Privacy Policy
Merchie · Last updated 2026-07-13
Summary
- We collect your name, email, phone, date of birth, and transactions so we can run your loyalty account.
- We do not sell or rent your data.
- We do not track you across other apps or websites.
- We do not collect medical records, precise location, or biometric identifiers used to identify you. If you choose to use optional AI features (like AI Skin Analysis), your photo is analyzed once and never stored — see Sections 5.4 and 8.
- You can delete your account at any time from inside the app or by emailing us at herrisellc@gmail.com. Deletion is permanent and applies across every app on the Merchie platform where you hold an account.
This Privacy Policy explains how Herrise LLC (d/b/a Merchie) ("Merchie", "we", "us", or "our") collects, uses, stores, shares, and protects your personal information when you use any mobile application or related service powered by the Merchie platform (collectively, the "Service"). By using the Service, you agree to this Privacy Policy.
1. About Merchie and the Apps We Power
Merchie is a software platform operated by Herrise LLC, a Delaware limited liability company doing business as "Merchie". Merchie provides white-labeled loyalty and rewards mobile apps to local businesses (each, a "Merchant") such as med spas, salons, aesthetic clinics, and similar service providers.
Each app on the Merchie platform is branded for an individual Merchant — for example, the Merchant's name, logo, and color scheme appear throughout the app. The services, products, prices, bookings, and rewards offered through the app are controlled by the Merchant. However, the underlying technology, hosting, account management, payments infrastructure, push notifications, and data handling are all operated by Merchie. This Privacy Policy applies uniformly across every app on the Merchie platform.
For purposes of data-protection law, Merchie acts as a data controller for platform-level data (account, authentication, security, device telemetry) and as a data processor for Merchant-specific transaction data, on behalf of the relevant Merchant. The Merchant is the data controller of their loyalty program data. If you have a question that only the Merchant can answer (for example, about a specific purchase, refund, or appointment), please contact the Merchant directly through the app.
Privacy contact: herrisellc@gmail.com.
2. Definitions
- Account — a unique account you create to access the Service.
- App — any mobile application powered by the Merchie platform.
- Merchant — the local business whose branding appears in the App you downloaded.
- Personal Data — any information that identifies or could reasonably identify you.
- Service — the App, related websites at merchie.app, and the supporting infrastructure operated by Merchie.
- Service Provider — any third party that processes Personal Data on our behalf to operate the Service.
- Usage Data — data collected automatically by the App or its infrastructure.
- You — the individual using the Service.
3. Device Permissions We Request
The App requests the following permissions from your device. We only request a permission when you take an action that needs it, and you can change your answer at any time in your device settings. Denying a permission does not block you from using the rest of the App.
| Permission | Why we need it | Required? |
|---|---|---|
| Camera | To scan check-in QR codes, let you take a profile photo, and — only if your Merchant offers it and you choose to use it — take a selfie for AI Skin Analysis (analyzed once, never stored; see Section 8). | Optional |
| Photo Library | To let you choose an existing photo as your profile picture or (optionally) for AI Skin Analysis. | Optional |
| Push Notifications | To send booking confirmations, reward updates, announcements from your Merchant (such as a new offer going live), and (if you opt in) other promotional messages. | Optional |
We do not request access to your contacts, calendar, microphone, precise location, motion sensors, health data, HealthKit, fitness data, biometric identifiers (Face ID / Touch ID enrollment), or any other sensitive permission.
4. App Tracking Transparency
We do not track you across apps or websites owned by other companies. We do not use advertising identifiers (IDFA on iOS or AAID on Android), we do not share your activity with data brokers or advertising networks, and we do not participate in cross-context behavioral advertising. Because we do not engage in tracking as Apple defines it in its App Tracking Transparency framework, the App Tracking Transparency prompt is normally not shown. If a third-party payment SDK embedded in the App ever surfaces the prompt, denying it does not affect any feature of the App.
5. Information We Collect
5.1 Information You Provide
- Account information: first and last name, email address, mobile phone number.
- Authentication credentials: a password (stored only in hashed form by our authentication provider) and one-time codes (OTP) sent by SMS.
- Profile information: date of birth (used for birthday rewards and age verification), gender, and any preferences you choose to share.
- Photos: profile photos you upload or capture with your device camera, and — only if you choose to use AI Skin Analysis — a selfie that is analyzed once and never stored (see Section 8).
