MercExe ("we", "us") provides an AI driven supply chain ERP and this website. Our office is at #228, 4th Avenue, Pearl City, Muthanallur, Bengaluru 560099, Karnataka, India.
This policy explains how we handle personal data when you use www.mercexe.com, www.mercexe.in, MercExe Supply Chain ERP on the web (erp.mercexe.in), the Windows desktop app, or the Android apps.
1. Who this applies to
This policy applies to:
- Visitors who use this website, including people who send us a message.
- People who sign in to MercExe Supply Chain ERP for a customer organization.
- People whose details a customer organization stores in MercExe Supply Chain ERP, such as customers, vendors, shippers, and contacts.
If a business that uses MercExe Supply Chain ERP holds your details, that business decides what is entered and why. Send requests about those records to that business. We assist that business when we are required to.
2. Our role
| Data | Role |
|---|---|
| Messages you send through the website contact form | MercExe is the Data Fiduciary. |
| Sign-in accounts, product diagnostics, and support messages sent to MercExe | MercExe is the Data Fiduciary. |
| Business records a customer organization enters (parties, contacts, transactions, documents) | The customer organization is the Data Fiduciary. MercExe processes that data to provide the service. |
3. Personal data we use
Website. If you contact us, we receive your name, email address, business name, and message.
Account and access. MercExe Supply Chain ERP stores your name, username, and email, your Microsoft sign-in identity, your role, organization, and facility, and session and device information used to sign in, open a register, and work offline.
Business records entered by the organization. These can include names, email addresses, phone and mobile numbers, job titles, postal addresses, map coordinates, remarks, PAN, GSTIN, and bank details such as account number, IFSC, and UPI ID, plus sales, purchase, inventory, payment, and shipment records that identify a person.
Files and messages. Documents uploaded for invoice or bill extraction. Email the organization sends through a mail account it configures. WhatsApp Business settings and messages when the organization connects WhatsApp.
Product operation. Error and diagnostic events such as source, operation, and status. We intend these events to leave out business content. An error message or request URL can still contain an identifier. The app also stores settings on the device, such as print layouts and import progress.
We do not ask for Aadhaar numbers. Do not enter them into the product.
4. How we use personal data
- Reply to messages sent from this website.
- Authenticate users and apply their role and facility access.
- Run purchase, inventory, warehouse, sales, POS, ecommerce, and accounting.
- Keep a local copy so the app can work offline and sync when a connection returns.
- Extract data from uploaded invoices and similar documents when that feature is used.
- Show maps and place search when location features are used.
- Send email or WhatsApp messages when the organization turns those channels on.
- Diagnose failures, secure the service, and answer support requests.
- Meet legal duties that apply to MercExe.
We do not sell personal data. We do not use it for third-party advertising.
5. Where data is stored
Application data is stored in MercExe services hosted on Microsoft Azure. Production diagnostics are sent to Azure Application Insights in the South India region. Automatic page, click, and network tracking in the browser is turned off. Errors are recorded when the application reports them.
The web app and the desktop app keep a local copy so work can continue offline:
- Sign-in tokens and some settings are stored in browser local storage.
- Short-lived sign-in state may be stored in session storage.
- Business data for offline use is stored in the browser database or in the desktop app's local database, then synchronized to MercExe services.
Anyone with access to that device or browser profile can reach data stored there. Sign out on a device you control.
6. Who else receives data
| Recipient | Purpose |
|---|---|
| Web3Forms | Delivers website contact-form messages to MercExe |
| Microsoft (Azure, Entra External ID, Application Insights) | Hosting, sign-in, and diagnostics |
| Google Maps | Address and place search, and map display, when those features are used |
| Google (Gemini) | Document extraction when invoice or bill extraction is used |
| The organization's email provider | Outbound email when mail is configured |
| Meta (WhatsApp Business) | Messages when WhatsApp is connected |
| The customer organization and its administrators | Access to that organization's own records |
We may also disclose data if the law requires it, or to protect the rights, safety, and security of MercExe, our customers, and others.
7. How long we keep data
- Website messages are kept for as long as needed to respond and to keep a record of the enquiry.
- Business records are kept for the life of the customer organization's subscription, and then for the period needed to finish export, backup expiry, and legal retention.
- Sign-in tokens remain on the device until sign-out, expiry, or clearing site data.
- Diagnostic events follow the retention period set in Azure Application Insights.
- Support correspondence is kept for as long as needed to resolve the request and meet record-keeping duties.
8. Security
Access to MercExe Supply Chain ERP is through Microsoft sign-in and organization roles. Data in transit uses HTTPS. Offline copies remain on the device until they are removed by sign-out, uninstall, or clearing site data. Administrators should limit each person's role to the access that person needs.
9. Children
MercExe Supply Chain ERP and this website are for businesses. We do not direct them at children, and we do not knowingly create accounts for anyone under 18.
10. Your rights
Where MercExe is the Data Fiduciary, you may ask us to:
- Confirm whether we process your personal data and provide a summary of it.
- Correct inaccurate or incomplete data.
- Erase personal data, subject to legal retention and to the customer organization's instructions where that organization controls the record.
- Withdraw consent where processing is based on consent.
- Nominate another person to exercise your rights if you die or become unable to do so.
- Raise a grievance with us, and then with the Data Protection Board of India.
Write to info@mercexe.com. We verify the request before we act on it. If the data sits in a customer organization's account, we direct you to that organization or act on its instruction.
11. Changes
We post updates on this page and change the effective date. If a change materially affects processing for which MercExe is the Data Fiduciary, we give notice through the product or by email where we have a contact address.
12. Contact and grievance redressal
MercExe
#228, 4th Avenue
Pearl City, Muthanallur
Bengaluru 560099
Karnataka, India
Email: info@mercexe.com
Phone: +91 99800 17897
Product support: support@mercexe.com
Grievance Officer under the Digital Personal Data Protection Act, 2023. Write to info@mercexe.com or call +91 99800 17897. We acknowledge grievances and work to resolve them within the time the DPDP Rules require.
