Data protection
Last updated: 9 août 2026
Translation. In the event of any discrepancy, the French version prevails.
We collect what is needed for a sale to go through, and nothing more. No advertising profiling, no sale of data, no audience measurement. This page describes the processing the code actually performs: it is re-read every time the code changes.
Who is responsible
The controller is GR2 SA, Chemin Falconnier 41, 1260 Nyon, Switzerland, the company that operates Merka. Swiss law applies, in particular the revised Federal Act on Data Protection, in force since 1 September 2023.
For any question about your data, write to contact@merka.ch or to the address above. If you have an account, the support form is faster: there we already see your orders. No data protection adviser has been appointed; the law does not require one of a company this size, and it is the management that answers.
What we collect
Your email address, essential for signing you in and notifying you of what concerns your sales and purchases. There is no password: a six-digit code is sent to you, and we keep only a hash of it, valid for fifteen minutes.
Your username, your town and your language, which you choose. Along with your photo, that is all other members see of you. For professional sellers, the shop also shows the registered business name and UID; your private address and email address are never shown.
Your profile photo, if you sign in through Google or Facebook. It is then copied to our servers rather than displayed from theirs: without that, the provider would learn the IP address of every visitor who views one of your listings. Its metadata is removed at copy time.
Your listings, your orders, your messages, your questions, your offers and your reviews, which are the very substance of the service. A question asked on a listing is read only by you and the seller; a review, on the other hand, is public under your username.
The photos you upload. Before being stored, they are resized and ALL their metadata is removed, including the GPS coordinates your phone writes into them. The photo is also re-encoded before automatic analysis, so its metadata is not sent to the model.
The delivery address: name, street, additional line, postcode, town, country, and the phone number if you provide it. It is the most sensitive piece of data on the site. The seller sees it only for as long as it takes to dispatch: as soon as the sale is settled, they no longer have access to it. You can save an address in your profile so as not to retype it; that one belongs to you alone.
What relates to payment: the amount, the state of the order, the payment identifier at our provider, the fees withheld, and, for a seller, the fact that a change of bank details took place, never the details themselves. No card number ever reaches our servers.
A few technical traces, and they must be named: one session row per sign-in, a call counter per IP address to stop abuse, one row per listing viewed, per visitor and per day (for a visitor who is not signed in, it is not their IP address but an irreversible fingerprint of it and of their browser), and a log of calls to the analysis engine: your identifier, the model, the number of tokens, the estimated cost. Retention periods are below.
What moderation retains: when a text or a photo triggers a check, the reason and the excerpt in question are recorded with your identifier. A report you file is recorded too, with its photos, as is an account suspension and its reason. This log cannot be consulted from the site, which is what makes it useful, but you can ask us for a copy.
What we do not collect
No banking data passes through our servers: payment takes place in an isolated frame provided by our provider, and we never see a card number.
No advertising tracker, no audience measurement tool, no social media button. We do not know where you come from or where you go next.
No sensitive data within the meaning of the law: no origin, no opinions, no health data, no religion, no biometric data. Nor do we ask for identity documents; it is our payment provider that verifies a seller's identity, on its own systems.
Who we pass data to
Each of these recipients corresponds to a call the code actually makes. There are no others.
Stripe, to collect and pay out. A seller provides them directly with their identity and bank details, as the law requires of any institution that pays out money; we do not store that information. For a buyer, we transmit the amount, the order identifier and their email address, which is used for the receipt. The card form is served by Stripe and runs in your browser: they see your IP address there.
Mistral, to analyse listing photos and, as a fallback, to translate. The re-encoded photo goes to them without metadata, and the listing text when translation falls to them. Your name, address and email address are never transmitted to them.
