Updated October 6, 2026 · Merchavelo is a brand of Zentara LLC.
Application and roles
These terms form part of an agreed Merchavelo Inventory service agreement where Zentara LLC processes personal data for a merchant. The merchant is controller and we are processor for store workflow data. A custom project must specify its own processing scope in writing. Our independent support and business-administration processing is described in the relevant privacy notice.
Subject, duration and instructions
The processing supplies authenticated inventory and purchasing workflows, permissions, synchronization, reports and support during the service and agreed export or deletion period. It includes storing, retrieving, organizing, calculating, transmitting authorized Shopify operations and deleting records. We process only documented merchant instructions, including these terms and authorized app commands, unless law requires otherwise. We will inform the merchant of such a requirement where permitted, and flag an instruction we believe infringes applicable data-protection law.
Data and people concerned
Data can include staff identifiers and contact details, supplier contact details, shop and product information, operational documents and imported records. People concerned include merchant staff, supplier contacts and anyone whose information the merchant includes in imported files or notes. Forecasting requests sales identifiers and quantities rather than customer contact information. The merchant should not submit special-category data or unnecessary customer information.
Confidentiality and security
People authorized to process the data must be bound by confidentiality. We implement measures appropriate to the risks, including authenticated access, shop isolation, role and location checks, encrypted transport, controlled credentials and recovery records. We review security measures as the service changes. The merchant remains responsible for authorized staff access and the lawfulness of its instructions.
Subprocessors and transfers
The merchant authorizes Shopify for store APIs and billing and Cloudflare for application hosting, storage and background processing to the extent each acts as a processor in the service. Provider role and terms can differ for their own activities. We require applicable data-protection obligations for subprocessors and remain responsible for our processor obligations. We will inform affected merchants of a proposed additional or replacement subprocessor and allow a reasonable objection period before use. If a justified objection cannot be resolved, the affected service can be terminated under the service agreement.
Transfers outside the EEA must have a lawful basis and appropriate safeguards where required. These terms do not claim that a particular transfer agreement has been signed merely because it is mentioned here. European database and bucket storage does not restrict all Worker or Queue processing to Europe.
Assistance and incidents
Taking account of the processing and information available, we assist with applicable data-subject requests, security obligations, breach assessment, impact assessments and authority consultations. We notify the merchant without undue delay after becoming aware of a personal-data breach affecting its processed data, provide available details and cooperate with reasonable mitigation. The merchant makes its own required notifications as controller.
Return, deletion and evidence
At the end of the service, we return or delete personal data according to the merchant's instruction, including copies, unless applicable law requires retention. Provider failures must be reconciled rather than treated as successful deletion. We make information reasonably needed to demonstrate these obligations available and support proportionate audits, with confidentiality and safeguards for other merchants' information. An export or request can be raised at support@merchavelo.com.