Privacy Policy
Effective date: 8 September 2026
This Privacy Policy explains how Vendable ("we," "us," or "our") collects, uses, and handles information when you install and use the Vendable Shopify app ("the App"). The App is operated by Giorgos Lamprakis.
1. Information we collect
When you install Vendable, we collect and store the following:
- Shopify shop domain — used to identify your store and authenticate API calls.
- Shopify access token — granted by Shopify to allow us to read your product catalog on your behalf. Stored securely in our database and used only to fulfil requests you initiate in the App.
-
Product catalog data — product titles, SKU
identifiers, and variant IDs pulled via the
read_productsscope. Data is imported only when you initiate an import in the App. - Manufacturer and responsible-person records — names, addresses, and contact details you enter into the App to satisfy EU GPSR obligations.
- Evidence documents — files you upload to attach as evidence to product records.
- App usage events — usage signals (e.g. "readiness summary viewed") linked to your shop account via an internal store identifier and a one-way HMAC hash of your shop domain. These identifiers are used only for internal analysis; they are not shared with third parties and are deleted when your store data is hard-deleted.
2. Information we do not collect
Vendable requests two Shopify scopes: read_products to
import your catalog, and write_products for the single
purpose described in section 3a — writing the product-safety metafield
that displays your GPSR information on your product pages. We do
not request or store:
- Customer names, email addresses, phone numbers, or any other customer personal data.
- Order history or transaction data.
- Payment or financial information.
When Shopify sends a customers/data_request or
customers/redact webhook, we respond immediately with 200
and take no further action because we hold no customer data.
3a. Information we write to your store
When you publish, Vendable writes one metafield
(vendable.gpsr) to each product you have prepared. It
contains only the GPSR information you entered in the App: the
manufacturer, the EU responsible person where one applies, the product
identifier, and your safety warnings and instructions. A theme block you
add yourself renders that metafield on your product page.
This is the only thing the App writes to your store. Vendable does not modify product titles, descriptions, prices, variants, inventory, collections, or your theme files. Publishing is something you trigger; nothing is written to your store until you do.
3. How we use your information
- To operate the App — displaying product readiness status and allowing you to apply GPSR records at scale.
- To generate evidence packs you request.
- To authenticate your session when you access the App from Shopify Admin.
- To improve the App using aggregated, anonymised usage signals.
We do not sell your data to third parties. We do not use your data for advertising.
4. Access token handling
Your Shopify access token is stored securely in our database. All data
at rest is protected by Fly.io disk encryption at the infrastructure
level. Application-layer column encryption is planned for a future
release. When you uninstall the App, Shopify sends us an
app/uninstalled webhook. Upon receipt we immediately null
the access token in our database, revoking the App's ability to call the
Shopify API on your behalf.
5. Data retention and deletion
Shopify sends a shop/redact webhook 48 hours after a store
uninstalls an app. When we receive this webhook we hard-delete all data
associated with your store, including:
- Your shop domain record and any residual access token.
- All product catalog data imported from your store.
- All manufacturer and responsible-person records.
- All evidence documents and associated metadata.
- All usage events linked to your shop.
Deletion occurs synchronously upon receipt of the webhook — your data is removed within seconds of the webhook arriving, well before the 48-hour window closes.
Database backups are retained for 30 days and then automatically purged. Your data may therefore persist in encrypted backups for up to 30 days after the hard-delete completes.
6. GDPR and data subject rights
Because Vendable does not store customer personal data, we cannot fulfil subject-access or erasure requests for your end-customers. If a customer requests their data under GDPR or CCPA, that data must be obtained directly from Shopify.
As a merchant (our direct user), you may request deletion of your data at any time by emailing us (see §9 Contact). Alternatively, uninstalling the App from your Shopify store triggers the automated deletion process described in §5.
We handle all three GDPR mandatory webhooks required by Shopify:
customers/data_request, customers/redact, and
shop/redact.
7. Third-party processors
We use the following sub-processors to deliver the App. Each processes data only as instructed by us.
- Fly.io — Application hosting, PostgreSQL database, and persistent file storage. All data is stored in the EU (Frankfurt region). fly.io/legal/privacy-policy.
- Tigris — PostgreSQL WAL backup storage (via Fly.io integration). Encrypted backups are retained for 30 days. tigrisdata.com/privacy.
We do not use third-party analytics services, advertising networks, or marketing tools that receive your data.
8. Security
- All connections use HTTPS / TLS.
- Access tokens and application secrets are stored encrypted at rest.
- Shopify webhooks are verified via HMAC-SHA256 signature before any data is processed.
- Access to production infrastructure is restricted to the operator.
9. Contact
For privacy-related questions or data deletion requests:
Email: giorgos@getvendable.com
Operator: Giorgos Lamprakis, operating as Vendable
10. Changes to this policy
We may update this policy as the App evolves. Material changes will be communicated via the Shopify Partner email associated with the app listing. The effective date at the top of this page shows when the policy was last revised.