- Communications: messages, feedback, reviews, or support requests you send to us or the Merchant, including messages you send to the AI advisor if your Merchant enables it.
- Social media information: if you choose to participate in a social rewards activity, the social media handle(s) you submit (for example Instagram, TikTok, or Facebook) and links to the public posts you ask us to verify.
- Gift recipients: if you send a gift card, we collect the recipient's name and email address and your personal message so we can deliver the gift and let the recipient redeem it. We use this information only for gift delivery, redemption, customer support, and fraud prevention. If someone sent you a gift through the Service, this is how we received your name and email.
5.2 Information Collected Automatically
- Transaction information: purchases, bookings, appointments, points balance, cash credits, memberships, redemptions, gift card balances, and check-ins.
- Usage information: screens you visit, services you view, interactions with rewards and offers.
- Device and diagnostic information: operating system, app version, runtime version, build identifier, language, and device identifiers used to keep the App functioning and secure.
- Push notification token: a token issued by Apple or Google that allows us to deliver push notifications to your device.
- Network information: IP address and connection metadata used for security, fraud prevention, and rate limiting.
- Consent records: when you give certain legal consents (for example, accepting these terms, opting in to marketing texts, or authorizing a recurring membership charge), we record the date, time, your IP address, and the exact disclosure text you agreed to, so we can demonstrate your consent if required by law.
5.3 Information from Third Parties
If you connect a payment method, our payment processor (Stripe) returns a token and limited card metadata (brand, last four digits, expiration). We do not see or store your full card number, CVV, or bank credentials.
If you claim reward points for posting a Google review, we retrieve the Merchant's public review listing from the Google Places API (public reviewer display names, review text, star ratings, and posting times) and compare it against your claim — including your name and any review text you drafted in the App — to verify the review exists; the matched public review details are stored with your claim.
If you submit a social post for verification, our verification provider (Apify) retrieves the public post you linked and returns its public details (author handle, caption, mentions, timestamp) so we can confirm the activity and award your points.
5.4 Sensitive Personal Information
We do not knowingly collect any "sensitive personal information" as defined under the California Consumer Privacy Act (CCPA/CPRA) or similar laws, with the narrow exceptions described below. We do not collect government identifiers (Social Security number, driver's license, passport), precise geolocation, racial or ethnic origin, religious beliefs, union membership, genetic data, biometric identifiers for unique identification, medical records, sex life or sexual orientation, or the contents of your communications.
Self-reported gender. We allow you to provide your gender (optional, with values such as "Female," "Male," "Non-binary," or "Prefer not to say") during signup for product personalization (e.g., addressing you correctly in marketing copy you opt into). Under the CPRA, gender identity is treated as sensitive personal information when collected alongside identifying data. We collect this only with your explicit choice — leaving it blank or selecting "Prefer not to say" is supported and does not block any feature — and we do not use it for cross-context advertising, profile-building, or inference about other sensitive characteristics. You may delete the value at any time from the App's profile settings or by deleting your account.
Optional AI Skin Analysis. If your Merchant offers AI Skin Analysis and you choose to use it, you may share cosmetic skin concerns (such as dryness, redness, or fine lines) through a short quiz and, optionally, a selfie. This is cosmetic information used solely to generate treatment suggestions in that session. The selfie is analyzed once and is never stored — not on our servers, not by the AI provider, and not in your account (see Section 8). We do not use facial recognition, we do not create a biometric template or “faceprint,” and we cannot identify you from this feature. If you prefer not to share a photo or skin concerns, you can skip the feature entirely.
5.5 Automated Decision-Making and Profiling
We do not use your Personal Data to make automated decisions that produce legal or similarly significant effects about you. Loyalty point calculations, reward eligibility, and automated offers — including birthday offers and win-back offers that are triggered automatically when you have not made a purchase for a period of time — are deterministic rules configured by the Merchant or the platform. If your Merchant enables the AI advisor or AI Skin Analysis, an AI model uses your conversation, limited account context (first name, points balance, membership status), and any photo or quiz answers you choose to share to generate personalized treatment suggestions in that session; these suggestions are informational only and never decide prices, eligibility, or access to any service.
6. How This Maps to App Store Privacy Labels
For transparency, here is how the data we collect aligns with Apple's privacy label categories. All categories are "Data Linked to You" (tied to your account), except AI Skin Analysis selfies, which are processed transiently and never stored. None of this data is "Used to Track You". This section is the source of truth for both the App Store Connect "App Privacy" form the App displays on its store listing and the PrivacyInfo.xcprivacy manifest the App ships inside the iOS bundle — the three are kept in sync.
