FloziWarranty – Privacy Policy
Last updated: 20 September 2026
FloziWarranty is a Shopify app that creates the EU GARAN label and the harmonised legal guarantee notice and shows them in a merchant's online store. This policy explains which data the app processes when a merchant installs and uses it.
1. Controller
Flozify GmbHBrühlstr. 3/1
75236 Kämpfelbach, Germany
Managing director: Colin Aydt
Commercial register: Amtsgericht Mannheim, HRB 759143
Email: service@flozify.com
For the data of a merchant's shop we act as a processor on behalf of the merchant; for the data of the merchant as our customer (shop domain, support requests) we are the controller.
2. No customer or order data
The app does not read, store or transmit data about a shop's customers, visitors or orders. It requests the Shopify permissions write_products and read_locales, and optionally read_themes if the merchant uses the automatic theme check. It has no access to customers, orders, checkouts or payment data. The storefront blocks and the checkout extension display product metafields and set no cookies. One exception makes a request to our server: if the merchant enables the cart drawer embed, the storefront asks for the labels of the variants in the cart through Shopify's app proxy. That request contains variant IDs and the storefront language only; we do not read or store any customer identifier from it.
3. Data we process
- Shop data: the shop domain (
*.myshopify.com), the shop's primary and published languages, the app settings chosen by the merchant. - Access token: the Shopify API token issued when the app is installed, stored encrypted at rest in our database and used only for the requests described here.
- Product data: product and variant IDs, titles, vendor, product type, tags, SKU, status, and the guarantee information the merchant enters (guarantor, duration, conditions).
- Generated files: label and notice files (SVG, PDF) and export files (CSV, ZIP) the merchant requests.
- Audit log: which action was taken and when, together with the numeric Shopify staff user ID of the person who triggered it. We do not store staff names or email addresses.
- Technical logs: webhook IDs, job status and error messages; server logs of our hosting provider with IP address and request time.
- Support requests: what you send to service@flozify.com.
4. Purposes and legal basis
We process this data to provide the app (Art. 6(1)(b) GDPR), to keep it secure and find errors (Art. 6(1)(f) GDPR) and to answer support requests (Art. 6(1)(b) and (f) GDPR). We do not use the data for advertising, profiling or analytics and we do not sell it.
5. Billing
The subscription is charged by Shopify through the Shopify Billing API. We receive no payment details; we only see whether a subscription is active.
6. Recipients and hosting
- Supabase (database and file storage), region Frankfurt, Germany.
- Vercel (application hosting), functions run in region Frankfurt (fra1). Vercel Inc. is based in the USA; transfers are covered by the EU–US Data Privacy Framework and standard contractual clauses.
- Shopify, through whose APIs the app reads products and writes metafields.
We have data processing agreements with these providers. There are no other recipients.
7. Retention and deletion
When the app is uninstalled, access tokens are deleted immediately and the shop's product data and generated files are removed by a clean-up job. At the latest when Shopify sends the shop/redact request (48 hours after uninstall) everything left for the shop is erased. Export files are replaced by the next export and removed with the shop. Server logs of the hosting provider expire according to its retention period. Support emails are deleted when they are no longer needed, unless statutory retention periods apply.
8. Shopify compliance webhooks
The app answers Shopify's mandatory requests customers/data_request, customers/redact and shop/redact. Because the app stores no customer data, the customer requests are confirmed without any data to return or erase.
9. Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability and the right to object (Art. 15–21 GDPR). Write to service@flozify.com. You may also lodge a complaint with a supervisory authority; the authority responsible for us is the Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg.
10. Changes
We update this policy when the app changes. The current version is always available on this page.
FloziWarranty – Datenschutzerklärung
Stand: 20. September 2026
FloziWarranty ist eine Shopify-App, die das EU-GARAN-Etikett und die harmonisierte Gewährleistungs-Mitteilung erstellt und im Onlineshop des Händlers anzeigt. Diese Erklärung beschreibt, welche Daten die App verarbeitet, wenn ein Händler sie installiert und nutzt.
1. Verantwortlicher
Flozify GmbHBrühlstr. 3/1
75236 Kämpfelbach, Deutschland
Geschäftsführer: Colin Aydt
Handelsregister: Amtsgericht Mannheim, HRB 759143
E-Mail: service@flozify.com
Für die Daten des Shops eines Händlers handeln wir als Auftragsverarbeiter des Händlers; für die Daten des Händlers als unseres Kunden (Shop-Domain, Supportanfragen) sind wir Verantwortlicher.
