TransparencyPassport Privacy Policy
Last updated: 10 October 2026
This policy explains what the TransparencyPassport Shopify app ("the app") collects, why, where it is kept, and for how long. The app is run by Otium ("we", "us"). Contact: [email protected].
Questions or requests: [email protected].
The short version
- The app only has the Shopify permission
read_products. It cannot read your customers, orders or payments. - We store the passports you create, the documents you upload, your app settings and anonymous view counts.
- We do not store shoppers' names, emails, IP addresses, device IDs or cookies.
- What you publish is public, except the fields and documents you reserve for repairers, recyclers or authorities. Those open only through access links you create.
- When you uninstall, your passports go offline at once. Shopify then asks us to erase your shop's data, and we do.
- We do not sell or rent data. We do not use it for advertising.
Who is responsible for what
For data about your store, you (the merchant) are the controller. We are your processor: we handle the data only to run the app for you. Our Data Processing Addendum sets out those terms.
For the few things we decide on our own (billing records we receive from Shopify, security logs, and support emails you send us), we are the controller.
Shoppers who open a passport stay anonymous to us. We do not try to identify them.
What we collect and why
1. Your shop and your Shopify connection
| Data | Why | Where |
|---|---|---|
Shop domain (your-store.myshopify.com) | To know which store the data belongs to | Firestore |
| Your store's name, as Shopify reports it | Shown as "Shared by …" on access-link views | Firestore |
| Shopify access token and granted scopes | To read your products when you ask the app to, and to send Shopify Flow triggers | Firestore (session record) |
| Your current plan, as reported by Shopify | To apply plan limits | Firestore |
The app uses Shopify "offline" tokens. These are tied to the store, not to a staff member. The app does not store staff names or staff emails.
2. Product data read from Shopify
When you open the editor, use AI auto-fill, bulk create or product sync, the app reads product data from Shopify: title, handle, description, vendor, product type, tags, images, variants (title, SKU, barcode, weight) and metafields.
We store only what ends up in a passport: the product ID, name, handle and image address, plus the passport fields you save. We keep passports in step with Shopify: a renamed product updates its passport, and a deleted product's passport goes offline at once (see "How long we keep data").
3. Passports you create
Supply-chain steps (place, country, date, transport, notes, photo links, facility names and GS1 location numbers), the transparency statement, certifications, identifiers (GTIN, SKU, batch, lot and serial numbers), manufacturer details (name, address, country, EORI, contact email, website), materials, substances of concern, recycling, care, repair, durability and warranty details, footprint figures, translations of your text, templates, and a version copy of every publish.
Who can see a published passport. The public page, the product-page blocks and the machine-readable passport (/dpp/<shop>/<handle>.json) show the public fields to anyone with the link or QR code. Anyone can download and keep a copy of the public JSON.
These fields are not public. They appear only to someone holding a valid access link for the right role:
- repairers: manufacturer address and contact email, substance details, spare-parts years;
- recyclers: substance details, batch number, manufacturing date;
- authorities: all of the above, plus the EORI number and facility names and numbers.
The same rule applies to documents: each one is marked public, repairer, recycler or authority. Access links are part of the Business plan; on other plans the restricted fields are simply not shown.
Do not put personal data or confidential details in public fields unless you mean to publish them.
4. Compliance documents (Business plan)
You can attach files to a passport, such as a declaration of conformity, test reports or certificates (PDF, PNG, JPG or WEBP, up to 20 MB). We store:
- the file itself, in object storage (see "Where data is stored");
- its title, kind, issuer, issue and expiry dates, the audience you chose, its size and type, and its SHA-256 fingerprint.
How it works:
- Your browser uploads the file straight to the storage bucket through a short-lived signed address.
- The app then reads the file back. It checks the type, the size and that the fingerprint matches.
- If a virus scanner is set up, the file is sent to it before it is accepted. If the scanner is unavailable, the upload is refused.
- When you publish, the documents in that version are locked. You cannot change or delete a locked document in the app, because the passport must keep what it showed. If a locked document contains data that must be removed, contact us.
- Public documents can be downloaded by anyone. Other documents only with an access link whose role covers them. Downloads go through a signed storage link that expires after 5 minutes, so the file comes from the storage provider, not from our servers.
The page shows each document's SHA-256 checksum ("Checksum recorded <date>"), recorded when the file was uploaded, and lets anyone compare the downloaded copy with it ("This file matches the checksum recorded on <date>"). That proves the file is unchanged. It says nothing about whether its content is true, and the app never calls a document "verified".
5. Access links (Business plan)
When you create an access link for a repairer, recycler or authority, we store the product, the role, your label for the link, when it was created, when it expires (90 days by default, up to 3 years), when it was revoked, how many times it was used and when it was last used.
We do not record who opens a link, or their IP address. The link itself is the key: anyone who has it can open that view until it expires or you revoke it. Share it like a password.
6. Settings
Brand colours, display options, default statement text, default language, your store name, and, if you switch on email (Professional and Business plans), a notification address and which emails you want. The notification address is never shown on public pages.
