Gransko
Privacy Policy
Gransko is a Shopify app that scans a merchant’s catalog for environmental marketing claims restricted by Directive (EU) 2024/825, suggests compliant rewrites, and adds product-page notices. This policy explains what data the app processes and why.
1. What we process
We process merchant and store data only — we do not read or store any shopper/customer personal data.
- Catalog and store content: the titles, descriptions/body text and text metafields (and IDs) of your products, collections, pages and blog articles — the text we scan for claims.
-
Store information: your
.myshopify.comdomain, and the store contact email (used to send the optional digest and alert emails). - App data we generate: findings, your dismissals and applied/reverted rewrites, scan metadata, your plan/subscription status, and app settings (e.g. digest opt-out, scan languages, rescan cadence).
- Authentication: the Shopify session/access tokens needed to call the Shopify Admin API on your behalf.
We request the write_products, read_content and
write_content scopes — to read and, on your approval, update the
text of your products, collections, pages and blog articles. We request
no customer or order scopes, so we never access data Shopify
classifies as protected customer data.
2. What we do NOT process
- No customer/shopper names, emails, addresses, orders, or payment data.
-
The content permission (
read_content/write_content) technically also covers blog comments and contributors, but Gransko only reads and writes the title and body text of pages and blog articles — we do not read or store blog comments or contributor personal data (such as a commenter’s email, IP address, or browser/operating system). - We do not use tracking or advertising cookies. The embedded admin app uses Shopify session tokens for authentication only.
3. How we use it
- To scan your catalog and produce findings with explanations and article references.
- To generate AI rewrite suggestions (which you review before applying) and, on your approval, to update the relevant product, collection, page or blog article via the Shopify Admin API.
- To render the storefront notice blocks.
- To send the optional weekly digest and daily new-finding alert emails to your store contact address, and to operate, secure and support the app.
4. Sub-processors
We share the minimum necessary data with:
| Provider | Purpose | Data shared |
|---|---|---|
| Shopify | Platform, Admin API | Auth tokens, catalog/content data via the API |
| Fly.io | App hosting | Requests to the app |
| Neon | Database (EU region) | Findings, rewrites, scan/app data, sessions |
| Anthropic (Claude API) | AI rewrite suggestions | The single field’s text being rewritten — product, collection, page or blog article copy only |
| Resend | Digest & alert emails | Store contact email + the finding summary |
Requests to the Claude API contain product, collection, page or blog article text only — never customer data.
5. Where data is stored
Application data is stored in the EU (Neon, Frankfurt) and the app is hosted in the EU (Fly.io, Stockholm). Sub-processors may process data in other regions under appropriate safeguards.
6. Retention and deletion
- App data is retained while the app is installed.
-
On uninstall, Shopify sends a
shop/redactrequest (about 48 hours later); we then delete all data we hold for your shop — scans, findings, rewrites, usage counters, settings and sessions. -
We also implement Shopify’s
customers/data_requestandcustomers/redactwebhooks; because we store no customer data, there is nothing to provide or erase in response. - You can delete your data at any time by uninstalling the app.
7. Legal basis and your rights (GDPR)
The catalog and content text we process is business content, and the store contact email is a business contact detail. Where the GDPR applies, our basis is the performance of our agreement with you and our legitimate interest in operating the app. You may request access to, correction of, or deletion of your data by contacting us at privacy@gransko.com; uninstalling the app triggers deletion automatically.
8. Security
Data is transmitted over TLS and access is restricted to what’s required to run the service. Access tokens are stored to call the Shopify API on your behalf and are deleted on uninstall.
9. Changes
We may update this policy; material changes will be reflected by the effective date above and, where appropriate, communicated in-app.
10. Contact
Questions or requests: privacy@gransko.com.