MerchLab Privacy Policy
Last updated: 22 October 2025
Thank you for being part of the MerchLab community. We are committed to protecting your privacy and ensuring your personal information is handled properly, lawfully, and transparently. This notice explains how MerchLab obtains, uses, and discloses your personal information, in accordance with the Protection of Personal Information Act ("POPIA") and GDPR.
What Information We Collect
We collect personal information directly from you when you register through our online portal, place orders, or interact with our services. We'll let you know what information is required and what is optional.
We may also collect website usage information using cookies.
This information may include:
Publicly Available Personal Information:
First name, last name, nickname, phone numbers, business email, current and former addresses, and similar data.
Personal Information Provided by You:
Purchase history and similar data.
Credentials:
Passwords and similar security information for account access.
Payment Data:
Data necessary to process payments, such as your payment instrument number and security code. All payment data is stored by AddPay, and you can find their privacy policy here: https://southafrica.payu.com/
Information Automatically Collected:
IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, and other technical information.
Online Identifiers:
IP addresses, cookie identifiers, device's geolocation, and other similar data used for analytics and marketing.
All personal information you provide must be true, complete, and accurate. Please notify us of any changes.
How We Use Your Information
We will use your personal information only for the purposes for which it was collected and agreed with you, including:
- To facilitate account creation and login.
- To send you marketing and promotional communications (you can opt-out at any time).
- To send you administrative information about our services and policies.
- To fulfil and manage your orders, payments, returns, and exchanges.
- To request feedback and contact you about your use of our services.
- To protect our services and prevent fraud.
- To enforce our terms, conditions, and policies.
- To respond to legal requests and prevent harm.
- To manage user accounts.
- To deliver services to you and respond to your inquiries.
- For other business purposes such as data analysis, identifying usage trends, and improving our services.
Disclosure of Information
We may disclose your personal information to our service providers who help us deliver products or services to you. We have agreements in place to ensure they comply with POPIA and GDPR requirements.
We may process your data based on:
- Consent: Where you have given us specific consent.
- Legitimate Interests: Where it is reasonably necessary for our legitimate business interests.
- Performance of a Contract: Where we have a contract with you.
- Legal Obligations: Where we are legally required to comply with applicable law.
- Vital Interests: Where we believe it is necessary to protect the safety of any person or prevent illegal activities.
More specifically, we may share your data in the following situations:
- With vendors, consultants, and other third-party service providers.
- In connection with a business transfer (merger, sale of assets, financing, etc.).
- With third-party advertising companies (subject to your consent where required).
- When legally required to comply with applicable law or legal process.
Information Security
We are legally obliged to provide adequate protection for the personal information we hold and to prevent unauthorized access and use. We continuously review our security controls and related processes to ensure your personal information remains secure.
Retention of Information
We will only keep your personal information for as long as necessary for the purposes set out in this policy, unless a longer retention period is required or permitted by law.
Data Security
We have implemented technical and organizational security measures to protect your personal information. However, we cannot guarantee that the internet is 100% secure.
Information Related to Minors
Our services are not intended for minors. We do not knowingly collect personal information from children.
Your Rights: Access to Information
You have the right to request a copy of the personal information we hold about you. Contact us using the details provided on our website and specify what information you require.
You also have the right to:
- Correct your information.
- Opt-out of email marketing.
- Complain to your local data protection supervisory authority (if you are in the European Economic Area).
How to Contact Us
If you have any questions about this policy or our privacy practices, please contact us at the numbers/addresses listed on our website.
This information is provided for general compliance purposes only and does not constitute legal advice.
