Privacy Policy
for the Shopify app “GPSR Compliance” and the website gpsr.syncventura.de · Last updated: October 2026 · Deutsche Fassung (the German version prevails)
1. Controller
SyncVentura, owner Igor Savostjanow, Bettina-von-Arnim-Str. 68, 28857 Syke, Germany
Email: support@syncventura.de
2. What this is about
The app helps Shopify merchants maintain the information required by the EU General Product Safety Regulation (GPSR) – manufacturer, EU responsible person, safety warnings – on their products and display it in their store. It is installed through Shopify and runs inside the merchant’s Shopify admin.
3. What data is processed
Store access. On installation, Shopify transmits the store address (myshopify domain) and an access token the app uses to access the merchant’s products on the merchant’s behalf. Where Shopify provides them at sign-in, the app also stores the ID, first and last name, email address and locale of the signed-in staff member.
Manufacturers and EU responsible persons. Whatever the merchant enters in the app: name or company, address, country, email address and phone number. Where these are individuals, this is personal data.
Product data. The app reads products (title and GPSR information) through Shopify’s API and writes GPSR information to product fields. This data stays in the store at Shopify; the app does not store it itself.
No end-customer data. The app has no access to customers, orders or payments – it may only read and write products. The block that shows the information on the product page runs in the store at Shopify; the app receives no data about store visitors.
Server logs. When gpsr.syncventura.de is accessed, the server processes technically necessary data (IP address, time, requested URL, user agent) in logs to keep the service secure and to find errors.
No analytics, no advertising. There are no analytics or advertising cookies and no analytics tools. The public pages load nothing from third-party servers.
4. Purposes and legal bases
Providing the app to the merchant: Art. 6(1)(b) GDPR (contract). Manufacturer and EU responsible person data: Art. 6(1)(b) and (f) GDPR – the merchant needs it to meet their obligations under the GPSR. Server logs: Art. 6(1)(f) GDPR (secure operation).
5. Recipients
- Shopify (Shopify International Limited, Victoria Buildings, 1–2 Haddington Road, Dublin 4, Ireland): the platform through which the app is installed, billed and used. Shopify is responsible for its own platform; Shopify’s privacy policy applies.
- netcup GmbH (Daimlerstraße 25, 76185 Karlsruhe, Germany): server hosting in Germany, as a processor.
- STRATO GmbH (Otto-Ostrowski-Straße 7, 10249 Berlin, Germany): storage for backups in Germany. Backups are encrypted before transfer; STRATO cannot read them.
We do not transfer data to countries outside the EU.
6. Retention
- On uninstall, the app immediately deletes the store’s access tokens.
- 48 hours after uninstall, Shopify requests deletion of all store data; the app then deletes manufacturers, EU responsible persons and all other data of that store completely.
- Server logs: 7 days.
- Backups: deleted data disappears when the respective backup expires, after 12 months at the latest. Until then it is not used.
7. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). An email to support@syncventura.de is sufficient.
You may also lodge a complaint with a data protection supervisory authority (Art. 77 GDPR); the competent authority is: Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover, Germany.
8. Automated decision-making
No automated decision-making takes place.