Infomaniak, which hosts the site, the database and the photos, in Switzerland, and which translates listings into the other national languages. A translated listing is a listing readable from one end of the country to the other; it is the text of the listing that goes out, nothing else.
swisstopo, when you type an address. Each entry of at least three characters goes to the federal register of buildings and dwellings to suggest the right address, and the full address goes there once more, to verify that it exists; one typo in a postcode and someone else's parcel goes astray. It is a service of the Confederation, hosted in Switzerland.
Swiss Post, for the carriage of the parcel: the delivery address is passed to the seller, who prints it on the label and hands it to Swiss Post. We also query its tracking with the parcel number alone, manually, from the operations console, when a dispute requires it.
Open Library and MusicBrainz, when you scan the barcode of a book or a record to fill in the listing in one move: only the thirteen digits of the code go out, nothing that concerns you.
Google, Facebook or Apple, only if you choose to sign in through them: they then return your verified email address and, where applicable, your photo. The payment page now loads the font from our own servers, including inside Stripe's frame.
No one else. We neither sell nor rent any data, and we pass none on for advertising purposes.
What leaves Switzerland
Hosting, the database, the photos and translation stay in Switzerland. Two processing operations leave it: Stripe, whose entity serving us is Irish and whose group is American, and Mistral, in France, which receives listing photos. Ireland and France are among the states whose protection the Federal Council recognises as adequate. Open Library and MusicBrainz are American and receive only a barcode.
For how long
Your account and your listings remain as long as you keep them. Orders and the exchanges relating to them are kept beyond that, because they serve as evidence in a dispute and because accounting law requires it. The detail, category by category:
| Call counter per IP address | one day, then the row is deleted by the automatic clean-up. |
|---|---|
| Listing view rows | thirty days. After that, only a total per listing remains, which no longer says who looked. |
| Sign-in code | valid fifteen minutes, five attempts at most. |
| Session | thirty days, or until you sign out, which deletes it immediately. |
| Account, profile, listings | as long as you keep them. A listing never sold can be deleted from "My listings"; its photos go on the next pass of the storage purge. |
| Orders, payments, state log, messages and delivery address | at least ten years: accounting law requires it (art. 958f CO) and these records serve as evidence in the event of a dispute. |
| Moderation log, reports, suspensions | kept for 365 days by default; the period is configurable with RETENTION_MODERATION_JOURS and must be confirmed legally. |
| Log of calls to the analysis engine | linked to the account for 30 days, then unlinked; the full row is deleted after 400 days (RETENTION_IA_LIEN_JOURS / RETENTION_IA_JOURS). |
What the machine decides on its own
Three mechanisms operate without human intervention, and you should know it. A model reads your photos to draft the listing, suggest a category and estimate the parcel size: it is only a suggestion, you correct everything before publishing.
A word filter and the reading of the photo can refuse a publication or flag it for review. And in a dispute, if the seller does not respond for three days, the platform can decide alone in the buyer's favour, but only below fifty francs, and never beyond two automatic refunds for the same buyer: on the third, a human takes over the case.
In each of these cases, write to us: a person will re-examine the decision.
How it is kept
The database separates rights row by row: a query made on your behalf cannot read what belongs to someone else, even if the code gets it wrong. Session tokens and sign-in codes are stored only as hashes; a leak of the database would not allow anyone to sign in to any account. Photos lose their metadata. Access to the operations console is restricted to a list of addresses kept outside the database.
Your rights
You can consult your data, correct it, have it deleted, object to a processing operation and request a copy. The username, town, language, photo and saved address can be changed from your profile; for the rest, write to us. There is no button yet, it is done by hand, and we reply within thirty days.
Deleting an account cannot carry with it the deletion of completed orders: they bind another person than you, the records of a sale must remain available in the event of a dispute, and accounting law retains them for ten years. What remains is then reduced to what those obligations require.
If you reside in the European Union (we deliver to Germany, France, Italy and Austria), the GDPR additionally applies to what concerns you: the same rights, plus portability and the possibility of applying to the supervisory authority of your country.
In Switzerland, you can contact the Federal Data Protection and Information Commissioner, in Bern.