Draft placeholder — not yet operative
This document requires owner approval and appropriate UK legal review before public payments are accepted.
Who is responsible
MerchantProof is a trading name of Yared Mekonnen. The data controller is Yared Mekonnen, trading as MerchantProof. The planned privacy contact is privacy@merchantproof.co.uk and will be made operational before public trading. An owner-approved geographic business correspondence address suitable for legal service will also be published before public trading.
Information and sources
MerchantProof processes contact and trading details, the public store URL and relevant public website content, Merchant Center issue evidence, optional product feeds, customer uploads, scan results, reviewer actions, reports, communications, payment references, delivery events, and proportionate security and audit metadata. MerchantProof does not store card details or ask for Google passwords, OAuth access or private Google-account access. Customers should redact unrelated personal or sensitive information before submitting evidence.
Why information is used
- requested qualification and delivery of the purchased diagnostic, under contractual necessity;
- applicable accounting, tax and regulatory records, under legal obligation; and
- proportionate security, abuse prevention, auditability, dispute handling and privacy-safe service analytics, under documented legitimate interests.
Consent will be used only for genuinely optional processing. Optional marketing and non-essential cookies are disabled for the initial pilot.
Providers, security and international transfers
MerchantProof uses controlled service providers for hosting and database storage, Stripe for hosted payment, transactional email, malware scanning and bounded AI-assisted analysis. Sentry is prepared for strictly server-side operational error monitoring in its European Union data region. MerchantProof permits only scrubbed internal error codes, application frames and bounded operational metadata to reach Sentry; customer identity, evidence, reports, payment payloads, access tokens, URLs, prompts and model output are prohibited. Sentry's DPA and transfer safeguards apply, and EU data storage does not mean every support or processing activity occurs exclusively in the EU. OpenAI is prepared for bounded structured diagnostic analysis using only the minimum approved evidence. Requests use no tools or browsing and are not stored as Responses application state, but OpenAI's default abuse-monitoring logs may retain submitted content for up to 30 days. MerchantProof has not been approved for Zero Data Retention or regional processing and does not claim either control. OpenAI's DPA, UK transfer safeguards and current subprocessor list apply. Ionx Solutions' Verisys Antivirus API is the intended malware-scanning provider. If activated after its contract and privacy gate, MerchantProof will send only file bytes with a neutral filename to the UK endpoint for synchronous scanning; no customer identity, Storage URL or callback is sent. Ionx's public documentation states that submitted files are deleted after scanning, but its DPA, subprocessors, transfer position and assistance terms must be verified before activation. The final notice will identify every actually deployed provider, processing location and applicable UK transfer safeguard before public trading. Uploads and reports remain in private storage with controlled access. MerchantProof does not send customer reports or evidence to Google.
Human review and automated analysis
Automated scanning and bounded AI analysis assist the diagnostic. A human reviewer controls the findings and report released to the customer. MerchantProof does not use solely automated processing to make decisions producing legal or similarly significant effects about individuals.
Retention and your rights
Preview scan data is normally deleted after 7 days. Paid uploads are deleted 30 days after initial report delivery or 7 days after a case is closed or refunded, whichever is earlier. Raw crawl and extracted evidence are deleted after 14 days. Each initial or supplementary report remains available for 90 days from its own delivery date; customers are warned to download a copy before it expires. Routine customer-service correspondence is deleted 12 months after case closure. Incomplete intake receives an inactivity notice after 30 days and a bounded opportunity to resume before administrative closure and any required refund review.
After working content is deleted, a minimal contract, payment, refund, tax and delivery record is kept for 7 years. It excludes uploads, feeds, crawl content, findings, report content, private review material, access tokens, signed links and card data. Backups roll off within 35 days and are unavailable for ordinary use. Active legal holds are narrow, owner-approved and reviewed every 30 days. Irreversibly anonymised aggregate statistics may be retained; pseudonymised identifiers remain subject to deletion schedules.
Subject to the applicable lawful basis and legal limits, individuals may request access, correction, erasure, restriction or portability, and may object to relevant processing. The operational privacy contact will receive those requests. Individuals may also complain to the Information Commissioner’s Office.