Last Updated: October 28, 2025
Mercana Corporation ("Mercana," "we," "us," or "our") is committed to protecting your privacy and ensuring transparency in how we collect, use, and share personal information. This Privacy Policy describes our practices regarding personal data we collect through our customer data enrichment platform and related services (the "Services").
This policy applies to customers of our business clients (DTC brands and e-commerce companies) whose personal information is processed through our Services. If you are a direct user of our platform (e.g., an employee of a client organization), additional terms may apply.
When processing customer data on behalf of our business clients, Mercana acts as a data processor. Our clients (DTC brands) are the data controllers who determine what data is collected and how it is used. We process customer data solely according to our clients' instructions and our Data Processing Addendum (DPA). We never use customer data for our own marketing purposes or share it with third parties except as necessary to provide the Services.
Our business clients (e.g., e-commerce brands) provide us with customer information obtained through purchases and interactions on their platforms, including:
To enhance customer profiles and provide better insights to our clients, we augment the information provided by our clients with publicly available data, including:
We do not collect or enrich profiles with sensitive personal data such as race, ethnicity, religious beliefs, health information, political affiliations, or sexual orientation.
We use the personal information we collect and enrich for the following purposes:
We share enriched customer profiles with the business clients who originally provided us with your information. Our clients are the data controllers and are responsible for their own use of this information in accordance with their privacy policies.
We share personal information with third-party service providers who perform services on our behalf, including:
These service providers are contractually obligated to use personal information only to provide services to us and not for their own purposes.
We may disclose personal information if required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency), or to protect our rights, property, or safety.
When personal information is no longer needed, we securely delete or anonymize it in accordance with our data retention policies and applicable laws.
Automatic Blocking: We do not enrich personal data for residents of the European Economic Area (EEA) or United Kingdom without a valid legal basis under the General Data Protection Regulation (GDPR). If you are an EU/UK resident and believe your data was processed in error, please contact us immediately at privacy@mercana.so.
Legal Basis: Where we do process EU/UK personal data, we rely on legitimate interests or consent as our legal basis.
California residents have specific rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
To exercise these rights, visit our Privacy Rights page or email us at privacy@mercana.so.
We comply with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). Canadian residents can access, correct, or request deletion of their personal information by contacting us at privacy@mercana.so. We obtain appropriate consent for data processing as required by Canadian law.
Addresses with APO (Armed Forces Pacific), FPO (Armed Forces Europe), or DPO (Diplomatic Post Office) designations are treated as United States jurisdiction for privacy compliance purposes.
Depending on your location, you may have the following rights:
To exercise any of these rights, please visit our Privacy Rights page or contact us at privacy@mercana.so. We will respond to your request within the timeframes required by applicable law (typically 30-45 days).
We implement industry-standard technical and organizational security measures to protect personal information against unauthorized access, alteration, disclosure, or destruction, including:
While we implement robust security measures, no method of transmission or storage is 100% secure. We will notify you and applicable authorities within 72 hours in the event of a data breach as required by law.
Our Services are not directed to children under the age of 16, and we do not knowingly collect personal information from children. If we learn that we have collected personal information from a child under 16, we will take steps to delete such information as quickly as possible. If you believe we have collected information from a child, please contact us at privacy@mercana.so.
We use cookies, web beacons, and similar tracking technologies to provide and improve our Services:
You can manage cookie preferences through your browser settings. Note that disabling certain cookies may limit functionality. For more information about cookies and how to control them, visit www.allaboutcookies.org.
Your personal information may be transferred to, stored, and processed in countries other than your country of residence, including the United States. These countries may have data protection laws that differ from those in your country.
When we transfer personal information from the European Economic Area (EEA) or United Kingdom to countries outside these regions, we implement appropriate safeguards including:
By using our Services, you acknowledge and consent to the transfer of your personal information to the United States and other countries where we operate.
Mercana does not sell or share personal information for cross-context behavioral advertising or any other purpose. We do not:
When we share data with service providers (see Section 3.2), they are contractually bound to use the data only to provide services to us and not for their own purposes. This means sharing with service providers does not constitute a "sale" under California law.
If our practices change in the future, we will update this policy and provide opt-out mechanisms as required by law.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the updated policy on this page and update the "Last Updated" date. If we make material changes, we will provide additional notice as required by law, such as by email or through a prominent notice on our website or platform.
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
Privacy Inquiries: privacy@mercana.so
General Support: dev@mercana.so
Postal Address:
Mercana Corporation
Attn: Privacy Team
New York, NY 10014, United States
For specific privacy rights requests (access, deletion, opt-out), please visit our Privacy Rights page where you can submit requests directly through our secure form.
We will respond to all requests within the timeframes required by applicable law (typically 30-45 days).