← Vendable

Privacy Policy

Effective date: 8 September 2026

This Privacy Policy explains how Vendable ("we," "us," or "our") collects, uses, and handles information when you install and use the Vendable Shopify app ("the App"). The App is operated by Giorgos Lamprakis.

1. Information we collect

When you install Vendable, we collect and store the following:

2. Information we do not collect

Vendable requests two Shopify scopes: read_products to import your catalog, and write_products for the single purpose described in section 3a — writing the product-safety metafield that displays your GPSR information on your product pages. We do not request or store:

When Shopify sends a customers/data_request or customers/redact webhook, we respond immediately with 200 and take no further action because we hold no customer data.

3a. Information we write to your store

When you publish, Vendable writes one metafield (vendable.gpsr) to each product you have prepared. It contains only the GPSR information you entered in the App: the manufacturer, the EU responsible person where one applies, the product identifier, and your safety warnings and instructions. A theme block you add yourself renders that metafield on your product page.

This is the only thing the App writes to your store. Vendable does not modify product titles, descriptions, prices, variants, inventory, collections, or your theme files. Publishing is something you trigger; nothing is written to your store until you do.

3. How we use your information

We do not sell your data to third parties. We do not use your data for advertising.

4. Access token handling

Your Shopify access token is stored securely in our database. All data at rest is protected by Fly.io disk encryption at the infrastructure level. Application-layer column encryption is planned for a future release. When you uninstall the App, Shopify sends us an app/uninstalled webhook. Upon receipt we immediately null the access token in our database, revoking the App's ability to call the Shopify API on your behalf.

5. Data retention and deletion

Shopify sends a shop/redact webhook 48 hours after a store uninstalls an app. When we receive this webhook we hard-delete all data associated with your store, including:

Deletion occurs synchronously upon receipt of the webhook — your data is removed within seconds of the webhook arriving, well before the 48-hour window closes.

Database backups are retained for 30 days and then automatically purged. Your data may therefore persist in encrypted backups for up to 30 days after the hard-delete completes.

6. GDPR and data subject rights

Because Vendable does not store customer personal data, we cannot fulfil subject-access or erasure requests for your end-customers. If a customer requests their data under GDPR or CCPA, that data must be obtained directly from Shopify.

As a merchant (our direct user), you may request deletion of your data at any time by emailing us (see §9 Contact). Alternatively, uninstalling the App from your Shopify store triggers the automated deletion process described in §5.

We handle all three GDPR mandatory webhooks required by Shopify: customers/data_request, customers/redact, and shop/redact.

7. Third-party processors

We use the following sub-processors to deliver the App. Each processes data only as instructed by us.

We do not use third-party analytics services, advertising networks, or marketing tools that receive your data.

8. Security

9. Contact

For privacy-related questions or data deletion requests:

Email: giorgos@getvendable.com

Operator: Giorgos Lamprakis, operating as Vendable

10. Changes to this policy

We may update this policy as the App evolves. Material changes will be communicated via the Shopify Partner email associated with the app listing. The effective date at the top of this page shows when the policy was last revised.