{"pageKey":"Privacy_and_Cookie","slug":"privacyandcookie","locale":"en-US","localeResolved":"en-US","fallbackApplied":false,"version":"privacyandcookie@2026-07-28T20:37:26.571Z","lastModified":"2026-07-28T20:37:26.571Z","canonicalUrl":"https://www.merchandaise.com/en-us/privacyandcookie","payload":{"slug":"privacyandcookie","purpose":"llm-privacy","title":"Privacy and Cookie Policy","description":"This policy explains how Hutter Products GmbH handles personal data across MerchandAise accounts, AI-assisted design sessions, shared project state, quotes, orders, production, support, and cookie choices.","sections":[{"heading":"Privacy and Cookie Policy","paragraphs":["This policy explains how Hutter Products GmbH handles personal data across MerchandAise accounts, AI-assisted design sessions, shared project state, quotes, orders, production, support, and cookie choices.","MerchandAise connects design, collaboration, quoting, buyer-facing sales, and fulfillment through one versioned project workflow. This policy describes what data we handle, why we handle it, which partners receive it, how long we keep it, and the choices and rights available to you.","Effective date: July 28, 2026"]},{"heading":"Policy Sections","items":[{"title":"1. Scope and Source Version","description":"This policy applies to MerchandAise websites and localized routes, accounts and workspaces, design and artwork tools, previews, quotes, order and production workflows, support, embeds, APIs, authorized assistant connections, and other services that link to it. It covers visitors, buyer and organization contacts, designers, supplier and production-partner contacts, developers, support contacts, and other people whose data we handle through those services. The /en-us/ route is the source English version. The route indicates language and regional context; it does not mean that only United States law applies, that all services are available in the United States, or that a United States automated checkout lane is open."},{"title":"2. Controller and Contact Details","description":"The controller is Hutter Products GmbH, Fortunastrasse 5, 9437 Marbach, Switzerland, Swiss enterprise identification number (UID) CHE-284.907.929 (\"Hutter Products\", \"MerchandAise\", \"we\", \"us\"). For privacy questions or rights requests, email privacy@merchandaise.com or write to Privacy, Hutter Products GmbH at the address above. Privacy requests sent to either address are handled by the team responsible for privacy compliance. We will publish any legally required representative or formally appointed Data Protection Officer here if that changes."},{"title":"3. When We Are a Controller or Processor","description":"Hutter Products acts as controller when it determines why and how data is used for Platform operation, account administration, security, product development, buyer-facing sales, quoting, order management, legal compliance, and its own communications. For some enterprise, workspace, API, or embedded services, an organization may control data submitted for its own purposes and instruct Hutter Products to process it on the organization’s behalf. In that case, the organization is the controller, Hutter Products is its processor, and the applicable data-processing agreement and organization privacy notice also apply. The same project can involve both roles. We remain an independent controller for data we must use for our own security, fraud prevention, legal duties, service administration, and merchant-of-record responsibilities."},{"title":"4. Data We Collect","description":"Identity, account, and organization data: name, business contact details, company and club information, role, permissions, sign-in records, language, and account preferences. Project and design data: prompts, messages, product and material choices, logos, artwork, fonts, brand guidance, files, annotations, previews, version history, knowledge references, approvals, and resume or session identifiers. Quote, order, and fulfillment data: requested products, quantities, destination, pricing and quote history, billing and shipping contacts, invoices, payment status, tax and customs information, proofs, sample approvals, production status, delivery events, returns, complaints, and support records. Supplier and production data: supplier-user details, capabilities, certifications or evidence, assignments, production updates, quality records, and private commercial information needed to operate the production network. Device, usage, and communications data: IP address, browser and device information, logs, security events, page and feature interactions, cookie choices, support messages, feedback, and records of consent or Terms acceptance. Please do not upload sensitive personal data, payment-card details, or personal data about others unless it is necessary, lawful, and appropriate for the requested service."},{"title":"5. Where Data Comes From","description":"We receive data directly from you when you browse, create an account, upload or generate content, join a workspace, request a quote, approve a proof or sample, place an order, contact support, or set cookie preferences. We may receive data from your organization administrator, authorized collaborators, buyers, production and logistics partners, payment and identity providers, an assistant or integration you choose, public business sources, and security or compliance service providers. If you give us personal data about another person, you are responsible for having authority and providing any notice required by law."