Privacy Policy

Version: 2026-09-02.1 · Effective date: September 2, 2026

Effective date: 2026-09-02 Last updated: 2026-09-02

MERO Consulting Inc. (“MERO,” “we,” “us,” or “our”) provides MeroFoundry, a hosted low-code backend platform (the “Service”). This Privacy Policy explains what information we collect, how we use and disclose it, how long we retain it, and your rights when you use our website, dashboard, API, SDKs, Model Context Protocol (MCP) server, public registration, or subscription checkout.

Two roles. MERO handles information in two distinct capacities:

  1. As a controller (or, where applicable, a “business”) for account, billing, usage/metering, security, and support data about our direct Customers and their team members (“Account Data”).
  2. As a processor (or, where applicable, a “service provider” or “contractor”) for data that our Customers store, process, or transmit through the Service on behalf of their own end users or customers (“Customer Application Data”). We process Customer Application Data only on the Customer’s instructions and under the Terms of Service and any Data Processing Addendum (“DPA”) that is effective with that Customer.

If you are an end user of a MeroFoundry Customer’s application (not a direct MERO Customer), your data is controlled by that Customer, and you should direct privacy requests to that Customer; see Section 8.

1. Information We Collect

1.1 Account Data (collected directly from Customers)

  • Identity/contact: company or workspace name, first and last name, email address, and billing contact information, if provided.
  • Authentication: hashed passwords, email-verification status, API keys, JWT tokens, session identifiers, and SSO identifiers (where applicable).
  • Billing: plan and subscription information, billing interval, payment status, transaction identifiers, tax information, and limited payment-method metadata processed through Stripe-hosted pages. We do not store full payment-card numbers; see Section 4.
  • Support/communications: content of support tickets, emails, or in-product messages.

1.2 Usage and Metering Data

  • API request logs (endpoint, timestamp, response code, tenant/API-key identifier), rate-limit and quota consumption (including API calls, storage, automation runs, and public-auth sessions), feature usage, and device/browser metadata (including IP address and user agent).
  • This data is used for billing, entitlement enforcement, security, abuse prevention, troubleshooting, product operation, and capacity planning.

1.3 Customer Application Data (processed as a processor, on Customer’s behalf)

  • Whatever the Customer configures the Service to store or process: records in Customer-defined data models, uploaded files/assets, vector embeddings, rule/automation execution data, and content the Customer directs to a connected AI provider, including prompts and completions.
  • We do not control the content or categories of Customer Application Data; those are determined by the Customer and its end users. The Customer is responsible for its privacy notices, lawful basis, instructions, and compliance with the Terms’ prohibited-data restrictions. We do not use Customer Application Data to train our own general-purpose AI models.

1.4 Cookies and similar technologies

We use cookies and local storage for authentication sessions, CSRF protection, security, preferences, and Service operation. Public registration uses Cloudflare Turnstile and a honeypot for bot protection. We do not use third-party advertising cookies or nonessential third-party analytics cookies at launch. See Section 9.

2. How We Use Information

We use Account Data and Usage/Metering Data to: provide, operate, secure, and support the Service; create and administer accounts; verify email addresses; authenticate requests; enforce tiers, quotas, and rate limits; prevent fraud, bots, and abuse; process subscriptions, cancellation, payments, and taxes through Stripe; send service, transaction, security, and legal notices; comply with law; and establish or defend legal claims. We use aggregated or de-identified usage data for product analytics and capacity planning.

We process Customer Application Data solely as instructed by the Customer to provide the Service, including storing files, executing rules, and transmitting selected information to a customer-connected AI provider at the Customer’s direction. We do not use Customer Application Data to train our own models, and we do not sell it. See any DPA that is effective with the Customer for additional processor obligations.

3. Legal Bases (EEA/UK Users)

Where and to the extent the GDPR or UK GDPR applies, our legal bases may include performance of a contract (providing the Service), legitimate interests (security, fraud prevention, and product operation), legal obligation (including tax and accounting records), and consent where required. For Customer Application Data, the Customer determines the applicable legal basis and MERO acts on the Customer’s documented instructions.

4. Service Providers, Customer-Directed Services, and Other Disclosure

To operate the Service, we disclose information to service providers that support hosting, payments, subscriptions, taxes, and bot protection. Customers may also direct the Service to transmit Customer Application Data to providers they select and connect. MERO may maintain a current service-provider or subprocessor list at merofoundry.com/legal/subprocessors.

