Privacy Policy

Last Updated: 25 April 2026

Merus is committed to keeping your data safe and respecting your privacy. This privacy policy informs you how we collect, use, and protect personal information.

1. Who We Are and How to Contact Us

Merus acts as the data controller responsible for the collection and processing of personal data obtained through our website, mobile applications, digital experiences, events, and other services or products (collectively, the “Merus Services”).

We have appointed a Data Protection Officer who is responsible for personal data. If you have any questions or if you wish to exercise your legal rights please contact us using the details below:

  • Email address: meruslab@meruslab.com

2. About this Privacy Policy

This version was last updated on 20 April 2026. Sometimes we may make changes to this policy to reflect how we process your data. If those changes are important, we will make this clear on our website, mobile app or by other means such as email.

Sometimes we link to other websites owned and operated by third parties. Those third party websites may also gather information about you, and it will be their privacy policies that apply to this. Please consult their privacy policies as appropriate. In addition to the Merus Experiences, we may also interact with you via our social media accounts on third party social media platforms. Where that is the case, both Merus and the social media platform may be jointly responsible for personal data, and this privacy policy will apply, together with the social media platform’s policy.

3. Information We May Collect From You

The personal data we collect depends on the activities you carry out with us via the Merus Experiences. We may collect, use, store and transfer the following types of personal data:

  • Identity Data: includes name, title, date of birth, interests, photographs, audio/visual material, personal descriptions, account details.
  • Contact Data: includes billing address, delivery address, email address and phone numbers, Whatsapp profile, contact history.
  • Financial Data: includes billing information and payment card details, or other payment method information.
  • Transaction Data: includes details about your order history and payments, saved items and contact history, together with details of any information, feedback or other correspondence you have with us via phone, email, post, live chat or social media.
  • Technical Data: includes IP address browser, data derived from the configuration of the device such as time zone setting, approximate device location, data on the connection of you to the website, mobile app browser plug-in types, device type, platform and operating system, browser type and version, as well as information about how you use our website, mobile app and systems.
  • Usage Data: includes information about how you use our website, mobile app, products and services, together with responses to surveys, competitions and promotions.
  • Marketing and Communications Data: includes your preferences in receiving marketing from us.

We also collect, use and share information that cannot be used to identify you. If we combine or connect this with your personal data so that it can identify you, we treat the combined data as personal data which will be used in accordance with this policy.

We do not generally collect sensitive personal data, for example your race, ethnicity or religious beliefs. However there may be occasions where we need to hold sensitive personal information. This information is subject to extra legal safeguards. Where this is the case, we inform you about this first, and we will tell you about how this data will be used.

Sometimes you can choose if you want to give us your personal data and let us use it. Where that is the case we will tell you and give you the choice before you give the personal data to us. Where we need to collect personal data by law, or under the terms of a contract we have with you and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you. In this case, we may have to cancel a product or service you have with us but we will notify you if this is the case at the time.

4. How is Your Personal Data Collected?

We use different methods to collect data from and about you including through:

  • Direct interactions: when you enter or send us information, such as by filling in forms or corresponding with us. This includes information you provide when you:
    • Subscribe to our service
    • Search for or Purchase a Product
    • Register to receive marketing
    • Participate in competitions, quizzes, reviews, feedback, surveys and panels, contests, promotions, discussions or other social functions
    • Create an account
    • Contact us (including but not limited to text, video and audio chat and conversations, contributions you make to our website and social media interactions)
  • Automated interactions: as you interact with the Merus Experiences, we may automatically collect Technical Data about your equipment, browsing actions and patterns. We usually collect this personal data by using cookies, SDKs, device fingerprinting, server logs and other similar technologies. Please see our cookie policy for further details.
  • Third parties: we may receive personal data about you from various third parties as set out below:
    • Analytics providers
    • Advertising networks
    • Search information providers
    • Data matching services such as Experian
    • Contact, Financial and Transaction Data from providers of technical, payment and delivery services, such as ApplePay
    • Digital customer experience delivery providers
    • Affiliate network publishers (such as partners who run competitions for us)
    • Social media providers and communication networks such as Whatsapp
    • Research providers, such as providers of customer surveys
    • App store platforms, such as Apple App Store Connect

We use Hotjar in order to better understand our users needs and to optimize this service and experience. Hotjar is a technology service that helps us better understand our users’ experience (e.g. how much time they spend on which pages, which links they choose to click, what users do and don’t like, etc.) and this enables us to build and maintain our service with user feedback. Hotjar uses cookies and other technologies to collect data on our users’ behavior and their devices. This includes a device’s IP address (processed during your session and stored in a de-identified form), device screen size, device type (unique device identifiers), browser information, geographic location (country only), and the preferred language used to display our website. Hotjar stores this information on our behalf in a pseudonymized user profile. Hotjar is contractually forbidden to sell any of the data collected on our behalf.

