This notice explains the processing associated with the MerchandAise services you use. A language or regional route does not determine which privacy law applies or whether a destination is available for orders. Consent to optional cookies is separate from agreeing to a contract or receiving marketing emails.
01Scope and Source Version
This policy applies to MerchandAise websites and localized routes, accounts and workspaces, design and artwork tools, previews, quotes, order and production workflows, support, embeds, APIs, authorized assistant connections, and other services that link to it.
It covers visitors, buyer and organization contacts, designers, supplier and production-partner contacts, developers, support contacts, and other people whose data we handle through those services.
The /en-us/ route is the source English version. The route indicates language and regional context; it does not mean that only United States law applies, that all services are available in the United States, or that a United States automated checkout lane is open.
02Controller and Contact Details
The controller is Hutter Products GmbH, Fortunastrasse 5, 9437 Marbach, Switzerland, Swiss enterprise identification number (UID) CHE-284.907.929 ("Hutter Products", "MerchandAise", "we", "us").
For privacy questions or rights requests, email privacy@merchandaise.com or write to Privacy, Hutter Products GmbH at the address above.
You can also contact us on +41 71 723 12 18. The privacy email reaches our privacy contact team; it is not a representation that a statutory Data Protection Officer or overseas representative has been appointed.
03When We Are a Controller or Processor
Hutter Products acts as controller when it determines why and how data is used for Platform operation, account administration, security, product development, buyer-facing sales, quoting, order management, legal compliance, and its own communications.
Where an organization engages us to process personal data solely on its documented instructions, its privacy notice and the applicable data-processing agreement govern that processing. Contact that organization about its own use of data; we can assist with requests concerning processing entrusted to us.
The same project can involve both roles. We remain an independent controller for data we must use for our own security, fraud prevention, legal duties, service administration, and merchant-of-record responsibilities.
04Data We Collect
Identity, account, and organization data: name, business contact details, company and club information, role, permissions, sign-in records, language, and account preferences.
Project and design data: prompts, messages, product and material choices, logos, artwork, fonts, brand guidance, files, annotations, previews, version history, knowledge references, approvals, and resume or session identifiers.
Quote, order, and fulfillment data: requested products, quantities, destination, pricing and quote history, billing and shipping contacts, invoices, payment status, tax and customs information, proofs, sample approvals, production status, delivery events, returns, complaints, and support records.
Supplier and production data: supplier-user details, capabilities, certifications or evidence, assignments, production updates, quality records, and private commercial information needed to operate the production network.
Device, usage, and communications data: IP address, browser and device information, logs, security events, page and feature interactions, cookie choices, support messages, feedback, and records of consent or Terms acceptance.
Please do not upload sensitive personal data, payment-card details, or personal data about others unless it is necessary, lawful, and appropriate for the requested service.
05Where Data Comes From
We receive data directly from you when you browse, create an account, upload or generate content, join a workspace, request a quote, approve a proof or sample, place an order, contact support, or set cookie preferences.
We may receive data from your organization administrator, authorized collaborators, buyers, production and logistics partners, payment and identity providers, an assistant or integration you choose, public business sources, and security or compliance service providers.
If you give us personal data about another person, you are responsible for having authority and providing any notice required by law.
06Why We Use Data and Our Legal Bases
Accounts, requested quotes, design sessions and purchases: we use your contact details, instructions, artwork, project history and order records to provide the requested service and take steps you request before a contract (GDPR Article 6(1)(b), where applicable). For staff or representatives acting for an organization, our legitimate interests are administering that business relationship and fulfilling the organization’s requests (Article 6(1)(f)).
Account protection, fraud prevention, troubleshooting and claims: we use relevant access logs, device details, communications and transaction records for our legitimate interests in operating a reliable, secure service and establishing or defending claims (Article 6(1)(f)). These interests do not override your applicable rights. Optional analytics tracking is subject to consent, including where it helps us improve the service.
Accounting, tax, customs, product safety and legally required disclosures: we use the records necessary to comply with applicable obligations (Article 6(1)(c), where applicable). Swiss data-protection principles also apply to our processing; the GDPR bases in this section apply where that law governs the activity.
Optional analytics and marketing technologies: we process device identifiers, page interactions and measurement events only after the relevant consent (Article 6(1)(a) and applicable device-storage rules). Direct marketing uses the permission or limited existing-customer exception required by the applicable law. You can unsubscribe at any time without affecting order or security messages.
