Legal
Privacy Policy
What personal data MartMint handles, why, who we share it with, and the rights you have over it.
Version 2026-08-30 · Effective 30 August 2026 · MARTMINT LTD, company number 17373502
1. Who this policy is for
This policy is written for the merchants who use MartMint, and for anyone who visits our website. MARTMINT LTD (company number 17373502, 20 Wenlock Road, London, England, N1 7GU) is the data controller for the personal data described in it.
2. What we collect about merchants
| Category | What it includes |
|---|---|
| Account | Name, email address, phone number, password (stored hashed, never in readable form), preferred language, profile photo if you upload one. |
| Business | Store name, subdomain or custom domain, business address, store location if you set one, logo and branding. |
| Billing | Plan, billing history, invoices, and the payment records our provider returns to us. We never see or store your full card number — the card is entered on the payment provider's page, and we receive only the brand, last four digits and expiry. |
| Usage | Pages you open in the dashboard, features you use, AI actions you consume, API requests, and the timing of all of it. |
| Technical | IP address, browser and device type, operating system, and for the mobile apps a push notification token. |
| Support and consent | Messages you send us, and a record of what you agreed to, when, and from which IP address. |
3. Why we use it, and on what lawful basis
| Purpose | Lawful basis |
|---|---|
| Providing the Platform, hosting your storefront, processing your orders | Performance of our contract with you |
| Taking payment, issuing receipts and invoices, chasing unpaid fees | Performance of our contract, and our legal obligation to keep accounting records |
| Service emails — password resets, expiry notices, receipts, security alerts | Performance of our contract |
| Keeping the Platform secure, preventing abuse, investigating incidents | Our legitimate interest in a service that is not broken by other people |
| Improving the product, understanding which features are used | Our legitimate interest in building software that works, using aggregated data wherever it will do |
| Marketing emails about MartMint | Your consent, which you can withdraw at any time |
| Meeting legal, tax and regulatory obligations | Legal obligation |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and we will explain that assessment if you ask.
4. Who we share it with
We do not sell personal data. We share it with the service providers we need in order to run the Platform, each of which acts on our instructions under a contract:
| Provider | What it does, and what it sees |
|---|---|
| Amazon Web Services | Hosting, databases and file storage. Sees anything stored on the Platform. Data is held in the EU (Frankfurt). |
| Cloudflare | DNS, CDN and network protection. Sees request metadata including IP addresses. |
| Stripe | Payments for plans and add-ons. Sees your name, email, billing details and card data, which it collects directly. |
| Whish Money | An alternative payment route for merchants paying us by transfer. Sees the payment reference and amount. |
| Brevo | Sending transactional and marketing email. Sees recipient addresses and message content. |
| Groq, Google (Gemini), OpenAI | AI features. See the content you submit to an AI feature and the store context needed to answer it. Which provider handles a given request depends on availability. |
| Meta Platforms | WhatsApp Business messaging, Facebook and Instagram posting, and conversion measurement where you enable it. Sees message content and the event data you configure. |
| TikTok | Posting and conversion measurement where you enable it. |
| Google (Firebase Cloud Messaging, Maps) | Push notifications to the mobile apps, and the map used to set a store location. |
| Sentry | Error monitoring. Sees technical error data, which can incidentally include an identifier. |
We also disclose data where the law requires it, to enforce our Terms, to protect our rights or someone's safety, and to a buyer or successor if our business is sold — in which case we will tell you.
5. Sending data outside the UK
Some of the providers above are outside the United Kingdom, mainly in the European Economic Area and the United States. Where we transfer personal data out of the UK we rely on UK adequacy regulations where they apply, and otherwise on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with any additional safeguards the transfer needs.
6. How long we keep it
| Data | Retention |
|---|---|
| Account and store data | While your account is active, then 30 days after it closes so you can request an export. |
| Payment, invoice and revenue records | Six years from the end of the accounting period, as UK tax and company law require. These records are held in an append-only ledger and cannot be altered after the fact. |
| Consent records — terms acceptance, marketing and messaging opt-ins | For as long as we may need to evidence the consent, and for six years after the relationship ends. |
| Security and access logs | Up to 12 months. |
| Support correspondence | Up to three years after the matter is closed. |
7. Your rights
Under UK data protection law you have the right to ask us for a copy of your personal data; to have inaccurate data corrected; to have data erased; to restrict or object to how we use it; to receive it in a portable format; and to withdraw consent where consent is what we rely on. You can also object to direct marketing at any time, with no reason needed.
Email [email protected] and we will respond within one month. We may ask you to confirm your identity first. Exercising these rights is free, and we will tell you if a request is one of the rare ones we can charge for or decline.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk, or on 0303 123 1113. We would rather you came to us first so we can put it right.
8. Your customers' data — where we are the processor
When someone shops in a store built on MartMint, the merchant running that store decides what data is collected and why. The merchant is the controller. We are the processor, and we handle that data only on the merchant's documented instructions, under the Data Processing Addendum at martmint.com/legal/dpa, which forms part of our Terms.
In that role we commit to:
- process shopper data only as instructed by the merchant, and tell them if an instruction appears to breach data protection law;
- keep it confidential and hold our staff to the same;
- apply appropriate technical and organisational security measures;
- use sub-processors only under equivalent obligations, and tell merchants before we add one;
- help the merchant respond to a data subject's request and to a security incident;
- delete or return the data when the merchant's account ends, except where we must keep it;
- never sell shopper data, and never use it to market to shoppers on our own behalf.
If you are a shopper and want to exercise a right over your data, contact the merchant whose store you used. If you cannot reach them, contact us and we will pass it on.
9. Cookies and tracking
We use cookies and similar technologies that are strictly necessary to run the Platform — keeping you signed in, remembering your language, and protecting against abuse. These do not need your consent.
MartMint also provides merchants with analytics about their own storefront: sessions, page views, funnels and click heatmaps. That tracking runs under the merchant's control, on their storefront, and consent for it is collected there under the merchant's own notice.
Merchants can additionally connect Meta or TikTok conversion tracking to their storefront. Where they do, those platforms receive event data about shopper activity. That is the merchant's decision and their disclosure to make.
10. Security
We encrypt data in transit, hash passwords, isolate each merchant's data at the database layer, restrict internal access to those who need it, keep an audit trail of administrative actions, and hold financial records in an append-only store so they cannot be quietly altered. Payment card details are collected by our payment provider and never reach our servers.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to people's rights, we will notify the ICO within 72 hours and tell affected people where the law requires it.
11. Children
MartMint is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18 in connection with a merchant account. If you believe we have, tell us and we will delete it.
12. Changes, and how to reach us
We may update this policy. The version and effective date are shown at the top of this page, and we will tell merchants about material changes by email or in the dashboard before they take effect.
MARTMINT LTD, 20 Wenlock Road, London, England, N1 7GU. Company number 17373502. Data protection enquiries: [email protected].
The English text of this policy is the only version that governs; any translation is provided for convenience.