Privacy Policy | MergeOS
Legal

MergeOS Privacy Policy

How we collect, use and protect your information — and your customers' information — when we build and run your document automation.

Last updated: 21 July 2026

The privacy of your data — and it is your data, not ours! — is a big deal to us. Because MergeOS is a done-for-you service, our team accesses your account and works with your files as part of your engagement: building your templates, configuring your business logic, testing your workflow, and investigating any problem you report. Outside of that work, we'll never open your files or access your account. We log all access to all accounts by IP address, so we can always verify that no unauthorized access has happened for as long as the logs are kept.

Identity & access

When you enquire about MergeOS or book a discovery call, we ask for your name, company name, and email address. That's so we can talk to you about your project and send you proposals, invoices, updates, or other essential information. We'll never sell your personal info to third parties. As described in our Terms of Service, we may identify you as a client (name and logo) in our marketing — tell us if you'd rather not be named and we'll respect that. We won't publish details of your workflow, results or a testimonial without your permission.

During an implementation engagement you provide us with materials — existing documents, branding, data samples, and access to relevant systems. We use these only to build and run your solution, and we treat them as confidential as set out in our Terms of Service.

When you pay for MergeOS — whether by credit card or invoice — we ask for your billing details. If you pay by credit card, your card is passed directly to our payment processor and doesn't ever go through our servers. We store a record of the payment transaction, including the last 4 digits of the credit card number, for account history, invoicing, and billing support. We store your billing address to calculate any taxes due in Australia, to detect fraudulent transactions, and to print on your invoices.

When you write MergeOS with a question or to ask for help, we'll keep that correspondence, and the email address, for future reference. When you browse our marketing pages, we'll track that for statistical purposes (like conversion rates and to test new designs). We also store any information you volunteer, like surveys, for as long as it makes sense.

The only times we'll ever share your info:

  • To provide products or services you've requested, with your permission.
  • To investigate, prevent, or take action regarding illegal activities, suspected fraud, situations involving potential threats to the physical safety of any person, violations of our Terms of Service, or as otherwise required by law.
  • If MergeOS is acquired by or merged with another company — we don't plan on that, but if it happens — we'll notify you well before any info about you is transferred and becomes subject to a different privacy policy.

Your customers' data

The document workflows we build and run for you often process personal information about your customers — answers submitted through your forms and quizzes, records you upload, and data sent from your systems via the API. For that information, you are the controller and we are a processor: we use it only to run your workflow and generate and deliver your documents, on your instructions. We never use your customers' data for our own purposes, and we never sell it or share it with anyone except the processors listed below, to the extent needed to provide the Service.

You are responsible for making sure you have the necessary rights and consents to collect your customers' information and have it processed through the Service. If one of your customers contacts us directly about their personal information, we'll refer them to you, unless the law requires otherwise.

Your Rights With Respect to Your Information

MergeOS is an Australian company, and we handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (“APPs”). Under Australian privacy law you have certain rights with respect to the personal information we hold about you:

  • Right to know what we collect and why. You're entitled to know what personal information we collect, why we collect it, how we use it and who we may disclose it to. This policy exists to tell you exactly that, and you can always ask us for more detail.
  • Right of Access. You can request access to the personal information we hold about you, and we'll provide it within a reasonable period unless a specific legal exception applies (if one does, we'll tell you why).
  • Right to Correction. If the personal information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, you can ask us to correct it and we will take reasonable steps to do so.
  • Right to Anonymity. Where it's lawful and practicable, you can deal with us anonymously or under a pseudonym — for example, when making a general enquiry. Most of the Service does require an identified account to function.
  • Right to opt out of direct marketing. You can opt out of marketing emails at any time using the unsubscribe link in the email or by contacting us, and we'll stop. This is in line with the Privacy Act and the Spam Act 2003 (Cth). Essential service emails (invoices, security notices) will still be sent.
  • Right to be notified of data breaches. Under the Notifiable Data Breaches scheme, if a data breach involving your personal information is likely to result in serious harm, we will notify you and the Office of the Australian Information Commissioner (“OAIC”) as required.
  • Right to Complain. If you believe we've mishandled your personal information, contact us first and we'll do our best to resolve it. If you're not satisfied with our response, you can complain to the OAIC.

Many of these rights can be exercised by signing in and directly updating your account information. If you have questions about exercising these rights or need assistance, please contact us at support@mergeos.com.

If you're located outside Australia — for example in the European Union or United Kingdom, where the GDPR gives you additional rights such as erasure and data portability — we'll honour reasonable requests to exercise equivalent rights, subject to applicable law. In practice we offer everyone the same deal: your data is yours, you can get a copy of it, and you can have it deleted (see “Deleted data” below).

Processors we use

As part of the services we provide, and only to the extent necessary, we may use certain third party processors to process some or all of your personal information. For identification of these processors, and where they are located, please see the listing below.

Law enforcement

MergeOS won't hand your data over to law enforcement unless a court order says we have to. We flat-out reject requests from law enforcement when they seek data without a court order. And unless we're legally prevented from it, we'll always inform you when such requests are made.

Security & Encryption

All data is encrypted via SSL/TLS when transmitted between our servers and your browser or systems — including data submitted through your forms and the API. The database backups are also encrypted. Data isn't encrypted while it's live in our database (since it needs to be ready to send to you when you need it), but we go to great lengths to secure your data at rest.

Deleted data

If you cancel the Platform Service, your content becomes inaccessible at the end of your final billing period. Within 30 days it is permanently deleted from our active systems and logs, and within 90 days from our backups. Anything you delete while your account is active will also be purged from our active systems within 30 days. Generated documents are automatically removed after their expiry period as part of normal operation.

Location of Site and Data

This Site is operated in Australia. If you are located in the European Union, the United States or elsewhere outside of Australia, please be aware that any information you provide to us will be transferred to Australia. By using our Site, participating in any of our services and/or providing us with your information, you consent to this transfer.

Changes & questions

MergeOS may update this policy once in a blue moon — we'll notify you about significant changes by emailing the account owner or by placing a prominent notice on our site. You can access, change or delete your personal information at any time by contacting our support team.

Questions about this privacy policy? Please get in touch and we'll be happy to answer them!

Adapted from the Basecamp open-source policies / CC BY 4.0

Questions about your data?

Email support@mergeos.com and we'll be happy to answer them. Or if you're ready to talk about a project, book a 15-minute call.