Privacy
This policy explains what the MergeTrace Marketing Site, the MergeTrace Portal, and the MergeTrace desktop app do with personal data, and what you can turn off. It covers mergetrace.com, portal.mergetrace.com, and the desktop app.
Last updated: October 5, 2026
Who is responsible
The controller responsible for the processing described in this policy is:
- Entity
- David Blume, Sole proprietor (Einzelunternehmen)
- Address
- Zur Lehmkuhle 31, 59846 Sundern, Germany
- Contact
- Email support@mergetrace.com, phone +49 2933 7870666
- VAT ID
- DE461037432
This website
The Marketing Site sets no cookies, runs no analytics, and loads no third-party scripts. Nothing you do here is tracked or profiled.
- Fonts are self-hosted from this domain. The site never calls Google Fonts.
- Installer downloads are served from the public bucket at dl.mergetrace.com, with no account required.
- The pages are prerendered static HTML, so reading them works without JavaScript.
Hosting and server logs
The site and the download bucket run on Cloudflare. To deliver pages and files and to protect the service against abuse, Cloudflare processes request data such as the IP address, the requested URL, the time of the request, and the user agent. Cloudflare acts as our processor under a data processing agreement. The legal basis is our legitimate interest in a secure and reliable website (Art. 6(1)(f) GDPR). The data is deleted or aggregated once it is no longer needed for these purposes.
Contact by email or phone
When you write to support@mergetrace.com or call +49 2933 7870666, we process your contact details, the content of your message, and the technical data your provider sends, in order to answer you. The legal basis is the performance of a contract or steps before entering one (Art. 6(1)(b) GDPR) or our legitimate interest in answering inquiries (Art. 6(1)(f) GDPR). We delete the correspondence when the inquiry is settled and no statutory retention duty applies.
MergeTrace Accounts, the Portal, and billing
A MergeTrace Account is optional and only needed for Pro and Team features. Accounts, teams, and billing are managed by the Portal. The Portal stores account data with Supabase as our auth and database provider. When you create or use an Account, we process:
- Your email address and a stable account ID. Sign-in uses one-time links sent to that address, and the link token is processed to complete the sign-in.
- Your profile, which stores the email address, the account creation date, and the Paddle customer ID once a paid plan exists.
- Team data when you use Teams: the team name, the owner and members with their account IDs and email addresses, pending invitations by email address, and an optional allowed email domain.
- Billing data for Pro and Team plans. Paddle is the merchant of record and handles checkout, payments, invoices, and taxes. Paddle processes your name, email address, billing address, payment details, and tax information. Payment card data never reaches MergeTrace servers. Paddle sends us the subscription state we need to grant your plan, such as the subscription ID, price, status, and renewal dates.
The legal bases are the performance of your contract (Art. 6(1)(b) GDPR), compliance with tax and commercial law (Art. 6(1)(c) GDPR), and our legitimate interest in securing the service and preventing abuse (Art. 6(1)(f) GDPR). Account and team data is kept while your Account exists. You can ask us to delete your Account at any time. We delete it without undue delay, except for records that tax or commercial law requires us to keep, such as invoices, which are kept for up to ten years.
The desktop app
What stays on your machine
- Forge tokens are stored in the operating system keychain and used from your machine to reach your forge.
- Repositories are cloned to local disk. MergeTrace does not upload repository contents, files, or diffs.
- Reviews, review history, and settings are stored locally in the app's data directory.
The app connects directly from your machine to your GitLab instance with your token. GitLab's own privacy terms apply to that connection. When you sign in, the app also talks to the Portal and Supabase to load your Account and entitlement state.
Telemetry and error reporting, on by default
Telemetry is one setting that covers usage analytics and error reporting. It is on by default, and while it is on:
- Usage analytics record product events such as page views and feature use, plus autocaptured interactions. When you are signed in, these events are tied to your MergeTrace Account, including the account ID and email address. Usage analytics go to PostHog, hosted in the EU. The SDK keeps its state in local storage on your machine.
- Error reports record crashes and failures, and can include a screen recording of the app while you review that may capture the code on screen, plus app and device details. Error reports go to Sentry, with storage in the EU. Error sessions are recorded in full; one in ten other sessions is recorded.
The data is used to operate and improve MergeTrace. It is not sold. Where consent is required, the legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Otherwise, the legal basis is our legitimate interest in keeping MergeTrace stable and improving it (Art. 6(1)(f) GDPR), and you can object at any time.
How to turn Telemetry off
Open Settings, then General, and switch Telemetry off. The change applies the next time you start MergeTrace. With Telemetry off, the analytics and error reporting SDKs are never started, so nothing leaves your machine and no session recording is taken. Every feature keeps working.
Recipients and international transfers
We do not sell personal data. We share it only with the providers that run the service for us and only as far as needed:
- Cloudflare: hosting, content delivery, and the download bucket.
- Supabase: account authentication and database for the Portal.
- Paddle: payment processing, invoicing, and tax as merchant of record.
- PostHog: product analytics, hosted in the EU cloud.
- Sentry: error reporting, stored in the EU.
These providers act under data processing agreements. Some of them are based outside the EEA. Where personal data leaves the EEA, the transfer is covered by an adequacy decision, such as the EU-US Data Privacy Framework for certified providers, or by the EU Standard Contractual Clauses. We may also disclose data where the law requires it.
How long we keep data
We keep personal data only as long as needed for the purposes described in this policy or as the law requires. Server and abuse logs are short-lived. Account and team data lives as long as your Account, and invoices are kept for up to ten years. Telemetry data is kept only as long as needed for product analytics and error fixing. When a purpose ends, we delete or aggregate the data.
Your rights
Under the GDPR you have the right to access your personal data, to have it corrected, to have it deleted, to restrict its processing, to receive it in a portable format, and to object to processing based on legitimate interests. Where processing is based on consent, you can withdraw that consent at any time with effect for the future. To exercise any of these rights, write to support@mergetrace.com.
You also have the right to complain to a supervisory authority. The authority responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2-4, 40213 Düsseldorf, Germany.
We do not use automated decision-making, including profiling, that produces legal effects or similarly significantly affects you (Art. 22 GDPR).
Changes to this policy
We update this policy when the processing changes. The current version is always available on this page, and the date at the top shows when it last changed.