- Contact Info: name, email, phone — for App Functionality and Customer Support.
- Identifiers: account ID (your user UUID) — for App Functionality and Analytics.
- Financial Info: payment-method token (brand + last 4 only), loyalty balance, transaction history — for App Functionality.
- User Content — Photos: profile photos you upload or capture — for App Functionality. (AI Skin Analysis selfies are processed for the single request and immediately discarded — never stored.)
- User Content — Customer Support: messages, feedback, and reviews you send to us or the Merchant — for Customer Support and App Functionality.
- Purchases: purchase history, memberships — for App Functionality and Analytics.
- Usage Data: product interactions, check-ins, screen views — for App Functionality and Analytics.
- Diagnostics: crash and error reports (which may include your account identifier when an authenticated session existed at the time of the error), app version — for App Functionality.
- Other Data: date of birth (used for birthday rewards and age verification), gender (optional) — for App Functionality.
7. How We Use Your Information
- Create and operate your Account and provide the Service.
- Process bookings, purchases, refunds, memberships, points, cash credits, gift cards, and rewards on behalf of the Merchant.
- Verify your identity by SMS one-time code and protect against fraud and unauthorized access.
- Personalize your experience based on your preferences and history.
- Send transactional notifications (booking confirmations, reward grants, order receipts) and announcements from your Merchant.
- Send promotional messages (such as birthday offers, win-back offers, and seasonal campaigns) where permitted by law. You can unsubscribe from promotional emails at any time using the unsubscribe link in any email.
- Generate AI advisor responses and AI skin-analysis suggestions, if your Merchant enables those features and you choose to use them.
- Verify reward activities you claim (such as Google reviews or social posts) so points can be awarded.
- Provide customer support and respond to your requests.
- Monitor, debug, and improve the Service, including diagnosing crashes and performance issues.
- Comply with legal obligations, enforce our agreements, and protect rights, property, and safety.
8. Third-Party Service Providers and SDKs
We share limited Personal Data with the following Service Providers and use the following third-party SDKs to operate the Service. Unless noted otherwise, each provider processes data only on our behalf under contractual obligations of confidentiality and security.
| Provider | Purpose | Data shared |
|---|---|---|
| Supabase | Hosting, database, authentication, file storage | Account, profile, transactions, photos |
| Vercel | Web hosting and edge functions | IP address, request metadata |
| Stripe, Inc. | Payment processing and (where applicable) Stripe Connect payouts to the Merchant | Payment method, billing details |
| Klarna / Affirm / Afterpay (via Stripe) | Pay-over-time financing, if the Merchant offers it and you choose it at checkout. These lenders use your data for their own credit decisions under their own privacy policies (as independent controllers), not on our behalf. | Name, email, billing country, transaction amount and details |
| Resend | Transactional and (where applicable) promotional email delivery | Email address, name, order/appointment details |
| Twilio | SMS delivery — one-time verification codes (via Twilio Verify) and, for customers who opt in, marketing texts sent on behalf of the Merchant | Phone number, verification code, and the content of texts we send you (e.g., offer details) |
| OpenRouter, Inc. (AI model routing) | Optional AI advisor chat and AI Skin Analysis, if the Merchant enables them and you use them | Messages you send the advisor, limited account context (first name, points balance, membership status), your skin-quiz answers, and — only if you choose to add one — your selfie (processed for the single request and immediately discarded — never stored) |
| Apify | Verification of public social posts you submit for social rewards | The public post link you submit and its public details (author handle, caption, mentions, timestamp) |
| Google Places API | Verification of Google-review reward claims | The Merchant's public review listing, compared against your name and claim |
| Apple Push Notification service (APNs) | Deliver push notifications on iOS | Push token, notification payload |
| Google Firebase Cloud Messaging (FCM) | Deliver push notifications on Android | Push token, notification payload |
| Expo (Expo Application Services) | App distribution, push routing, OTA updates | Device info, app version |
| Apple App Store / Google Play | App distribution | Whatever Apple/Google collect from app downloads (governed by their own policies) |
| Google Calendar (Merchant-side only) | Sync the Merchant's appointment calendar (only if the Merchant connects it) | Appointment time, attendee name/email |
Stripe's privacy practices are described at stripe.com/privacy. We do not share your Personal Data with advertisers or data brokers, and we do not sell it.
