Version 2026-09-16 ยท Effective 2026-09-16

Merqo Privacy Policy

This Privacy Policy explains how Merqo collects, uses, discloses, and retains personal data across the Merqo family of small-business software tools (qkit, loopkit, paykit, stockkit, printkit, and any other product Merqo launches under the Merqo name, each a "Kit" and together the "Service"). It applies to vendors who create a Merqo account and to the end customers of those vendors. It should be read together with our Vendor Terms of Service.

Our roles: controller and data intermediary

Merqo is the data controller for the following categories of personal data, because we determine the purpose and manner of processing them ourselves:

For a different category of data, Merqo acts as a data intermediary, processing personal data only on the vendor's written instruction (including instructions given through a vendor's own configuration of a Kit): the day-to-day order, booking, loyalty-stamp, and stock records a Kit generates for a vendor's business. For that category, the vendor is the data controller. The vendor is responsible for giving their end customers the notices the Personal Data Protection Act ("PDPA") requires and for obtaining any consent the vendor needs before collecting, using, or disclosing that data through a Kit.

What we collect

From a vendor, when they create and use a Merqo account: name, email address, business or stall name, social media or website links, and payment plan.

From a vendor's end customers, because a vendor uses a Kit to serve them: phone number, name, Telegram chat ID (where the end customer connects Telegram), order or booking history, and, for loopkit's birthday-bonus feature, birthdate (day and month, used to time a loyalty reward).

Referral host data: loopkit's referral mechanic lets a vendor enter a referral host's phone number (a named individual who is not necessarily an existing customer, and who has no direct relationship with Merqo), so that a referral reward can be tracked and, where Telegram is connected, notified. We treat a referral host's phone number with the same protection as any other personal data we hold, even though the referral host has not themselves signed up to any Kit.

Why we collect it

Each category above is collected for a specific purpose:

Cross-kit customer identity

merqo.customers is the shared record that lets an end customer's phone number and, where connected, Telegram chat ID be recognised across every Kit they interact with, so, for example, a transactional notification reaches them regardless of which Kit triggered it, and they are not treated as a stranger the first time a second vendor uses a different Kit to serve them.

Where an end customer connects their Telegram account to a vendor's Kit, we capture their consent to that connection at the point they connect it. The Telegram connection flow itself is the consent step, and /stop (see Our Telegram bot below) withdraws it.

Known gap. An end customer who only ever gives their phone number to a vendor, and never connects Telegram, has not gone through an explicit consent step for being linked into the cross-kit customer-identity store today. We are aware of this gap, we are tracking it, and it is not yet fixed; we do not claim an explicit consent mechanism exists for phone-only linkage until it is actually built. Until it is fixed, an end customer in this position can exercise the rights described in Your rights below by contacting us directly.

Our Telegram bot

Merqo operates one Telegram bot, used for one purpose: transactional order and reward alerts to end customers, and vendor activity alerts to vendors. The bot is never used to send marketing messages to anyone.

Sending /stop to the bot disconnects a chat from Merqo and stops further messages to it. Sending /privacy returns a link back to this Privacy Policy. Because Telegram is a third-party service, data we send to it (a message's content and the recipient's Telegram chat ID) is processed on Telegram's infrastructure outside Singapore, subject to Telegram's own privacy policy (see Who we share it with below).

Cookies

We use two kinds of cookie, and no others:

We do not use third-party advertising or tracking cookies.

Who we share it with

We share personal data with the following sub-processors, each acting under their own terms of service and privacy policy, and each engaged only to the extent needed to provide the Service:

We do not sell personal data, and we do not share personal data with any other third party except as described above, as required by law, or with a vendor's or end customer's separate consent.

Where your data is stored

Our infrastructure runs on Supabase and Vercel. Merqo's cloud infrastructure (Supabase, Vercel) is hosted in the Singapore region.

Where a sub-processor listed in Who we share it with processes data outside Singapore (for example, Telegram), that transfer is made on the basis described in this policy and that provider's own terms.

How long we keep it

We keep personal data only as long as needed for the purpose it was collected for, or as required by law:

Audit and security logs

Every Kit keeps an immutable audit trail of admin and vendor actions taken in the Service (for example, changes to a vendor's configuration or an admin action on a vendor's account). An audit log entry can include the actor's email address in its detail, so that an action can be attributed to a specific person.

Audit log rows are retained for 5 years as a legal and security record, and are exempt from a correction request or from deletion on withdrawal of consent: altering or deleting an audit log entry would defeat its purpose as a reliable record of what happened. We state this as policy rather than leaving it silent.

Your rights

Under the PDPA, you can ask us for access to and correction of your personal data, and you can withdraw any consent you have given us to collect, use, or disclose it, by contacting us at the address in Contact and DPO below. The PDPA does not give you a standalone right to demand deletion of your data; where you withdraw consent, we stop collecting, using, or disclosing your personal data for the purpose(s) you withdrew consent for, and, once we no longer need it for any purpose (including a legal or business purpose), we delete or anonymise it, in line with How long we keep it above.

We will act on a valid request as quickly as we reasonably can. Today, fulfilling an access, correction, or consent-withdrawal request at scale is a manual process. We do not yet have a self-serve tool for this, and we do not claim to. Where a request affects data we hold as a data intermediary on a vendor's instruction (see Our roles above), we will direct you to that vendor, or process the request on the vendor's instruction where the vendor has authorised us to.

Some data is exempt from a correction request or from deletion on withdrawal of consent; see Audit and security logs above for the audit-log exemption, and How long we keep it for records we retain as evidence of a contract.

Data breaches

If we become aware of a data breach affecting personal data, we will assess it and, where the PDPA requires, notify the Personal Data Protection Commission ("PDPC") and the affected individuals.

Where a breach affects a vendor's end customer data, we will notify the affected vendor without undue delay, with the information reasonably available to us at the time, so that the vendor can meet their own notification obligations to the PDPC and to their affected customers under Part 6A of the PDPA.

Contact and DPO

Merqo is operated by Clarence Lee, trading as Merqo (sole proprietorship, ACRA registration pending) ("Merqo", "we", "us", "our").

For a question about this Privacy Policy, or to make a request described in Your rights above, contact our Data Protection Officer at legal@merqo.io.