Privacy Policy

PriceProof: GPSR — Privacy Policy

Effective: 2026-07-10

Gyutae Oh (sole proprietor) ("we") provides the PriceProof: GPSR Shopify app, which helps merchants display, manage, and export the product-safety information described by the EU General Product Safety Regulation (Reg (EU) 2023/988, Art. 19). This policy explains what personal data we process. We are an independent data controller for the limited account data described below. We do not collect, receive, or store your customers' (consumers') personal data. We are also not, and do not provide, a Responsible Person under the GPSR — we only store and display the manufacturer and Responsible-Person details you choose to enter and publish.

1. What we collect

We request only the write_products API scope (product read and metafield read/write) needed to store and mirror your GPSR fields. We do not request the orders or customers API scopes and do not process consumer personal data. Compliance webhooks that Shopify requires us to register (customers/data_request, customers/redact) may deliver a payload containing a customer identifier; we do not store the body of these payloads — we acknowledge receipt only.

2. Legal bases (GDPR)

Performance of our contract with you (providing and billing the App) and our legitimate interests in operating, securing, and supporting the service. The manufacturer/Responsible-Person contact data you enter is processed on your instruction to render the disclosures you have decided to publish.

3. Where data is stored

Our servers are located in the European Union (Frankfurt, Germany), hosted on Fly.io. Your data does not leave the EU, so no third-country transfer mechanism (adequacy decision, Standard Contractual Clauses) is needed. Product identifiers and GPSR disclosure fields are commercial/compliance data.

4. Retention & deletion

We retain your GPSR disclosure fields and product data for as long as needed to provide the service (and for the audit-evidence exports you rely on). When you uninstall, Shopify sends a shop/redact request approximately 48 hours later; we permanently delete your shop's data within 30 days of receiving it.

5. Sharing

We do not sell your data and do not use data from one merchant for the benefit of another (no cross-merchant use). Subprocessors (hosting) act on our behalf under contract; a current list is available on request. We do not act as your Responsible Person and do not transmit your manufacturer/RP data to any Responsible-Person provider. If we later offer an optional referral to an independent external RP partner, that referral would be clearly separate, opt-in, and governed by that partner's own terms — the App itself would still never act as your RP.

6. Your rights

You may request access, correction, deletion, or export of your account data, or object to processing, by contacting us at nsjokt@gmail.com. You may also lodge a complaint with a supervisory authority. We respond to requests within 30 days. If a manufacturer or Responsible-Person individual you have listed contacts us about their business contact data, we will direct them to you as the controller who chose to publish it, and assist you as needed.

7. EU representative (Art. 27 GDPR)

An EU representative under Art. 27 has not yet been appointed. When appointed, their name and contact details will be listed here. Until then, contact us directly at nsjokt@gmail.com.

8. Contact

Controller: Gyutae Oh (sole proprietor), nsjokt@gmail.com