AI processing. If your Merchant enables the AI advisor or AI Skin Analysis, the content you submit to those features (chat messages, quiz answers, and an optional selfie) is processed by third-party AI models routed through OpenRouter, Inc. (current model providers include OpenAI and others; the specific model may change). We configure this routing to exclude providers that retain or train on inputs, so your content is not used to train AI models, and your selfie is processed once and never stored. Separately, some Merchant-facing back-office tools (such as generating weekly business reports for the Merchant) use AI services (OpenAI, Anthropic, Browserless); those back-office tools receive only the Merchant's own business information, not your Personal Data.
8.1 Sharing with Your Merchant and Other Users
- Your Merchant and its staff. The Merchant whose branded app you use — including its owners and authorized staff — can view the personal information connected to your loyalty account, such as your name, contact details, purchases, memberships, appointments, and points and credit balances. Where a staff member referred you to a membership, that staff member's referral dashboard shows your name, plan, and signup date.
- The person who referred you. If you create your account using another customer's referral code, that customer can see in their app that you joined — your name, the email address you signed up with, the date you joined, and whether you have completed your first purchase — so they can track their referral rewards.
- Gift senders and recipients. If someone sends you a gift card (or you send one), the sender and recipient each see the information needed to deliver and redeem the gift (names, the gift message, and redemption status).
9. Push Notifications
With your device's notification permission, we send push notifications about your account and your Merchant's services — including booking confirmations, reward updates, and announcements from your Merchant, such as a new offer going live. Additional personalized promotional messages are sent only if you opt in. We do not include sensitive medical information in a push notification. You can stop push notifications at any time in your device's system settings.
10. Text Messages (SMS)
When you sign up or sign in, we send a one-time verification code by SMS to confirm that you control the phone number; these support an action you initiated and are sent regardless of marketing preferences. We also send promotional texts (such as offers, loyalty rewards, and win-back discounts) only if you expressly opt in by checking the “Text me deals & offers” consent box when you sign up, or by enabling the “Text me deals & offers” toggle in the App under Settings → Notifications — a consent that is separate from push notifications and recorded per customer. Message frequency varies and standard message and data rates from your carrier may apply. You can opt out of marketing texts at any time by turning the toggle off or by replying STOP to any message; reply HELP for help. We do not share, sell, rent, or otherwise provide your mobile phone number, SMS opt-in, or messaging consent data to any third parties or affiliates for marketing or promotional purposes.
11. Camera, Photo Library, and QR Codes
If you grant permission, the App uses your device's camera or photo library so that you can set a profile photo, scan QR codes at check-in, and — only if your Merchant offers it and you choose to use it — take or select a selfie for AI Skin Analysis. Profile photos you upload are stored securely (via Supabase Storage) and associated with your account. AI Skin Analysis selfies are not stored — they are analyzed once and immediately discarded (see Section 8). QR codes used in the Service contain only a customer identifier and a timestamp; they do not contain medical or financial information.
12. Payment Information
Payments are processed by Stripe. When you save a card or make a payment, your card details are submitted directly to Stripe; we receive a token and limited card metadata (brand, last four digits, expiration). We do not store your full card number, CVV, or bank account credentials. Stripe is certified as a PCI-DSS Level 1 service provider, the highest level of payment security certification available. Stripe processes your information in accordance with its own privacy notice at stripe.com/privacy. If you choose pay-over-time financing at checkout, see Section 8 for what is shared with the financing provider.
13. Cookies and Similar Technologies
When you access web-based portions of the Service, we use a small number of necessary cookies and similar technologies (such as local storage and secure storage on your device) for authentication, security, and remembering your preferences. We do not use advertising cookies, cross-site tracking pixels, or third-party analytics that profile you across the internet. You can clear cookies and reset device identifiers in your browser or device settings; doing so may sign you out and reset preferences.
14. Data Retention
We retain your Personal Data for as long as your Account is active or as needed to provide the Service. When you delete your Account from inside the App, your personal identifiers are removed from our active systems immediately; when you delete by email request, they are removed within 7 business days (or the 30-day legal maximum if verification is delayed — see Section 19). We retain the following for the periods indicated, even after deletion:
- Transaction records (orders, payments, refunds) — up to 7 years, to comply with tax, accounting, and anti-fraud obligations.
- Communications (support emails, fraud reports) — up to 3 years, for dispute resolution and audit.
- Authentication logs (sign-in events) — up to 1 year, for security investigations.
