Privacy Policy
Effective date: 2026-09-09 Controller for the App's own data: Kadosh (카도쉬), proprietor Kang Seung-hyun (강승현), Republic of Korea — cadosy@gmail.com
This policy explains how GPSR Shield (the "App") handles data. For personal data that we process on behalf of a merchant, the merchant is the controller and we are the processor — see the Data Processing Addendum.
1. Data we access and store
From the merchant's Shopify store (via the Shopify API), only what the App needs:
- Store identity & OAuth: shop domain, access token, plan, locale, basic shop info.
- Product data needed to read/write GPSR fields: product IDs, titles, images, and the
gpsrmetafields /gpsr_economic_operator&gpsr_warningmetaobjects. - App session and review records: the current warning/no-warning reviewer and the last person
who published a product, with their timestamps (
reviewed_by,reviewed_at). - Saved gap scans: the latest Pro scan and, separately, the latest Free sample of up to 50 products: product IDs, titles, Shopify pagination positions, detected gap descriptions, counts and progress timestamps. We do not copy economic-operator contact details, authored warning text or publication snapshots into these saved scan records.
- Reusable profile revisions and bulk jobs: merchant-chosen profile names, source reference IDs and fingerprints, selected product IDs/titles, proposed reference changes, technical comparison digests, operation markers, job progress and result messages. Operator contact details, authored warning text and original publication snapshots are read from Shopify when needed, not copied into these saved profile/job records. Avoid personal data in profile names and product titles.
- Saved CSV jobs also retain the parsed product model/type and batch/serial values selected for assignment, their before/after values, original row numbers, and parsing/handle-resolution notices. The original uploaded CSV file is not retained. Do not include personal data in identifiers or unsupported columns. Skipped input rows are identified in saved results/exports.
- Opt-in product review inbox: product/reference IDs, titles, notification reasons, deduplication hashes, observed-state fingerprints, check timestamps, pending flags, and record acknowledgments. Full notification bodies, operator contact fields, warning text and publication snapshots are not retained in this inbox. A notification is not treated as a verified safety-data change.
Personal data this may include:
- Economic-operator contact details (manufacturer / responsible operator) — where these refer to a natural person or a sole trader, they are personal data. They are entered by the merchant and are displayed publicly on the storefront because Article 19 requires it.
- Reviewer/staff identifiers (
reviewed_by) used to record the current review and last publication.
The App does not collect storefront visitors' or end-consumers' personal data, and does not use the data for advertising or profiling.
2. Why we process it (purposes & legal bases)
- To provide the App's features (store, organise, display, gap-detect GPSR data) — performance of the contract / our legitimate interest in operating the service.
- To record the current warning review and the last product publication — legitimate interest and the merchant's record-keeping needs. The App does not retain a history of every publication.
- To secure, debug and improve the App — legitimate interest.
- Where we act as processor, we process personal data only on the merchant's documented instructions (the DPA).
3. Sub-processors
We use Shopify (app platform and merchant-store data), Vercel (application hosting, compute, and service logs), Neon (PostgreSQL session, saved scan and bulk-work storage), and Google (support email when you contact us). We require these providers to protect data consistent with this policy and the DPA. A current list is available on request.
4. International transfers
Data may be processed outside the EU/EEA (including in Republic of Korea). Where required, transfers rely on appropriate safeguards (e.g. EU Standard Contractual Clauses) — see the DPA.
5. Retention
- Operational data is retained while the App is installed.
- Only the latest Pro gap scan and the latest Free sample are kept per store, independently. The Free sample does not replace the Pro report. You can clear either or explicitly replace it in the app; viewing, pausing and clearing existing saved results do not require Pro. Saved scans are removed during uninstall/redaction cleanup or when a verified replacement installation is opened.
- Bulk work retains up to 50 combined profile/CSV jobs, 1,000 profile revisions and 500 managed-product memberships per installation. Finished/cancelled job history can be explicitly removed after in-flight work settles; removing a membership does not delete Shopify product data. Saved results, downloads, uncertain-result rechecks and membership removal remain available without Pro. Profile revisions are retained until installation cleanup; contact support for an earlier data-removal request.
- The opt-in inbox retains up to 1,000 current product records. You can stop notification capture, export records or remove individual inbox records without Pro; these actions do not delete Shopify products or managed-product associations. An inbox previously enabled on Pro continues receiving minimal notifications after downgrade until you stop it, but new checks require Pro.
- Review history shows up to 1,000 observation/acknowledgment entries from the past 90 days. Older history is pruned when a new history entry is saved. Delivery-deduplication hashes are pruned to 2,000 entries and a 24-hour window on new accepted deliveries. These are activity-based cleanup rules, not continuous background deletion schedules. Installation cleanup removes the inbox, history and deduplication records. Contact support for earlier removal of retained history.
- On uninstall, we delete or anonymise the App-side data we hold within 30 days, except where longer retention is required by law. Data stored inside the merchant's Shopify store (metafields/metaobjects) remains under the merchant's control in their store.
- Mandatory Shopify webhooks (
customers/redact,shop/redact,customers/data_request) are honoured.
6. Data subject rights (GDPR & similar)
Where GDPR applies, data subjects have rights of access, rectification, erasure, restriction, objection and portability. Because much of the personal data is controlled by the merchant, we will route requests we receive to the relevant merchant and assist them. To exercise rights or ask questions, contact cadosy@gmail.com (or the merchant who published the data).
7. Security
We use reasonable technical and organisational measures (encryption in transit, least-privilege access, minimal scopes, restricted access tokens). No method is perfectly secure, but we work to protect data and to minimise what we store.
8. Changes
We may update this policy; material changes will be notified via the App or cadosy@gmail.com.
9. Contact
Kadosh (카도쉬) · proprietor Kang Seung-hyun (강승현) 개인사업자 / Business Registration No. 418-06-17117 경기도 고양시 덕양구 향동로 217, 425호 (#425, 217 Hyangdong-ro, Deogyang-gu, Goyang-si, Gyeonggi-do, Republic of Korea) Tel. 02-1522-7824 · cadosy@gmail.com