Privacy policy
Last updated: 20 August 2026
This policy explains how Merchu collects, uses and protects your personal data when you use www.merchu.ai. It is written to comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR). If anything is unclear, email privacy@1clickprint.com.
1. Who we are
Jekat Limited (trading as Merchu) is the data controller for the personal data processed through www.merchu.ai. We are a company registered in England and Wales (company number 09048025), with our registered office at Unit 48 Dinnington Business Centre, Sheffield, S25 3QX, United Kingdom.
You can contact us about anything in this policy by email at privacy@1clickprint.com.
2. What personal data we collect
We collect only the data we need to run the service:
- Account data. Your email address, password (stored as a hash by our identity provider), display name, and account preferences such as default garment colour and image count.
- Designs and uploads. Any briefs, prompts, reference images and generated designs you create or upload. These are stored against your account.
- Listing data. When you publish to a connected marketplace such as Etsy or eBay, we store the listing metadata you created (title, tags, description, price, mockups) and a reference to the resulting external listing.
- Marketplace access tokens. If you connect an Etsy or eBay account, we store the OAuth access token, refresh token, expiry and shop identifier returned to us by the marketplace. We do not store your marketplace password (we never see it).
- Order and delivery data. When you order printed transfers we store what you ordered (your sheets, the names you gave them, sizes and quantities), the delivery option you chose, and the delivery name, address and phone number you enter at checkout. The phone number is there because carriers ask for one on the label. Once the parcel goes out we also store which carrier took it and the tracking reference.
- Usage and technical data. IP address, browser type, device identifiers, timestamps, and records of which features you use. This is collected automatically by the infrastructure that serves the site.
- Billing data. If you upgrade to a paid plan, our payment processor handles card details on our behalf. We receive only a customer identifier, plan, and the status of payments, never your card number.
- Communications. Any emails or messages you send us, and our replies.
3. How we use your data and our legal bases
Under UK GDPR we must have a legal basis for every purpose we process your data for. Ours are as follows:
- To provide the service. Authenticating you, storing your designs, running AI generation, producing print files, and (where you ask us to) publishing listings to your connected marketplaces. Legal basis: performance of a contract (the Terms of Service you accept when signing up).
- To print and deliver your orders. Sending your artwork and sheet layouts to our print server, printing and cutting the film, passing the delivery details to the carrier so the parcel can be labelled and delivered, and emailing you the confirmation, dispatch and tracking updates. Legal basis: performance of a contract (the order you place with us).
- To keep the service secure. Detecting abuse, rate-limiting, debugging, and preventing fraud. Legal basis: legitimate interests (running a secure and reliable service).
- To improve the product. Aggregated, non-identifying analysis of how features are used. Legal basis: legitimate interests (improving the service for all users).
- To handle billing. Passing the minimum necessary information to our payment processor and keeping records of payments. Legal basis: performance of a contract and legal obligation (we must keep accounting records).
- To send service emails. Confirming sign-up, password resets, billing receipts and important changes to the service. Legal basis: performance of a contract.
- To send marketing emails. Only if you have opted in, and you can unsubscribe from any email. Legal basis: consent.
5. Connected marketplaces (Etsy, eBay)
If you choose to connect your Etsy or eBay account, you will be redirected to the marketplace to sign in there and grant us permission to act on your behalf. You can revoke that permission at any time from inside the marketplace's account settings.
With your authorisation we will:
- Create, update and (optionally) publish listings.
- Read order and listing data we need to fulfil and track what you have sold through Merchu.
- Refresh the access token in the background so the connection keeps working.
We store the access token, refresh token and shop identifier in our database with encryption at rest, and access it only from our server-side code. We will not use marketplace data for any purpose other than running the features you have asked for. If you disconnect a marketplace, we delete the stored tokens.
The Merchu Lister browser extension fills in your Etsy listing form inside your own browser session. It never sees or sends your Etsy password, session or cookies. So that we can keep it working when Etsy changes its pages, the extension sends us diagnostics: which step it was on, whether it succeeded, your locale and browser version, an anonymous install identifier and your shop identifier. If a step fails, it may also send a small snippet of the listing form's page structure. Before that snippet leaves your browser we strip links, images, hidden fields, account and shipping details, and any text that looks like an email address, phone number, card number or postcode, and we mask the values of form fields. We use these diagnostics only to fix the extension, and you can ask us to delete them (section 9).
6. International transfers
Several of the providers listed above are based in the United States. When we transfer your data to them, we rely on one or more of the safeguards permitted by UK GDPR:
- The UK Government's adequacy decision for the EU–US Data Privacy Framework (and its UK Extension), where the recipient is certified under it.
- The UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, with appropriate supplementary measures.
You can request a copy of the safeguards in place for any given transfer by emailing privacy@1clickprint.com.
7. How long we keep your data
We keep personal data only for as long as we need it for the purposes set out in this policy:
- Account and design data: for as long as your account is active. If you delete your account, we erase or anonymise this data within 30 days, except where we must retain something to meet a legal obligation.
- Marketplace tokens: deleted immediately when you disconnect the marketplace, or when your account is deleted.
- Print files on the print server: the rendered film, its previews and the artwork they were made from are deleted 21 days after the order is dispatched, and 60 days after an order is cancelled or fails. The print server keeps the record of how each sheet was laid out, so that an order can be reprinted if something goes wrong later. That record is kept indefinitely and holds the names you gave your sheets, the sizes and print settings used, and the file paths the artwork was read from, but not the artwork itself. If you ask us to erase your data, we delete that order's files and records from the print server by hand.
- Billing records: kept for six years after the end of the tax year, as required by UK tax law.
- Server logs: kept for up to 90 days for security and debugging, then deleted or anonymised.
8. Security
We use industry-standard measures to protect your data, including TLS for data in transit, encryption at rest for credentials and marketplace tokens, role-based access controls, audit logging, and least-privilege server-side keys. No system is completely secure. If we ever become aware of a personal data breach that is likely to affect your rights, we will notify the ICO within 72 hours and tell you directly where required by law.
9. Your rights
Under UK GDPR you have the right to:
- Be informed about how we use your data (this policy).
- Access a copy of the data we hold about you.
- Have inaccurate data corrected.
- Have your data erased ("right to be forgotten"), subject to limited exceptions.
- Restrict or object to certain processing.
- Receive your data in a portable, machine-readable format.
- Withdraw consent at any time where we rely on consent (for example, marketing emails).
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects on you.
To exercise any of these rights, email privacy@1clickprint.com. We will respond within one calendar month. We do not charge a fee for handling a reasonable request.
11. AI-generated content
Merchu uses third-party AI models (named in section 4) to generate designs, listing copy and related content from the briefs you provide. The prompts you submit are sent to these providers under their respective business or commercial API terms, which prohibit them from using the content to train their models. We do not share your name or email address with the AI providers in the request itself.
AI-generated outputs can be imperfect or unexpected. You are responsible for reviewing each design and listing before publishing it to a marketplace.
12. Children
Merchu is not directed at children under 13, and we do not knowingly collect personal data from anyone under 13. If you believe a child has provided us with personal data, please contact us and we will delete it.
13. Changes to this policy
We may update this policy from time to time. When we do, we will change the "Last updated" date at the top of the page and, for material changes, notify you by email or in-app notice before the change takes effect.
14. Contact and complaints
For any privacy question or request, email privacy@1clickprint.com.
If you believe we have not handled your data correctly, you have the right to complain to the Information Commissioner's Office (the UK's data protection regulator):
Information Commissioner's OfficeWycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
ico.org.uk
We would appreciate the chance to address any concern before you contact the ICO. Please email us first if you can.