Legal

Privacy Policy

Last updated: April 2026

1. Introduction

MelQart ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our competitive intelligence platform at melqart.me and associated services (the "Service").

By using the Service, you consent to the data practices described in this policy. If you do not agree with these practices, please do not use the Service.

2. Information We Collect

Account Data

When you create an account, we collect your name, email address, and a hashed version of your password. We never store plaintext passwords.

Store Data

If you connect your e-commerce store, we import your product catalogue including product names, descriptions, prices, images, and availability status. This data is used to match your products against competitors.

Usage Data

We collect information about how you interact with the Service, including pages visited, features used, actions taken, and session duration. This helps us improve the product experience.

Competitor Data

We monitor publicly available data from competitor websites, including product listings, prices, and availability. This is not personal data — it is publicly displayed commercial information.

Payment Data

All payment processing is handled entirely by Paddle, our Merchant of Record. We do not collect, store, or have access to your credit card numbers or bank account details. Paddle's privacy policy governs the handling of your payment information.

3. How We Use Your Data

We use the information we collect to:

  • Provide and maintain the Service, including competitor tracking and product matching
  • Generate AI-powered insights, briefings, and recommendations
  • Send email alerts and daily briefings about competitor activity
  • Communicate with you about your account, updates, and support requests
  • Improve and optimize the Service based on usage patterns
  • Detect and prevent fraud, abuse, or security incidents

4. Data Sharing

We do not sell your personal data. We share data only with the following service providers, solely for the purpose of operating the Service:

  • Paddle — payment processing, invoicing, and tax compliance
  • Supabase — database hosting and authentication
  • Anthropic — AI processing for generating insights and briefings
  • Resend — transactional and briefing email delivery

Each provider processes data only as necessary to perform their service and is bound by their respective privacy policies and data processing agreements.

5. Data Retention

We retain your account data and associated information for as long as your account is active. Upon account closure or cancellation:

  • Your data is retained for 30 days to allow for reactivation
  • After 30 days, all personal data and store data is permanently deleted
  • Aggregated, anonymized analytics data may be retained indefinitely
  • AI call logs are retained for service improvement but do not contain personally identifiable information

6. Cookies

We use only essential cookies required for the Service to function properly:

  • Authentication session cookies — to keep you signed in
  • CSRF tokens — to protect against cross-site request forgery

We do not use tracking cookies, advertising cookies, or third-party analytics cookies. We do not participate in any ad networks or cross-site tracking.

7. Your Rights

You have the right to:

  • Access — request a copy of the personal data we hold about you
  • Correction — request corrections to inaccurate personal data
  • Deletion — request deletion of your personal data and account
  • Export — request a machine-readable export of your data

To exercise any of these rights, email us at support@melqart.me. We will respond within 30 days.

8. Security

We implement industry-standard security measures to protect your data:

  • All data is encrypted at rest and in transit (TLS 1.2+)
  • Row-Level Security (RLS) policies ensure data isolation between users
  • Access tokens and API keys are encrypted before storage
  • Password hashes use bcrypt with appropriate salt rounds
  • Regular security audits and dependency updates

9. International Transfers

Your data may be processed in the United States and/or the European Union, depending on our infrastructure providers. By using the Service, you consent to the transfer of your data to these locations. We ensure appropriate safeguards are in place for international data transfers in compliance with applicable data protection laws.

10. Children

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from anyone under 18. If we become aware that we have collected data from someone under 18, we will take steps to delete that information promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email at the address associated with your account at least 14 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.

12. Contact

If you have questions or concerns about this Privacy Policy or our data practices, contact us at:

Email: support@melqart.me

Website: melqart.me