Privacy Policy
Last updated: 2026-09-05
This policy explains what data the Shopify app Conforma: EU Guarantee Label and this website process, why, on what legal basis, and how long it is kept. It is written for the merchant who installs the app. It is not legal advice about your own obligations as a trader.
1. Who is responsible
The controller for the processing described here is EU Guarantee Label, operated by an individual developer. Contact for anything in this document, including all data-protection requests: gimbernat13@gmail.com.
Operator legal name and address: [to be added]
For the personal data of your customers, you remain the controller and Shopify is your processor under Shopify's own terms. This app never receives that data — see section 4.
2. Data the app processes
All of it comes from Shopify when you install the app and while you use it. In detail:
- Store record. Your
.myshopify.comshop domain, your store's primary locale, your current plan on this app, and timestamps and flags describing your setup: install and uninstall time, when the storefront notice was first detected as live, whether the label block is placed, whether the notice shows on product pages and in the footer, the EU-only toggle, the branding toggle, whether the onboarding was dismissed, whether the review prompt was shown, and a cached count of how many products carry a label. - Sessions. The Shopify access token issued to the app for your store, together with the shop domain, stored so the app can call Shopify's API on your behalf. The app uses offline tokens; it does not create per-staff-user sessions.
- Product data, read but not stored. Product identifiers, titles and vendors are read from Shopify's Admin API to draw the products screen and to apply bulk changes. They are not written to our database. The guarantee duration you set per product is stored as a metafield on your own Shopify store, not with us; our database keeps only the count.
- Green-claims scan results (Pro plan). A record of each scan run (start, finish, status, how many products, pages and articles were read, how many findings) and, per finding, the resource type and id, its title, the field it was found in, the matched phrase, the language, the rule reference, a short excerpt of your own product, page or article text around the match, and the Shopify admin link. Full descriptions are never stored — only the excerpt around a match.
- Compliance reports (Complete and Pro plans). The generated PDF and the summary it was built from, so you can download a report again later.
- Product-usage events. Shop domain, an event name from a fixed list (install, embed enabled, label block placed, first label set, bulk assign, scan run, report generated, plan changed, review prompted, uninstall) and a timestamp. This is how we know which steps merchants get stuck on.
- Server logs. Standard web-server and application logs: request time, path, status code, IP address, user agent, and error traces.
- Support correspondence. If you email us, we keep the message and our reply.
Where any of this is personal data, it is the personal data of you — the merchant and your staff — not of your customers.
3. Data on your storefront
The notice and the GARAN label are rendered by a Shopify theme app extension. They set no cookies, load no external scripts, and make no third-party requests: the official artwork is served from Shopify's own CDN as part of the extension. Nothing about your shoppers is sent to us, and we run no analytics on your storefront.
4. What we never process
- Your customers' personal data — names, addresses, email addresses, phone numbers.
- Orders, carts, checkouts, payment or card data.
- Your theme code. The app reads two theme settings files to detect whether the notice and label block are in place, and writes nothing to your theme.
- Anything from a sales channel other than the store that installed the app.
Shopify sends every public app the two mandatory customer-privacy webhooks
(customers/data_request and customers/redact). We acknowledge them and have
nothing to return or erase, because we hold no customer data.
5. This website
This site is a set of static pages. It sets no cookies, runs no analytics, and contains no tracking pixels, no advertising tags and no embedded third-party content. The typeface is self-hosted rather than loaded from a font CDN, so opening a page here makes no request to any server other than the one serving the page. The host of these pages (GitHub Pages) processes the request data any web server sees, including your IP address, to deliver them.
6. Why we process it, and on what legal basis
- To provide the app you installed — showing the notice and label, storing your settings, running scans, generating reports, applying your plan's limits. Legal basis: performance of a contract, Art. 6(1)(b) GDPR.
- To bill you through Shopify's Managed Pricing. We read which plan is active; Shopify performs the billing. Legal basis: Art. 6(1)(b) GDPR.
- To keep the service secure and working — server logs, error traces, abuse prevention, and the usage events that tell us which steps fail. Legal basis: legitimate interests, Art. 6(1)(f) GDPR, in operating and improving a service we are contractually obliged to deliver.
- To answer support requests. Legal basis: Art. 6(1)(b) and (f) GDPR.
