, and supported features. Credential-like settings, passwords, private keys, API keys, and tokens are not intended to be included. The current plugin does not index WooCommerce orders or shopper payment data.
Search, chat, and feedback information
When a shopper uses an enabled Merquly search or chat feature on a connected store, we process the question or search phrase, recent conversation context, language and search preferences, returned product or content references, result-quality signals, and optional helpful or not-helpful feedback.
The plugin creates a random pseudonymous browser identifier in local storage. Merquly uses a daily cryptographic transformation of that identifier to estimate unique use and protect the Service from abuse. The raw browser identifier is not stored in our PostgreSQL analytics tables. Search text is automatically checked for common email addresses, URLs, and phone-number patterns before it is stored in short-term quality analytics, but users should not submit personal, confidential, or sensitive information in search or chat fields.
Website, device, and log information
Like most online services, our servers and service providers may process IP address, browser and device type, operating system, referring pages, timestamps, requested URLs, diagnostic events, security events, and cookie or local-storage identifiers. We use this information to deliver and secure the Services, troubleshoot failures, prevent fraud and abuse, and understand service performance.
Support information
We process information you provide through email, the Help Center, support chat, or other communications. Our public AI support assistant is limited to general product documentation and is not designed to access customer accounts, catalogs, license keys, or private store data. Do not include passwords, access tokens, customer data, or other secrets in support messages.
3. How we use information
We use information to:
- create and maintain accounts, orders, subscriptions, and licenses;
- index authorized product and store information and provide search, chat, and answer generation;
- generate vector representations and structured product analysis used to improve relevance;
- measure plan usage, enforce product, content, and search limits, and apply purchased add-ons;
- send transactional, service, security, renewal, and usage-limit communications;
- provide support, diagnose errors, maintain availability, and improve search quality;
- prevent fraud, abuse, unauthorized access, and violations of our Terms;
- comply with legal, tax, accounting, and regulatory obligations; and
- establish, exercise, or defend legal claims.
Where applicable, our legal bases include performance of a contract, legitimate interests in operating and securing the Services, compliance with law, and consent where consent is required. A connected merchant is responsible for identifying the legal basis that applies to its shoppers’ data.
4. AI processing
Merquly uses third-party AI infrastructure, including the OpenAI API, to create embeddings, analyze product information, interpret searches, and generate answers. Relevant product text, selected store content, search questions, and limited conversation context may be sent to an AI provider for those purposes.
OpenAI states that data submitted through its API is not used to train its models by default unless the API customer affirmatively opts in. Depending on the applicable OpenAI account configuration and endpoint, abuse-monitoring logs may be retained by OpenAI for up to 30 days, unless a longer period is required by law or needed to address misuse. Merquly does not use shopper queries or merchant content to train a general-purpose AI model.
5. Cookies and local storage
Our website may use cookies required for WordPress, WooCommerce, account sign-in, shopping-cart and checkout functionality, security, and user preferences. On connected merchant sites, the Merquly plugin may use local storage for a random anonymous visitor identifier and short-lived chat history. The current chat history is stored in the shopper’s browser for up to 24 hours unless it is cleared sooner. A visitor can clear browser storage through browser settings, although doing so may reset chat history and anonymous usage counting.
6. How we disclose information
We may disclose information only as reasonably necessary to:
- hosting, database, infrastructure, security, monitoring, email, and customer-support providers;
- AI and machine-learning service providers that process requests for the Services;
- payment processors, tax services, and commerce providers used for purchases and renewals;
- professional advisers, auditors, insurers, and authorities where required or permitted by law;
- a buyer, investor, successor, or adviser in connection with a merger, financing, reorganization, or sale of all or part of the business, subject to appropriate protections; and
- other parties when you direct us or provide valid consent.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising, and we do not use merchant product data or shopper queries to target advertising.
7. International transfers
Merquly and its service providers may process information in Israel, the United States, the European Economic Area, or other countries where they operate. Those countries may have different data-protection laws. Where required, we use contractual safeguards or another legally recognized transfer mechanism.
8. Retention
We retain information only for as long as reasonably necessary for the purposes described above:
- query-level search analytics and search-quality records are retained for no more than 7 days under the current service configuration;
- pseudonymous daily unique-user data in the rate-limiting and counting system expires after approximately 8 days;
- individual request identifiers used to prevent duplicate search charges are normally removed after 3 days;
- billing-period usage summaries may be retained for up to approximately 370 days after a period ends;
- indexed product data, selected store content, store configuration, and generated vectors are retained while needed to provide the connected service, until removed through synchronization, account deletion, or a valid deletion request, subject to backups and legal obligations;
- account, order, subscription, payment-status, tax, and licensing records are retained while the account is active and afterward as required for accounting, fraud prevention, dispute resolution, and applicable law; and
- security and infrastructure logs are retained for a limited period appropriate to their purpose.
Backup copies may remain for a limited additional period and are isolated from ordinary use until overwritten.
9. Your choices and rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, or objection; withdraw consent; and complain to a data-protection authority. You may also have the right to know the categories and specific pieces of personal information collected, request deletion or correction, and receive equal service when exercising a privacy right.
Merchants can deselect content sources, exclude products, deactivate a connected installation, and manage subscriptions through their WordPress and Merquly accounts. Shoppers seeking to exercise rights concerning a merchant’s use of Merquly should ordinarily contact that merchant first. We will assist connected merchants with valid requests as required by law.
Submit requests to support@merquly.com. We may need to verify your identity and authority before completing a request. We will not discriminate against you for exercising an applicable privacy right.
10. Security
We use administrative, technical, and organizational safeguards designed to protect information, including authenticated installation credentials, credential hashing, encrypted network transport where supported, access controls, separation of customer indexes, bounded retention, and security monitoring. No online service is completely secure, and we cannot guarantee absolute security.
11. Children
The Services are intended for businesses and adults and are not directed to children under 16. We do not knowingly collect personal information directly from children. Contact us if you believe a child has provided personal information to Merquly.
12. Changes to this policy
We may update this Privacy Policy as the Services, providers, or legal requirements change. We will post the revised version at this URL and update the date above. If a change materially affects how we use personal information, we will provide additional notice where required.
13. Contact
Privacy questions and requests: support@merquly.com
General support: support@merquly.com or the Merquly Help Center.
Related terms: Terms of Service.