Privacy Policy
This policy describes what data the EPREL Auto Energy Labels app for Shopify processes, why, and what rights you have. It is written for merchants who install the app; a short note for visitors of our demo store is at the end.
The short version
- We process your shop's product catalog, never your customers' personal data.
- Product/label information comes from EPREL, the European Commission's public registry.
- Everything we write to your store (labels, sheets, metafields) stays yours.
- When you uninstall, your shop's data is deleted within 30 days.
What we process, and why
| Data | Examples | Why |
|---|---|---|
| Shop identity | shop domain (your-store.myshopify.com), install date | operating the service for your shop |
| Access credentials | Shopify OAuth tokens (stored encrypted) | reading your catalog and writing labels, as you authorised on install |
| App configuration | field mapping, Product information sheet language | applying your settings |
| Product catalog | product titles, vendors, models, SKUs, barcodes, the metafields you mapped | matching your products against the EPREL registry |
| Match results | matched EPREL registration numbers, statuses, your approvals/rejections | showing the correct label and remembering your decisions |
The legal basis is the performance of our contract with you (Art. 6(1)(b) GDPR) and, for service security and operational logs, our legitimate interest (Art. 6(1)(f) GDPR).
What we do NOT process
We do not read, store or process your customers' personal data — no names, addresses,
orders or payment data. The app subscribes to Shopify's mandatory privacy webhooks: a
customers/data_request for our app returns nothing (we hold nothing),
customers/redact has nothing to delete, and shop/redact permanently purges all
data we hold about your shop.
Where product data comes from
Energy labels, classes and Product information sheets originate from EPREL — the European Product Registry for Energy Labelling (eprel.ec.europa.eu), operated by the European Commission. The records there are created by product suppliers. We send EPREL product model identifiers for matching; we never send it any personal data.
What we write to your store
For matched products the app stores the label image and the Product information sheet in your shop's Files and writes app-owned product metafields (registration number, class, links). These stay in your store under your control; after uninstalling they remain but are no longer updated.
Retention
We keep your shop's data while the app is installed. After uninstall it is deleted within 30 days. Operational server logs rotate automatically after approximately one week.
Subprocessors and transfers
- Shopify (platform through which the app runs) — see Shopify's privacy policy.
- OVHcloud (EU) — hosts the app's server, database and our support mailbox.
Data is processed within the EU/EEA.
Security
Transport is encrypted (TLS); Shopify access tokens are encrypted at rest; access to production systems is restricted to authorised personnel.
Cookies and tracking
The embedded app authenticates with Shopify session tokens and sets no cookies and no third-party trackers. The storefront components load only files hosted in your own shop.
Your rights
Under the GDPR you may request access, rectification, erasure, restriction, portability, or object to processing — write to sales@easium.eu. Uninstalling the app (or asking us) deletes your shop's data as described above. You may lodge a complaint with your supervisory authority.
Our demo store
Our demonstration storefront does not sell or ship products and does not collect customer data beyond the standard cookies set by the Shopify platform (see the cookie banner). Any accounts or carts created there are test data and may be removed at any time.
Changes
We may update this policy; the effective date above always reflects the current version. Material changes will be announced in the app.