Privacy Policy — EU Compliance Kit
Effective date: 21 August 2026
Publisher: Universal Exporters LLC, 10006 Rolke Rd, Houston, TX 77099, United States
Contact: support@justarobot.online
EU Compliance Kit ("the app") is a Shopify app that tracks your catalogue prices to display the Omnibus reference price, and helps you publish GPSR product-safety information on your storefront. This policy explains what data the app handles when you install it on your Shopify store, and why.
The short version: the app stores no personal data about your customers. It stores your store's domain, an access token, the store owner's name and email, your product prices over time, and your settings. All of it is deleted 48 hours after you uninstall.
1. Who we are and our role
Universal Exporters LLC ("we") publishes the app and is the controller for the account data described in §2(a).
For any data the app reads from your store on your instructions (§2(b)), you are the controller and we are your processor under Art. 28 GDPR. We process that data only to provide the app's functions, as described here, and on no other instructions.
2. What we collect and why
(a) Account data (we are controller)
| Data | Source | Purpose | Legal basis |
|---|---|---|---|
Store domain (yourstore.myshopify.com) |
Shopify, at install | Identify your store; all other data is keyed to it | Contract (Art. 6(1)(b)) |
| API access token | Shopify, at install | Read your products and write metafields on your behalf | Contract |
| Store owner name, email, locale | Shopify session, at install and each login | Show who is signed in; contact you about the service | Contract |
| Support correspondence | You | Answer your questions | Contract / legitimate interest |
(b) Store data processed on your behalf (you are controller)
| Data | Why the app needs it |
|---|---|
| Product and variant IDs, titles, prices, compare-at prices, per market and currency | To compute the lowest price of the prior 30 days (or your configured reference period) — the Omnibus reference price |
| Your store's published languages | To check that GPSR safety information exists in each language you sell in |
| Your published theme's product templates | To verify that the app's storefront blocks are still placed |
| Your Omnibus and GPSR settings, product exemptions | To apply your configuration |
What we do not collect. The app requests no access to customers, orders, checkout, addresses, payment data, or analytics, and stores none. GPSR manufacturer and Responsible Person details you enter are stored in your own Shopify store as metaobjects, not in our database; if those details identify a natural person (a sole trader, for instance), you are the controller of that record and Shopify's terms govern its storage.
Technical logs. Our hosting provider records request metadata (IP address, timestamp, path) for security and debugging; retained 30 days.
3. How long we keep it
| Data | Retained |
|---|---|
| Price observations | 400 days from the observation, then pruned automatically |
| Computed reference prices, settings, exemptions | While the app is installed |
| Access token, store owner details | While the app is installed; token invalidated by Shopify at uninstall |
| Everything above | Deleted 48 hours after uninstall, when Shopify sends the shop/redact notice |
| Support correspondence | 2 years |
4. Who else sees it (sub-processors)
| Provider | What | Where |
|---|---|---|
| Shopify Inc. | Platform, authentication, billing. Shopify never sends us card data. | Per Shopify's policy |
| Railway Corp. | Application hosting and primary database | European Union (Amsterdam) |
| Cloudflare, Inc. (R2) | Continuous encrypted database replica for disaster recovery | European Union (R2 EU jurisdiction) |
The app and its database run in the European Union (Netherlands). Shopify itself processes data under its own transfer arrangements.
We do not sell data, share it with advertisers, or use it to train models.
5. Security
Data in transit is TLS-encrypted. Access tokens are stored server-side and never exposed to the browser or the storefront. The storefront blocks read only the reference price and safety fields written to your store's metafields — the app's server is not in the path of a shopper's page load. The database replica is encrypted at rest by the provider.
6. Your rights and Shopify's data requests
If you are a store owner or staff member, you may ask us to access, correct, export, or delete the account data in §2(a) at support@justarobot.online. We answer within 30 days. You may lodge a complaint with your supervisory authority.
The app implements Shopify's mandatory privacy webhooks:
- customers/data_request — we hold no customer data; we report that.
- customers/redact — nothing to redact; we confirm.
- shop/redact — every record keyed to your store is deleted.
7. Cookies
The app runs inside the Shopify admin and uses only the session cookie Shopify requires for embedded apps. The storefront blocks set no cookies.
8. Changes
We will post changes here with a new effective date and, for material changes, notify the store owner email on file before they take effect.
9. Contact
Universal Exporters LLC · 10006 Rolke Rd, Houston, TX 77099, United States · support@justarobot.online
Changelog: 21 August 2026 — first version.