← Back to Legal

Merchant Privacy Policy

Last updated: 10 July 2026

1. Overview

This Merchant Privacy Policy (“Policy”) explains how MarlinX Technologies Pte. Ltd. (operating as “Directo”, “we”, “us”, “our”) collects, uses, discloses, and protects personal data about individuals associated with Merchants, including sole proprietors, business owners, authorised representatives, employees, and other contact persons, in connection with your use of Directo.

We may process End Customer personal data in different capacities depending on the purpose of the processing. Where we process personal data solely on behalf of a Merchant and for the Merchant’s purposes, we act as a data intermediary. Where we determine the purposes and means of processing for Directo’s own operations, including Discovery, customer-store attribution, payment and settlement support, fraud prevention, security, analytics, service improvement, dispute handling, and legal compliance, we act as an organisation under the PDPA.

We handle personal data in accordance with the Personal Data Protection Act 2012 (“PDPA”) of Singapore.

2. Data We Collect

This Policy covers two categories of personal data we process in connection with providing Directo:

CategoryExamplesOur Role
Merchant Contact DataName, business email address, business contact number, role or position, account and login information, account activity, IP address, device and browser information, support communications, and identity, authority, billing, or verification records where collected by usOrganisation
End Customer Personal DataName, email address, telephone number, delivery address, account identifiers, order and transaction information, payment status, saved stores, channel and attribution information, and activity relating to Directo storefronts and DiscoveryData intermediary and/or organisation, depending on the purpose of processing

3. How We Use Personal Data

A. Merchant Contact Data

We use this personal data for the following purposes:

  • Setting up and managing your Merchant account and dashboard access
  • Billing and account administration
  • Sending service notices, account alerts, and service-related communications
  • Detecting and responding to suspected fraud, abuse, security incidents, or prohibited use
  • Enforcing the Merchant Terms of Service and Acceptable Use Policy
  • Complying with legal obligations and responding to lawful requests from authorities
  • Sending marketing communications about Directo products and features, where permitted under applicable law and your communication preferences. You may opt out of marketing communications at any time.

B. End Customer Personal Data

We may process End Customer personal data as a data intermediary where we act solely on behalf of a Merchant, including to enable order fulfilment and provide merchant support tools.

We may also process End Customer personal data in our own capacity as an organisation for the following purposes:

  • Creating and administering End Customer accounts
  • Operating Directo storefronts and Discovery
  • Determining customer-store and channel attribution
  • Processing and supporting orders, payments, settlements, cancellations, refunds, and disputes
  • Allowing End Customers to save stores and return to them
  • Detecting and preventing fraud, abuse, manipulation, and security incidents
  • Providing analytics, measuring service performance, and improving Directo
  • Complying with legal and regulatory obligations and enforcing our terms and policies

We do not sell or rent identifiable End Customer personal data. We will not use such personal data for purposes unrelated to Directo without an applicable legal basis and any notification or consent required by law.

End Customer personal data is retained in accordance with Section 5. Where we act solely as a data intermediary, we may also retain, return, or delete such data in accordance with the Merchant’s lawful instructions, subject to our legal, regulatory, security, fraud-prevention, dispute-management, and record-keeping obligations.

End Customer privacy requests may be handled through available product settings or relevant request channels, subject to applicable legal retention requirements.

You are responsible for ensuring that End Customer personal data made available to you through Directo is used solely for order fulfilment, customer service, and related lawful business purposes, and not for any other purpose without the End Customer’s consent.

4. Sharing and Disclosure

We do not sell or rent identifiable Merchant personal data or End Customer personal data to third parties. We may disclose personal data, where necessary, to:

  • Merchants: Where an End Customer places an order with a Merchant, we may provide that Merchant with the information reasonably required to fulfil the order, provide customer support, and handle cancellations, returns, or refunds.
  • Payment, settlement, and delivery providers: Information may be disclosed where necessary to process payments, complete settlement, provide delivery services, prevent fraud, or resolve transaction issues.
  • Service providers: Cloud hosting providers, payment service providers, communication tools, and other vendors that support the operation of Directo, engaged under appropriate contractual protections.
  • Professional advisers: Lawyers, accountants, auditors, and insurers, where necessary and subject to confidentiality obligations.
  • Authorities: Government, regulatory, law enforcement, court, or other public authorities where required or permitted by applicable law.
  • Business transfers: In the event of a merger, acquisition, restructuring, or sale of assets, relevant data may be transferred to the successor entity, subject to applicable legal requirements.

A Merchant receives only the personal data reasonably required for its own transactions with an End Customer. Merchants do not have access to an End Customer’s full profile, saved stores, or activity and spending across other stores or the wider Directo Merchant Network.

5. Retention

We retain personal data only for as long as necessary for the purposes described in this Policy or as required by applicable law.

Data CategoryRetention Period
Merchant Contact DataDuration of Merchant relationship, plus up to 7 years where required for accounting, tax, legal, or dispute purposes
End Customer Personal DataFor as long as reasonably necessary to provide Directo, operate Discovery, maintain customer-store attribution and transaction records, support settlement, prevent fraud, handle disputes, and comply with legal, accounting, audit, and regulatory requirements.
Audit logs and security recordsUp to 3 years, or longer where required for security, legal, or dispute purposes

Where personal data is no longer required, we will securely delete or anonymise it.

6. Security

We implement reasonable security measures to protect personal data against unauthorised access, disclosure, alteration, or destruction, which may include encryption, access controls, and incident response procedures.

No system is completely secure, and we do not guarantee absolute security.

7. Your Rights Under the PDPA

Subject to the exceptions and limitations set out in the PDPA, individuals whose Merchant Contact Data we process may request access to or correction of their personal data. Where we rely on consent to process such personal data, the individual may withdraw that consent at any time, though this will not affect processing already carried out and may impact our ability to provide certain services.

To make a request, please contact us at support@marlinxtech.com. We will respond within the timelines required under applicable law.

8. Overseas Transfers

We may engage overseas service providers, including cloud hosting and infrastructure providers, in connection with operating and supporting Directo. Where personal data is transferred outside Singapore, we take reasonable steps to ensure that the receiving party provides a standard of protection comparable to that required under the PDPA, including through appropriate contractual protections where applicable.

9. Data Breach

In the event of a data breach involving personal data we process as the organisation, we will assess the breach and notify the PDPC and, where required, affected individuals in accordance with applicable law.

Where we process End Customer personal data as a data intermediary on your behalf, we will notify you without undue delay after becoming aware of, or having reason to believe that there has been, a data breach affecting such personal data. We will provide available information reasonably required to support your assessment and notification obligations.

You must promptly notify us at support@marlinxtech.com of any suspected or confirmed security incident that may affect our systems or data.

10. Cookies

Our Merchant dashboard uses cookies for authentication, session management, and to maintain, secure, and improve dashboard functionality. Some browser settings may allow you to block or delete cookies, but this may affect certain features.

11. Changes

We may update this Policy from time to time. Where changes are material, we will provide you with reasonable prior notice via your registered account email address or through the Merchant dashboard, unless changes are required immediately for legal, regulatory, or security reasons. The updated Policy will apply to your continued use of Directo from its effective date.

12. Contact and Data Protection Officer

For any questions, requests, or complaints relating to this Policy or our data protection practices, please contact our Data Protection Officer at:

MarlinX Technologies Pte. Ltd.
Email: support@marlinxtech.com
Singapore

If you are not satisfied with our response, you may contact the Personal Data Protection Commission of Singapore at www.pdpc.gov.sg.