2. Keine Kunden- und Bestelldaten
Die App liest, speichert und übermittelt keine Daten über Kunden, Besucher oder Bestellungen eines Shops. Sie fordert die Shopify-Berechtigungen write_products und read_locales an, optional read_themes, wenn der Händler die automatische Theme-Prüfung nutzt. Auf Kunden, Bestellungen, Checkouts oder Zahlungsdaten hat sie keinen Zugriff. Die Blöcke im Shop und die Checkout-Erweiterung zeigen Produkt-Metafelder an und setzen keine Cookies. Eine Ausnahme sendet eine Anfrage an unseren Server: Aktiviert der Händler das Embed für den Warenkorb-Drawer, fragt der Shop die Etiketten der Varianten im Warenkorb über Shopifys App-Proxy ab. Diese Anfrage enthält nur Varianten-IDs und die Sprache des Shops; eine Kundenkennung lesen oder speichern wir daraus nicht.
3. Verarbeitete Daten
- Shopdaten: Shop-Domain (
*.myshopify.com), Haupt- und veröffentlichte Sprachen des Shops, die vom Händler gewählten App-Einstellungen. - Zugriffstoken: das bei der Installation ausgestellte Shopify-API-Token, verschlüsselt gespeichert und nur für die hier beschriebenen Abfragen verwendet.
- Produktdaten: Produkt- und Varianten-IDs, Titel, Hersteller, Produkttyp, Tags, SKU, Status sowie die vom Händler eingegebenen Garantieangaben (Garantiegeber, Dauer, Bedingungen).
- Erzeugte Dateien: Etikett- und Mitteilungsdateien (SVG, PDF) sowie Exportdateien (CSV, ZIP), die der Händler anfordert.
- Änderungsprotokoll: welche Aktion wann ausgeführt wurde, zusammen mit der numerischen Shopify-Benutzer-ID des Mitarbeiters. Namen oder E-Mail-Adressen von Mitarbeitern speichern wir nicht.
- Technische Protokolle: Webhook-IDs, Job-Status und Fehlermeldungen; Server-Logs unseres Hosting-Anbieters mit IP-Adresse und Zeitpunkt der Anfrage.
- Supportanfragen: was Sie an service@flozify.com senden.
4. Zwecke und Rechtsgrundlagen
Wir verarbeiten diese Daten, um die App bereitzustellen (Art. 6 Abs. 1 lit. b DSGVO), sie sicher zu betreiben und Fehler zu finden (Art. 6 Abs. 1 lit. f DSGVO) und Supportanfragen zu beantworten (Art. 6 Abs. 1 lit. b und f DSGVO). Wir nutzen die Daten nicht für Werbung, Profilbildung oder Analysen und verkaufen sie nicht.
5. Abrechnung
Das Abonnement rechnet Shopify über die Shopify Billing API ab. Wir erhalten keine Zahlungsdaten; wir sehen nur, ob ein Abonnement aktiv ist.
6. Empfänger und Hosting
- Supabase (Datenbank und Dateispeicher), Region Frankfurt, Deutschland.
- Vercel (Anwendungs-Hosting), Funktionen laufen in der Region Frankfurt (fra1). Vercel Inc. hat ihren Sitz in den USA; Übermittlungen sind durch das EU-US Data Privacy Framework und Standardvertragsklauseln abgesichert.
- Shopify, über dessen APIs die App Produkte liest und Metafelder schreibt.
Mit diesen Anbietern bestehen Auftragsverarbeitungsverträge. Weitere Empfänger gibt es nicht.
7. Speicherdauer und Löschung
Bei der Deinstallation werden Zugriffstoken sofort gelöscht, Produktdaten und erzeugte Dateien des Shops entfernt ein Aufräumjob. Spätestens mit Shopifys Anforderung shop/redact (48 Stunden nach der Deinstallation) wird alles gelöscht, was zum Shop noch vorhanden ist. Exportdateien werden durch den nächsten Export ersetzt und mit dem Shop entfernt. Server-Logs des Hosting-Anbieters verfallen nach dessen Aufbewahrungsfrist. Support-E-Mails löschen wir, sobald sie nicht mehr benötigt werden, soweit keine gesetzlichen Aufbewahrungsfristen gelten.
8. Shopify-Compliance-Webhooks
Die App beantwortet Shopifys Pflichtanfragen customers/data_request, customers/redact und shop/redact. Da die App keine Kundendaten speichert, werden die Kundenanfragen bestätigt, ohne dass Daten herauszugeben oder zu löschen sind.
9. Ihre Rechte
Sie haben das Recht auf Auskunft, Berichtigung, Löschung, Einschränkung der Verarbeitung, Datenübertragbarkeit und Widerspruch (Art. 15–21 DSGVO). Schreiben Sie an service@flozify.com. Außerdem können Sie sich bei einer Aufsichtsbehörde beschweren; für uns zuständig ist der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg.
10. Änderungen
Wir passen diese Erklärung an, wenn sich die App ändert. Die aktuelle Fassung steht immer auf dieser Seite.