EU AI LabelEU AI Label
WordPress pluginFind it on Shopify

Shopify app

Privacy Policy

Last updated: 28 July 2026


1. Data controller

The controller of your personal data within the meaning of Regulation (EU) 2016/679 (General Data Protection Regulation, “GDPR”) and the Polish Act of 10 May 2018 on the Protection of Personal Data (implementing GDPR, “RODO”) is:

Damian Klimarczyk MDGA
ul. Olecka 16/4
60-458 Poznań
Poland

VAT ID (NIP): PL7812019335
Email (privacy & GDPR requests): privacy@euailabel.com
General support: support@euailabel.com
Website: https://euailabel.app

We have not appointed a Data Protection Officer. For all data-protection matters, contact us at privacy@euailabel.com.


2. Scope of this policy

This Privacy Policy explains how we collect, use, store, and protect personal data when you:

  • visit euailabel.app or related marketing pages;
  • install or use the EU AI Label Shopify app;
  • install or use the EU AI Label WordPress / WooCommerce plugin;
  • contact us for support, partnerships, or sales;
  • use the website support chatbot; or
  • interact with us in any other way in connection with the above (collectively, the “Service”).

The Service is intended for business and professional users only (B2B). It is not directed at consumers acting outside their trade, business, craft, or profession.

This policy does not apply to:

  • third-party websites, platforms, or services we link to (including Shopify, WordPress, Calendly, and social networks), which have their own privacy policies;
  • your own online store’s processing of your customers’ personal data — for that, you (the merchant) are the controller and must provide your own privacy notice to shoppers;
  • sister products on separate domains (e.g. euaiicon.com, aiacticon.com) unless explicitly stated on those sites.

3. Roles under GDPR: controller and processor

Depending on the data involved, we act in different roles:

Context Our role Your role (merchant)
Your account, billing, support emails, website analytics Controller Data subject
Product IDs, image IDs, label settings, audit logs processed to operate the app on your store Processor (on your instructions) Controller
Content you publish via Compliance Hub on your storefront Processor (technical hosting) Controller (content and legal basis)

When we process store data on your behalf, we do so only to provide the Service, under your instructions as reflected in your use of the app and these Terms. A Data Processing Agreement (DPA) incorporating Standard Contractual Clauses is available on request at privacy@euailabel.com and is incorporated by reference for business customers where required by GDPR Art. 28.


4. What personal data we collect

4.1 Merchant and account data (Shopify app / WordPress plugin)

When you install and use the Service, we may process:

  • store domain (e.g. yourstore.myshopify.com) or site URL;
  • merchant contact email (as provided by Shopify OAuth, WordPress, or you directly);
  • Shopify shop ID, access tokens (stored securely, used only to operate the app);
  • subscription plan, billing status, trial dates, and billing metadata via Shopify Billing API or the WordPress licensing flow;
  • preferences and configuration you set in the app dashboard.

Legal basis: performance of a contract (GDPR Art. 6(1)(b)); legitimate interest in operating and securing the Service (Art. 6(1)(f)).

4.2 App operational data (processed on your behalf)

To render labels on your storefront, we process business/operational data, not shopper personal data:

  • Shopify or WooCommerce product IDs, product handles, and media/image IDs;
  • label configuration (type, text, position, styling, locale, validation results);
  • optional snapshot of the product image URL at the time of labeling;
  • audit log entries: creation/update timestamps and Shopify admin staff user ID of the person who applied or changed a label;
  • theme app extension status and publish state.

We do not collect names, emails, addresses, order details, or other personal data of your store’s customers (shoppers) through the Shopify app.

Legal basis: performance of a contract (Art. 6(1)(b)); processing on your instructions as controller (Art. 6(1)(b) and Art. 28).

4.3 Website visitors

When you browse euailabel.app, we may process:

  • IP address, browser type, device type, operating system, referring URL;
  • pages viewed, session duration, and interaction events;
  • cookie identifiers (see Section 8);
  • data you voluntarily submit (contact forms, waitlist, newsletter if offered).

Legal basis: consent for non-essential cookies and analytics (Art. 6(1)(a)); legitimate interest for strictly necessary operation and security (Art. 6(1)(f)).

4.4 Support and communications

  • email address and message content when you write to support@, partners@, privacy@, or other listed addresses;
  • any attachments or store details you choose to share;
  • metadata (date, subject, thread history).

Legal basis: contract (Art. 6(1)(b)); legitimate interest in handling enquiries (Art. 6(1)(f)).

