Last updated 20 July 2026

Privacy Policy

Alnage ("the app") helps Shopify merchants meet their obligations under the EU General Product Safety Regulation (EU) 2023/988. This policy explains exactly what the app stores, why it stores it, who it is shared with, and how to have it deleted.

The short version: the app stores the compliance information you enter about your products and your business. It does not collect, request or retain any of your customers' personal data. Everything belonging to your store is permanently deleted after you uninstall.

1. Who is responsible for your data

The app is operated by an independent developer, contactable at gpsrapplication@gmail.com.

For the compliance data you enter, you are the data controller and the app acts as a data processor on your instructions. For your own details as a merchant using the app (store domain and contact address), the app operator is the controller.

2. What the app stores

CategoryExamplesWhy
Store identity Your .myshopify.com domain, store name, access token To connect to Shopify on your behalf and keep your data separate from other stores
Responsible Persons Name, company, address, email, phone of the EU/UK Responsible Person you appoint GPSR requires this contact to be published with your products
Manufacturers Name, trade name, address, email, phone GPSR requires manufacturer details on every product
Product compliance data Safety warnings per language, pictograms, GTIN, model, batch, serial, CE status, care instructions The core function of the app
Documents File names, links or Shopify Files references, retention dates GPSR requires technical documentation to be retained for 10 years
Incidents and recalls Records you create, and matches against public EU recall alerts GPSR requires records of complaints, incidents and recalls
Supplier requests Supplier email address, product reference, request status To collect missing safety data from your suppliers at your request
Activity log Which compliance action was taken and when So you can show regulators an audit trail

Responsible Person, manufacturer and supplier records may contain the personal data of named individuals at those businesses. You enter this data and remain its controller. The app processes it only to display it on your product pages, include it in marketplace export files you generate, and send supplier request emails you choose to send.

3. What the app does not store

4. Legal basis for processing

5. Who data is shared with

Only the providers needed to run the service. None of them sell or reuse your data.

ProviderPurposeWhat they receive
ShopifyProduct data, file storage, billingCompliance data written to your own store
RailwayApplication hosting and databaseAll app data, at rest
ResendDelivery of supplier request emailsSupplier email address and message content
AnthropicOptional AI drafting of safety warningsOnly the product title you ask it to draft for
EU Safety Gate (open data)Recall alert matchingNothing — the app downloads public alerts; no store data is sent

Data is never sold, rented, or used for advertising or model training.

6. International transfers

The app's infrastructure providers may process data outside the European Economic Area. Where that happens, transfers rely on the European Commission's Standard Contractual Clauses or an equivalent recognised safeguard. You can request details of the current hosting region using the contact address above.

7. Security

No system is perfectly secure. If a breach affects your data, you will be notified without undue delay and, where required, within 72 hours of the operator becoming aware of it.

8. Retention and deletion

9. Your rights

Under the GDPR and equivalent UK law you have the right to:

Requests sent to gpsrapplication@gmail.com are answered within 30 days.

10. Children

The app is a business tool sold to merchants. It is not directed at children and does not knowingly process data relating to anyone under 16.

11. Changes to this policy

If this policy changes materially, the date at the top of this page is updated and, where the change affects how your data is handled, active merchants are notified by email.

12. Contact

Email: gpsrapplication@gmail.com
Please include your store domain so requests can be located quickly.