},{"title":"6. Why We Use Data and Our Legal Bases","description":"We use data to provide and secure accounts and workspaces; maintain shared project state; generate and review designs; prepare and manage quotes; accept and fulfill orders; coordinate proofs, genuine production samples, production, delivery, and remedies; provide support; and keep necessary records. We also use data to prevent fraud and misuse, enforce legal terms, debug and improve the Platform, communicate service information, measure consented analytics or marketing, establish or defend legal claims, and meet tax, accounting, customs, product-safety, sanctions, regulatory, and law-enforcement duties. Where the EU/UK GDPR or a similar law applies, our bases may include performance of a contract or pre-contract steps, legitimate interests, legal obligations, consent, and protection of legal claims or vital interests where relevant. We assess and use the basis appropriate to the purpose and jurisdiction. You may withdraw consent at any time. Withdrawal does not affect processing already carried out lawfully, and it does not stop processing needed for a contract, legal obligation, security, or another valid basis."},{"title":"7. AI-Assisted Design and External Assistants","description":"MerchandAise may process prompts, messages, selections, uploads, project knowledge, previews, and version events to provide AI-assisted concepts, file checks, product or material suggestions, workflow support, and resumable project sessions. If you choose a ChatGPT or other external-assistant connection, the data needed to perform your request may pass between that provider and MerchandAise. This can include your prompt, selected project context, tool inputs and results, session or resume identifiers, and action history. The provider’s own privacy notice and your relationship with that provider may also apply. We limit automated access through authorization, scope, and project-state controls. AI results can be incomplete or wrong and are reviewed through the applicable user, human, technical, or production workflow before a consequential order step. You may ask for information or human review if you believe an automated result materially affected your access, order, or legal rights."},{"title":"8. Projects, Proofs, Samples, and Version History","description":"A project may move between the website, an embed, an authorized assistant, a mobile experience, an API client, and human support. We use project identifiers, access controls, version history, and action records to preserve the relevant design, artwork, instructions, quote assumptions, and approvals across those surfaces. We record explicit approval of the applicable digital proof and genuine physical production sample because both are required before mass production. We do not infer production approval from silence. Project data may be retained after a project becomes inactive when needed to resume work, document an approval or accepted quote, handle an order or claim, protect rights, or meet legal recordkeeping duties."},{"title":"9. Payments","description":"Payment providers process payment-card or other payment credentials under their own notices and security responsibilities. Hutter Products receives transaction references, status, amount, payment method summary, fraud signals, and refund or dispute information needed to manage the purchase. Do not enter complete card details in prompts, artwork, support messages, or other general Platform fields. We do not need or intend to store complete card numbers or card security codes in those fields. Payment, fraud, accounting, and tax data may be retained even after an account or design is deleted when required for an order, dispute, audit, or legal obligation."},{"title":"10. Buyers, Suppliers, and Production Partners","description":"Hutter Products is the buyer-facing seller and merchant of record for purchases it accepts under the Terms of Sale. Suppliers and factories support Hutter Products as private production partners rather than acting as buyer-facing sellers merely because they fulfill work. We share with a production or logistics partner only the project, contact, delivery, technical, approval, and compliance data reasonably needed for its assigned work. A partner may not use buyer data, artwork, or private project information for its own marketing or unrelated purposes. We may keep supplier identity, negotiated cost, sourcing, audit, and capacity information private while still giving buyers the disclosures, product information, traceability, and rights required by law or the applicable sales agreement."},{"title":"11. Recipients and Service Providers","description":"Depending on the service, recipients can include authorized workspace members; contracted manufacturers, decorators, quality, warehousing, and logistics partners; payment, identity, fraud, tax, and accounting providers; hosting, storage, communications, support, analytics, and AI providers; professional advisers, insurers, auditors, and authorities. Providers receive only data reasonably needed for their role and are subject to contracts and safeguards appropriate to the service and applicable law. Some recipients, such as payment providers, external assistants, authorities, or an organization you work for, may act as independent controllers for their own purposes. We may disclose data in a corporate transaction or restructuring subject to confidentiality and legally required notice, or when reasonably necessary to protect people, the Platform, rights, and legal claims."