Privacy
This site sets no cookies. The plugin makes no outbound connections at all. That is most of the policy — the rest is detail you are welcome to check.
Updated 30 September 2026 — the full scan with a code: what we record when a code is activated or sold, and how long the result lives; a counter of visits through short addresses (merchlint.com/o/…) and failed checks in the journal. 29 September 2026 — new section on the free catalogue audit.
Who is responsible for your data
Behind Baltano, publisher of the Merchlint plugin, stands one person, and that person is the
controller of the personal data described on this page. Everything to do with data goes to
contact@merchlint.com — questions, corrections, requests to delete something. We answer from the
same address, and it reaches the person who wrote the code. There is no data protection officer,
because the scale of processing described below does not call for one.
The plugin
Merchlint makes no outbound connections. Not to us, not to anyone. It has no account, no sign-up, no licence check and no telemetry — not even anonymous usage counts. Nothing about your store, your catalogue, your orders or your customers reaches us or any third party, because there is no code in the plugin capable of sending it.
This is checked by an automated gate on every build, and it is required by the WordPress.org plugin directory guidelines, which prohibit phoning home without explicit consent.
Everything the plugin stores stays in your own database: the scan results table and the list of findings you chose to hide. Uninstalling removes both, across every site of a multisite network.
One clarification about links. From version 0.2.1, findings in the plugin link to the matching explanation on this site. Those are ordinary links: nothing is sent until you click one, and then it is your browser making the request, exactly as if you had typed the address. The link carries one parameter — your site’s language, so you land on the right version of the page. It carries no domain, no version, no identifier of any kind.
This site
No cookies are set. There is no consent banner because there is nothing to consent to. One exception belongs to the hosting provider: during a detected attack it may ask your browser to pass a check that needs a cookie (once a day) — protection against automated traffic, not tracking. A second exception does not concern visitors: the panel where the service’s owner issues full-scan codes sets a session cookie only after the owner signs in, and only on its own path.
Analytics. We use Cloudflare Web Analytics — no cookies and no cross-site identifiers; it does not recognise people by IP address or browser. It tells us how many people visited a page, where they came from and roughly where they are (country level). It cannot identify you, and it does not follow you anywhere else. It shows data for the last 6 months. The provider is Cloudflare, Inc. (USA) — the only recipient outside the European Economic Area; it is certified under the EU-U.S. Data Privacy Framework, so the transfer relies on the European Commission’s adequacy decision of 10 July 2023.
Hosting. The site is a set of static files on a web server. Like every web server on earth, it processes request data — your IP address, the page requested, your browser’s user agent — in order to send you the page, and keeps it briefly in access logs for security and abuse prevention. There is no database, no application and no session behind these pages — with one exception, described in the section below: the store check you start yourself.
Fonts are hosted here. The typefaces come from this domain, not from Google Fonts or any other font service. Apart from the analytics beacon above, a page makes no requests to third parties — no images, scripts or stylesheets are loaded from anywhere else.
No embeds, no trackers, no advertising pixels, no chat widget. If a page ever embeds something external — a video, for instance — it will say so on the page itself.
Storefront Scan — checking a store without installing
This is the only place on this site with a running application behind it. You start it yourself by entering a store address, and it takes a dozen seconds or so — a full scan with a code up to two minutes.
What we fetch. Only public data of the store whose address you gave: its robots.txt, up to 150
products (up to 2,000 with a full-scan code) and the category list, through the same public API the
store’s own cart uses, and the headers of three product pages — to check that they open. A full scan
also asks for the headers of the main images of 40 products — the file size only, without downloading
the images. We sign in nowhere and change nothing in the store.
What we store, and for how long:
| What | Where | How long |
|---|---|---|
| The result: store domain, finding counts, up to five example product names per finding with links to those products, and whether product pages open | a page at an address that cannot be guessed, not indexed | 7 days, then gone |
| A full-scan result (with a code): the same, but with the complete list of product names and links for every finding — to the product and to editing it in the store admin — also as a CSV file | a page at an address that cannot be guessed, not indexed | until the end of access — 30 days from activating the code, or longer if an offer with a group or partner code says so (terms, section 13); then gone |
| A journal line: date, store domain, counts or the reason the check failed, which site you came from (the site name only) and through which short address, if any | with us, never published | indefinitely |
A visit through a short address, e.g. merchlint.com/o/al1 from a listing or a post: date, which place it is, and whether a person or an automated client came (by the browser’s name) — no IP address, nothing about you | with us, never published | indefinitely |
| Counter for the check, code-activation and wrong-code limits: a hash of the IP address, not the address itself | with us | one day |
| A full-scan code activation: store domain, code, activation date and end of access, the short address you came through, ids of the full-scan results | with us, never published | indefinitely |
| A purchased code: the code, date and amount of the sale, the transaction number from the listing site — not the buyer’s name, username or email | with us | 5 years from the end of the tax year — the sales record requires it |
| A hit on the activation or wrong-code limit: date, which limit, the code — no IP address | with us, never published | indefinitely |
| Working data of the scan | with us | deleted on completion, at most one hour |
| A click through to the plugin: date, the checked store’s domain and the result id — no IP address, nothing about who clicked | with us, never published | indefinitely |
What we do not store. Your store’s content beyond those few example names — no prices, no descriptions, no images. Your customers’ data (the public API does not expose it and we do not go looking). An email address, because we never ask for one. The IP address in the journal — everything is there except that. For a purchased code — your name, username or email address: those stay with the listing site where you bought the code, under its rules.
What we never publish: store names. If we ever show numbers from these scans, they will be aggregates without names, with the method and sample size stated. The directory holding the journal is cut off from the web, and the service checks that itself and refuses to work if it ever stops being.
Legal bases. Performing the service you asked for — Article 6(1)(b) GDPR. Limits that guard against abuse and against overloading other people’s servers — Article 6(1)(f), our legitimate interest and that of the owners of the stores being checked. The register of purchased codes — performing the contract (point (b)) and the legal duty to keep a sales record (Article 6(1)(c)).
One note about the store address itself. It is usually business data rather than personal data. With a sole trader it can nevertheless point to a particular person, so we treat it as carefully as personal data and do not publish it.
The rules for using the service are in the terms.
If you write to contact@merchlint.com, your message and address sit in a mailbox until the
conversation is done, and are kept afterwards only as long as they are useful for support history.
They are not added to any mailing list, because there is no mailing list.
Free catalogue audit
Until 15 November 2026 we review plugin exports from up to ten stores, on request; the offer is on the Polish side of this site (darmowy audyt). If you send us an export, the file reaches us because you send it — the plugin itself still makes no connections.
- What is in the file: product names, amounts and links to edit screens in your store’s admin. No data about your customers.
- Who reads it: the person who answers the email, and a small script on their computer. Apart from the mailbox, the file goes to no other service, AI tools included.
- How long we keep it: 30 days after we reply, or less if you ask. The correspondence itself is kept like any other email (section above).
- What we don’t do with it: we don’t publish the file or the store’s name. Numbers from your store go into any summary only with your separate consent.
Legal basis: performing the service you asked for — Article 6(1)(b) GDPR.
Your rights
Under the GDPR you may ask what personal data we hold about you, ask for a copy, ask for it to be
corrected or deleted, and complain to a supervisory authority. In practice the only personal data
we are likely to hold is an email conversation you started — and a transaction number, if you bought
a full-scan code. Write to contact@merchlint.com.
Controller: Baltano, publisher of Merchlint. Contact: contact@merchlint.com.
Changes to this page
If this policy changes, the date at the top of this page changes with it. Material changes will be noted in the changelog as well, so they are not made quietly.