Privacy Policy
GPSR Compliance Manager — Last updated: July 2026
What data we collect
When you install GPSR Compliance Manager, we store: your shop domain, an API access token provided by Shopify, your product catalog data (titles, handles, GPSR compliance metafields), and the EU Responsible Person contact details you enter in the app. We do not collect or store any data about your customers.
How we use it
Exclusively to provide the service: computing GPSR compliance scores, writing GPSR metafields to your products, generating CSV/PDF exports, and sending you service emails (welcome, weekly compliance report). We never sell or share your data with third parties.
Where it is stored
Data is hosted in the European Union (Supabase, eu-west region) and processed on Vercel. Access tokens are stored server-side only and never exposed to browsers.
Data retention and deletion
When you uninstall the app, your access token is revoked immediately. Upon receiving Shopify's shop/redact webhook (48 hours after uninstall), all data related to your shop is permanently deleted. You can also request deletion at any time.
GDPR
We comply with Shopify's mandatory privacy webhooks (customers/data_request, customers/redact, shop/redact). As we store no end-customer data, customer data requests return empty results.
Contact
For any privacy question or request: dogan.sezer@outlook.fr