4.5 Website chatbot

If you use our website chatbot:

  • email address (required before the second question);
  • chat messages and session metadata (locale, source page, audience type);
  • session timestamps.

Chat content may be processed by OpenAI via its API to generate responses. Do not submit special categories of data (health, biometric, etc.) or third parties’ personal data via the chatbot.

No use of your data to train AI models: We use OpenAI’s commercial API, not the consumer ChatGPT product. Under OpenAI’s API data usage policies, data submitted through the API is not used by OpenAI to train or improve its models by default. We do not permit OpenAI to use your chatbot messages or email for model training, and we do not use merchant store data, product images, or app configuration to train any AI models. Your chat data is processed solely to generate responses during your session and for support quality purposes within the retention period in §10.

Legal basis: consent (Art. 6(1)(a)) by continuing after the email prompt; contract/legitimate interest for support quality (Art. 6(1)(b)/(f)).

4.6 Operational and security logs

  • IP address, user agent, request timestamps, error traces, authentication events;
  • retained for reliability, fraud prevention, and incident response.

Legal basis: legitimate interest (Art. 6(1)(f)).

4.7 What we do not collect

Through the Shopify app specifically, we do not intentionally collect:

  • shopper/customer personal data;
  • payment card numbers (billing is handled by Shopify);
  • permanent copies of your product image files (labels are rendered as an overlay; original files are not modified on our servers);
  • C2PA, IPTC, or other embedded image metadata.

5. Legal bases summary (GDPR Art. 6)

Purpose Legal basis
Providing the installed app and plugin Contract
Billing, invoicing, VAT records Legal obligation (Polish tax and accounting law)
Security, abuse prevention, service logs Legitimate interest
Non-essential cookies, GA4, Clarity, chatbot email Consent
Responding to GDPR requests Legal obligation / contract

You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal. Withdrawing consent for analytics does not affect app functionality.


6. How we use personal data

We use personal data to:

  • install, authenticate, and operate the Service on your store;
  • render AI transparency labels via the theme app extension or plugin;
  • manage subscriptions, plan limits, and billing through Shopify;
  • provide support, documentation, and onboarding;
  • send service-related notices (e.g. material policy changes, security alerts);
  • maintain audit logs you may use for internal compliance workflows;
  • improve the Service through aggregated, anonymised usage insights where permitted;
  • comply with legal obligations and enforce our Terms of Service;
  • protect the Service against fraud, abuse, and security incidents.

We do not sell personal data. We do not use merchant store data for advertising profiling. We do not use your product images, label settings, or other app data to train AI models — now or in the future.


7. Subprocessors and third-party recipients

We use the following categories of providers. Each processes data only as needed to deliver their service and is bound by contractual data-protection obligations where applicable.

Provider Purpose Location / transfers
Shopify Inc. App hosting, OAuth, Admin API, Billing API, mandatory GDPR webhooks Canada, EU — Shopify Privacy Policy
Supabase (Lovable Cloud) Database, authentication, backend storage EU
Cloudflare, Inc. CDN, DNS, edge security Global — SCCs / DPF where applicable
Google LLC — Analytics 4 Website analytics (consent only) USA/EU — measurement ID G-DJN0V28ZY4, IP anonymised
Google LLC — Tag Manager / gtag.js Analytics loader (consent only) USA/EU
Google LLC — Fonts Web font delivery USA/EU
Microsoft Corporation — Clarity Heatmaps & session replay (consent only); sensitive fields masked USA/EU
OpenAI Website chatbot response generation via API only; not used for model training (see §4.5) USA — SCCs / DPF
Automattic / WordPress.org Open-source plugin distribution USA
GitHub, Inc. Open-source releases USA
Calendly LLC Demo and partnership booking scheduling USA — only if you book a call

International transfers: Where personal data is transferred outside the European Economic Area, we rely on adequacy decisions, the EU–US Data Privacy Framework (where the recipient is certified), and/or Standard Contractual Clauses approved by the European Commission, plus supplementary measures where required.

We will update this list if we add or change subprocessors. Where we act as your processor, material sub-processor changes are notified by updating this page and by email and/or in-app notice to the merchant contact on file at least 14 days before the change takes effect (see our DPA §6.3).


8. Cookies and similar technologies

8.1 Strictly necessary cookies

Required for site operation, security, and consent management. These do not require consent under the ePrivacy Directive when strictly necessary.