7. Email notifications
Email is sent only when all of these are true: we have switched on email delivery for the app, your plan includes email, you turned notifications on, you gave an address, and you chose that email. The four emails are:
- a passport went live;
- a weekly check (Mondays) of passports missing EU fields and documents about to expire;
- a background job finished with failed items;
- a document expires within 30 days.
Each email contains product names, passport links, counts, and document titles and expiry dates. We send them through Resend. When email delivery is off, the app only notes that an email would have been sent, without the address or the content.
8. Anonymous passport analytics
When someone opens a published passport page, scans its QR code, sees the product-page block, or clicks it, the app stores one event with:
- the event type (
view,qr_scan,widget_vieworwidget_click) - the product handle and product name
- your shop domain
- the time (set by our server)
- the source label (
direct,qr,widget, or a short label from the link) - the referring website, cut down to its origin (for example
https://www.instagram.com, never the full address)
That is all. Events contain no IP address, no user agent, no cookie, no device ID and no customer ID. Events are only accepted for published passports.
Why: to show you the Analytics page (views, scans, block click rate, top passports, where visits come from). Events are deleted after 24 months.
9. AI features (optional)
If AI is switched on, the app sends product text only to Google's Gemini API:
- for auto-fill: the product facts listed in section 2;
- for a transparency statement: the product name and its supply-chain steps;
- for translations (Professional and Business): the shopper-facing text of the passport (product name, statement, care, repair and disposal instructions, substance details, step names and notes).
No customer or shopper data is sent. Results come back as drafts that you review before anything is published. If AI is not switched on, the app builds drafts from a template on our own server.
We use Gemini under Google's paid API terms.
10. Shopify Flow
The app sends four Shopify Flow triggers to your own store: passport published, passport unpublished, product without a passport, and EU fields incomplete. Each carries the product's Shopify ID and, depending on the trigger, the passport link, version number, how many EU fields are filled in, the names of missing fields, the product title or the reason for unpublishing. This data stays in Shopify, for workflows you build.
11. EU registry
The EU has not yet published how businesses connect to its Digital Product Passport registry. Until it does, the app only records your registration request (the product identifier and passport links) in our database, with the status "waiting for the EU". Nothing is sent to the EU. We will update this policy before any data goes to the registry.
12. Backups (Business plan)
Every night, and when you click "Back up now", the app makes a backup of your shop: passports and their versions, live copies, settings (including the notification address), templates, access links, registry records and copies of your documents. Analytics, jobs and usage counters are not included.
Each backup is checksummed and signed, and stored in a second storage bucket in another region (DigitalOcean Spaces, Amsterdam). It is used only to restore your shop when you ask, or after a loss of data.
13. Data used briefly for security
- IP address. To stop abuse, the app counts requests per IP address on its public routes (for example 60 analytics events, 120 QR-code lookups and 120 document downloads per minute). The counter lives only in memory (Redis or the server process). It is never written to our database. In Redis it expires after one minute; an in-process counter is cleared when the server sweeps old counters or restarts.
- Shopify's customer ID on storefront requests. The product-page blocks load through Shopify's app proxy. For a signed-in shopper, Shopify adds that shopper's customer ID to the request. The app does not read or store it, and it is not passed on to the passport page.
- Logs and errors. Our servers write operational logs (for example: shop domain, product ID, which webhook ran, error messages). If error tracking is switched on, error reports go to Sentry, set up not to send IP addresses or cookies.
14. Billing
Paid plans are billed by Shopify. We never see card or bank details. Shopify tells us which plan is active, and we keep a copy of that plan record.
15. Support
If you email us, we keep the emails and the details you include so we can help you.
Cookies and browser storage
- Public passport pages and the product-page blocks set no cookies and use no browser storage.
- In the admin, the app saves one flag in your browser's local storage: whether you have seen the EU guide.
- Shopify uses its own cookies to sign you in to the Shopify admin. See Shopify's privacy policy.
Shoppers' browsers load a font stylesheet from Shopify's CDN (cdn.shopify.com). Product images normally load from Shopify too. Document downloads come from our storage provider. If you add a step photo by URL, it loads from the address you entered.
Who we share data with (subprocessors)
We use these providers to run the app. Each one only gets what it needs.
