Privacy Policy
1. Privacy at a Glance
General Information
The following information provides a simple overview of what happens to your personal data when you use this website. Personal data is any data that can be used to personally identify you.
Who is responsible for data collection?
MuchWerk UG (haftungsbeschränkt)Managing Director: Matthias Much
Kollwitzstr. 19
10405 Berlin, Germany
Email: info@merchscout.io
How do we collect your data?
Your data is collected in part when you provide it to us — e.g. by entering information in a registration form. Other data is collected automatically by our IT systems when you visit the website (e.g. browser type, operating system, time of access).
What do we use your data for?
- Providing and operating the MerchScout platform
- User accounts and authentication
- Processing payments
- Sending transactional emails (e.g. password reset, reports)
- Improving our services
What are your rights?
You have the right to access, correct, or delete your data at any time. You may also request restriction of processing or object to processing. You also have the right to lodge a complaint with the competent supervisory authority.
2. Hosting
Our website is hosted by external service providers. Server data (e.g. IP address, browser type, access time) is processed on servers in Germany and the EU. For certain CDN services that enable fast delivery of the website, data may also be transferred to the USA; this is covered by the EU Commission's Standard Contractual Clauses.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the reliable operation of the website).
3. General Information and Mandatory Disclosures
Data Controller
MuchWerk UG (haftungsbeschränkt)Managing Director: Matthias Much
Kollwitzstr. 19
10405 Berlin, Germany
Email: info@merchscout.io
Data Retention
Your personal data will remain with us until the purpose for processing no longer applies. If you assert a legitimate request for deletion or revoke consent, your data will be deleted unless other legally permissible reasons for storage exist (e.g. tax or commercial law retention periods).
Right to Complain
You have the right to lodge a complaint with the competent supervisory authority:
Berliner Beauftragte für Datenschutz und InformationsfreiheitFriedrichstr. 219
10969 Berlin, Germany
Email: mailbox@datenschutz-berlin.de
Right to Object (Art. 21 GDPR)
Where data processing is based on Art. 6(1)(f) GDPR, you have the right to object to processing at any time for reasons arising from your particular situation. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds that override your interests.
4. Data Collection on This Website
Cookies
This website uses only technically necessary cookies for authentication and your settings. No tracking, analytics, or marketing cookies are used. Legal basis: Art. 6(1)(f) GDPR.
Server Log Files
Data automatically collected with each page request:
- Browser type and version
- Operating system
- Referrer URL
- Time of server request
- IP address
This data is not merged with other data sources. Collection is based on Art. 6(1)(f) GDPR.
Registration
Data entered during registration (email address, password) is stored to provide our services. Processing is based on Art. 6(1)(b) GDPR (performance of a contract). Data is stored as long as you are registered and deleted thereafter.
Withdrawal Consent
During registration, we store the timestamp of your consent to the immediate commencement of services, as well as your IP address at the time of consent. This data serves as proof of the consent given in accordance with § 356(4) of the German Civil Code (BGB). Legal basis: Art. 6(1)(f) GDPR (legitimate interest in documenting withdrawal consent). The data is retained for the duration of the business relationship and beyond for the duration of any statutory retention periods.
5. Payment Processing
Payments are processed by Polar Software, Inc., 3500 South DuPont Highway, Dover, DE 19901, USA, as Merchant of Record. Payment data is processed exclusively by Polar and is not stored on our servers. Legal basis: Art. 6(1)(b) GDPR; transfer to the USA is based on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). Details: Polar Privacy Policy
6. Your Rights as a Data Subject
- Right of Access (Art. 15 GDPR): Information about your stored data.
- Rectification (Art. 16 GDPR): Correction of inaccurate data.
- Erasure (Art. 17 GDPR): Deletion of your data. You can delete your account and all associated data at any time in your account settings.
- Restriction (Art. 18 GDPR): Restriction of processing.
- Data Portability (Art. 20 GDPR): Receive your data in a machine-readable format.
- Objection (Art. 21 GDPR): Object to processing.
To exercise your rights, simply send an email to: info@merchscout.io
7. Updates to This Privacy Policy
This privacy policy is currently valid as of March 2026. Due to ongoing development of our website or changes in legal requirements, it may become necessary to update this privacy policy.