Privacy Policy
M&N Gewährleistungslabel Pro

Last updated: October 2026

1. Controller

The controller for data processing in connection with the Shopify app "M&N Gewährleistungslabel Pro" (the "App") is:

KEVIN METZDORF LTD
71–75 Shelton Street, Covent Garden
London WC2H 9JQ, United Kingdom
Email: info@kevin-metzdorf.com

2. The essentials in brief

The App displays the EU notice on the legal guarantee in the merchant's online store and — where the merchant maintains the producer details — the commercial guarantee label ("GARAN"). It stores only data about the shop: the shop domain, the access token issued by Shopify, two settings, and technical server logs. End-customer data — name, email, address, IP address, orders — is neither retrieved by the App nor sent to or stored on its servers. The label in the store is produced in the buyer's browser and on Shopify's infrastructure; the guarantee details are kept at Shopify as product metafields.

3. What data the App processes

a) Shop and settings data (stored)

When the App is installed and used, the following is stored: the shop's myshopify domain with its installation status and timestamps, the access token issued by Shopify (with expiry and refresh token) together with session data and the granted permission, and two settings — the language of the App's interface and which of the three setup steps the merchant has marked as done. The App requests only the write_productspermission from Shopify; it requests no permission for customer, order or checkout data. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR / UK GDPR).

b) Shop and product data (retrieved, not stored)

When the App is opened in the Shopify admin, it retrieves via Shopify's Admin API whether the shop is on Shopify Plus or is a development store (this determines whether a label block in checkout is possible), and, for up to 250 products, the product ID, product title and the stored guarantee duration (to flag unusual durations). This data is used for display only and is not stored.

The guarantee details themselves — producer, model and duration in months — are product metafields that the App creates at Shopify. The merchant maintains them directly on the product in the Shopify admin. They are stored at Shopify, not on the App's servers, and are publicly visible in the store like any other product information. This is product data, not personal data.

c) End customers in the online store (not on the App's servers)

Store pages and cart: Shopify writes the notice into the page on the server side. The buyer's browser loads the App's script and the official label graphics from Shopify's CDN, not from the App's servers. On the cart page, the script reads the store's own cart (/cart.js, same domain as the store) so that the GARAN label appears only for products in the cart. This data does not leave the browser towards the App. The script sets no cookies and uses no browser storage.

Checkout (Shopify Plus only) and thank-you page: The App's extension runs in Shopify's sandboxed environment. It reads only the cart lines and the three guarantee metafields and has no network access — so it cannot send anything to the App.

Order confirmation: The App sends no emails. It provides a code snippet that the merchant pastes into their own Shopify notification template; the email is sent by Shopify on the merchant's behalf.

Links: The label links to the EU portal "Your Europe" (europa.eu). A connection to it is only made when a buyer clicks the link.

The controller for processing end-customer data in the store is the respective merchant, with Shopify as their processor.

d) Merchant staff in the App's interface

The App works exclusively with shop-level sessions; names or email addresses of the merchant's staff are not stored. When someone opens the App in the Shopify admin, their browser necessarily transmits the IP address, browser details and a session token signed by Shopify (containing a Shopify-internal user ID) to the App's server. The App uses the token only to authenticate the request and does not store it; it writes no access logs with IP addresses. The App's interface loads the scripts Shopify requires for embedded apps. The legal basis is the performance of a contract or the legitimate interest in providing the App securely (Art. 6(1)(b) or (f) GDPR).

e) Billing

The App is paid; billing runs entirely through Shopify. Shopify shows the pricing page, concludes the subscription and handles charges, the trial period and cancellation. The App receives and stores no payment data. It only asks the Shopify Partner API whether a subscription is currently active for the shop, transmitting the identifiers of the shop and the App for this purpose. The answer (active or not, and the end of the trial period where applicable) is held in the server's memory for at most five minutes and is not stored in the database. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).

f) Server logs

The App's server writes technical logs (errors, warnings, incoming webhooks). The shop's myshopify domain appears in them regularly, for example when the App is opened and on sign-in. Access tokens are redacted. Customer identifiers or email addresses from the privacy webhooks are not logged, and the App writes no IP addresses to its logs. The legal basis is the legitimate interest in operational security and troubleshooting (Art. 6(1)(f) GDPR).

g) Support requests

If you write toinfo@kevin-metzdorf.com, we process your email address, your name and the content of your message solely to handle your request (Art. 6(1)(b) or (f) GDPR). The data is deleted once it is no longer needed for this purpose and no statutory retention obligations apply.

4. Recipients and processors

Fly.io Inc. (USA) operates the App's server infrastructure as hosting provider, including the Postgres database and log storage. The server location is Frankfurt am Main, Germany (EU region); as Fly.io is a US company, it is engaged on the basis of EU Standard Contractual Clauses (SCCs). The logs contain no personal data of end customers.

Shopify, as the e-commerce platform, is the technical origin of all data: Shopify holds the shop and product data including the guarantee metafields, delivers the App's script and label graphics via its CDN, runs the checkout extension and handles billing. Shopify's privacy policy applies to processing by Shopify.

There are no other recipients — the App uses no analytics, tracking, error-tracking or email services.

5. International transfers

The controller is established in the United Kingdom; an adequacy decision of the European Commission exists for transfers from the EU. For the US provider Fly.io, EU Standard Contractual Clauses apply with a server location in Germany.

6. Retention and deletion

End-customer data: not stored (see above). Shop and settings data is stored for as long as the App is installed in the shop. On uninstallation, the App immediately deletes all session data including the access token and marks the shop as inactive. After uninstallation, Shopify sends the deletion request (shop/redact, usually 48 hours later) — upon which the shop record, all settings and all session data are deleted completely. The hosting provider's database backups are kept for ten days and then overwritten; until then, deleted data may still be contained in them. Server logs in which the shop domain may appear are not covered by this deletion; they are deleted automatically after seven days.

The guarantee metafields are kept at Shopify. According to Shopify's documentation, on uninstallation Shopify deletes the field definitions created by the App and temporarily retains the values in case the App is reinstalled; Shopify does not specify for how long. The App has no influence on this.

7. Shopify privacy webhooks

The App implements all privacy endpoints mandated by Shopify: data requests (customers/data_request) and deletion requests (customers/redact) are answered — since the App does not store end-customer data, there is nothing to hand over or delete. The shop deletion request (shop/redact) leads to the complete deletion described in section 6.

8. Your rights

Data subjects have — within the scope of the applicable law (GDPR / UK GDPR) — the right of access, rectification, erasure, restriction of processing, data portability and objection to processing based on legitimate interests. Please contactinfo@kevin-metzdorf.com. You also have the right to lodge a complaint with a data protection supervisory authority — in the United Kingdom the Information Commissioner's Office (ICO), in the EU the authority responsible for you.

Note for end customers of shops using the App: the App stores no data about you. The controller for the processing of your order data is the respective merchant. Please direct data subject requests about an order to the shop you ordered from.

9. Changes to this privacy policy

This privacy policy is updated when the App or legal requirements change. The version published here applies.