CategoryPurposeData sharedExamples
Customer-directed AI providersFulfilling Customer-configured AI calls at the Customer’s directionPrompt content and other Customer Application Data selected by the CustomerProvider accounts and credentials selected and supplied by the Customer; not a MERO subprocessor solely because the Customer connects it
Cloud infrastructure and object storageCompute, database, network, DNS, and MERO-operated object storageInformation hosted or transmitted through the ServiceLinode LLC (an Akamai Technologies company), U.S. regions; MERO-operated MinIO / S3-compatible storage
Payment processorHosted checkout, payment processing, subscription billing, customer portal, invoicing, and tax calculation if enabledBilling contact information, transaction and subscription data, tax information, and payment-method tokens (not full card numbers)Stripe, Inc. or the applicable Stripe entity
Bot protectionDetecting automated or abusive public registration activityIP address, browser and device signals, user agent, network or country information, challenge events, and short-lived identifiersCloudflare Turnstile
MERO-operated servicesTransactional email, source-code hosting, and object-storage operationAccount, communication, code, and file information as applicableCompany-operated mail, git, and MinIO services; no third-party advertising, product-analytics, error-monitoring, or transactional-email vendor at launch

Customer choice over AI provider. Customers configure and connect their own AI-provider accounts and credentials. MERO does not select or contract with those providers on the Customer’s behalf and transmits Customer Application Data only at the Customer’s direction. The provider’s own terms and privacy practices apply.

Subprocessor changes. If a DPA effective with a Customer requires notice of a new or replaced subprocessor, MERO will provide notice through the mechanism stated in that DPA, which may include an update to the public subprocessor page and email to the account’s designated contact.

We do not sell Account Data or Customer Application Data, and we do not share personal information for third-party targeted or cross-context behavioral advertising.

5. Data Retention

  • Account Data: retained for the life of the account and generally for 90 days after closure, except that billing, transaction, invoice, and tax records may be retained for seven years or another period required by law.
  • Usage/Metering Data: generally retained in identifiable form for 12 months for billing, security, abuse prevention, troubleshooting, and capacity planning, and may then be aggregated or de-identified.
  • Customer Application Data: retained according to the Customer’s instructions, account status, and applicable terms. Following account closure or termination, data is ordinarily available for export for 30 days and deleted from active systems within 30 days after the applicable export or deletion period, subject to legal, security, fraud-prevention, and dispute-related retention.
  • Backups: operational backups are retained on a seven-day rolling basis. Deletion requests are honored in active systems as described above, and backup copies ordinarily age out within the standard seven-day backup cycle.
  • Logs: infrastructure, access, and security logs are generally retained for 90 days, subject to longer retention for an incident, investigation, dispute, or legal requirement.

6. Security

We maintain administrative and technical safeguards designed to protect information, including:

  • TLS encryption for information transmitted to and from the Service.
  • Encryption at rest for service credentials.
  • Role-based access controls and audit logging.
  • Automated dependency, secret, and container scanning in the development and build process.
  • Customers are responsible for configuring their applications, roles, credentials, integrations, and access controls appropriately and for complying with the Terms’ prohibited-data restrictions.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Any breach-notification commitment applies only under a DPA or other agreement effective with the applicable Customer.

7. International Data Transfers

The Service is currently intended for U.S.-focused business use and is hosted in United States regions. If you access the Service from another country, information may be transferred to and processed in the United States, where laws may differ. MERO does not currently represent that the Service is configured for regulated international transfers or targeted to individuals in the European Economic Area, United Kingdom, or Switzerland. Customers requiring international transfer terms should contact MERO before using the Service for that purpose.

8. Your Rights

If you are a MERO Customer (Account Data): depending on your jurisdiction and whether an applicable privacy law covers MERO, you may have rights to access, correct, delete, or obtain a copy of personal information, or to object to or restrict certain processing. Submit requests to privacy@meroconsulting.com. We may verify your identity and authority and may deny or limit a request where permitted by law.

If you are an end user of a MeroFoundry Customer’s application (Customer Application Data): MERO generally processes this data for the Customer. Please direct your request to the Customer or business you interacted with. If you contact us, we may refer the request to that Customer and provide assistance as required by applicable law or an effective DPA.

Self-service: account owners may access and update certain Account Data through the Service and may use then-available dashboard or API tools to export or delete Customer Application Data, subject to plan, security, contractual, and legal limitations.

U.S. state privacy rights: depending on your state, the law’s applicability thresholds, and your relationship with MERO, you may have rights to access, correct, delete, or obtain a copy of personal information and to appeal a request decision. MERO does not sell or share personal information for targeted or cross-context behavioral advertising.

EEA/UK users: where applicable law provides the right, you may lodge a complaint with the supervisory authority in your country or region.

9. Cookies

We use strictly necessary cookies and local storage for authentication, sessions, security, CSRF protection, preferences, and Service operation. Cloudflare Turnstile may process IP address, browser and device signals, user-agent information, network or country information, challenge events, and short-lived identifiers to detect automated activity. We do not use third-party advertising cookies or nonessential third-party analytics cookies at launch. If those practices change, we will update this Policy and implement any consent or preference mechanism required by applicable law.

10. Children’s Privacy

The Service is intended for business use by persons age 18 and older and is not directed to children. We do not knowingly collect personal information directly from children under 13. Customers may not use the Service to collect or process children’s data in violation of the Terms or applicable law. If you believe a child provided personal information directly to MERO, contact privacy@meroconsulting.com.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version and effective date and provide at least 30 days’ notice of a material adverse change by email, in-dashboard notice, or another reasonable method. Changes reasonably necessary for legal, security, or abuse-prevention reasons may take effect sooner.

12. Contact

Privacy questions or requests: privacy@meroconsulting.com. MERO Consulting Inc., 2355 State St, East Petersburg, PA 17520.