TransparencyPassport

TransparencyPassport Privacy Policy

Last updated: 10 October 2026

This policy explains what the TransparencyPassport Shopify app ("the app") collects, why, where it is kept, and for how long. The app is run by Otium ("we", "us"). Contact: [email protected].

Questions or requests: [email protected].

The short version

  • The app only has the Shopify permission read_products. It cannot read your customers, orders or payments.
  • We store the passports you create, the documents you upload, your app settings and anonymous view counts.
  • We do not store shoppers' names, emails, IP addresses, device IDs or cookies.
  • What you publish is public, except the fields and documents you reserve for repairers, recyclers or authorities. Those open only through access links you create.
  • When you uninstall, your passports go offline at once. Shopify then asks us to erase your shop's data, and we do.
  • We do not sell or rent data. We do not use it for advertising.

Who is responsible for what

For data about your store, you (the merchant) are the controller. We are your processor: we handle the data only to run the app for you. Our Data Processing Addendum sets out those terms.

For the few things we decide on our own (billing records we receive from Shopify, security logs, and support emails you send us), we are the controller.

Shoppers who open a passport stay anonymous to us. We do not try to identify them.

What we collect and why

1. Your shop and your Shopify connection

DataWhyWhere
Shop domain (your-store.myshopify.com)To know which store the data belongs toFirestore
Your store's name, as Shopify reports itShown as "Shared by …" on access-link viewsFirestore
Shopify access token and granted scopesTo read your products when you ask the app to, and to send Shopify Flow triggersFirestore (session record)
Your current plan, as reported by ShopifyTo apply plan limitsFirestore

The app uses Shopify "offline" tokens. These are tied to the store, not to a staff member. The app does not store staff names or staff emails.

2. Product data read from Shopify

When you open the editor, use AI auto-fill, bulk create or product sync, the app reads product data from Shopify: title, handle, description, vendor, product type, tags, images, variants (title, SKU, barcode, weight) and metafields.

We store only what ends up in a passport: the product ID, name, handle and image address, plus the passport fields you save. We keep passports in step with Shopify: a renamed product updates its passport, and a deleted product's passport goes offline at once (see "How long we keep data").

3. Passports you create

Supply-chain steps (place, country, date, transport, notes, photo links, facility names and GS1 location numbers), the transparency statement, certifications, identifiers (GTIN, SKU, batch, lot and serial numbers), manufacturer details (name, address, country, EORI, contact email, website), materials, substances of concern, recycling, care, repair, durability and warranty details, footprint figures, translations of your text, templates, and a version copy of every publish.

Who can see a published passport. The public page, the product-page blocks and the machine-readable passport (/dpp/<shop>/<handle>.json) show the public fields to anyone with the link or QR code. Anyone can download and keep a copy of the public JSON.

These fields are not public. They appear only to someone holding a valid access link for the right role:

  • repairers: manufacturer address and contact email, substance details, spare-parts years;
  • recyclers: substance details, batch number, manufacturing date;
  • authorities: all of the above, plus the EORI number and facility names and numbers.

The same rule applies to documents: each one is marked public, repairer, recycler or authority. Access links are part of the Business plan; on other plans the restricted fields are simply not shown.

Do not put personal data or confidential details in public fields unless you mean to publish them.

4. Compliance documents (Business plan)

You can attach files to a passport, such as a declaration of conformity, test reports or certificates (PDF, PNG, JPG or WEBP, up to 20 MB). We store:

  • the file itself, in object storage (see "Where data is stored");
  • its title, kind, issuer, issue and expiry dates, the audience you chose, its size and type, and its SHA-256 fingerprint.

How it works:

  • Your browser uploads the file straight to the storage bucket through a short-lived signed address.
  • The app then reads the file back. It checks the type, the size and that the fingerprint matches.
  • If a virus scanner is set up, the file is sent to it before it is accepted. If the scanner is unavailable, the upload is refused.
  • When you publish, the documents in that version are locked. You cannot change or delete a locked document in the app, because the passport must keep what it showed. If a locked document contains data that must be removed, contact us.
  • Public documents can be downloaded by anyone. Other documents only with an access link whose role covers them. Downloads go through a signed storage link that expires after 5 minutes, so the file comes from the storage provider, not from our servers.

The page shows each document's SHA-256 checksum ("Checksum recorded <date>"), recorded when the file was uploaded, and lets anyone compare the downloaded copy with it ("This file matches the checksum recorded on <date>"). That proves the file is unchanged. It says nothing about whether its content is true, and the app never calls a document "verified".

When you create an access link for a repairer, recycler or authority, we store the product, the role, your label for the link, when it was created, when it expires (90 days by default, up to 3 years), when it was revoked, how many times it was used and when it was last used.

We do not record who opens a link, or their IP address. The link itself is the key: anyone who has it can open that view until it expires or you revoke it. Share it like a password.

6. Settings

Brand colours, display options, default statement text, default language, your store name, and, if you switch on email (Professional and Business plans), a notification address and which emails you want. The notification address is never shown on public pages.