| Provider | What it does | Data it handles | When |
|---|---|---|---|
| Shopify | App platform, sign-in, billing, webhooks, app proxy, Shopify Flow, CDN for fonts and product images | Shop data, plan, product data, Flow trigger data | Always |
| Google Firebase / Cloud Firestore | Database for passport and app data | Passports, settings, templates, jobs, access links, analytics events, plan copy, backup records | Always |
| Supabase (PostgreSQL) | Database for Shopify sign-in sessions | Shop domain, Shopify access token, granted scopes, session expiry | Always |
| DigitalOcean | Hosting (App Platform), object storage (Spaces) for documents, Redis (Valkey) when the app runs on more than one instance | Everything the app processes; document files; short-lived rate-limit counters | Always |
| DigitalOcean Spaces, Amsterdam (Netherlands) | Second storage bucket for backups | Signed backup bundles and copies of document files | Business shops |
| Cloudflare | CDN in front of the app's domain | Every request to the app's domain (including the visitor's IP address and browser details, as with any CDN); cached copies of public pages, public JSON and QR-code redirects | When the CDN is enabled |
| Google (Gemini API) | AI drafting and translation | Product text only | Only if AI is switched on |
| Resend | Email delivery | Notification address, email content | Only when email delivery is switched on |
| Sentry | Error tracking | Error details, route, shop domain; no IP addresses or cookies | Only if error tracking is switched on |
Access-link pages and their documents are never stored in the CDN's cache, but their requests (and the token in the address) pass through it like any other request.
We may also disclose data if the law requires it, or to protect our rights or users' safety. If the business is sold or merged, data may move to the new owner under this policy.
Where data is stored
- App servers and Redis: DigitalOcean. Our deployment file uses the New York (USA) region.
- Documents: DigitalOcean Spaces, Frankfurt (Germany).
- Backups: DigitalOcean Spaces, Amsterdam (Netherlands).
- Firestore: Google Cloud, region Europe (eur3 multi-region: Belgium and the Netherlands).
- Cloudflare, Google (Gemini), Resend and Sentry may process data in the USA and other countries.
When EU, UK or Swiss personal data leaves those areas, we rely on the European Commission's Standard Contractual Clauses (and the UK addendum), or the EU–US Data Privacy Framework where the provider is certified.
How long we keep data
| Data | How long |
|---|---|
| Passports, version history, templates, settings, plan copy, jobs, access links, registry records, AI usage counters | While the app is installed |
| Documents | While the app is installed. Unpublished documents can be deleted at any time; locked documents stay with their published version |
| Passport of a product you delete in Shopify | Offline at once; the draft and its versions are deleted by the nightly sync once 30 days have passed |
| A passport you delete in the app | Deleted at once |
| Analytics events | Deleted automatically after 24 months (nightly clean-up), or earlier when the shop's data is erased |
| Backups | 35 days, then deleted |
| Copies of document files in the backup bucket | Shared between backups by fingerprint; deleted as soon as no remaining backup uses them (checked every night and when a shop's data is erased) |
| Shopify session and access token | Deleted when you uninstall |
| All shop data (passports, versions, documents, settings, templates, jobs, access links, analytics, backups) | Erased when Shopify sends the shop/redact request, 48 hours after you uninstall |
| Rate-limit counters (IP addresses) | About one minute; never written to our database |
| Emails at Resend | 30 days (Resend keeps content, events and logs for 30 days on every plan) |
| Server logs | Kept by DigitalOcean's App Platform for its runtime-log window only (under 30 days); we do not forward logs anywhere |
| Sentry error reports | 90 days (Sentry's standard retention) |
| Support emails | Up to 3 years after the conversation ends |
| Billing records | As long as tax law requires |
When you uninstall
- Straight away: the app deletes its Shopify session and takes all your passports offline. Passport links, QR codes on printed labels, access links and the product-page blocks stop working.
- 48 hours later, Shopify sends
shop/redact. The app then erases all your shop's data: the database records (including analytics and access links), your document files and your backup bundles. Copies of document files in the backup bucket expire under the rule above.
If you reinstall within those 48 hours, your drafts are still there, but you will need to publish your passports again.
Export your passports (Passports, then Export) and your analytics (Analytics, then Export CSV) before you uninstall if you want to keep them. Download any documents you need.
Shopify's customer privacy requests
Shopify sends apps three privacy webhooks. The app handles all three at https://transparencypassport.online/webhooks/compliance:
customers/data_request: the app stores no customer data, so there is nothing to return. The request is logged.customers/redact: nothing to delete, for the same reason. The request is logged.shop/redact: the app erases all data for that shop, as described above.
Your rights
Depending on where you live, you can ask us to:
- tell you what data we hold about you and give you a copy
- correct it
- delete it
- limit or object to how we use it
- send it to you or another service in a common format
Merchants can do most of this in the app: edit or delete passports and unpublished documents, revoke access links, export CSV files, change settings, or uninstall.
Write to [email protected]. We answer within 30 days. If we hold the data for a merchant (as processor), we will pass your request to that merchant and help them answer it.
You can also complain to your data protection authority.
California and other US states: we do not sell or share personal information for cross-context behavioural advertising.
Security
We protect data with server-only database access, Shopify's request signatures, signed access links and storage links, file checks, signed backups, HTTPS, plan checks on the server and rate limits. Details are in our security overview. No system is perfectly secure. If a breach affects your data, we will tell you without undue delay.
Children
The app is for businesses. It is not meant for children, and we do not knowingly collect children's data.
Changes to this policy
We will post any change here and update the date at the top. For important changes we will tell merchants in the app or by email at least 30 days before they apply.
Contact
Otium
[email protected]