EU AI LabelEU AI Label
WordPress pluginFind it on Shopify

Shopify app

Privacy Policy

Privacy Policy — EU AI Label (Shopify App)

Published at: https://euailabel.app/app-privacy-policy
Last updated: 1 August 2026


1. Data controller

The controller of your personal data within the meaning of Regulation (EU) 2016/679 (GDPR) and the Polish Act of 10 May 2018 on the Protection of Personal Data (RODO) is:

Damian Klimarczyk MDGA
ul. Olecka 16/4
60-458 Poznań
Poland

VAT ID (NIP): PL7812019335
Privacy & GDPR: privacy@euailabel.com
Support: support@euailabel.com
App listing: https://euailabel.app

We have not appointed a Data Protection Officer. Contact privacy@euailabel.com for all data-protection matters.


2. Scope

This Privacy Policy applies to the EU AI Label Shopify app — the embedded admin app, theme app extension, and related backend services that render AI transparency labels on your storefront.

It covers personal data we process when you:

  • install or use the Shopify app;
  • contact us for app support; or
  • communicate with us about your app account.

This policy does not describe:

  • how your store processes your customers’ data (you are the controller toward shoppers);
  • third-party platforms such as Shopify, which have their own privacy policies;
  • our marketing website at euailabel.app, which has separate cookie and analytics practices not used inside the Shopify app.

The app is intended for business and professional users only (B2B).


3. Roles under GDPR

Context Our role Your role (merchant)
Your app account, billing, support emails Controller Data subject
Product IDs, image IDs, label settings, audit logs processed to run the app Processor (on your instructions) Controller
Compliance Hub content you publish on your storefront Processor (technical hosting) Controller (content and legal basis)

When we process store data on your behalf, we do so only to provide the app under your instructions. Our Data Processing Agreement (DPA) is incorporated by reference for business customers where required by GDPR Art. 28. A signed copy is available on request at privacy@euailabel.com.


4. What data the Shopify app processes

This section follows Shopify’s recommended app privacy policy structure for data collected through Shopify.

4.1 Data collected through Shopify APIs

When you install EU AI Label, we access Merchant Data via Shopify’s Admin API, Billing API, and embedded app framework only as needed to operate the app:

Data Source Purpose
Shop domain, shop ID, shop name OAuth / Admin API Identify your store and operate the app
Merchant staff email and account identifiers OAuth Account association, support, billing notices
Access tokens OAuth Authenticate API calls on your behalf (stored securely)
Product IDs, product handles, media/image IDs Admin API Select photos and render labels
Subscription plan, billing status, charge IDs Billing API Plan limits and paid features
Theme app extension status Admin API / extension Publish labels to your storefront

We request only the API access scopes required for these functions. We do not access customer orders, payment instruments, or customer personal data through Shopify APIs for this app’s core features.

Legal basis: contract (GDPR Art. 6(1)(b)); legitimate interest in operating and securing the app (Art. 6(1)(f)).

4.2 Data collected directly from you (the merchant)

In addition to Shopify API data, we may collect directly from you:

  • email address and message content when you contact support@, partners@, or privacy@;
  • attachments or store details you voluntarily share;
  • preferences and label configuration you set in the app admin;
  • operational logs: IP address, user agent, request timestamps, and error traces from app API calls.

We do not ask for your customers’ personal data to use the app.

Legal basis: contract (Art. 6(1)(b)); legitimate interest in handling enquiries and securing the app (Art. 6(1)(f)).

4.3 Data from your customers (shoppers)

The EU AI Label app does not:

  • drop cookies or use tracking technologies on your storefront visitors through the app;
  • collect, log, or profile Customer Data (names, emails, order history, etc.) from your Shopify store;
  • communicate directly with your customers.

Labels render on product images in your theme; that display is part of your storefront, under your privacy obligations toward shoppers.

If you voluntarily include a person’s name or other personal data in custom label text or Compliance Hub content, you are the controller for that content.

4.4 App operational data (processed on your behalf)

To render labels, we also process business/operational data on your instructions:

  • label configuration (type, text, position, styling, locale, validation results);
  • optional snapshot of the product image URL at the time of labeling;
  • audit log entries: timestamps and Shopify admin staff user ID of whoever applied or changed a label;
  • theme app extension publish state.

Legal basis: contract (Art. 6(1)(b)); processing on your instructions as controller (Art. 6(1)(b) and Art. 28).

4.5 What the app does not collect or do

The Shopify app does not:

  • collect shopper/customer personal data;
  • process payment card numbers (Shopify handles billing);
  • permanently store copies of your product image files (labels render as an overlay; originals are not modified on our servers);
  • read or write C2PA, IPTC, or other embedded image metadata;
  • use analytics trackers, session replay, chatbots, or advertising pixels inside the app;
  • use your store data, product images, or label settings to train AI models.

