Legal

Privacy Policy

Draft document. This is a starting template for an MVP, not a legally reviewed policy. Before processing real customer or transaction data, have this reviewed by a qualified lawyer for compliance with GDPR (EU), KVKK (Türkiye), and any other jurisdiction where you operate.
Last updated: July 2026

1. Who we are

MeraFraud ("we", "us", "our") provides a fraud-detection API and dashboard for e-commerce businesses ("Merchants", "you"). This policy explains what data we collect, why, and how it's handled — both about our Merchants and about the transactions Merchants send us to score.

2. What we collect

2.1 Account data

2.2 Transaction data submitted for scoring

When you call our API, you send transaction-level signals to be scored — for example transaction amount, account age, device/payment novelty flags, and similar behavioral indicators. We do not require or intentionally collect full card numbers, CVV codes, or other regulated cardholder data (PCI scope) — Merchants must not submit such data to our API.

3. How we use data

4. Model training and data use across customers

In this MVP, the underlying model is trained on synthetic data, not on live merchant transactions. If and when we introduce training on real merchant data, we will: (a) anonymize or aggregate signals wherever feasible, (b) not share one Merchant's raw transaction records with another Merchant, and (c) provide an opt-out for Merchants who do not want their data used in shared model training. This section should be revisited and finalized with legal counsel before that capability ships.

5. Data retention

Account and usage data is retained for as long as your account is active, plus a reasonable period afterward for legal, tax, and dispute-resolution purposes. You may request deletion of your account data by contacting us (see Contact page).

6. Data storage and security

In this MVP, tenant and API key data is stored in a local file on the serving infrastructure, not a dedicated secrets vault or encrypted database. Before handling real customer data, this must be upgraded to encrypted storage (e.g. a managed database with encryption at rest) with proper access controls.

7. Your rights

Depending on your jurisdiction (e.g. under GDPR or KVKK), you may have rights to access, correct, export, or delete your data, and to object to certain processing. Contact us to exercise these rights.

8. Cookies and tracking

This dashboard and marketing site do not currently use third-party advertising cookies or trackers. The map component loads map tiles from third-party providers (Esri), which may log standard request metadata (e.g. IP address) per their own policies.

9. Changes to this policy

We may update this policy as the product evolves. Material changes will be reflected with an updated "Last updated" date above.

10. Contact

Questions about this policy? Reach us at hello@merafraud.com or via our Contact page.