5. How We Use Your Personal Data

We use your personal data in a number of different ways, and only when the law allows us to. Most commonly, we use personal data:

  1. Where we need to perform a contract with you.
  2. Where it is a reasonably expected part of running our business (Legitimate Interests).
  3. Where we need to comply with a legal obligation.
  4. Where you consent to us doing so.

Detailed Usage Table:

PurposeType of DataWhy?
To register you as a new customer/memberIdentity, ContactTo perform a contract with you
To take payments, deliver orders and refundsIdentity, Contact, Financial, TransactionTo perform a contract; run our business
To manage our relationship (notices, reviews)Identity, Contact, Profile, MarketingTo perform a contract; Legal obligation; Study customer use
To enable account registration and online activitiesIdentity, Contact, Profile, Usage, MarketingTo run our business; develop products
To prevent and detect fraudIdentity, Contact, TechnicalTo run/protect our business; Legal obligation
To measure effectiveness of marketingIdentity, Contact, UsageConsent; Legitimate interests
To personalise our website for youIdentity, Profile, Usage, Marketing, TechnicalConsent; Legitimate interests
To allocate a unique ID for shoppingTechnicalFulfil contract; Legitimate interests
Analytical purposes for site intuitionIdentity, Contact, Profile, Usage, Marketing, TechnicalConsent; Legitimate interests
To show adverts and make recommendationsIdentity, Contact, Profile, Usage, Marketing, TechnicalLegitimate interests; Consent
To enforce legal rightsAllLegal obligation; Protect business
To analyse customer baseIdentity, Contact, Transaction, Technical, UsageLegitimate interests (efficiency)
Disclosures for legal complianceAllComply with legal obligations
Corporate transactions (mergers/sales)AllLegal obligations; Legitimate interests

6. Marketing, Promotions and Offers

We use personal data to send marketing messages by email, text, push notification and instant message, phone or post. Generally, we do not rely on consent as a legal basis for processing your personal data although we will get your consent before sending third party direct marketing communications to you via email or text message. You have the right to withdraw consent at any time.

  • Opt-out: Follow the unsubscribe link in emails or email info@meruslab.com.
  • Personalised Advertising: We may show you personalised advertising on other sites based on technologies like cookies, pixels, and web beacons.
  • Third-party platforms: We may work with platforms like Instagram or TikTok for targeted or “lookalike” advertising.

7. SMS Marketing

If you sign up to receive SMS marketing messages, you can unsubscribe at any time by texting the keyword STOP to our shortcode. You will receive one additional message confirming the request.

8. Cookies

We use cookies and similar tech. For more information, please see our Cookie Policy.

9. Change of Purpose

We will only use your personal data for the purposes for which we collected it, unless we consider that we need to use it for another reason compatible with the original purpose. If we need to use it for an unrelated purpose, we will notify you.

10. Sharing Your Information

We do not sell your data – we are committed to respecting your privacy.

11. Children

The Merus Experiences are not intended for children.

  • If you are under 13, please do not send any information to us. If we become aware we have collected such data, it will be deleted.
  • If you are between 13 and 18, please ask for parental permission before sending information.

12. Security

We have put in place security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way. We use industry-standard encryption technologies. However, no data transmission over the Internet can be guaranteed to be 100% secure.

13. How Long We Keep Data For

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, considering the amount, nature, and sensitivity of the data.

14. Your Rights

You have the right to:

  • Request access to your personal data.
  • Request correction of your personal data.
  • Request erasure of your personal data.
  • Object to processing.
  • Request restriction of processing.
  • Request transfer of your data.
  • Withdraw consent.
  • Complain to your regulator (e.g., ICO in the UK).

If you wish to exercise any of these rights, please contact us. We try to respond within one month.

DO YOU NEED EXTRA HELP?

If you would like this policy in another format (for example large print) please contact us at meruslab@meruslab.com.