Legal

Privacy Policy

Privacy information for the Simplyfirst: EU Warranty/GARAN Shopify app.

1. Controller

Simplyfirst – Oliver Weiland

Orlamünder Weg 37
12249 Berlin
Germany

Email: info@simplyfirst.de

2. Scope

This policy applies to merchants who install or use the Simplyfirst: EU Warranty/GARAN app and to visitors of these public information pages. It does not govern a merchant's own storefront privacy practices.

3. Data we process

Installation and authentication data

We process the store domain, Shopify session identifiers, granted scopes, access and refresh tokens, token expiry information and authentication state. Where Shopify supplies online-session data, this can also include the Shopify user ID, name, email address, locale and account or collaborator status of an authorized store user.

Product and configuration data

The app accesses product information required to configure and display EU guarantee and GARAN warranty content. Configuration is stored primarily in Shopify metafields. PDF warranty statements are uploaded to and stored in Shopify Files; the app does not maintain a separate permanent copy of the uploaded file.

Checkout data

Checkout extensions use the product and cart-line context required to display configured labels. The app does not request Shopify API access to customer, order, payment or shipping-address data and does not use such data for advertising or profiling.

Technical data

When the app or these pages are accessed, our hosting provider may process IP address, request time, requested URL, browser or user-agent information and operational error logs to deliver and secure the service.

4. Purposes and legal bases

  • Providing, authenticating and operating the app (Article 6(1)(b) GDPR).
  • Protecting the service, diagnosing errors and preventing misuse (Article 6(1)(f) GDPR).
  • Responding to legally required privacy and compliance requests (Article 6(1)(c) GDPR).

Our legitimate interest is the secure, reliable and economically efficient operation of the app.

5. Service providers and international transfers

We use Shopify to provide the app platform, Admin API, app extensions, metafields and file storage. The application and its PostgreSQL session database are hosted using Railway. These providers process data on our behalf or under their own applicable terms. Processing outside the European Economic Area may occur. Where required, the providers use recognized transfer safeguards such as adequacy decisions or standard contractual clauses.

We do not sell personal data and do not use the public information pages for advertising tracking.

6. Retention and deletion

Shopify session records are retained while needed to operate the app. When Shopify sends an app-uninstalled or shop-redact webhook, stored session records for that shop are deleted. Product metafields and files stored in the merchant's Shopify account remain subject to the merchant's and Shopify's controls. Security and operational logs are retained only for the period reasonably necessary for service operation, troubleshooting and legal obligations.

7. Cookies and analytics

These public pages do not use advertising cookies or third-party marketing analytics. Authentication inside Shopify relies on Shopify's session-token mechanisms and technically necessary processing.

8. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, data portability or object to processing. You may also lodge a complaint with a competent data-protection authority. Send requests to info@simplyfirst.de.

9. Changes

We may update this policy when the app, providers or legal requirements change. The current version is published here.

Last updated: September 17, 2026