Information marked required in an account, quote or order flow is needed to provide that service or meet a stated legal requirement; without it we may be unable to proceed. Optional information and optional cookies are not conditions of ordering. We do not obtain consent merely because you read this policy. You can withdraw consent without affecting earlier lawful processing.
07AI-Assisted Design and External Assistants
MerchandAise may process prompts, messages, selections, uploads, project knowledge, previews, and version events to provide AI-assisted concepts, file checks, product or material suggestions, workflow support, and resumable project sessions.
If you use the MerchandAise connection in OpenAI’s ChatGPT, prompts, selected project context, tool inputs and results, and limited session identifiers pass between ChatGPT and MerchandAise to carry out your request. Files or context you choose to share can contain personal data. OpenAI’s privacy notice (https://openai.com/policies/privacy-policy/) and the settings and terms of your ChatGPT account govern its separate processing; our cookie controls do not control ChatGPT.
Our AI service providers receive the prompt, file and project context needed for the enabled feature. Review what you submit, particularly information about other people. A request for design assistance does not itself grant permission to publish your private artwork or use it in marketing. Any separate optional permission for reuse must be obtained for that purpose.
You may ask for information or human review if you believe an automated result materially affected your access, order, or legal rights.
08Projects, Proofs, Samples, and Version History
A project may move between the website, an embed, an authorized assistant, a mobile experience, an API client, and human support. We use project identifiers, access controls, version history, and action records to preserve the relevant design, artwork, instructions, quote assumptions, and approvals across those surfaces.
We record the versioned digital-proof approval, any sample choice and required sample approval, and other prerequisites for the supported production path. Existing sample requirements continue unless an expressly offered and enabled order path permits a different recorded choice. We do not infer production approval or a sample waiver from silence.
Project data may be retained after a project becomes inactive when needed to resume work, document an approval or accepted quote, handle an order or claim, protect rights, or meet legal recordkeeping duties.
09Payments
Stripe processes payment credentials and payment authentication for supported payment flows under its privacy notice (https://stripe.com/privacy). Hutter Products receives transaction references, payment status, amounts, method summaries and relevant fraud, refund and dispute information needed to manage the sale. Complete card numbers and card security codes should be entered only in the payment provider’s designated payment fields.
Do not enter complete card details in prompts, artwork, support messages, or other general Platform fields. We do not need or intend to store complete card numbers or card security codes in those fields.
Payment, fraud, accounting, and tax data may be retained even after an account or design is deleted when required for an order, dispute, audit, or legal obligation.
10Buyers, Suppliers, and Production Partners
Hutter Products is the buyer-facing seller and merchant of record for purchases it accepts under the Terms of Sale. Suppliers and factories support Hutter Products as private production partners rather than acting as buyer-facing sellers merely because they fulfill work.
For the production and delivery you request, we disclose the necessary artwork, specifications, proof or sample approvals and, where needed, delivery/contact or customs details to the assigned production and logistics partners. We do not disclose your entire account or unrelated projects simply because a partner works on an order.
We may keep supplier identity, negotiated cost, sourcing, audit, and capacity information private while still giving buyers the disclosures, product information, traceability, and rights required by law or the applicable sales agreement.
11Recipients and Service Providers
Depending on the service, recipients can include authorized workspace members; contracted manufacturers, decorators, quality, warehousing, and logistics partners; payment, identity, fraud, tax, and accounting providers; hosting, storage, communications, support, analytics, and AI providers; professional advisers, insurers, auditors, and authorities.
The website uses Vercel hosting, Amazon Web Services file storage and MongoDB database services. Relevant content, identifiers, requests and technical logs are processed to operate those services. Stripe supports payments; OpenAI supports the ChatGPT connection and enabled AI services; Google Analytics 4 receives usage and device identifiers after analytics consent. The categories of information in this notice apply only to the functions you use. An enabled integration’s notice also explains its independent processing.
Providers receive only data reasonably needed for their role and are subject to contracts and safeguards appropriate to the service and applicable law. Some recipients, such as payment providers, external assistants, authorities, or an organization you work for, may act as independent controllers for their own purposes.
We may disclose data in a corporate transaction or restructuring subject to confidentiality and legally required notice, or when reasonably necessary to protect people, the Platform, rights, and legal claims.
