Shopify app
Privacy Policy
Privacy Policy — EU AI Label (Shopify App)
Published at: https://euailabel.app/app-privacy-policy
Last updated: 1 August 2026
1. Data controller
The controller of your personal data within the meaning of Regulation (EU) 2016/679 (GDPR) and the Polish Act of 10 May 2018 on the Protection of Personal Data (RODO) is:
Damian Klimarczyk MDGA
ul. Olecka 16/4
60-458 Poznań
Poland
VAT ID (NIP): PL7812019335
Privacy & GDPR: privacy@euailabel.com
Support: support@euailabel.com
App listing: https://euailabel.app
We have not appointed a Data Protection Officer. Contact privacy@euailabel.com for all data-protection matters.
2. Scope
This Privacy Policy applies to the EU AI Label Shopify app — the embedded admin app, theme app extension, and related backend services that render AI transparency labels on your storefront.
It covers personal data we process when you:
- install or use the Shopify app;
- contact us for app support; or
- communicate with us about your app account.
This policy does not describe:
- how your store processes your customers’ data (you are the controller toward shoppers);
- third-party platforms such as Shopify, which have their own privacy policies;
- our marketing website at euailabel.app, which has separate cookie and analytics practices not used inside the Shopify app.
The app is intended for business and professional users only (B2B).
3. Roles under GDPR
| Context | Our role | Your role (merchant) |
|---|---|---|
| Your app account, billing, support emails | Controller | Data subject |
| Product IDs, image IDs, label settings, audit logs processed to run the app | Processor (on your instructions) | Controller |
| Compliance Hub content you publish on your storefront | Processor (technical hosting) | Controller (content and legal basis) |
When we process store data on your behalf, we do so only to provide the app under your instructions. Our Data Processing Agreement (DPA) is incorporated by reference for business customers where required by GDPR Art. 28. A signed copy is available on request at privacy@euailabel.com.
4. What data the Shopify app processes
This section follows Shopify’s recommended app privacy policy structure for data collected through Shopify.
4.1 Data collected through Shopify APIs
When you install EU AI Label, we access Merchant Data via Shopify’s Admin API, Billing API, and embedded app framework only as needed to operate the app:
| Data | Source | Purpose |
|---|---|---|
| Shop domain, shop ID, shop name | OAuth / Admin API | Identify your store and operate the app |
| Merchant staff email and account identifiers | OAuth | Account association, support, billing notices |
| Access tokens | OAuth | Authenticate API calls on your behalf (stored securely) |
| Product IDs, product handles, media/image IDs | Admin API | Select photos and render labels |
| Subscription plan, billing status, charge IDs | Billing API | Plan limits and paid features |
| Theme app extension status | Admin API / extension | Publish labels to your storefront |
We request only the API access scopes required for these functions. We do not access customer orders, payment instruments, or customer personal data through Shopify APIs for this app’s core features.
Legal basis: contract (GDPR Art. 6(1)(b)); legitimate interest in operating and securing the app (Art. 6(1)(f)).
4.2 Data collected directly from you (the merchant)
In addition to Shopify API data, we may collect directly from you:
- email address and message content when you contact support@, partners@, or privacy@;
- attachments or store details you voluntarily share;
- preferences and label configuration you set in the app admin;
- operational logs: IP address, user agent, request timestamps, and error traces from app API calls.
We do not ask for your customers’ personal data to use the app.
Legal basis: contract (Art. 6(1)(b)); legitimate interest in handling enquiries and securing the app (Art. 6(1)(f)).
4.3 Data from your customers (shoppers)
The EU AI Label app does not:
- drop cookies or use tracking technologies on your storefront visitors through the app;
- collect, log, or profile Customer Data (names, emails, order history, etc.) from your Shopify store;
- communicate directly with your customers.
Labels render on product images in your theme; that display is part of your storefront, under your privacy obligations toward shoppers.
If you voluntarily include a person’s name or other personal data in custom label text or Compliance Hub content, you are the controller for that content.
4.4 App operational data (processed on your behalf)
To render labels, we also process business/operational data on your instructions:
- label configuration (type, text, position, styling, locale, validation results);
- optional snapshot of the product image URL at the time of labeling;
- audit log entries: timestamps and Shopify admin staff user ID of whoever applied or changed a label;
- theme app extension publish state.
Legal basis: contract (Art. 6(1)(b)); processing on your instructions as controller (Art. 6(1)(b) and Art. 28).
4.5 What the app does not collect or do
The Shopify app does not:
- collect shopper/customer personal data;
- process payment card numbers (Shopify handles billing);
- permanently store copies of your product image files (labels render as an overlay; originals are not modified on our servers);
- read or write C2PA, IPTC, or other embedded image metadata;
- use analytics trackers, session replay, chatbots, or advertising pixels inside the app;
- use your store data, product images, or label settings to train AI models.