5. Legal bases summary

Purpose Legal basis
Providing the installed Shopify app Contract
Billing, invoicing, VAT records Legal obligation (Polish tax and accounting law)
Security, abuse prevention, app logs Legitimate interest
Responding to GDPR requests Legal obligation / contract

6. How we use data

We use data to:

  • install, authenticate, and operate the app on your store;
  • render AI transparency labels via the theme app extension;
  • manage subscriptions, plan limits, and billing through Shopify;
  • provide support and service-related notices;
  • maintain audit logs for your internal compliance workflows;
  • comply with legal obligations and enforce our Terms of Service;
  • protect the app against fraud, abuse, and security incidents.

We do not sell personal data, use merchant store data for advertising profiling, use data for purposes unrelated to providing the app, or train AI models on your content.


7. Established in Europe and international transfers

We are established in Poland (European Union) at the address in §1.

Primary app infrastructure (Neon database and Render application hosting) runs in the EU (Frankfurt, Germany). Some sub-processors (e.g. Shopify) may process data in Canada, the United States, or other countries. Where personal data is transferred outside the European Economic Area, we rely on adequacy decisions, the EU–US Data Privacy Framework (where the recipient is certified), and/or Standard Contractual Clauses approved by the European Commission, plus supplementary measures where required.


8. Subprocessors (Shopify app)

We use the following providers to run the Shopify app. Each processes data only as needed and is bound by contractual data-protection obligations where applicable.

Provider Purpose Location / transfers
Shopify Inc. Embedded app hosting, OAuth, Admin API, Billing API, mandatory GDPR webhooks Canada, EU — Shopify Privacy Policy
Neon App database (Postgres), backend storage EU — Frankfurt, Germany (AWS eu-central-1)
Render Application hosting, backend infrastructure EU — Frankfurt, Germany

International transfers: Where data is transferred outside the EEA, we rely on adequacy decisions, the EU–US Data Privacy Framework (where certified), and/or Standard Contractual Clauses, plus supplementary measures where required.

We will notify you of material sub-processor changes by updating this page and by email and/or in-app notice at least 14 days before the change takes effect (see DPA §6.3).


9. Shopify mandatory GDPR compliance webhooks

We implement Shopify’s mandatory compliance webhooks:

Webhook Our response
customers/data_request We confirm we do not store end-customer personal data from your store. If any were inadvertently received, we provide it to you or the customer as required.
customers/redact We confirm and delete any end-customer data if present, within 30 days of the request.
shop/redact Shopify sends this webhook approximately 48 hours after you uninstall the app. We delete or anonymise associated merchant and app data within 30 days of receiving it, except where retention is required by law.

We verify webhook HMAC signatures and return 401 for invalid requests and 200 for valid requests, as required by Shopify.

You remain responsible for your own GDPR obligations toward your customers.


10. Retention

Data category Retention
Merchant account & app configuration Life of installation; deleted within 30 days of uninstall, shop/redact webhook, or enforceable deletion request
Audit logs Same as account data, unless you export them earlier
Support emails Up to 3 years after case closure, unless longer needed for disputes
Invoices & tax/accounting records 5 years, counting from the end of the calendar year in which the tax payment deadline expired (Ordynacja podatkowa, ustawa o rachunkowości)
Operational/security logs Up to 90 days

After retention periods expire, data is deleted or irreversibly anonymised.


11. Security

We implement appropriate technical and organisational measures, including TLS in transit, access controls, administrative logging, security updates, and secure storage of OAuth tokens.

If we become aware of a personal data breach likely to affect your rights, we will notify you and, where required, the supervisory authority within GDPR Art. 33–34 timeframes.


12. Your rights

Under GDPR you have the right to access, rectify, erase, restrict, port, and object to processing, and to withdraw consent where processing is consent-based.

Contact privacy@euailabel.com. We respond within one month, extendable by two months for complex requests.

You may lodge a complaint with:

Urząd Ochrony Danych Osobowych (UODO)https://uodo.gov.pl


13. Children’s data

The app is for business users aged 18+. We do not knowingly collect data from children.


14. Automated decision-making

We do not use automated decision-making or profiling with legal or similarly significant effects.


15. Changes

Material changes will be posted here with an updated date. Significant changes affecting app users may also be notified by email or in-app notice.


16. Contact

Damian Klimarczyk MDGA
ul. Olecka 16/4, 60-458 Poznań, Poland
Privacy: privacy@euailabel.com · Support: support@euailabel.com


This document is provided for transparency and regulatory compliance. It does not constitute legal advice.

Cookies on EU AI Label

We use strictly necessary cookies to run the site. With your consent we also use Google Analytics 4 and Microsoft Clarity to understand traffic and improve the product. Read more in our privacy policy.