This policy explains what Merik (“we”, “us”) collects when you use the website at merik.in and the Merik application at merik.in/app, why, who processes it, and what you can ask us to do. Contact: merik.msk@gmail.com.
Two roles: visitor data and workspace data
Merik handles data in two different capacities.
- Website visitors and people who contact us. For this data, Merik decides what is collected and why.
- Company workspaces. A company that uses Merik puts its employees' and clients' data into its workspace. That company decides why the data is collected and is responsible to its employees for it; Merik stores and processes it on the company's behalf and on its instructions. If you are an employee with a question about data your employer keeps in Merik, your employer is the first place to ask, and we will help them answer.
What we collect from website visitors
- Analytics. The marketing pages use Google Analytics 4 to count visits, pages viewed, and interactions such as clicking a call-to-action or using the ROI calculator. This uses cookies and sends usage data to Google. It is not loaded inside the application.
- Workspace requests and contact forms. Company name, your name, work email, optional phone and message, and — if you arrived from a page on our site — which page. We use this to review the request, create the workspace, and reply. It is stored in our database and emailed to the Merik team.
- Server logs. Our hosting provider records standard request logs (IP address, user agent, URL, time) for security and operations.
What a company workspace contains
Depending on which modules a company uses, its workspace may hold:
- Employee records: name, work email, phone, department, designation, date of joining, salary structure (CTC and components), documents the admin uploads, and login credentials managed by the authentication service.
- Attendance: check-in and check-out times, and — if the employee grants permission — the coordinates at the moment of the punch, plus a readable place name derived from them. Location is recorded at the punch only.
- Leave and work-from-home requests and approvals; the company holiday calendar.
- Payroll: monthly computed pay, deductions, arrears, salary history and generated payslips.
- Daily task logs, including time spent, blockers, and proof links; performance reviews.
- Clients, projects, quotes and invoices; hardware and software registers.
- Digital Operations: the URLs of websites and APIs the company registers for monitoring, the results of Merik's checks on them, and error reports from the optional browser snippet on those sites (see below).
The browser snippet on monitored sites
A company may place merik.js on a website it monitors. That script reports JavaScript errors, unhandled rejections and failed requests to Merik so the company can fix them. It sets no cookie, assigns no user identity, and by construction never reads form contents, input values, cookies, local storage, request or response bodies, headers, or URL query strings. What it sends is redacted again on our server before storage. The company that installs the snippet is responsible for telling its own visitors about it where required.
Why we process data
- To provide the service a company asked for: recording attendance, computing payroll, monitoring sites, and so on.
- To create and support workspaces, answer requests, and send service emails such as payslips, password resets and incident alerts.
- To keep the service secure and working, including redacting sensitive strings from error reports.
- To understand how the public website is used, in aggregate.
We do not sell personal data, we do not use one company's workspace data for another company, and we do not use workspace data to train AI models. Where a company switches on Merik's optional AI features, the text those features are given is sent to the AI provider the Merik team has configured, for that request only.
Services that process data for us
- Supabase — managed Postgres database, authentication and server-side functions for the application.
- Vercel — hosting for the website.
- Google — Google Analytics 4 on the marketing pages; Google Fonts for typefaces.
- BigDataCloud and OpenStreetMap Nominatim — converting attendance coordinates to a place name. The coordinates are sent to these services for that purpose.
- Email delivery (SMTP) — sending payslips, welcome and reset emails, and alerts.
- Slack — only if a company connects it for incident alerts.
- AI providers (Anthropic, OpenAI, Google, xAI, or a custom endpoint) — only for workspaces where AI features are switched on, and only for the text of each request.
- Vendor status feeds and GitHub/Vercel webhooks — only if a company connects them for its Digital Operations timeline.
How long we keep it
- Workspace data is kept for as long as the company's workspace is active, because payroll and attendance history is the point of the product. A company can ask us to delete its workspace; we then delete it, except where a legal obligation requires a copy to be kept.
- Workspace requests and contact messages are kept so we can act on and refer back to them.
- Analytics data is kept according to Google Analytics' retention settings for our property.
Your rights
You can ask what personal data we hold about you, ask for it to be corrected or deleted, and withdraw consent where processing is based on consent. Email merik.msk@gmail.com. If your data is in an employer's workspace we will work with that employer to respond. Merik is built for Indian businesses and is designed to support the obligations employers have under India's Digital Personal Data Protection Act, 2023; a company using Merik remains responsible for its own notices to and consent from its employees.
Cookies
The website uses Google Analytics cookies. The application uses the browser storage needed to keep you signed in. The merik.js snippet sets no cookies on the sites it is installed on.
Children
Merik is a business tool and is not directed at children.
Changes
If this policy changes in a way that matters, we will update the date at the top and, for material changes, tell workspace admins by email.
Effective 11 September 2026.