1. Who is responsible
MerchantProof is operated by Yared Mekonnen, who is the data controller for the purposes described in this notice.
Capital Office124 City RoadLondonEC1V 2NXUnited Kingdom2. Information we collect
We collect the information you provide during the scope check and paid intake, including your business and contact details, website address, issue description, product information, uploaded screenshots, feeds and documents, and support messages.
We also collect relevant information from the public pages of your store, together with scan results, reviewer decisions, reports, payment and refund references, delivery records, and limited security and audit information needed to operate the service safely. We do not store card details and never ask for your Google login or password. Please remove unrelated personal or sensitive information before uploading evidence.
You are not legally required to provide this information. However, MerchantProof cannot assess or deliver the diagnostic without the required store, issue and evidence information. Evidence marked optional may be omitted.
3. How we use it
We use information to:
- check whether a case is within scope and provide the service you purchase;
- examine permitted evidence, prepare findings and deliver your action plan;
- provide the included clarification and limited rescan;
- process payments and refunds and keep required accounting and tax records;
- protect the service against malware, fraud, misuse and security threats; and
- answer support, privacy, complaint and dispute correspondence.
We rely on the business contract where processing is needed to provide MerchantProof, legal obligations for required records, and legitimate interests for proportionate security, service integrity, support and dispute handling.
4. Automated tools and human review
Automated tools may help organise and analyse the evidence supplied for a diagnostic. A human reviewer controls the findings and action plan delivered to the customer. Automated analysis does not independently decide whether your store will be accepted or approved by Google.
5. Who we share information with
We use carefully selected service providers to operate MerchantProof. They help us host the service, store case information and uploaded evidence, process payments, scan files for security threats, support diagnostic analysis and deliver transactional emails.
Each provider receives only the information reasonably required to perform its role. Providers acting on our behalf must protect the information and use it only for the agreed service. Recipient categories include secure hosting and storage providers, payment-processing providers, file-security providers, diagnostic-analysis support providers, transactional-email and communication providers, and professional advisers, regulators or authorities where legally required.
Payment details are entered with the payment processor; MerchantProof receives payment status and references rather than card details. We do not send customer reports or evidence to Google.
6. International processing
Some service providers or their subprocessors may process information outside the United Kingdom. Where this happens, we use the safeguard that applies to the destination and service, such as UK adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to approved EU standard contractual clauses. To ask for more information about the safeguards used for your information, email support@merchantproof.co.uk.
7. How long we keep information
We keep information only for as long as it is needed for the service, required records, security or dispute handling.
| Information | Usual retention period |
|---|---|
| Free scope-check data | Normally deleted after 7 days. |
| Uploaded evidence | Deleted 30 days after the initial report is delivered, or 7 days after the case is closed or refunded if that is sooner. |
| Public-page scan data | Deleted 14 days after collection. |
| Completed reports | Available for 90 days from each report’s delivery date, then the report content is deleted. |
| Support correspondence | Deleted 12 months after the case closes. |
| Essential contract and financial records | A minimal record is kept for 7 years for accounting, tax, payment, refund and dispute purposes. It does not include uploaded evidence or full report content. |
| Backups | Encrypted backup copies expire within 35 days and are not used for ordinary service activity. |
If an intake is inactive for 30 days, we send a notice and allow time to resume before closing the case and considering any refund due. We may keep information longer where required by law, to resolve a dispute or to protect legal rights.
9. Your rights
Depending on the circumstances, you may ask for access to your personal information, correction, deletion, restriction or portability, or object to relevant processing. Some rights are subject to legal limits and the lawful basis for processing.
10. Contact and complaints
For privacy questions or to exercise a right, email support@merchantproof.co.uk. You may also complain to the Information Commissioner’s Office at ico.org.uk.