12International Transfers
Hutter Products is based in Switzerland. Our international technology providers include providers based in the United States; data and support access may therefore involve Switzerland and the United States, as well as the hosting locations and production or delivery countries relevant to the service. Provider headquarters do not establish the location of a particular database or file.
Where a transfer is subject to Swiss or European transfer restrictions, the applicable basis must be an adequacy decision covering the destination and recipient, approved standard contractual clauses (with Swiss adaptations where needed) and any necessary supplementary measures, or a specific statutory exception whose conditions are met. A provider being based in a country, or this policy mentioning it, is not itself a transfer safeguard.
You can request the recipient countries and a copy or description of safeguards applicable to your data at privacy@merchandaise.com. We provide any additional information required for a new service or order-specific transfer before that processing. Confidential commercial details may be redacted without withholding the information the law requires.
13Cookies and Similar Technologies
Cookies are small browser records; local storage, tags and similar technologies can also store or access information on your device. Our controls have three categories: essential, analytics and marketing. The same rules apply to a technology regardless of whether it is called a cookie.
Essential: authentication, security, the shopping cart and requested project state, language settings and remembering cookie choices. These functions operate when needed for the service you request. The preference records cookie_consent and cookieConsent store your categories and choice time; consent_id, consentId and cookieConsentId associate a choice with a consent record. They are not advertising consent.
Analytics: Google Analytics 4 and our first-party usage measurement receive page/feature interactions, device/browser information, referrer information and pseudonymous identifiers after analytics opt-in. Recognized Google cookies include _ga and _ga_*; first-party analytics uses __messenger_telemetry_session_v1. Pseudonymous data is not necessarily anonymous.
Marketing: campaign or advertising measurement through configured tags requires marketing opt-in. The availability of a marketing choice does not mean a particular advertising vendor is active. Google Tag Manager, where enabled, is a container for tags; each optional tag still requires the relevant consent. Accepting marketing cookies does not subscribe you to email or SMS marketing.
14Cookie Choices and Retention
Use Manage cookies at any time to accept all, reject optional cookies, or save separate analytics and marketing choices. Optional categories start off. Changing a switch is a draft choice until you select Save preferences; closing the settings does not grant consent. Essential settings remain active.
Your browser choice is valid for up to 180 days, unless you change it or a new choice is needed sooner. The cookie has a 180-day expiry; local-storage records have no native expiry but the site checks the choice date and stops treating expired choices as consent. Clearing browser storage, changing browsers or using another device may require you to choose again.
Google Analytics cookies are configured with a lifetime of up to 180 days; automatic expiry renewal is disabled in our Google Analytics configuration. Withdrawal stops future optional measurement controlled by this site and removes recognized first-party analytics records where technically possible. It cannot recall information already lawfully sent or erase cookies on another provider’s domain. Contact us separately if you also want data deletion.
You can block or delete cookies and local storage in your browser. Essential features, sign-in or saved state may then stop working. Cookie controls apply to this browser/site; use the separate settings for an external assistant or another service.
15Retention
We keep personal data only for as long as needed for the purpose collected, an active account or project, an accepted order, security, dispute handling, or legal obligations. We consider record type, sensitivity, risk, contractual commitments, limitation periods, and tax, accounting, customs, product, and consumer-law requirements.
Swiss accounting books and supporting vouchers are generally kept for 10 years from the end of the relevant financial year. We retain the associated order and approval evidence where needed to substantiate those records or handle claims. Other data is kept according to its purpose and applicable limitation or recordkeeping periods, rather than automatically being retained for 10 years.
Our default configured privacy-record schedules are 730 days after the last update for consent evidence, 30 days after a privacy export request for its export record, and 365 days after a deletion request for the request record, subject to necessary legal holds and the applicable service configuration. These schedules do not mean that every copy of your personal data is deleted at the same time. Project, artwork, support and security data is retained while needed for the requested service, a dispute or a documented legal obligation; restricted backup copies expire through the relevant backup cycle.
We may retain anonymized data that can no longer reasonably identify a person.
16Security and Personal-Data Breaches
We use technical and organizational measures appropriate to the data and risk, including access controls, separation of duties where appropriate, transport encryption, credential and session protections, logging, backups, vendor controls, and incident procedures.
No service is completely secure. Protect credentials and private project links, use only authorized integrations, and report suspected security issues to security@merchandaise.com.
