Privacy Policy — Saal: EU Garan

Last updated: 12 September 2026

DE

This policy explains what data the Saal: EU Garan Shopify app ("the app") processes, why, and for how long. The app processes merchant and product data only — it collects no personal data about your customers and adds no tracking to your storefront.

1. Controller

Micha Saalmüller
Mittenwalder Str. 32
10961 Berlin
Germany

Privacy enquiries: privacy@michasaalmueller.com
General contact: hello@michasaalmueller.com

We have not appointed a Data Protection Officer. Given the scope and nature of the processing described below, there is no statutory obligation for us to do so under Art. 37 GDPR or § 38 BDSG.

2. Scope

This policy covers the Shopify app Saal: EU Garan ("the app"), which generates EU producer-durability-guarantee labels and the statutory legal guarantee notice, and writes them to a merchant's products as Shopify metafields.

It does not cover michasaalmueller.com, which has its own privacy policy, nor the Shopify platform itself, which Shopify operates under its own terms.

3. The short version

The app processes merchant and product data. It does not collect, store, or process personal data about your customers, and it adds no tracking of any kind to your storefront. The app holds no access to customer or order data: the permissions it requests cannot return either.

The remainder of this policy sets out the detail.

4. Our role

We act as controller for the merchant data described in section 5.1 — principally your shop domain and the operational records the app keeps in order to function.

The app does not process personal data belonging to your customers, so we do not act as your processor for any such data. We will nonetheless enter into a data processing agreement with you on request; see section 12.

5. What we process

5.1 Merchant and installation data

DataPurpose
Shop domain (example.myshopify.com)Identifying your installation; associating your configuration and billing records with it
Shopify API access token and refresh token, granted scopes, expiry timestampsAuthenticating the app's calls to the Shopify Admin API on your behalf
Subscription and trial status, usage-meter handle, Shopify subscription ID, activation timestampsBilling the one-time plan activation fee through Shopify, and ensuring a reinstallation is not charged twice
Support correspondence, where you contact usAnswering your enquiry

We request offline access tokens only. We therefore never receive the name, email address, or locale of the staff member who installs or uses the app — that information is carried only by online access tokens, which the app does not use.

5.2 Configuration and catalogue data

To do its work, the app stores the following. None of it is personal data about your customers.

  • Guarantee programmes: a programme name, guarantee duration, where to read the brand and model identifier from each product, an optional link to your guarantee terms, and the name of the guarantor.
  • Programme rules: the collections, vendors, tags, or individual products a programme applies to.
  • Per-product records: Shopify product IDs, the applied guarantee duration, brand and model identifier, a content hash, and a status flag. This is a cache of what the app believes is on each product, so that your dashboard does not have to page your entire catalogue on every load. The product metafield remains authoritative.
  • Generated label artwork: the brand, model identifier, and duration that produced each file, a content hash, and the resulting Shopify file ID and URL.
  • Bulk job records: pagination cursors, progress counters, and for products needing your attention, the product ID, product title, and reason.

One note on the guarantor field. The guarantor you enter is rendered into the label artwork, and that artwork is published as a publicly accessible file on the Shopify CDN and shown on your storefront. This is deliberate: the applicable EU rules require the guarantor to be identifiable. If you trade as a sole proprietor and enter your own name, that name is personal data which you are publishing about yourself. Enter a company name instead if you prefer not to.

5.3 Technical logs

Our hosting provider records ordinary technical log data for the app's requests, including timestamps, request paths, response codes, and error details. Application log lines identify the shop domain and the nature of any error. Access tokens, session contents, and request bodies are not logged.

Our hosting provider separately processes connection metadata such as IP addresses and user agents at its network edge, under its own retention rules.

5.4 Cookies

The app sets one cookie: a short-lived OAuth state cookie during installation, which exists to protect the authorisation exchange against cross-site request forgery. It is strictly necessary within the meaning of § 25(2) TTDSG and requires no consent.

Inside the Shopify admin, the app authenticates using Shopify session tokens rather than cookies. The app sets no cookies on your storefront and uses no analytics, tag managers, pixels, or advertising services.

6. What we do not process

For the avoidance of doubt, the app does not access, receive, or store:

  • customer or consumer personal data of any kind — names, email addresses, postal addresses, phone numbers, or customer IDs;
  • order, checkout, cart, or payment data;
  • storefront visitor behaviour. The app's theme extension is static Liquid markup and CSS. It contains no JavaScript, makes no network requests, sets no cookies, writes nothing to browser storage, and cannot observe your shoppers.

