Legal
Privacy Policy
This policy explains what Merxis collects, what we refuse to collect, and who can see what.
Effective August 12, 2026
In short
- We run no analytics or advertising trackers of any kind. The only cookie we set is a functional one remembering your language choice, and only after you pick a language.
- We never sell your information, and we never share it for marketing.
- Documents you upload are encrypted so that no one at Merxis can open them.
- Nearly everything runs on servers we operate ourselves. The one outside company we rely on is an email delivery provider.
01 / Who we are
Who is responsible
Merxis Technologies Inc. is the organization responsible for personal information handled through merxis.ca. In this policy, “Merxis”, “we”, and “us” mean that company. For anything in this policy, write to [email protected].
02 / Collected
What we collect
We collect what the marketplace needs to function, and little else.
- Account. Your full name, your email address, and your password. The password is stored only as a hash, and it is also used, without being stored, to derive the keys that encrypt your documents. A profile photo is optional.
- Professional details. If you apply as an advisor, accountant, attorney, or lender: your firm and a license or credential number.
- Buyer profile. Optional: a headline, a short background, your target check size, and how your funding stands.
- Listings. If you sell: your business’s name, industry, location, financial figures, and the documents and photos you upload.
- Messages and offers. Messages you exchange with counterparties, and the terms of offers you draft and submit.
- Access records. When someone views a teaser, accepts an NDA, opens a document, or attempts a download, we record the account email, the action, the time, and the IP address. This audit trail is a core confidentiality feature, and sellers rely on it.
- Technical logs. Standard request logs and performance telemetry, kept on our own infrastructure.
03 / Refused
What we deliberately do not collect
Merxis sets no tracking cookies. The only cookie we use is a functional one that stores your language choice (English or French), and it is set only when you pick a language yourself. It identifies nothing about you. Your sign-in session is a token kept in your own browser’s local storage, and it is removed when you sign out.
There are no analytics scripts, no advertising trackers, and no social media pixels anywhere on the site. We do not build advertising profiles, and we do not sell or rent personal information to anyone.
04 / Use
How we use information
- Running the marketplace. Accounts, listings, access requests, messaging, and offers.
- Enforcing confidentiality. Document pages are watermarked with the viewer’s email address, and confidential access is written to the audit log.
- Transactional email. Verification links, password resets, invitations, access decisions, and notifications about new messages and offers. We send no marketing email.
- Estimates you request. The price check runs on the figures you enter and on aggregated market data.
- Prefilling financials when you ask. If you request it, your uploaded statements are processed by extraction software running on hardware we operate. Your documents are never sent to an outside AI service.
05 / Encryption
Encryption, honestly
Files you upload are encrypted at rest with keys derived from your password. There is no master key, and there is no staff tool that opens customer files. If you lose both your password and your recovery code, your files are cryptographically gone, and no one, including us, can bring them back.
Approved viewers never receive your original files. They see page images rendered on our servers, stamped with their email address and the date of their NDA. All traffic between your browser and Merxis is encrypted in transit.
Honesty about the edges: structured data, such as listing figures, messages, offer terms, and written answers, lives in our database with standard protections rather than under your personal key. While we process a file, for example rendering pages or extracting figures at your request, it passes through server memory in readable form. Profile photos are not encrypted; they are served from an address that is practically unguessable and changes whenever you replace the photo.
06 / Visibility
Who sees what
- Anonymous visitors see the public teaser: figures, category, and area, never the business’s name, and only photos the seller has explicitly released.
- Approved buyers see the business’s identity and documents only after the seller approves them and they accept the NDA, and documents only as watermarked pages.
- Sellers see the name and profile of every buyer who requests access. Buyers never see sell-side names, before or after the NDA; sellers and their advisors appear by role.
- Merxis staff can see account and listing metadata and the audit log, for support and enforcement. Staff cannot open documents and have no interface for reading messages.
Emails we send about a listing use its anonymous headline, never the business’s name.
07 / Providers
Service providers
We keep this list short on purpose.
- Resend delivers our transactional email and is based in the United States. It processes recipient addresses, names where they appear in a message, and subject lines, which are built from anonymous listing headlines.
- Cloudflare sits in front of merxis.ca for network security and content delivery. Like any such provider, it processes traffic data such as IP addresses and request metadata, and it may set a strictly necessary cookie while protecting the site from an attack.
Everything else, including the database, file storage, document rendering, financial extraction, and telemetry, runs on infrastructure we operate ourselves. We use no cloud analytics, no third-party storage, and no outside AI services.
08 / Location
Where your data lives
Merxis runs on servers we operate in Canada. Email delivery through Resend involves processing in the United States. Merxis serves buyers and sellers in Canada and the United States.
09 / Retention
How long we keep things
Account information is kept for as long as your account exists. You can delete uploaded files at any time, and deleting a file removes the original and every derived copy from our servers.
- Sign-in sessions expire after 7 days.
- Share and invitation links expire after 30 days.
- Email verification links expire after 24 hours, and password reset links after 1 hour.
The record of who accepted an NDA and what they viewed is kept even after a listing or account closes. It exists to protect sellers, and it is the evidence either side may need if confidentiality is ever disputed.
You can delete your account at any time from Settings. That immediately deletes your personal information, except the audit records above and anything we need to keep to meet legal obligations or resolve disputes. You can also ask us to do it by emailing [email protected] from your account address.
10 / Your rights
Your rights
You can ask to see the personal information we hold about you, have it corrected, withdraw consents you have given, and ask us to delete it, subject to the exceptions above. Write to [email protected] from your account address and we will respond promptly.
If you are in Canada, you may also complain to the Office of the Privacy Commissioner of Canada. If you are in the United States, you may have rights under your state’s privacy law, and we will honor requests made under them.
11 / Breaches
If something goes wrong
If a security breach creates a real risk of significant harm to you, we will notify you and the appropriate regulators as the law requires, and we will tell you plainly what happened and what we are doing about it.
12 / Under 18
Under 18
Merxis is for adults. We do not offer the Service to anyone under 18, and we do not knowingly collect information from minors.
13 / Changes
Changes to this policy
When we change this policy in any material way, we will email the address on your account before the change takes effect and update the date at the top of this page.
14 / Identity checks
Identity verification
You can choose to verify your identity. The check runs on a page hosted by Stripe, Inc., our payment and identity provider: you show a government-issued ID and take a selfie there, and Stripe confirms the document and the match. Stripe processes those images on its own infrastructure, outside Canada, under its own privacy terms. Merxis never receives or stores the images, the document number, your address or your date of birth.
What Merxis keeps is the name as printed on the document, the country that issued it, the dates the check was made and expires, and a one-way hash we use only to notice when one person holds more than one verified account. Your card details go to Stripe only; we keep the amount, the date and a link to Stripe’s receipt. When you delete your account we ask Stripe to erase the verification data it holds.
A verified badge is information the other side of a deal may read. It never decides what you can do on Merxis, and we never use it for credit, employment, housing or insurance decisions.
15 / Contact
Contact
Write to [email protected].