- To meet legal obligations, including Shopify's mandatory compliance webhooks. Legal basis: Art. 6(1)(c) GDPR.
We do not use your data for advertising, we do not profile you, and we never sell or rent it.
7. How long we keep it
- Sessions: deleted immediately when Shopify sends the
app/uninstalledwebhook. - Everything else about your shop — the store record, scan runs and findings, generated
reports, usage events: deleted when Shopify sends the
shop/redactwebhook, which Shopify dispatches 48 hours after uninstall. If you ask us to delete earlier, we do it on request. - Server logs: kept no longer than 30 days, then rotated out.
- Support correspondence: kept up to 24 months, so a follow-up question a year later still has context. Deleted sooner on request.
8. Who else is involved (sub-processors)
| Sub-processor | Company country | What they do | Where the servers are |
|---|---|---|---|
| Shopify International Ltd | Ireland | The platform the app runs on and the source of all store data; also handles billing | Per Shopify's own DPA |
| Hostinger International Ltd | Cyprus | Application hosting — the virtual server the app runs on | Boston, Massachusetts, United States |
| netcup GmbH | Germany | Database hosting — the PostgreSQL database holding everything in section 2 | Manassas, Virginia, United States |
| GitHub, Inc. | United States | Hosting of this website only — no app data reaches it | GitHub Pages global infrastructure |
There is no analytics provider, no error-tracking SaaS, no email marketing tool and no CRM in this list, because the app uses none. Support email is handled by an ordinary mail provider. We will update this table before any new sub-processor starts processing, and announce the change on the changelog page.
9. International transfers
Merchant data processed through the app is stored on servers located in the United States — the application server in Boston, Massachusetts and the database in Manassas, Virginia. Both are operated for us by European companies (Hostinger International Ltd, Cyprus; netcup GmbH, Germany), but the processing itself happens outside the EEA, which engages Chapter V of the GDPR.
For those transfers we rely on the Standard Contractual Clauses included in those providers' data processing terms, together with the technical and organisational security commitments described in section 10.
The app stores no end-customer personal data, so nothing about your shoppers is transferred anywhere. What crosses the border is the store configuration, scan findings, reports and access tokens listed in section 2.
Hosting locations can change — a move to an EU region is possible. Any change of hosting location, like any change of sub-processor, is announced on the changelog page. Shopify may transfer data internationally under its own DPA and transfer mechanisms, which govern the Shopify-to-merchant relationship independently of this policy.
10. Security
What we can state plainly:
- All traffic to the app and to this website is served over HTTPS/TLS. There is no plaintext endpoint.
- The database is not exposed to the public internet: the firewall accepts PostgreSQL connections from the application server's IP address only, and authentication is password-based over an encrypted connection.
- Shopify access tokens are stored in that database and are never written to logs or shown in the UI.
- Administrative access to the server and the database is limited to the operator, over SSH with key authentication.
- Webhook requests from Shopify are verified by HMAC signature before anything is acted on.
- The app requests the minimum Shopify scopes it needs: read products, write products, read content, read themes, read locales. It asks for no customer, order or payment scope.
We do not claim a formal certification (no ISO 27001, no SOC 2) and we do not claim encryption at rest beyond what the hosting providers apply to their own storage.
11. Your rights
Under the GDPR you can ask us to:
- confirm what we hold about you and give you a copy (access, Art. 15);
- correct anything inaccurate (rectification, Art. 16);
- delete it (erasure, Art. 17);
- restrict what we do with it (Art. 18);
- hand it over in a machine-readable form, or send it to another provider (portability, Art. 20);
- stop processing based on legitimate interests (objection, Art. 21).
Email gimbernat13@gmail.com and we will answer within one month. You do not need to justify a request. Uninstalling the app triggers deletion automatically, as described in section 7.
You can also complain to a data-protection supervisory authority — normally the one where you live, work, or where you believe the problem occurred. A complaint costs you nothing and does not affect any other remedy.
12. Changes to this policy
When this policy changes, the new version appears on this page with a new date at the top, and material changes are noted on the changelog page. The version in force is the one published here.
13. Contact
gimbernat13@gmail.com — data-protection requests, security reports and everything else. See also our Terms of Service and the Data Processing Agreement.