Updated October 6, 2026 · Merchavelo is a brand of Zentara LLC.
Scope and responsibilities
This notice describes Merchavelo Inventory, currently preparing for release. Zentara LLC provides the app. The merchant generally determines the purpose of store information and is its controller; we process workflow information on the merchant's instructions. We are responsible for our own support, account and service-administration records. Contact support@merchavelo.com. Our data processing terms set out the processor relationship.
Information used by the app
- Shop identity, domain, currency, installation and synchronization state.
- Shopify authentication sessions and access tokens, used for authorized store API calls.
- Staff identifiers, names and email addresses supplied for authentication, roles, permitted locations and audit events.
- Product and variant identifiers, titles, SKUs, barcodes, prices, costs, inventory identifiers, locations and stock quantities.
- Supplier contact details, terms, lead times, currencies, supplier SKUs and purchasing prices.
- Purchase orders, receipts, invoice references, charges, exchange-rate records, approvals, revisions, transfers, stocktakes and operational history.
- Sales identifiers, product and location identifiers, dates and quantities used for demand suggestions. The forecasting workflow does not request customer names, customer email addresses or delivery addresses.
- Imported CSV files, raw rows and field mapping. Files can include personal information if a merchant includes it; avoid uploading columns the workflow does not need.
- Support correspondence, subscription state and technical error records needed to operate and troubleshoot the service.
How we use and share it
We use this information to synchronize catalog and stock, enforce staff permissions, maintain purchasing documents, process approved stock operations, calculate receipt costs, produce reports and help the merchant recover failed operations. It is not sold or used to advertise to the merchant's customers. Authorized stock and cost operations are sent to Shopify. App access depends on the permissions granted at installation and later scope changes.
Providers and processing locations
Shopify supplies store APIs, authentication and app billing where configured. Cloudflare hosts the application and provides database, object storage and background processing. The app's database and document buckets are configured for European storage. Cloudflare Workers and Queues use global infrastructure; European storage does not establish that every processing step stays in Europe. Provider transfers must use applicable legal safeguards where required. Access to support information is limited to the people who need it for the service.
Security and retention
Controls include authenticated requests, shop isolation, server-side role and location checks, encrypted transport, restricted credentials and audit records. No service can promise perfect security. Operational records are retained to supply the service and its recovery and history functions, subject to merchant instructions and applicable obligations. We do not promise an accounting retention period on the merchant's behalf.
Uninstallation stops authorized app access and pending work; it is not a claim that every historical record disappears at that instant. Shopify privacy and shop-redaction requests are processed through the app's privacy workflow. Deletion may require retrying provider operations and observing legal retention requirements. Ask us for an export or deletion request before terminating access if you need a particular handover.
Requests and rights
A customer or staff member should normally contact the merchant responsible for their store information. We assist the merchant with applicable requests. For information we control, contact support@merchavelo.com; access, correction, deletion, restriction, objection and portability are available where the applicable law provides them. You may complain to the relevant privacy authority.
Changes
Material processing changes will be reflected here. A website description is not a grant of permission: store access comes from Shopify authentication and merchant authorization.