8.2 Analytics and performance (consent required)

With your consent, we load:

  • Google Analytics 4 — aggregated traffic statistics; IP anonymisation enabled; default retention 14 months;
  • Microsoft Clarity — heatmaps and session recordings; input fields masked by default;
  • Google Tag Manager / gtag.js — loads GA4.

8.3 Fonts

Google Fonts may be requested from Google servers when you visit our site.

8.4 Managing consent

You can accept, reject, or change cookie preferences at any time via the cookie settings link in our site footer. Withdrawing consent stops non-essential scripts from loading on subsequent visits.


9. Shopify mandatory GDPR compliance webhooks

As a Shopify app, we implement Shopify’s mandatory compliance webhooks:

  • customers/data_request — we confirm we do not store end-customer personal data from your store; if any such data were inadvertently received, we would provide it to you;
  • customers/redact — we confirm and delete any end-customer data if present;
  • shop/redact — upon permanent shop deletion, we delete or anonymise associated merchant and app data within 30 days, except where retention is required by law.

Merchants remain responsible for their own GDPR obligations toward their customers.


10. Retention periods

Data category Retention
Merchant account & app configuration For the life of the installation, then deleted within 30 days of app uninstall or shop/redact webhook
Audit logs Same as account data, unless you export them earlier
Support emails Up to 3 years after case closure, unless longer needed for disputes
Invoices, tax books & accounting records 5 years, counting from the end of the calendar year in which the tax payment deadline expired, as required by the Polish Tax Ordinance Act (Ordynacja podatkowa), and related accounting rules under the Polish Accounting Act (ustawa o rachunkowości)
Operational/security logs Up to 90 days
Analytics (GA4) 14 months (Google default)
Chatbot sessions Up to 12 months, then deleted or anonymised

After retention periods expire, data is deleted or irreversibly anonymised.


11. Security measures

We implement appropriate technical and organisational measures, including:

  • TLS encryption in transit;
  • access controls and role-based permissions on production systems;
  • logging and monitoring of administrative access;
  • regular dependency and security updates;
  • secure storage of OAuth tokens and secrets;
  • pseudonymisation where practical for analytics.

No method of transmission or storage is 100% secure. If we become aware of a personal data breach likely to affect your rights, we will notify you and, where required, the supervisory authority within the timeframes required by GDPR Art. 33–34.


12. Your rights under GDPR and RODO

If you are in the EEA, UK, or another jurisdiction with similar rights, you have the right to:

  1. Access — obtain confirmation and a copy of your personal data;
  2. Rectification — correct inaccurate data;
  3. Erasure (“right to be forgotten”) — in applicable cases;
  4. Restriction — limit processing in certain circumstances;
  5. Data portability — receive data you provided in a structured, machine-readable format;
  6. Object — to processing based on legitimate interest, including profiling;
  7. Withdraw consent — at any time, for consent-based processing;
  8. Not be subject to solely automated decisions with legal/significant effects — we do not make such decisions.

To exercise any right, email privacy@euailabel.com. We respond within one month, extendable by two months for complex requests. We may request reasonable identity verification.

You may also lodge a complaint with a supervisory authority:

Urząd Ochrony Danych Osobowych (UODO)
ul. Stawki 2
00-193 Warszawa
Poland
Website: https://uodo.gov.pl
Email: kancelaria@uodo.gov.pl

If you are habitually resident in another EU member state, you may also complain to your local supervisory authority.


13. Children’s data

The Service is intended for business and professional users aged 18 and over acting in a commercial or professional capacity. It is not offered to consumers for personal, household, or non-commercial use. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact privacy@euailabel.com and we will delete it.


14. Automated decision-making

We do not use automated decision-making or profiling that produces legal or similarly significant effects on data subjects.


15. Changes to this policy

We may update this Privacy Policy to reflect legal, technical, or business changes. Material changes will be posted on this page with an updated “Last updated” date. For significant changes affecting app users, we may also notify you by email or in-app notice. Continued use after the effective date constitutes acknowledgment of the updated policy.


16. Contact

Damian Klimarczyk MDGA
ul. Olecka 16/4, 60-458 Poznań, Poland
Privacy & GDPR: privacy@euailabel.com
Support: support@euailabel.com


This document is provided for transparency and regulatory compliance. It does not constitute legal advice.

Cookies on EU AI Label

We use strictly necessary cookies to run the site. With your consent we also use Google Analytics 4 and Microsoft Clarity to understand traffic and improve the product. Read more in our privacy policy.