Gransko

Privacy Policy

Effective date: 6 August 2026
Controller: ViewState Holding AB (org.nr 559493-8440, registered in Sweden) (“Gransko”, “we”, “us”). Contact: privacy@gransko.com.

Gransko is a Shopify app that scans a merchant’s catalog for environmental marketing claims restricted by Directive (EU) 2024/825, suggests compliant rewrites, and adds product-page notices. This policy explains what data the app processes and why.

1. What we process

We process merchant and store data only — we do not read or store any shopper/customer personal data.

We request the write_products, read_content and write_content scopes — to read and, on your approval, update the text of your products, collections, pages and blog articles. We request no customer or order scopes, so we never access data Shopify classifies as protected customer data.

2. What we do NOT process

3. How we use it

4. Sub-processors

We share the minimum necessary data with:

ProviderPurposeData shared
ShopifyPlatform, Admin APIAuth tokens, catalog/content data via the API
Fly.ioApp hostingRequests to the app
NeonDatabase (EU region)Findings, rewrites, scan/app data, sessions
Anthropic (Claude API)AI rewrite suggestionsThe single field’s text being rewritten — product, collection, page or blog article copy only
ResendDigest & alert emailsStore contact email + the finding summary

Requests to the Claude API contain product, collection, page or blog article text only — never customer data.

5. Where data is stored

Application data is stored in the EU (Neon, Frankfurt) and the app is hosted in the EU (Fly.io, Stockholm). Sub-processors may process data in other regions under appropriate safeguards.

6. Retention and deletion

7. Legal basis and your rights (GDPR)

The catalog and content text we process is business content, and the store contact email is a business contact detail. Where the GDPR applies, our basis is the performance of our agreement with you and our legitimate interest in operating the app. You may request access to, correction of, or deletion of your data by contacting us at privacy@gransko.com; uninstalling the app triggers deletion automatically.

8. Security

Data is transmitted over TLS and access is restricted to what’s required to run the service. Access tokens are stored to call the Shopify API on your behalf and are deleted on uninstall.

9. Changes

We may update this policy; material changes will be reflected by the effective date above and, where appropriate, communicated in-app.

10. Contact

Questions or requests: privacy@gransko.com.