},{"title":"12. International Transfers","description":"Hutter Products is based in Switzerland. Data may be processed in Switzerland, the EU/EEA, the United States, and countries where a selected production, logistics, support, or technology partner must perform the requested service. Where a destination does not provide recognized adequate protection, we use an available lawful transfer mechanism such as approved standard contractual clauses with Swiss adaptations, together with supplementary measures where appropriate. Exceptions permitted by law may apply to a transfer you request or one necessary for a contract. The exact production and delivery destination can affect recipients and transfer countries. Contact privacy@merchandaise.com for information about material destinations and a copy or description of applicable safeguards, subject to protection of confidential information."},{"title":"13. Cookies and Similar Technologies","description":"We use cookies, local storage, tags, pixels, and comparable technologies in three categories: essential, analytics, and marketing. Essential technologies support security, authentication, carts, locale, accessibility, consent records, and core functions and are active when needed. Analytics technologies, including consent-aware Google Analytics 4 where configured, measure use and performance only after the relevant choice. Marketing technologies support campaign, conversion, or advertising measurement only after the relevant choice and only when enabled. We do not describe personalization or sustainability measurement as separate cookie-consent categories. Features may remember necessary project state as an essential service function; optional measurement belongs to the analytics or marketing category shown in the consent interface."},{"title":"14. Cookie Choices and Retention","description":"You can accept all, reject non-essential categories, or customize analytics and marketing choices. Essential technologies cannot be disabled through our preference tool because the requested service may depend on them. We store the cookie preference and consent identifier for up to 180 days before asking again, unless you change your choice earlier or a legal or technical change requires a new choice. Withdrawing analytics consent triggers removal of recognized Google Analytics cookies from our domain where technically available. You can also block or delete cookies in your browser. Doing so may sign you out, clear a cart or project preference, or prevent a requested function. A footer or consent control lets you revisit choices when available."},{"title":"15. Retention","description":"We keep personal data only for as long as needed for the purpose collected, an active account or project, an accepted order, security, dispute handling, or legal obligations. We consider record type, sensitivity, risk, contractual commitments, limitation periods, and tax, accounting, customs, product, and consumer-law requirements. Relevant Swiss commercial, order, invoice, tax, and accounting records are ordinarily retained for the legally required period, which can be 10 years. Consent evidence may be kept for up to 730 days; generated privacy-export files for up to 30 days; and records documenting a completed privacy deletion request for up to 365 days, unless a longer hold is required. Short-lived session and authorization tokens expire according to their security purpose. Project, prompt, artwork, support, supplier, analytics, and security records use purpose-based schedules rather than one blanket period. Backups may retain deleted data for a limited cycle before overwrite, subject to restricted use. We may retain anonymized data that can no longer reasonably identify a person."},{"title":"16. Security and Personal-Data Breaches","description":"We use technical and organizational measures appropriate to the data and risk, including access controls, separation of duties where appropriate, transport encryption, credential and session protections, logging, backups, vendor controls, and incident procedures. No service is completely secure. Protect credentials and private project links, use only authorized integrations, and report suspected security issues to security@merchandaise.com. If a personal-data breach occurs, we investigate, contain, document, and notify the competent authority or affected people when and within the time required by applicable law. Under Swiss law, this includes notifying the FDPIC when a breach is likely to result in a high risk and notifying affected people when needed for their protection or when directed."},{"title":"17. Your Rights in Switzerland, the EEA, and the UK","description":"Depending on the law that applies, you may request access, correction, deletion, restriction, data delivery or portability, or object to certain processing. You may withdraw consent and object to direct marketing at any time. You may also ask for information about data sources, purposes, recipients, retention, transfer safeguards, and relevant automated processing. Rights can be limited by another person’s rights, legal privilege, security, an active contract, recordkeeping duties, or other lawful exceptions. Send a request to privacy@merchandaise.com. We may verify identity and authority and will normally respond within 30 days or within the period set by applicable law; complex requests may take longer where the law allows and we will explain the extension. You may complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, where applicable, the data-protection authority for your location or our relevant establishment."