7. Email notifications

Email is sent only when all of these are true: we have switched on email delivery for the app, your plan includes email, you turned notifications on, you gave an address, and you chose that email. The four emails are:

  • a passport went live;
  • a weekly check (Mondays) of passports missing EU fields and documents about to expire;
  • a background job finished with failed items;
  • a document expires within 30 days.

Each email contains product names, passport links, counts, and document titles and expiry dates. We send them through Resend. When email delivery is off, the app only notes that an email would have been sent, without the address or the content.

8. Anonymous passport analytics

When someone opens a published passport page, scans its QR code, sees the product-page block, or clicks it, the app stores one event with:

  • the event type (view, qr_scan, widget_view or widget_click)
  • the product handle and product name
  • your shop domain
  • the time (set by our server)
  • the source label (direct, qr, widget, or a short label from the link)
  • the referring website, cut down to its origin (for example https://www.instagram.com, never the full address)

That is all. Events contain no IP address, no user agent, no cookie, no device ID and no customer ID. Events are only accepted for published passports.

Why: to show you the Analytics page (views, scans, block click rate, top passports, where visits come from). Events are deleted after 24 months.

9. AI features (optional)

If AI is switched on, the app sends product text only to Google's Gemini API:

  • for auto-fill: the product facts listed in section 2;
  • for a transparency statement: the product name and its supply-chain steps;
  • for translations (Professional and Business): the shopper-facing text of the passport (product name, statement, care, repair and disposal instructions, substance details, step names and notes).

No customer or shopper data is sent. Results come back as drafts that you review before anything is published. If AI is not switched on, the app builds drafts from a template on our own server.

We use Gemini under Google's paid API terms.

10. Shopify Flow

The app sends four Shopify Flow triggers to your own store: passport published, passport unpublished, product without a passport, and EU fields incomplete. Each carries the product's Shopify ID and, depending on the trigger, the passport link, version number, how many EU fields are filled in, the names of missing fields, the product title or the reason for unpublishing. This data stays in Shopify, for workflows you build.

11. EU registry

The EU has not yet published how businesses connect to its Digital Product Passport registry. Until it does, the app only records your registration request (the product identifier and passport links) in our database, with the status "waiting for the EU". Nothing is sent to the EU. We will update this policy before any data goes to the registry.

12. Backups (Business plan)

Every night, and when you click "Back up now", the app makes a backup of your shop: passports and their versions, live copies, settings (including the notification address), templates, access links, registry records and copies of your documents. Analytics, jobs and usage counters are not included.

Each backup is checksummed and signed, and stored in a second storage bucket in another region (DigitalOcean Spaces, Amsterdam). It is used only to restore your shop when you ask, or after a loss of data.

13. Data used briefly for security

  • IP address. To stop abuse, the app counts requests per IP address on its public routes (for example 60 analytics events, 120 QR-code lookups and 120 document downloads per minute). The counter lives only in memory (Redis or the server process). It is never written to our database. In Redis it expires after one minute; an in-process counter is cleared when the server sweeps old counters or restarts.
  • Shopify's customer ID on storefront requests. The product-page blocks load through Shopify's app proxy. For a signed-in shopper, Shopify adds that shopper's customer ID to the request. The app does not read or store it, and it is not passed on to the passport page.
  • Logs and errors. Our servers write operational logs (for example: shop domain, product ID, which webhook ran, error messages). If error tracking is switched on, error reports go to Sentry, set up not to send IP addresses or cookies.

14. Billing

Paid plans are billed by Shopify. We never see card or bank details. Shopify tells us which plan is active, and we keep a copy of that plan record.

15. Support

If you email us, we keep the emails and the details you include so we can help you.

Cookies and browser storage

  • Public passport pages and the product-page blocks set no cookies and use no browser storage.
  • In the admin, the app saves one flag in your browser's local storage: whether you have seen the EU guide.
  • Shopify uses its own cookies to sign you in to the Shopify admin. See Shopify's privacy policy.

Shoppers' browsers load a font stylesheet from Shopify's CDN (cdn.shopify.com). Product images normally load from Shopify too. Document downloads come from our storage provider. If you add a step photo by URL, it loads from the address you entered.

Who we share data with (subprocessors)

We use these providers to run the app. Each one only gets what it needs.