- Consent records — a log of when you opted in or out of marketing channels and accepted legal terms, including the IP address and device/browser details captured at the time — up to 5 years after your last consent change, to demonstrate compliance with the TCPA, CAN-SPAM, and similar laws.
- Deletion integrity record — a one-way cryptographic hash of your email address kept after account deletion so we can recognize that a deletion occurred (for example, to prevent abuse of signup bonuses); the hash cannot be reversed into your email address.
- Encrypted backups — overwritten in the normal course of business within 90 days.
De-identified or aggregated data may be retained indefinitely.
If your Merchant leaves the Merchie platform, we may return the loyalty-program data we process on that Merchant's behalf (including your account and transaction information) to the Merchant, who remains its data controller, and we delete or de-identify the copies remaining on the platform in the normal course of business. Your app account for that Merchant will stop working when the Merchant leaves the platform.
15. International Transfers
Your information may be processed and stored on servers operated by our Service Providers in the United States and other countries where they or their sub-processors are located. By using the Service, you understand that your information may be transferred to countries with different data-protection laws than your home jurisdiction. When we transfer Personal Data from the European Economic Area, the United Kingdom, or Switzerland to the United States, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, the UK International Data Transfer Agreement, or other lawful transfer mechanisms.
16. Security
We use commercially reasonable administrative, technical, and physical safeguards designed to protect your Personal Data, including:
- Encryption in transit using HTTPS/TLS for all client-server communication.
- Encryption at rest for stored data, including database fields and uploaded files.
- Hashed passwords using industry-standard algorithms (bcrypt or stronger).
- Encrypted secure storage of authentication tokens on your device (iOS Keychain, Android Keystore).
- Role-based access controls and the principle of least privilege for our team.
- Rate limiting and brute-force protection on authentication and verification endpoints.
- Routine security monitoring and dependency updates.
No method of transmission over the internet or electronic storage is 100% secure; we cannot guarantee absolute security.
17. Data Breach Notification
If we discover a data breach affecting your Personal Data, we will notify you and applicable regulators as required by law, generally within 72 hours of confirming the breach for individuals in the EEA/UK and without unreasonable delay for individuals in the United States. Notifications will describe the nature of the breach, the data affected, and the steps you can take to protect yourself.
18. Your Rights
Depending on where you live, you may have some or all of the following rights with respect to your Personal Data:
- Access — request a copy of the Personal Data we hold about you.
- Correction — ask us to correct inaccurate or incomplete information.
- Deletion — request that we delete your Personal Data.
- Portability — receive a copy of your information in a portable, machine-readable format.
- Objection / restriction — object to or restrict certain uses of your information.
- Withdrawal of consent — withdraw any consent you previously gave (this does not affect processing already carried out).
- Non-discrimination — you will not be discriminated against (in price, service, or quality) for exercising any of these rights.
- Complaint — lodge a complaint with your local data-protection authority.
To exercise any right, contact herrisellc@gmail.com from the email address associated with your account. We will verify your identity (typically by emailing a confirmation link or asking you to confirm details on file) and respond within the timeframe required by applicable law — typically 30 days, extendable by up to 60 additional days for complex requests.
18.1 California Residents (CCPA / CPRA)
If you are a California resident, you have the rights described above, plus the right to know what categories of Personal Data we collect, the purposes for which we use it, and the categories of third parties with whom we share it (see Sections 5 and 8 of this Policy). We do not "sell" or "share" your Personal Data for cross-context behavioral advertising as those terms are defined under California law. To the extent optional features involve information treated as sensitive under the CPRA (see Section 5.4), we use it only to provide the feature you requested and do not use it to infer characteristics about you, so no right-to-limit action is required; you may nonetheless contact us with any request. You may designate an authorized agent to make a request on your behalf; we may require proof of the agent's authorization.
18.2 Other U.S. State Privacy Rights
If you are a resident of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another U.S. state with a comprehensive consumer privacy law, you have substantially similar rights to those described in Section 18.1. To exercise these rights, contact us at herrisellc@gmail.com. If we deny your request, you may appeal by replying to our response email; appeals are reviewed within 45 days.
18.3 European Economic Area, United Kingdom, and Switzerland
If you are in the EEA, UK, or Switzerland, we process your Personal Data on the following legal bases under the GDPR / UK GDPR:
- Contract — to provide the Service you signed up for (Art. 6(1)(b)).
