Merdot Connect

Privacy policy

What we collect, what we refuse to do with it, and how the data of the people you message is handled.

Last updated 2 August 2026

Who we are

Merdot Connect is a communications platform operated by Merdot, registered in India at A-401, Privilon, Bopal Ambli Road, Ahmedabad, Gujarat 380059, India. You can reach us at [email protected].

This policy covers the platform itself. It does not cover what our customers do with the messages they send through us, which is governed by their own policies.

Two kinds of data, kept separate

We hold data about our CUSTOMERS, meaning the businesses that use the platform. That is an email address, an account name, billing details, and a record of what was sent.

We also process data about our customers' RECIPIENTS, meaning the people they message. Here we act only on our customer's instructions. We are a processor of that data, not its owner, and we do not use it for our own purposes.

What we collect from customers

An email address, because it is how you sign in. There are no passwords in this product, so we never hold one.

Your account and business details, including a GST number where you give one for invoicing.

A record of every message sent through your account: the recipient, the channel, the status, the cost and the content. This is what makes the delivery log possible.

Contacts you upload, with the attributes and consent state you record against them.

What we do not do

We do not sell data. Not to anyone, for any purpose.

We do not use your recipients' data to build profiles, train models, or improve anything outside your own account.

We do not read your message content except where processing it is necessary to deliver it, or where we are compelled by law.

We do not share your data with other customers. Every query in the platform is scoped to one account.

Where it is held

Our infrastructure runs in India. Email is delivered from servers we operate ourselves rather than a third party.

For channels where delivery depends on an external network, such as WhatsApp, SMS and voice, the message necessarily passes to that network to reach the recipient. We pass only what delivery requires.

How long we keep it

Message records are kept for as long as your account is open, because you need them to audit what was sent. You can export or delete them.

One-time verification codes are stored hashed and are deleted once used or expired. We cannot read them at any point, including while they are live.

Closing your account removes your data within 30 days, except records we are required by law to retain, such as tax invoices.

Security

API keys are stored as hashes. The key itself is shown once and cannot be recovered, by you or by us.

Signing keys for your sending domains are encrypted before storage.

Sessions are signed and expire. There are no passwords in the product to be stolen.

Access to production data is limited to people who need it to operate the service.

Requests from public authorities

Governments and law enforcement occasionally demand data. This is what we do when that happens, and it is a commitment, not a description of what we might feel like doing.

We review whether the request is lawful before acting on it. A demand that does not identify a legal basis, or that appears to exceed the authority of the body making it, is not complied with on request alone.

We challenge requests we believe are unlawful or overbroad, through counsel where necessary, rather than complying to avoid difficulty.

We disclose the minimum necessary. If a request can be satisfied with less than it asks for, we provide less. We do not hand over an entire account because one record was asked for.

We keep a record of every such request: what was asked, what we provided, the legal reasoning, and who was involved.

We tell the affected customer unless we are legally prohibited from doing so, and where a prohibition is time limited we tell them once it lapses.

Payments and billing data

The platform is prepaid. When you add credit, the payment itself is handled by our payment gateway and we never see or store your card number, security code or bank credentials. Nothing in our database could be used to make a payment.

We store what the gateway tells us: that a payment of a certain amount succeeded, its reference, and the time. That is what an invoice and a refund enquiry need, and nothing more.

If you switch on automatic top-up, the gateway holds a token authorising us to charge the amount you chose when your balance falls below the level you set. We hold that token's identifier only, never the card behind it. Switching it off withdraws the authorisation.

Every movement of money is a ledger entry you can read and export. A balance is never adjusted without a corresponding entry, which is what makes the account reconcilable rather than merely believable.

Push notification data

If you use the push channel, we store the subscription the recipient's browser issued: an endpoint address and two encryption keys. Those are issued by the browser vendor's push service and are meaningless outside it.

We store your own identifier for that person, because that is what you address a notification to. We know nothing about them beyond what you tell us.

When a push service reports a subscription as gone, we delete it immediately. We do not retain endpoints that can no longer be delivered to.

Link tracking

If you shorten a link through the platform, we record each click: the time, and a salted one-way hash of the visitor's network address and browser.

We do not store the address itself. The hash lets us count one person twice as one and is useless to anybody reading the database. Keeping raw addresses beside a phone number would turn a click log into a location history, which is not something we are willing to hold.

The assistant

The console includes an assistant that answers questions about your account. It runs on Merdot's own AI service, so your questions are not sent to a third-party model vendor.

It is given facts about your account so its answers are correct: which channels are live, which domains you hold, your plan and your balance. It is not given the content of your messages or your contact list.

Questions are used to answer you. They are not used to train anything.

Who else processes your data

We use a small number of sub-processors, and we name them, because a policy that hides them is not a policy.

Amazon Web Services, for email delivery and infrastructure, in the Asia Pacific (Mumbai) region.

Meta Platforms, where you use the WhatsApp channel. Messages on that channel necessarily pass through Meta and are subject to their terms as well as ours.

Our payment gateway, for processing payments. It holds the card details we deliberately never touch.

Browser push services operated by the browser vendors, where you use the push channel. A notification is delivered by whichever service issued the subscription.

We will update this list before adding to it, not after.

Your rights

You may ask for a copy of your data, ask us to correct it, or ask us to delete it. Write to us and we will act within 30 days.

You may export your delivery log, your contacts and your ledger from the console at any time without asking us first.

If you are a recipient rather than a customer, the business that messaged you controls that data. We will pass your request to them and help them act on it. We will also honour an opt-out directly: replying STOP suppresses your number immediately, whatever the business intends.

Changes

If we change this policy in a way that matters, we will tell account holders by email before it takes effect rather than quietly amending the page.

Contact

Merdot
A-401, Privilon, Bopal Ambli Road, Ahmedabad, Gujarat 380059, India
[email protected]