Skip to main content

What is Merge?

Merge is a unified API platform that powers Windmill’s connections to HR and payroll systems. Instead of building and maintaining separate integrations for each HRIS platform, Windmill uses Merge’s single API to connect to multiple systems reliably and securely.

Why Windmill uses Merge

Reliability and maintenance: Merge handles the complexity of connecting to different HRIS platforms, managing API changes, and ensuring consistent data syncing. This means your Windmill integration stays up-to-date without interruption. Security and compliance: Merge provides enterprise-grade security with SOC 2 Type II compliance, ensuring your employee data is protected throughout the sync process. Faster setup: Merge’s standardized authentication flow makes it easier to connect your HRIS to Windmill, with clear setup instructions and support for multiple authentication methods.

How it works

When you connect your HRIS to Windmill:
  1. Authentication: You authenticate with your HRIS provider through Merge’s secure OAuth flow or by providing API credentials
  2. Authorization: You grant Windmill read-only access to your employee directory and org structure
  3. Syncing: Merge pulls employee, organization, and available time-off data from your HRIS and delivers it to Windmill on a regular schedule
  4. Updates: As employees join, leave, or change roles in your HRIS, Windmill automatically reflects those changes
All integrations are read-only — Windmill never writes data back to your HRIS.

Security and Privacy

Data protection: Merge encrypts data in transit and at rest, following industry best practices for data security. Data collected: Windmill can store name, work and personal email, job title, department, manager and reporting structure, start date, employment status, gender, work location, and time-off records. The available fields depend on the HR system and the permissions that you grant. Windmill does not store compensation, payroll, benefits, home address, Social Security Numbers, dates of birth, phone numbers, or employment contracts as employee-profile fields. See Personally Identifiable Information for the canonical list. Compliance: Merge maintains SOC 2 Type II compliance and adheres to GDPR and other privacy regulations. Read-only access: Your HRIS remains the system of record. Windmill cannot modify employee data, payroll, or benefits through the integration.

Learn more

For more technical details about Merge’s platform, security, and API capabilities, visit merge.dev.