Legal
Privacy Policy
What we collect, why, and exactly who processes it.
Last updated 2026
Draft template, not legal advice. This policy is written to be accurate about how MerchLab actually works today; have a lawyer review and localize it before relying on it in a regulated market.
1. Who we are
MerchLab is a software tool that generates print-on-demand merch designs and publishes them to your own connected Printify store. This policy explains what data MerchLab collects when you use it, why, and who processes it on our behalf. Questions or requests: support@merchlab.app.
2. What we collect
We collect only what the product needs to work:
- Account data, your email address and name, handled by our authentication provider (Clerk). We never see or store your password.
- Workspace content, the prompts you write, the designs you generate, scores, review decisions, schedules, and listing metadata. This is the product; it lives in our database so your workspace survives restarts and new devices.
- Store connection, the Printify Personal Access Token you paste when connecting your store. It is encrypted at rest (AES-256-GCM) and only decrypted server-side to act on your store at your direction. It is never shown back to you or anyone else.
- Billing data, your subscription plan, credit balance, and payment status. Card numbers are handled entirely by Stripe; they never touch MerchLab's servers.
- Usage + diagnostics, funnel events (e.g. "job created", "invoice paid") and error reports so we can fix what breaks. These carry your workspace id, not your designs or prompts.
3. How we use it
To run the service: generate designs from your prompts, publish to your connected store, meter credits, bill your subscription, send transactional email (receipts, failure notices), and debug errors. We do not sell your data, do not use your prompts or designs to train models, and do not send marketing email without your consent.
4. Subprocessors
MerchLab runs on a small set of infrastructure providers. Each receives only the data needed for its role:
- Vercel, application hosting; processes all request traffic.
- Neon, Postgres database; stores your workspace, designs, credits, and encrypted store tokens.
- Clerk, authentication; stores your email, name, and login credentials.
- Stripe, payments; stores your card and billing details, issues receipts.
- fal.ai, AI image generation; receives design prompts (never your identity).
- OpenAI, AI image generation (alternative models); receives design prompts.
- Anthropic, trend research and design quality scoring; receives prompts and generated images.
- Printify, product creation and publishing, via your own connected Printify account.
- Resend, transactional email delivery; receives your email address and message content.
- PostHog, product analytics; receives usage events keyed to your workspace id.
- Sentry, error monitoring; receives error messages and technical context when something breaks.
- Cloudflare R2, object storage; stores generated design image files.
If we add or replace a subprocessor that handles personal data, we will update this page.
5. Retention and deletion
Your workspace data is kept while your account is active. When you delete your account (or ask us to), we delete your workspace content, disconnect and delete your encrypted store token, and instruct subprocessors to do the same, except where the law requires retention (e.g. Stripe keeps invoice records for tax purposes). Backups age out on a rolling schedule.
6. Cookies
MerchLab uses cookies only to keep you signed in (authentication session cookies set by Clerk). There are no advertising cookies and no cross-site trackers.
7. Your rights
You can ask us to access, export, correct, or delete your personal data at any time by emailing support@merchlab.app from your account email. If you are in the EU/UK, you additionally have the rights granted by the GDPR/UK GDPR, including the right to lodge a complaint with your supervisory authority.
8. Security
All traffic is encrypted in transit (TLS). Store tokens are encrypted at rest. Access to production data is limited to the operator. No system is perfectly secure, if we become aware of a breach affecting your personal data, we will notify you without undue delay.
9. Changes and contact
If this policy changes materially, we will note it here and, for significant changes, email you. Contact: support@merchlab.app.