If a personal-data breach occurs, we investigate, contain, document, and notify the competent authority or affected people when and within the time required by applicable law. Under Swiss law, this includes notifying the FDPIC when a breach is likely to result in a high risk and notifying affected people when needed for their protection or when directed.
17Your Rights in Switzerland, the EEA, and the UK
Depending on the law that applies, you may request access, correction, deletion, restriction, data delivery or portability, or object to certain processing. You may withdraw consent and object to direct marketing at any time.
You may also ask for information about data sources, purposes, recipients, retention, transfer safeguards, and relevant automated processing. Some requests, particularly deletion, are subject to specific legal exceptions, including required recordkeeping and the rights of other people. We explain any applicable restriction; an active contract does not by itself remove your rights of access or correction.
Send a request to privacy@merchandaise.com or our postal address. We may request proportionate information to verify identity and authority; do not send a password. Where the GDPR applies, we normally respond within one month; the Swiss access-request period is normally 30 days. We explain any extension or lawful refusal as required by the applicable law.
You may complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, where applicable, the data-protection authority for your location or our relevant establishment.
18Other Regional Privacy Rights
Privacy rights vary by location. If another law applies to you, we will honor the rights and disclosures it requires, which may include knowing, correcting, deleting, or receiving data and opting out of targeted advertising, profiling, or a legally defined sale or sharing of personal data.
We do not sell personal data for money. Where an enabled advertising use qualifies as a sale, sharing or targeted advertising under a law that applies to you, you may opt out by rejecting marketing cookies and contacting privacy@merchandaise.com for any processing outside this browser. Applicable rights and recognized opt-out requests do not depend on accepting optional cookies.
The California Consumer Privacy Act applies only when its statutory scope and thresholds are met. This policy does not claim that every regional privacy law applies to Hutter Products GmbH merely because the page is available on a localized route.
We do not discriminate unlawfully against a person for exercising a privacy right.
19Automated Decisions, Direct Marketing, and Children
Automated tools support recommendations, file checks, fraud/security screening and workflow routing. AI recommendations are not a substitute for the explicit proof and sample approvals required for an order. If an automated decision has legal or similarly significant effects for you, contact privacy@merchandaise.com for information, to contest it or request human review; the safeguards and exceptions in applicable law govern such decisions.
You can opt out of marketing email through the message or your available preferences. Service, security, quote, approval, and order communications may still be sent when needed.
Accounts and purchasing are intended for adults acting for themselves or with authority to act for their organization. We do not direct the service to children. If artwork or an order contains information about a child, the person submitting it must have the necessary authority and provide the required notices. Tell us if information about a child has been submitted inappropriately so that we can investigate and remove it where required.
20Changes and Contact
We publish changes to this policy with an updated date. Material new purposes, recipients or optional tracking may require an additional notice or a new consent before that processing begins. A policy update does not retrospectively create consent or remove an existing right.
Privacy questions and rights requests: privacy@merchandaise.com. Security reports: security@merchandaise.com. General support: support@merchandaise.com.
Postal address: Privacy, Hutter Products GmbH, Fortunastrasse 5, 9437 Marbach, Switzerland. Include enough information for us to identify your relationship with MerchandAise and the request, but do not email passwords or payment-card details.
Privacy and cookie questions
- Who is responsible for my personal data?
- Hutter Products GmbH, Fortunastrasse 5, 9437 Marbach, Switzerland, is the controller for MerchandAise operations and sales. Contact privacy@merchandaise.com.
- Can I use the site without analytics or marketing cookies?
- Yes. Reject optional cookies or choose each category in Manage cookies. Essential storage needed for the requested service remains active.
- Does accepting marketing cookies subscribe me to emails?
- No. Browser tracking choices and marketing-message permissions are separate. You can unsubscribe from marketing emails using the link in the message.
- What happens when I use ChatGPT?
- The project context, prompts, tool results and limited session data needed for your request pass between MerchandAise and OpenAI. Your ChatGPT account settings and OpenAI’s notice also apply.
- How do I request access or deletion?
- Email privacy@merchandaise.com or write to our postal address. We verify identity proportionately and explain any records that must be retained for legal obligations or claims.
- Does withdrawing cookies delete data already sent?
- Withdrawal stops future optional tracking controlled by this site. It does not recall earlier transmissions. Contact our privacy team if you also wish to request deletion.