Privacy Policy
Alnage ("the app") helps Shopify merchants meet their obligations under the EU General Product Safety Regulation (EU) 2023/988. This policy explains exactly what the app stores, why it stores it, who it is shared with, and how to have it deleted.
1. Who is responsible for your data
The app is operated by an independent developer, contactable at gpsrapplication@gmail.com.
For the compliance data you enter, you are the data controller and the app acts as a data processor on your instructions. For your own details as a merchant using the app (store domain and contact address), the app operator is the controller.
2. What the app stores
| Category | Examples | Why |
|---|---|---|
| Store identity | Your .myshopify.com domain, store name, access token |
To connect to Shopify on your behalf and keep your data separate from other stores |
| Responsible Persons | Name, company, address, email, phone of the EU/UK Responsible Person you appoint | GPSR requires this contact to be published with your products |
| Manufacturers | Name, trade name, address, email, phone | GPSR requires manufacturer details on every product |
| Product compliance data | Safety warnings per language, pictograms, GTIN, model, batch, serial, CE status, care instructions | The core function of the app |
| Documents | File names, links or Shopify Files references, retention dates | GPSR requires technical documentation to be retained for 10 years |
| Incidents and recalls | Records you create, and matches against public EU recall alerts | GPSR requires records of complaints, incidents and recalls |
| Supplier requests | Supplier email address, product reference, request status | To collect missing safety data from your suppliers at your request |
| Activity log | Which compliance action was taken and when | So you can show regulators an audit trail |
Responsible Person, manufacturer and supplier records may contain the personal data of named individuals at those businesses. You enter this data and remain its controller. The app processes it only to display it on your product pages, include it in marketplace export files you generate, and send supplier request emails you choose to send.
3. What the app does not store
- No customer personal data. The app does not request the
read_customersorread_orderspermissions and holds no customer names, addresses, email addresses or order history. - No payment data. Subscriptions are billed by Shopify. The app never sees card numbers or bank details.
- No tracking. The app sets no advertising or analytics cookies and runs no third-party trackers. The only cookies used are the session cookies Shopify requires for the embedded admin to function.
4. Legal basis for processing
- Performance of a contract — processing your store's data is necessary to provide the service you signed up for.
- Legal obligation — some retention exists because GPSR itself requires documentation to be kept.
- Legitimate interests — keeping the service secure, preventing abuse, and maintaining an audit trail.
5. Who data is shared with
Only the providers needed to run the service. None of them sell or reuse your data.
| Provider | Purpose | What they receive |
|---|---|---|
| Shopify | Product data, file storage, billing | Compliance data written to your own store |
| Railway | Application hosting and database | All app data, at rest |
| Resend | Delivery of supplier request emails | Supplier email address and message content |
| Anthropic | Optional AI drafting of safety warnings | Only the product title you ask it to draft for |
| EU Safety Gate (open data) | Recall alert matching | Nothing — the app downloads public alerts; no store data is sent |
Data is never sold, rented, or used for advertising or model training.
6. International transfers
The app's infrastructure providers may process data outside the European Economic Area. Where that happens, transfers rely on the European Commission's Standard Contractual Clauses or an equivalent recognised safeguard. You can request details of the current hosting region using the contact address above.
7. Security
- All traffic is encrypted in transit over HTTPS.
- Access tokens are stored server-side and never exposed to the browser.
- Data is separated per store; one merchant cannot read another's records.
- Access to production infrastructure is restricted to the app operator.
No system is perfectly secure. If a breach affects your data, you will be notified without undue delay and, where required, within 72 hours of the operator becoming aware of it.
8. Retention and deletion
- Data is retained while the app is installed on your store.
- On uninstall, stored access tokens are deleted immediately.
- Shopify sends a
shop/redactrequest 48 hours after uninstall. On receiving it, all data belonging to your store is permanently deleted from the app's database. The delay exists so a reinstall within two days does not lose your work. - You can request immediate deletion at any time using the contact address below.
- Files you uploaded live in your own Shopify Files and remain under your control; the app stores only a reference to them.
9. Your rights
Under the GDPR and equivalent UK law you have the right to:
- access the data held about you;
- have inaccurate data corrected;
- have your data deleted;
- restrict or object to processing;
- receive your data in a portable format;
- lodge a complaint with your national data protection supervisory authority.
Requests sent to gpsrapplication@gmail.com are answered within 30 days.
10. Children
The app is a business tool sold to merchants. It is not directed at children and does not knowingly process data relating to anyone under 16.
11. Changes to this policy
If this policy changes materially, the date at the top of this page is updated and, where the change affects how your data is handled, active merchants are notified by email.
12. Contact
Email: gpsrapplication@gmail.com
Please include your store domain so requests can be located quickly.