GPSR Compass

Privacy policy

This policy explains how GPSR Compass handles information when a merchant installs and uses the Shopify app.

Last updated: 3 September 2026

1. Who is responsible for the data?

SJL Ventures ApS (CVR 46390733), Allégade 23, 1., 5000 Odense C, Denmark, operates GPSR Compass and is responsible for the personal data described in this policy. Questions and privacy requests can be sent to sofus@wakey.dk.

2. Information we process

  • Shopify account and session information needed to authenticate users, including shop domain, access token, user ID, name, email, locale, permissions, and session expiry information.
  • Shop settings entered in the app, including business role, markets, languages, manufacturer and responsible-person details, safety defaults, and an optional alert email address.
  • Shopify product IDs and compliance information, assessments, checklists, findings, storefront-check results, and associated audit history created through the app.
  • Subscription status obtained from Shopify. GPSR Compass does not receive or store payment-card information.
  • Limited technical logs needed for security, troubleshooting, and reliable operation.

3. How and why we use information

We process information to provide the requested app functions, authenticate users, save settings, update Shopify product metafields, run compliance and storefront checks, enforce plan limits, send optional alerts, provide support, and protect the service. The legal bases are performance of the service agreement, steps requested by the merchant, and our legitimate interests in operating and securing the service. Optional emails are sent only when enabled by the merchant.

4. Shopify customer and storefront data

GPSR Compass requests product access, but it does not request order or customer scopes and does not intentionally collect buyer data. The theme extension does not set cookies, track visitors, or send visitor data to GPSR Compass. Storefront checks request public product URLs and retain the URL, response status, check time, and whether expected safety information was visible.

5. Service providers and international transfers

Shopify provides the commerce platform and authentication. Render hosts the app and PostgreSQL database in the Frankfurt region. Resend processes the recipient address and email content when a merchant enables email alerts. These providers can process limited technical and account data under their own terms and data-processing arrangements. Where data is transferred outside the EEA, the provider’s applicable transfer safeguards are used.

6. Retention and deletion

Active app data is retained while needed to provide the service. Product-specific local records are deleted when Shopify tells us a product has been deleted. Local shop data and sessions are deleted when the app is uninstalled or Shopify sends a shop-redaction request. Limited residual copies can remain temporarily in provider backups or security logs until they expire under the provider’s retention schedule or must be kept to meet a legal obligation.

7. Security and sharing

We use access controls, encrypted HTTPS connections, Shopify webhook verification, and restricted service credentials. We do not sell personal data. Information is shared only with the service providers described above, when instructed by the merchant, or when required by law.

8. Your rights

Depending on applicable law, individuals can have rights to access, correct, delete, restrict, or receive a copy of their personal data, object to certain processing, and complain to a data-protection authority. Contact us at sofus@wakey.dk. Merchants can also remove active app data by uninstalling the app.

9. Changes

We can update this policy when the service or legal requirements change. The date at the top shows the latest revision.