5. Legal bases summary
| Purpose | Legal basis |
|---|---|
| Providing the installed Shopify app | Contract |
| Billing, invoicing, VAT records | Legal obligation (Polish tax and accounting law) |
| Security, abuse prevention, app logs | Legitimate interest |
| Responding to GDPR requests | Legal obligation / contract |
6. How we use data
We use data to:
- install, authenticate, and operate the app on your store;
- render AI transparency labels via the theme app extension;
- manage subscriptions, plan limits, and billing through Shopify;
- provide support and service-related notices;
- maintain audit logs for your internal compliance workflows;
- comply with legal obligations and enforce our Terms of Service;
- protect the app against fraud, abuse, and security incidents.
We do not sell personal data, use merchant store data for advertising profiling, use data for purposes unrelated to providing the app, or train AI models on your content.
7. Established in Europe and international transfers
We are established in Poland (European Union) at the address in §1.
Primary app infrastructure (Neon database and Render application hosting) runs in the EU (Frankfurt, Germany). Some sub-processors (e.g. Shopify) may process data in Canada, the United States, or other countries. Where personal data is transferred outside the European Economic Area, we rely on adequacy decisions, the EU–US Data Privacy Framework (where the recipient is certified), and/or Standard Contractual Clauses approved by the European Commission, plus supplementary measures where required.
8. Subprocessors (Shopify app)
We use the following providers to run the Shopify app. Each processes data only as needed and is bound by contractual data-protection obligations where applicable.
| Provider | Purpose | Location / transfers |
|---|---|---|
| Shopify Inc. | Embedded app hosting, OAuth, Admin API, Billing API, mandatory GDPR webhooks | Canada, EU — Shopify Privacy Policy |
| Neon | App database (Postgres), backend storage | EU — Frankfurt, Germany (AWS eu-central-1) |
| Render | Application hosting, backend infrastructure | EU — Frankfurt, Germany |
International transfers: Where data is transferred outside the EEA, we rely on adequacy decisions, the EU–US Data Privacy Framework (where certified), and/or Standard Contractual Clauses, plus supplementary measures where required.
We will notify you of material sub-processor changes by updating this page and by email and/or in-app notice at least 14 days before the change takes effect (see DPA §6.3).
9. Shopify mandatory GDPR compliance webhooks
We implement Shopify’s mandatory compliance webhooks:
| Webhook | Our response |
|---|---|
| customers/data_request | We confirm we do not store end-customer personal data from your store. If any were inadvertently received, we provide it to you or the customer as required. |
| customers/redact | We confirm and delete any end-customer data if present, within 30 days of the request. |
| shop/redact | Shopify sends this webhook approximately 48 hours after you uninstall the app. We delete or anonymise associated merchant and app data within 30 days of receiving it, except where retention is required by law. |
We verify webhook HMAC signatures and return 401 for invalid requests and 200 for valid requests, as required by Shopify.
You remain responsible for your own GDPR obligations toward your customers.
10. Retention
| Data category | Retention |
|---|---|
| Merchant account & app configuration | Life of installation; deleted within 30 days of uninstall, shop/redact webhook, or enforceable deletion request |
| Audit logs | Same as account data, unless you export them earlier |
| Support emails | Up to 3 years after case closure, unless longer needed for disputes |
| Invoices & tax/accounting records | 5 years, counting from the end of the calendar year in which the tax payment deadline expired (Ordynacja podatkowa, ustawa o rachunkowości) |
| Operational/security logs | Up to 90 days |
After retention periods expire, data is deleted or irreversibly anonymised.
11. Security
We implement appropriate technical and organisational measures, including TLS in transit, access controls, administrative logging, security updates, and secure storage of OAuth tokens.
If we become aware of a personal data breach likely to affect your rights, we will notify you and, where required, the supervisory authority within GDPR Art. 33–34 timeframes.
12. Your rights
Under GDPR you have the right to access, rectify, erase, restrict, port, and object to processing, and to withdraw consent where processing is consent-based.
Contact privacy@euailabel.com. We respond within one month, extendable by two months for complex requests.
You may lodge a complaint with:
Urząd Ochrony Danych Osobowych (UODO) — https://uodo.gov.pl
13. Children’s data
The app is for business users aged 18+. We do not knowingly collect data from children.
14. Automated decision-making
We do not use automated decision-making or profiling with legal or similarly significant effects.
15. Changes
Material changes will be posted here with an updated date. Significant changes affecting app users may also be notified by email or in-app notice.
16. Contact
Damian Klimarczyk MDGA
ul. Olecka 16/4, 60-458 Poznań, Poland
Privacy: privacy@euailabel.com · Support: support@euailabel.com
This document is provided for transparency and regulatory compliance. It does not constitute legal advice.