ProviderWhat it doesData it handlesWhen
ShopifyApp platform, sign-in, billing, webhooks, app proxy, Shopify Flow, CDN for fonts and product imagesShop data, plan, product data, Flow trigger dataAlways
Google Firebase / Cloud FirestoreDatabase for passport and app dataPassports, settings, templates, jobs, access links, analytics events, plan copy, backup recordsAlways
Supabase (PostgreSQL)Database for Shopify sign-in sessionsShop domain, Shopify access token, granted scopes, session expiryAlways
DigitalOceanHosting (App Platform), object storage (Spaces) for documents, Redis (Valkey) when the app runs on more than one instanceEverything the app processes; document files; short-lived rate-limit countersAlways
DigitalOcean Spaces, Amsterdam (Netherlands)Second storage bucket for backupsSigned backup bundles and copies of document filesBusiness shops
CloudflareCDN in front of the app's domainEvery request to the app's domain (including the visitor's IP address and browser details, as with any CDN); cached copies of public pages, public JSON and QR-code redirectsWhen the CDN is enabled
Google (Gemini API)AI drafting and translationProduct text onlyOnly if AI is switched on
ResendEmail deliveryNotification address, email contentOnly when email delivery is switched on
SentryError trackingError details, route, shop domain; no IP addresses or cookiesOnly if error tracking is switched on

Access-link pages and their documents are never stored in the CDN's cache, but their requests (and the token in the address) pass through it like any other request.

We may also disclose data if the law requires it, or to protect our rights or users' safety. If the business is sold or merged, data may move to the new owner under this policy.

Where data is stored

  • App servers and Redis: DigitalOcean. Our deployment file uses the New York (USA) region.
  • Documents: DigitalOcean Spaces, Frankfurt (Germany).
  • Backups: DigitalOcean Spaces, Amsterdam (Netherlands).
  • Firestore: Google Cloud, region Europe (eur3 multi-region: Belgium and the Netherlands).
  • Cloudflare, Google (Gemini), Resend and Sentry may process data in the USA and other countries.

When EU, UK or Swiss personal data leaves those areas, we rely on the European Commission's Standard Contractual Clauses (and the UK addendum), or the EU–US Data Privacy Framework where the provider is certified.

How long we keep data

DataHow long
Passports, version history, templates, settings, plan copy, jobs, access links, registry records, AI usage countersWhile the app is installed
DocumentsWhile the app is installed. Unpublished documents can be deleted at any time; locked documents stay with their published version
Passport of a product you delete in ShopifyOffline at once; the draft and its versions are deleted by the nightly sync once 30 days have passed
A passport you delete in the appDeleted at once
Analytics eventsDeleted automatically after 24 months (nightly clean-up), or earlier when the shop's data is erased
Backups35 days, then deleted
Copies of document files in the backup bucketShared between backups by fingerprint; deleted as soon as no remaining backup uses them (checked every night and when a shop's data is erased)
Shopify session and access tokenDeleted when you uninstall
All shop data (passports, versions, documents, settings, templates, jobs, access links, analytics, backups)Erased when Shopify sends the shop/redact request, 48 hours after you uninstall
Rate-limit counters (IP addresses)About one minute; never written to our database
Emails at Resend30 days (Resend keeps content, events and logs for 30 days on every plan)
Server logsKept by DigitalOcean's App Platform for its runtime-log window only (under 30 days); we do not forward logs anywhere
Sentry error reports90 days (Sentry's standard retention)
Support emailsUp to 3 years after the conversation ends
Billing recordsAs long as tax law requires

When you uninstall

  1. Straight away: the app deletes its Shopify session and takes all your passports offline. Passport links, QR codes on printed labels, access links and the product-page blocks stop working.
  2. 48 hours later, Shopify sends shop/redact. The app then erases all your shop's data: the database records (including analytics and access links), your document files and your backup bundles. Copies of document files in the backup bucket expire under the rule above.

If you reinstall within those 48 hours, your drafts are still there, but you will need to publish your passports again.

Export your passports (Passports, then Export) and your analytics (Analytics, then Export CSV) before you uninstall if you want to keep them. Download any documents you need.

Shopify's customer privacy requests

Shopify sends apps three privacy webhooks. The app handles all three at https://transparencypassport.online/webhooks/compliance:

  • customers/data_request: the app stores no customer data, so there is nothing to return. The request is logged.
  • customers/redact: nothing to delete, for the same reason. The request is logged.
  • shop/redact: the app erases all data for that shop, as described above.

Your rights

Depending on where you live, you can ask us to:

  • tell you what data we hold about you and give you a copy
  • correct it
  • delete it
  • limit or object to how we use it
  • send it to you or another service in a common format

Merchants can do most of this in the app: edit or delete passports and unpublished documents, revoke access links, export CSV files, change settings, or uninstall.

Write to [email protected]. We answer within 30 days. If we hold the data for a merchant (as processor), we will pass your request to that merchant and help them answer it.

You can also complain to your data protection authority.

California and other US states: we do not sell or share personal information for cross-context behavioural advertising.

Security

We protect data with server-only database access, Shopify's request signatures, signed access links and storage links, file checks, signed backups, HTTPS, plan checks on the server and rate limits. Details are in our security overview. No system is perfectly secure. If a breach affects your data, we will tell you without undue delay.

Children

The app is for businesses. It is not meant for children, and we do not knowingly collect children's data.

Changes to this policy

We will post any change here and update the date at the top. For important changes we will tell merchants in the app or by email at least 30 days before they apply.

Contact

Otium
[email protected]