Security & trust

Read-only by design.

Mercantle reads your revenue data through a scoped, read-only Partner API credential you create in your Partner dashboard. We never see card numbers, never write to your account, and you can rotate or revoke the credential at any time.

Read-only by design

The Partner connection reads your revenue data and never writes back. We can't change a charge, a plan, or a payout. Optional features like the SDK/ingest API only receive data you choose to send.

Scoped Partner credential

You create a scoped, read-only Partner API credential in your Shopify Partner dashboard and paste it into Mercantle. We encrypt it at rest, and you can rotate or revoke it in your Partner dashboard at any time. The optional Google Analytics connection uses Google's official OAuth with a read-only scope.

We never see card numbers

Payment details never touch Mercantle. Recovery works through your existing billing, we surface what failed, not how it's paid.

Revoke anytime

Rotate or revoke the credential in your Partner dashboard at any time, and remove it from Mercantle to end syncing. You stay in control of your data the whole time.

GDPR-conscious

Read-only access, credentials encrypted at rest, and EU data-subject requests honored — a data-processing addendum is available on request.

Encrypted throughout

Data is encrypted in transit and at rest. Your revenue powers your insights, never anyone else's.

In plain terms

What we never do.

Connect read-only in minutes.

Connect in minutes, read-only and code-free, and watch all six apps, plus AI insights, come to life.