Who we are
Passportify (“we”, “us”, “the app”) is a Shopify application operated by ONLINE SHOP SYSTEMS SRL, registered in Romania. The app helps merchants create and publish EU Digital Product Passport (ESPR-oriented) disclosures linked to their Shopify products.
Privacy contact: ionut.lazar2701@gmail.com.
Scope
This policy applies to merchant use of the Passportify admin experience inside Shopify, and to publicly published passport pages we host (for example /p/:passportId). It does not replace Shopify’s own privacy policy for the Shopify platform.
Data we process
Merchant / shop data: Shopify shop domain, OAuth session tokens, optional shop contact details provided by Shopify, subscription and plan information, one-time (PAYG) purchase records, branding settings, and Digital Product Passport content you enter or import (including materials, supply-chain stages, carbon/water figures, care and circularity text, content hashes, and Merkle-related integrity metadata).
AI Auto-Fill: when you upload documents, we may process filenames, content hashes, extraction snapshots, and AI-provider metadata. We do not keep raw PDF blobs after processing for the Auto-Fill flow.
Staff session fields: Shopify may provide staff identifiers (for example name or email) on the session used to authenticate the embedded admin.
Purposes and legal bases
We process this data to provide the app (authentication, passport editing, publishing, billing entitlements, integrity features, support), to improve reliability and security, and to comply with Shopify platform requirements (including mandatory privacy webhooks).
Where GDPR applies, processing is typically based on performance of a contract with you (providing the app you installed), legitimate interests in securing and operating the service, and/or legal obligations related to platform compliance.
Customer (buyer) data
Passportify does not request Shopify customer or order access scopes and does not store storefront buyer personal data. The storefront badge and public passport pages show product sustainability information you choose to publish, not customer profiles.
Mandatory Shopify compliance webhooks (customers/data_request, customers/redact) are acknowledged. When no customer personal data is stored by Passportify, there is nothing for us to export or erase for that customer.
Public passport pages
Passports you publish (or seal) may be available at public URLs, GS1 Digital Link paths (/01/{gtin}), and linked from your storefront. Only statuses intended for public viewing are shown. Content you publish can be indexed or shared by third parties outside our control once it is public.
Integrity seal, hashing, and on-chain data
What is hashed: a canonical JSON snapshot of sealed passport fields for a given version (schema v4+). Supplier names, emails, and other identity fields in the supply chain are omitted from the hashed document. Images, notes, and language overlays are never hashed.
What is on-chain forever: if you turn on Integrity seal and we broadcast a batch, the public chain stores a Merkle root (a hash of hashes) and a transaction identifier — not the bill of materials, not supplier identities, and not the full passport. That commitment cannot be erased from the network.
What you can unpublish: the live public page, storefront metafields, and the shop-scoped database record can be unpublished or deleted. An on-chain hash may remain as a tombstone that no longer resolves to a live passport.
Processors and subprocessors
Shopify provides authentication, billing, and the merchant admin environment.
Infrastructure: our application and database are hosted on cloud providers we contract with (currently including Fly.io for application hosting and a managed PostgreSQL database).
Optional AI providers (for example Anthropic, OpenAI, or Google Gemini when configured) process documents or text you submit for Auto-Fill or translation features. Blockchain networks may receive cryptographic hashes / Merkle roots you choose to anchor; on-chain data is public by design.
Retention and deletion
We retain shop-scoped data while the app remains installed and as needed for billing, security, and dispute handling.
When you uninstall the app, or when Shopify sends a shop/redact request, we delete OAuth sessions and shop-scoped Passportify database records (shop, passports, related logs and purchases, and shop-owned Merkle batch rows where applicable).
Global multi-shop Merkle batch rows and already-broadcast blockchain transactions cannot be erased from a public chain.
International transfers
Depending on hosting and AI providers, data may be processed in the EU and/or other countries. Where required, we rely on appropriate safeguards offered by our providers (for example standard contractual clauses).
Your rights
Depending on applicable law (including GDPR where it applies), you may have rights to access, rectify, erase, restrict, or object to certain processing, and to lodge a complaint with a supervisory authority. For Romania, the national authority is ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal).
To exercise rights related to Passportify-held merchant data, email ionut.lazar2701@gmail.com.
Contact
ONLINE SHOP SYSTEMS SRL, Romania.
Email: ionut.lazar2701@gmail.com (mailto:ionut.lazar2701@gmail.com).
You can also open the Support page linked from the app’s Billing screen.
Updates
We may update this policy when the product or legal requirements change. The updated version will be published at this URL. Continued use of the app after changes constitutes acceptance of the revised policy where permitted by law.