C Capyo
en

Privacy Policy

Last updated: 2026-09-05

This policy explains what data the Shopify app Conforma: EU Guarantee Label and this website process, why, on what legal basis, and how long it is kept. It is written for the merchant who installs the app. It is not legal advice about your own obligations as a trader.

1. Who is responsible

The controller for the processing described here is EU Guarantee Label, operated by an individual developer. Contact for anything in this document, including all data-protection requests: gimbernat13@gmail.com.

Operator legal name and address: [to be added]

For the personal data of your customers, you remain the controller and Shopify is your processor under Shopify's own terms. This app never receives that data — see section 4.

2. Data the app processes

All of it comes from Shopify when you install the app and while you use it. In detail:

Where any of this is personal data, it is the personal data of you — the merchant and your staff — not of your customers.

3. Data on your storefront

The notice and the GARAN label are rendered by a Shopify theme app extension. They set no cookies, load no external scripts, and make no third-party requests: the official artwork is served from Shopify's own CDN as part of the extension. Nothing about your shoppers is sent to us, and we run no analytics on your storefront.

4. What we never process

Shopify sends every public app the two mandatory customer-privacy webhooks (customers/data_request and customers/redact). We acknowledge them and have nothing to return or erase, because we hold no customer data.

5. This website

This site is a set of static pages. It sets no cookies, runs no analytics, and contains no tracking pixels, no advertising tags and no embedded third-party content. The typeface is self-hosted rather than loaded from a font CDN, so opening a page here makes no request to any server other than the one serving the page. The host of these pages (GitHub Pages) processes the request data any web server sees, including your IP address, to deliver them.

6. Why we process it, and on what legal basis

We do not use your data for advertising, we do not profile you, and we never sell or rent it.

7. How long we keep it

8. Who else is involved (sub-processors)

Sub-processorCompany countryWhat they doWhere the servers are
Shopify International Ltd Ireland The platform the app runs on and the source of all store data; also handles billing Per Shopify's own DPA
Hostinger International Ltd Cyprus Application hosting — the virtual server the app runs on Boston, Massachusetts, United States
netcup GmbH Germany Database hosting — the PostgreSQL database holding everything in section 2 Manassas, Virginia, United States
GitHub, Inc. United States Hosting of this website only — no app data reaches it GitHub Pages global infrastructure

There is no analytics provider, no error-tracking SaaS, no email marketing tool and no CRM in this list, because the app uses none. Support email is handled by an ordinary mail provider. We will update this table before any new sub-processor starts processing, and announce the change on the changelog page.

9. International transfers

Merchant data processed through the app is stored on servers located in the United States — the application server in Boston, Massachusetts and the database in Manassas, Virginia. Both are operated for us by European companies (Hostinger International Ltd, Cyprus; netcup GmbH, Germany), but the processing itself happens outside the EEA, which engages Chapter V of the GDPR.

For those transfers we rely on the Standard Contractual Clauses included in those providers' data processing terms, together with the technical and organisational security commitments described in section 10.

The app stores no end-customer personal data, so nothing about your shoppers is transferred anywhere. What crosses the border is the store configuration, scan findings, reports and access tokens listed in section 2.

Hosting locations can change — a move to an EU region is possible. Any change of hosting location, like any change of sub-processor, is announced on the changelog page. Shopify may transfer data internationally under its own DPA and transfer mechanisms, which govern the Shopify-to-merchant relationship independently of this policy.

10. Security

What we can state plainly:

We do not claim a formal certification (no ISO 27001, no SOC 2) and we do not claim encryption at rest beyond what the hosting providers apply to their own storage.

11. Your rights

Under the GDPR you can ask us to:

Email gimbernat13@gmail.com and we will answer within one month. You do not need to justify a request. Uninstalling the app triggers deletion automatically, as described in section 7.

You can also complain to a data-protection supervisory authority — normally the one where you live, work, or where you believe the problem occurred. A complaint costs you nothing and does not affect any other remedy.

12. Changes to this policy

When this policy changes, the new version appears on this page with a new date at the top, and material changes are noted on the changelog page. The version in force is the one published here.

13. Contact

gimbernat13@gmail.com — data-protection requests, security reports and everything else. See also our Terms of Service and the Data Processing Agreement.