The permissions the app requests are read_products, write_products, read_locales, read_files, write_files, read_themes, and read_inventory. None of them returns customer or order data. The app holds no customer-write permission.

7. Legal bases

  • Art. 6(1)(b) GDPR (performance of a contract) — for the processing in sections 5.1 and 5.2, which is necessary to provide the app you installed.
  • Art. 6(1)(f) GDPR (legitimate interests) — for the technical logs in section 5.3, our legitimate interest being the security, availability, and debugging of the service.
  • Art. 6(1)(c) GDPR (legal obligation) — for the retention of billing and activation records under German commercial and tax law.

8. Sub-processors and hosting

ProviderPurposeLocation
Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USAApplication hosting (Workers), database (D1), object storage (R2), and loggingThe database runs in Cloudflare's Eastern Europe region, within the European Union. Cloudflare is a US-established provider; transfers are governed by the EU Standard Contractual Clauses.
Shopify Inc., 151 O'Connor Street, Ottawa, Ontario, CanadaThe platform the app runs on, its Admin API, file storage for the generated artwork, and all billingGoverned by your own agreements with Shopify. Shopify is not our sub-processor.

Our object storage holds only the official artwork templates and font files the app draws labels with. It contains no shop, merchant, or customer data.

All payment processing is handled by Shopify through Shopify Billing. We never see or store your payment details.

9. Retention and deletion

DataRetained
Session records and access tokensDeleted when you uninstall the app
Programmes, programme rules, per-product records, label asset records, and job recordsDeleted when you uninstall the app
Plan activation records (shop domain, usage-meter handle, subscription ID, timestamps)7 years, under § 147 AO and § 257 HGB
Technical logsApproximately 3 days, then automatically deleted
Support correspondence12 months after the enquiry is resolved

When you uninstall, the app deletes your sessions and all of its operational records immediately, on Shopify's app/uninstalled webhook. Shopify's shop/redact webhook, which arrives roughly 48 hours later, triggers the same deletion again as a backstop in case the first did not run.

Plan activation records are the one exception, and they are kept for two reasons: German commercial and tax law requires us to retain records of what we have billed, and the record is what prevents a reinstallation from being charged the same one-time activation fee twice. These records contain your shop domain and billing metadata, and no other data described in this policy.

The guarantee metafields the app wrote to your products are removed by Shopify when the app is uninstalled. The label artwork remains in your own Shopify Files, because it is yours; you may delete it there at any time.

10. Shopify's mandatory compliance webhooks

Shopify requires every app to implement three privacy webhooks. The app implements all three. Because it stores no customer data, the customers/data_request and customers/redact webhooks have nothing of ours to export or erase and are acknowledged accordingly. The shop/redact webhook erases your shop's records as described in section 9.

11. Your rights

Under Arts. 15–21 GDPR you have the right to request access to your personal data, its rectification or erasure, restriction of processing, data portability, and to object to processing carried out on the basis of our legitimate interests. Where processing rests on consent, you may withdraw it at any time.

To exercise any of these rights, write to privacy@michasaalmueller.com. We respond within one month.

You also have the right to lodge a complaint with a supervisory authority. The authority competent for us is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin
Germany

If you are a shopper rather than a merchant: we hold no data about you. If you have a question about a shop that uses this app, please contact that shop directly — the merchant is the controller of their customers' data.

12. Data processing agreement

Because the app processes no customer personal data, a data processing agreement under Art. 28 GDPR is not ordinarily required. We will nevertheless conclude one with you on request. Write to privacy@michasaalmueller.com.

13. Security

We apply the measures required by Art. 32 GDPR, including scoped API tokens, two-factor authentication on all administrative accounts, separated development and production environments, TLS for all data in transit, HMAC verification of every incoming webhook, managed infrastructure with automated backups and point-in-time recovery, and data minimisation — the app requests only the permissions it exercises and stores only the fields it needs.

Access to production systems is limited to the sole developer named in section 1.

Should a personal data breach occur, we will notify the competent supervisory authority within 72 hours as required by Art. 33 GDPR, and affected merchants without undue delay.

14. Changes

We may update this policy as the app changes. The date at the top reflects the current version. Material changes affecting your rights will be communicated to installed merchants by email or through the app.