Data processing
Data processing terms built around merchant control.
These public data-processing terms describe Metrico's baseline commitments when it processes personal data on behalf of a merchant through the service. Contract-specific terms or an executed order form can supplement them.
Last updated: September 30, 2026
Roles
For merchant data submitted or synchronized to provide Metrico features, the merchant determines why that data is used and Metrico processes it to provide the service. For Metrico's own account administration, security, fraud prevention, and service operations, applicable privacy law may assign different roles.
Documented instructions
Metrico processes merchant data to deliver the features the merchant enables, including synchronization, analytics, reporting, product-to-ad analysis, first-party behavior analysis when enabled, and support. Connecting or disconnecting a supported provider is part of those instructions.
Confidentiality and access
Access to production systems and merchant data should be limited to people and systems that need it to operate, secure, support, or improve the service. People with access are expected to be bound by appropriate confidentiality obligations.
Security
Metrico uses technical and organizational measures intended to protect merchant data, including authenticated access, provider authorization boundaries, protected credentials, tenant-aware application controls, operational logging, and data-quality safeguards. See the security page for the product-level security model.
Subprocessors
Metrico may use infrastructure and service providers to host, secure, monitor, communicate, and operate the service. Those providers are expected to process data only for the contracted service purpose. See the subprocessor page for the current public disclosure model.
Data-subject requests
Where Metrico processes personal data for a merchant, the merchant remains the primary point of contact for its customers. Metrico will provide reasonable assistance available through the service and support channels so the merchant can respond to valid access, correction, deletion, restriction, or portability requests that apply to its data.
Deletion and return
On verified account deletion, applicable merchant data is scheduled for deletion subject to security, backup, fraud-prevention, dispute, and legal-retention requirements. Disconnecting a provider stops future synchronization but does not by itself guarantee immediate deletion of previously synchronized data. See data deletion.
International processing
Infrastructure providers can process data in more than one country. Where applicable law requires a transfer mechanism, Metrico and its providers should rely on an appropriate contractual or legal transfer mechanism for the relevant processing.
Incident cooperation
If Metrico confirms a security incident affecting merchant personal data, it will use the available merchant contact channels to provide information reasonably necessary for the merchant to meet its own obligations, consistent with investigation and security needs.
Contact
Questions about data-processing terms or a contract-specific DPA can be submitted through the contact page.