- Legal obligation — to meet tax, accounting, anti-fraud, and other legal requirements (Art. 6(1)(c)).
- Legitimate interests — to secure the Service, prevent fraud, debug issues, and improve our product, where those interests are not overridden by your rights (Art. 6(1)(f)).
- Consent — for any processing that requires it, such as marketing communications in certain jurisdictions and optional AI features (Art. 6(1)(a)). You may withdraw consent at any time.
You may lodge a complaint with your local supervisory authority. A list of EEA authorities is available at edpb.europa.eu; the UK authority is the Information Commissioner's Office (ico.org.uk).
19. How to Delete Your Account and Data
You can delete your Account and the Personal Data associated with it in two ways:
- From inside the App: Open the App, go to Profile → Settings → Delete Account, and confirm. Deletion takes effect immediately — your personal identifiers are removed from our active systems the moment you confirm, and you are signed out on every device.
- By email request (web-accessible): Send an email to herrisellc@gmail.com from the email address linked to your account, with the subject line "Delete my account." We will verify the request and complete deletion within 7 business days. If we cannot verify your identity within that window (for example, you do not respond to a follow-up question), we will complete the deletion in any event within the legal maximum of 30 days from the original request.
Deletion applies platform-wide. Because Merchie powers apps for many businesses, deleting your account deletes your identity across the platform: if you also hold accounts at other businesses on the Merchie platform under the same email address or phone number, those accounts are deleted at the same time, and any points, credits, or memberships there are forfeited or cancelled as described in the Terms of Service.
Deletion is permanent. It cannot be undone, and a later account created with the same email or phone number starts fresh — prior balances and history cannot be restored.
What happens when you delete your Account: your profile, photos (including the stored photo files), push notification token, and personal identifiers are removed from our active systems. Transaction history, financial records, consent records, and other information that we are required or permitted to retain by law will be retained for the periods described in Section 14 and then deleted. Encrypted backups containing your data are overwritten within 90 days.
20. Children's Privacy
The Service is not directed to anyone under 16, and we do not knowingly collect Personal Data from anyone under 16. Individual Merchant apps on the Merchie platform set their own App Store / Google Play age ratings based on the services they offer; regardless of the rating, the underlying account-creation flow enforces a minimum age of 16. If you are a parent or guardian and you believe your child under 16 has provided us with Personal Data, please contact us at herrisellc@gmail.com and we will delete that information promptly. If your local law (for example, GDPR Article 8) sets a higher minimum age, that age applies in your jurisdiction.
21. Health Information Disclaimer
The Service is a loyalty and rewards application. It is not a health record, electronic medical record, or other healthcare-information system, and Merchie is not a "covered entity" or "business associate" under the U.S. Health Insurance Portability and Accountability Act (HIPAA). Please do not enter medical history, diagnoses, treatment notes, prescriptions, or other protected health information into the Service. The optional AI Skin Analysis and AI advisor provide cosmetic guidance only — they are not medical tools, and their suggestions are not medical advice, diagnosis, or treatment. If you believe a Merchant has invited you to share health information through the App, contact the Merchant or us before doing so.
22. Business Transfers
If Merchie is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or a portion of its assets, your Personal Data may be transferred as part of that transaction. We will notify you (for example, by email or an in-app notice) before your information becomes subject to a different privacy policy.
23. Law Enforcement and Other Legal Disclosures
We may disclose your Personal Data if we believe in good faith that doing so is necessary to: (a) comply with a legal obligation, subpoena, court order, or government request; (b) protect and defend the rights or property of Merchie, a Merchant, or third parties; (c) prevent or investigate possible wrongdoing in connection with the Service; (d) protect the personal safety of users of the Service or the public; or (e) protect against legal liability.
24. Links to Other Sites
The Service may contain links to third-party websites or services that we do not operate — including, where the Merchant offers it, an external financing application with Cherry Technologies, Inc. (see the Terms of Service). We are not responsible for the content, privacy policies, or practices of any third-party site or service. We encourage you to review the privacy policy of every site you visit.
25. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. Material changes will be communicated through the App, by email, or by a prominent notice posted in the Service. Your continued use of the Service after the effective date constitutes your acceptance of the changes.
26. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, you can contact:
- Herrise LLC (d/b/a Merchie)
- Email: herrisellc@gmail.com
- State of formation: Delaware, United States
For questions about a specific purchase, appointment, refund, or other Merchant-controlled matter, please contact the Merchant whose branding appears in the App you are using.