},{"title":"18. Other Regional Privacy Rights","description":"Privacy rights vary by location. If another law applies to you, we will honor the rights and disclosures it requires, which may include knowing, correcting, deleting, or receiving data and opting out of targeted advertising, profiling, or a legally defined sale or sharing of personal data. We do not sell personal data for money. If our use of a marketing technology is treated as a \"sale,\" \"sharing,\" or targeted advertising under an applicable United States state law, we will provide the required opt-out mechanism and honor recognized requests where legally required. The California Consumer Privacy Act applies only when its statutory scope and thresholds are met. This policy does not claim that every regional privacy law applies to Hutter Products GmbH merely because the page is available on a localized route. We do not discriminate unlawfully against a person for exercising a privacy right."},{"title":"19. Automated Decisions, Direct Marketing, and Children","description":"We may use automated tools to support recommendations, file checks, fraud and security screening, content moderation, and workflow routing. We do not intend to rely solely on automated processing to make a decision with legal or similarly significant effects unless we give the required notice, basis, safeguards, and review rights. You can opt out of marketing email through the message or your available preferences. Service, security, quote, approval, and order communications may still be sent when needed. MerchandAise is designed primarily for organizations and adults acting for them. It is not directed to children under 16, and we do not knowingly collect their personal data. Contact us if you believe a child submitted data so we can review and take appropriate action."},{"title":"20. Changes and Contact","description":"We may update this policy when our services, partners, laws, or practices change. We will publish the updated date and provide additional notice or request a new choice when required. Earlier processing remains governed by the policy and law applicable at that time. Privacy questions and rights requests: privacy@merchandaise.com. Security reports: security@merchandaise.com. General support: support@merchandaise.com. Postal address: Privacy, Hutter Products GmbH, Fortunastrasse 5, 9437 Marbach, Switzerland. Include enough information for us to identify your relationship with MerchandAise and the request, but do not email passwords or payment-card details."}]},{"heading":"Cookie Preferences","paragraphs":["We use essential technologies to operate and secure MerchandAise. With your choice, we also use analytics and marketing technologies. You can accept, reject, or customize non-essential categories and change your choice later in our {{privacyPolicyLink}}."],"items":[{"title":"Essential","description":"Required for security, sign-in, carts, locale, consent records, and core site functions. Always active."},{"title":"Analytics","description":"Allows consent-aware Google Analytics 4 measurement so we can understand use and improve the service. Off until you choose it."},{"title":"Marketing","description":"Allows campaign, conversion, or advertising measurement when those tools are enabled. Off until you choose it."}]},{"heading":"Privacy and Cookie Questions","items":[{"title":"Does the /en-us/ route mean only United States law applies?","description":"No. It is the source English route and can provide regional context, but applicable privacy law depends on the people, processing, services, and jurisdictions involved."},{"title":"Who is the controller?","description":"Hutter Products GmbH is the controller for its Platform operations and buyer-facing sales responsibilities. For some enterprise or embedded services, it may process particular data on an organization’s documented instructions."},{"title":"What happens when I use ChatGPT with MerchandAise?","description":"The prompt, selected project context, tool inputs and results, and limited session or resume data needed for your request may pass between the external assistant and MerchandAise. The assistant provider’s own privacy notice may also apply."},{"title":"Do suppliers become the seller or receive my whole project?","description":"No. Hutter Products remains the buyer-facing seller for accepted purchases. A production or logistics partner receives only the project and personal data reasonably needed for its assigned work."},{"title":"Can I reject analytics and marketing cookies?","description":"Yes. You can reject non-essential categories or choose analytics and marketing separately. Essential technologies remain active when needed to operate and secure the requested service."},{"title":"Does MerchandAise store my complete payment-card number?","description":"Payment providers handle payment credentials. MerchandAise uses transaction references and status information needed to manage the purchase and does not need complete card numbers or security codes in ordinary Platform fields."},{"title":"How do I exercise a privacy right?","description":"Email privacy@merchandaise.com with the request and enough information to identify your relationship with MerchandAise. We may verify identity or authority before responding."}]}],"source":{"type":"page-copy","id":"Privacy_and_Cookie"}},"metadata":{"source":"page-content","schema":"2025-11-05"}}