Privacy Policy
Last updated: September 23, 2026
SafetyKit is a Shopify app that helps a merchant record the product-safety information the EU General Product Safety Regulation (GPSR) expects on product listings — the manufacturer, the EU Responsible Person, and safety information. This policy explains what data the app processes, why, and how it is protected.
SafetyKit stores no customer (buyer) data. It requests only the read_products and write_products scopes — to list the merchant's products and save each product's GPSR information to it. It requests no customer scopes, reads no orders, and never stores a buyer's name, email, or address.
1. What We Process
1.1 Merchant / Store Data
The store's myshopify.com domain, an expiring Shopify access token, the subscription plan tier, and install status — the data needed to run the app for the store and bill it through Shopify. Shopify's session data for a signed-in staff member may include that staff member's name, email address, and admin language, as provided by Shopify.
1.2 GPSR Information
The shop-wide GPSR defaults the merchant enters — the manufacturer's name, postal address, and email address or website; whether the manufacturer is established in the EU; the EU Responsible Person's name, postal address, and email address or website; and default safety warnings — and any per-product GPSR details the merchant enters (including product identifiers such as type, model, or batch). This is business information about the manufacturer and economic operators that GPSR requires to be shown publicly on product listings; it is not personal data about buyers. Per-product details are saved to the product in Shopify as a product metafield, and the defaults are also published to Shopify so the storefront can read them; the app keeps a copy to run its coverage report.
1.3 Product Catalog
The app reads the store's product titles and IDs from Shopify to show the coverage report. It keeps no copy of the catalog beyond the titles of products that have their own GPSR details.
We process the minimum data needed to provide the app's value and use it only for that purpose. We do not sell data, and we do not use it for advertising or automated decision-making.
2. How We Collect It
- From Shopify, when a merchant installs the app and grants access, and through the Admin API for the products the merchant already holds.
- From the merchant, when staff enter GPSR defaults and product details in the embedded admin.
3. How We Protect It
- All traffic is served over TLS 1.2+.
- Data is stored on a DigitalOcean server; production access is SSH-key-only and limited to the operator, and the host runs standard hardening. Development and production data are kept separate.
- Access tokens are stored server-side only and are never exposed to the browser.
- Because SafetyKit holds no buyer personal data, there is no customer name, address, or payment information at rest to expose.
- We maintain a security incident-response process and will notify affected merchants of a confirmed data breach within 72 hours.
4. How Long We Keep It
- GPSR defaults and product details are kept while the app is installed so the coverage report and storefront data stay current.
- When a merchant uninstalls, access tokens are deleted immediately and the store's data held by the app is deleted in response to Shopify's shop-redaction request, in all cases within 30 days of uninstall. GPSR details already saved to the merchant's own products in Shopify remain part of the merchant's store data.
5. Who We Share It With
We use a small number of sub-processors, only as needed to run the service:
- DigitalOcean — server and database hosting (United States).
- Shopify — the platform the app runs on.
We do not share data with anyone else, and we never sell it.
6. Data Subject Rights (Shopify Privacy Webhooks / GDPR)
SafetyKit implements Shopify's mandatory privacy webhooks in full. Because the app stores no customer personal data:
- A customer data request returns no customer records, because SafetyKit holds none.
- A customer redaction has no customer data to remove.
- A shop redaction deletes all of the store's data held by the app (GPSR defaults, product details, plan and install records, and sessions).
These support the merchant's obligations under the GDPR, the CCPA/CPRA, and similar laws. Merchants agree to SafetyKit's terms and this policy when they install the app.
7. Changes
We will update this page when our practices change and revise the date at the top.
8. Contact Us
If you have questions about this Privacy Policy or how we handle your data, contact us at:
NerdLabs (operated by Joren Winge)
Email: support@nerdlabs.us
Website: nerdlabs.us