Merdot Connect

Privacy policy

What we collect, what we refuse to do with it, and how the data of the people you message is handled.

Last updated 2 August 2026

Who we are

Merdot Connect is a communications platform operated by Merdot, registered in India at A-401, Privilon, Bopal Ambli Road, Ahmedabad, Gujarat 380059, India. You can reach us at [email protected].

This policy covers the platform itself. It does not cover what our customers do with the messages they send through us, which is governed by their own policies.

Two kinds of data, kept separate

We hold data about our CUSTOMERS, meaning the businesses that use the platform. That is an email address, an account name, billing details, and a record of what was sent.

We also process data about our customers' RECIPIENTS, meaning the people they message. Here we act only on our customer's instructions. We are a processor of that data, not its owner, and we do not use it for our own purposes.

What we collect from customers

An email address, because it is how you sign in. There are no passwords in this product, so we never hold one.

Your account and business details, including a GST number where you give one for invoicing.

A record of every message sent through your account: the recipient, the channel, the status, the cost and the content. This is what makes the delivery log possible.

Contacts you upload, with the attributes and consent state you record against them.

What we do not do

We do not sell data. Not to anyone, for any purpose.

We do not use your recipients' data to build profiles, train models, or improve anything outside your own account.

We do not read your message content except where processing it is necessary to deliver it, or where we are compelled by law.

We do not share your data with other customers. Every query in the platform is scoped to one account.

Where it is held

Our infrastructure runs in India. Email is delivered from servers we operate ourselves rather than a third party.

For channels where delivery depends on an external network, such as WhatsApp, SMS and voice, the message necessarily passes to that network to reach the recipient. We pass only what delivery requires.

How long we keep it

Message records are kept for as long as your account is open, because you need them to audit what was sent. You can export or delete them.

One-time verification codes are stored hashed and are deleted once used or expired. We cannot read them at any point, including while they are live.

Closing your account removes your data within 30 days, except records we are required by law to retain, such as tax invoices.

Security

API keys are stored as hashes. The key itself is shown once and cannot be recovered, by you or by us.

Signing keys for your sending domains are encrypted before storage.

Sessions are signed and expire. There are no passwords in the product to be stolen.

Access to production data is limited to people who need it to operate the service.

Your rights

You may ask for a copy of your data, ask us to correct it, or ask us to delete it. Write to us and we will act within 30 days.

If you are a recipient rather than a customer, the business that messaged you controls that data. We will pass your request to them and help them act on it.

Changes

If we change this policy in a way that matters, we will tell account holders by email before it takes effect rather than quietly amending the page.

Contact

Merdot
A-401, Privilon, Bopal Ambli Road, Ahmedabad, Gujarat 380059, India
[email protected]