Eren Labs

Merchuno Merchant Data Statement

Effective date: 1 October 2026

This statement is for store owners who use Merchuno. It explains where your store data lives, who is responsible for it, and which data leaves your site.

1. Your store data stays on your server

Merchuno is a plugin that runs inside your own WordPress site. Your orders, customers, products, payments, cash records and other store data are stored in your site’s database, in WooCommerce’s tables and in Merchuno’s own tables.

Eren Labs does not host this data, does not receive copies of it and has no access to it. We do not back it up for you. Deleting Merchuno does not delete these records: they stay in your database until you delete them.

2. You are the controller

For the personal data of your customers, business customers, staff and suppliers, you are the controller (in KVKK terms, “veri sorumlusu”). You decide which Merchuno features to use and for what purpose.

Your privacy notice should cover the features you turn on, for example:

  • cart reminder emails, back-in-stock emails and review requests, and the consent boxes that come with them;
  • the order tracking page, gift card balance checks and product questions;
  • shipping labels, which send recipient details to your carrier;
  • WhatsApp message drafts;
  • risky-customer flags, cash-on-delivery blocks and purchase limits, which look at customers’ order history; and
  • the activity log of your team’s actions and the email history (tell your staff about the activity log).

To prevent abuse, some storefront forms (order tracking, gift card balance check, back-in-stock sign-up and product questions) briefly use the visitor’s IP address on your server.

3. Eren Labs is not your processor for store data

A processor processes personal data on behalf of a controller. Merchuno runs under your control and we have no access to your store data, so we do not process it on your behalf. You therefore do not need a data processing agreement (DPA) with Eren Labs for your store data.

Exception: support access. If you give us access to your site, database or server, or send us files that contain personal data, we act as your processor for that access under Annex A (Support Access Terms) of our Terms. Before you do:

  • try a support report, screenshots or a staging copy with anonymized data first;
  • create a temporary account with the least access needed, and remove it afterwards; and
  • if the GDPR or the UK GDPR applies to you, contact us first so that we can sign the EU Standard Contractual Clauses or the UK Addendum, because we are based in Türkiye.

4. What Freemius receives

Licensing, Trials and updates run through Freemius, Inc. (USA), which processes this data on our behalf. The data is about you and your site, not about your customers:

  • your site’s home URL, the Merchuno and SDK versions, whether Merchuno is active, deactivated or uninstalled, and the License Key;
  • the name and email address of the license owner, or of the user who starts a Trial; and
  • only if you allow it: your WordPress and PHP versions, site language and title, and the list of installed plugins and themes.

With Lite, nothing is sent unless you click “Allow & Continue” on the opt-in screen, and you can opt out later from the Plugins screen. Payments are handled by Freemius and its payment processors, such as Stripe and PayPal; we never see full card numbers. Our Privacy Policy has the details.

5. Services you may connect

You connect these services with your own accounts and keys. Data travels directly from your site to the provider, not through us, and the provider’s own terms and privacy policy apply.

ServiceWhen data is sentWhat is sent
Shipping: EasyPost, Sendcloud, Geliver, KargonomiWhen you request rates, buy a label or check trackingRecipient name, address, phone and email as the carrier needs them; your sender address; parcel weight and size; order reference; customs details for international parcels
Google Merchant Center, Meta Commerce ManagerWhen they fetch the feed URL you gave themProduct data only: titles, descriptions, prices, stock, images, links and product identifiers. No customer data. Feed URLs are public.
Google product category listWhen you map feed categoriesYour server downloads Google’s public list. No store data is sent; Google sees your server’s IP address.
WhatsAppWhen a team member clicks a WhatsApp button, or a shopper clicks your store’s WhatsApp link on the order tracking pageFor your team, Merchuno opens a prefilled draft (phone number and message) in WhatsApp on that person’s device. The shopper link only opens a chat with your store’s number, without order details. Nothing is sent until the person sends it.
EmailWhen your store sends Merchuno emailsRecipient address and name, and the message, sent through your site’s own email setup (for example your SMTP plugin or email service).
Supplier catalog importWhen you import from a web addressYour server downloads the file from the address you entered. No store data is sent.
Notifications to your team’s phones and browsersWhen an alert is triggeredAn encrypted notification travels through the push service of your team’s browser (Google, Mozilla, Microsoft or Apple). The keys are created on your site, and the push service cannot read the content.

Marketplace integrations, such as Trendyol, are not part of this version. If we add new connections, we will update this statement.

For each provider you connect, check whether you need a data processing agreement with it and a lawful basis for any transfer abroad (Article 9 of KVKK, Chapter V of the GDPR), and name it in your privacy notice.

6. Built-in privacy tools

  • Merchuno connects to WordPress’s personal data export and erasure tools for the data it stores.
  • The consent boxes for review requests and back-in-stock emails start unticked. Cart reminders start only after you confirm that your store collects the required permissions.
  • Some data is deleted automatically after a set time, for example cart reminder details and the email history. The documentation lists the periods.

These tools help you; they do not make your store compliant on their own.

7. Cookies and browser storage

On your storefront, Merchuno relies mainly on WooCommerce’s own session and sets few cookies of its own. For example, when a customer picks a language on their quote page, a preference cookie (qg_lang, kept for one year) remembers that choice. In the admin area, Merchuno keeps some screen preferences, such as saved views, in the browser’s local storage. Cover these in your cookie notice as your local law requires.

8. Questions

Write to support@erenlabs.net. For questions about the personal data we process ourselves, see our Privacy Policy or write to support@erenlabs.net.