Privacy policy
Last updated: Sep 22, 2026
This privacy policy describes how we collect, use and protect data when you install our Shopify app or use our dashboard.
For the store data our app syncs, we act as a data processor on behalf of the merchant, who remains the data controller. We deliberately limit that data to what profit analytics needs, and it does not include your customers' identifying details — see below.
Who is responsible
The controller for the personal data described in this policy is DHPPS GmbH, Handel-Mazzetti-Straße 127/20, 3100 St. Pölten, Österreich. You can reach us at the contact address below, and our full company details are in the legal notice.
Data about you
To give you an account and run the dashboard, we store:
- Dashboard account data: your name, email address and team memberships.
- Settings you enter: product costs, shipping rules and payment fee configuration.
- Technical data: server logs (such as IP address and browser type) kept for security and troubleshooting.
Data we sync from your Shopify store
When you connect your Shopify store, we sync and store the following data to compute your profit analytics:
- Store information: shop name, domain, contact email, currency and plan.
- Product catalog: products, variants, SKUs, prices and inventory levels.
- Orders, refunds and payment transactions, including line items, discounts, taxes, shipping and payment fees.
We do not collect your customers' personal data. Our order sync deliberately requests no customer names, email addresses, phone numbers or street addresses — the only address detail we read is the destination country code, which we use to attribute orders to shipping zones. Nothing that identifies an individual shopper reaches our database.
How we use data
We use this data exclusively to provide the service:
- Computing profit, cost and inventory analytics for your store.
- Providing customer support and troubleshooting sync issues.
- Managing your subscription through Shopify Billing.
- Securing the service and preventing abuse.
We never sell data, and we never use it for advertising or profiling.
Legal bases (GDPR)
We process data to perform our contract with you (providing the analytics you signed up for), to pursue our legitimate interest in operating and securing the service, and to comply with legal obligations.
Sharing and subprocessors
We share data only with the infrastructure providers needed to run the service — hosting and database providers, and our email delivery provider for sign-in and notification emails — and with Shopify as part of the app platform. We never sell data to third parties.
Retention and deletion
We keep synced store data for as long as the app is installed, so your analytics keep their history.
When you uninstall the app, we honor Shopify's GDPR webhooks: customer data redaction requests and shop redaction requests lead to permanent deletion of the related personal data from our database, typically within 30 days.
Your rights
Under the GDPR and similar laws you can request access to, correction, deletion, restriction or portability of your personal data, and object to its processing. Contact us to exercise these rights; you can also lodge a complaint with your local data protection authority.
If you are a customer of a store that uses this app, please direct requests to that store — we support merchants in fulfilling them, including through Shopify's customer data request and redaction process.
Security
Data is encrypted in transit (TLS) and at rest — the database and all backups — access is restricted to authorized personnel, and each store's data is isolated by a strict tenant boundary.
Changes to this policy
We may update this policy as the service evolves. Material changes will be announced in the dashboard. The date above always reflects the latest revision.
Contact
For any privacy question or request, contact us at support@geslr.com