Skip to content
mercer
USUSDSetup docs →Docs
≡
Privacy

What we collect. And why.

Last updated · 2026-09-23

Mercer is a Shopify theme developed by ZBANG LTD. This page covers mercertheme.com — the marketing and documentation site you are on now. It does not cover what your own Shopify storefront collects when you install Mercer. That is governed by Shopify policies and your own.

What we collect

  • Support form submissions — when you contact us via /support, we receive: name, email, store URL, issue type, subject, message, and optional files you attach.
  • Anti-spam verification — we use Cloudflare Turnstile to verify form submissions are not from bots. Cloudflare processes some technical signals (IP, browser fingerprint) to issue verification tokens.
  • Server access logs — Railway (our hosting provider) logs basic HTTP request data, used for debugging and abuse prevention.
  • Support rate limits — our private Redis service on Railway stores counters associated with your IP address to limit spam and repeated submissions. It does not store your contact details, message contents, or attachments.

Optional analytics and marketing

Analytics and marketing are separate choices. Both are off until you give permission, and you can use the site and contact support without accepting either.

  • Analytics — with your permission, Google Analytics 4 measures page views so we can understand how people use the site. Google may process cookie identifiers, page information, and technical information about your browser and connection.
  • Marketing — with your permission, Google Ads and Meta Pixel load to support advertising measurement. Meta receives page-view events. These providers may use cookies and similar identifiers to connect website visits with advertising activity, according to their policies and your account settings.

Our tracking events do not include support form fields, email addresses, hashed email addresses, or attachments. We do not send support submissions as advertising conversions or forward them to advertising providers from our server.

Open Cookie settings in the footer at any time to change or withdraw either permission. See our cookie policy for the categories, browser storage, and retention details.

Preferences and support drafts

We save your cookie choices in a Mercer-specific cookie and local browser storage so we can respect them on later visits. Your chosen light or dark theme is also saved locally. The support form keeps a temporary draft in your tab's session storage so a validation error does not erase your work. Drafts can contain the text you entered, including your contact details, but not attachments or the privacy checkbox. These browser preferences and drafts are separate from optional analytics and marketing. If we cannot reliably save your cookie choice, optional tracking stays off.

How we use what we collect

Support form data is used only to respond to your inquiry. It is sent via Resend (a transactional email service) to our support inbox and to send your confirmation receipt. Attached files are delivered to the support inbox only; the confirmation receipt does not echo them back. We do not use support data for marketing, sell it, or send it to advertising providers.

Retention

  • Resolved support threads — retained for 18 months after the last reply, then deleted from our inbox.
  • Open support threads — retained until resolved.
  • Support rate-limit counters — expire automatically within 48 hours and one second.
  • Server logs— retained according to Railway's plan-dependent log retention policy (opens in a new window).
  • Cookie choices — remembered for 183 days when you reject both optional categories, or 365 days when you accept either. Saving a new choice starts a new period.
  • Support drafts — available in the current tab for up to one hour after the last edit and cleared after a successful submission. Expired drafts are discarded when read.
  • Theme preference — remains in local browser storage until you change it or clear that storage.
  • Optional measurement data — cookie lifetimes and provider-side retention depend on the provider, its account settings, and your choices. Withdrawing permission stops future optional tracking on this site; it does not undo processing that has already occurred.

Your rights

You can request a copy of your data, correct it, or delete it. Email privacy@mercertheme.com and we will respond within 30 days.

If you are in the EU, UK, or California, you have specific rights under GDPR, UK-GDPR, and CCPA respectively, including the rights of access, rectification, erasure, restriction, portability, and objection. The contact above is the way to exercise them.

Third parties

The services that touch your data on this site:

Updates

If we change this policy materially, we update the date at the top. The last-updated stamp is the definitive version. Significant changes get a banner notice for 30 days.

Contact

ZBANG LTD · privacy@mercertheme.com