Last updated: 2026-08-04
Controller: Kavero Labs — Enes Ay, Eskişehir, Türkiye Contact: [email protected]
The controller is established in Türkiye; all data is stored and processed in the EU (section 5).
This entity will be updated if a company is registered later.
The app displays the official EU harmonised notice on the legal guarantee of conformity and the GARAN durability label on a merchant's storefront, and provides a Right to Repair claim workflow. It is installed by a merchant on their Shopify store.
This app displays the official EU harmonised notice. It is not legal advice.
When a merchant installs the app we store: the shop domain, the Shopify access token, install and uninstall timestamps, the shop's locale, and the app's own settings (selected markets, display options, exclusions, guarantee profiles, guarantee duration per market).
We use this only to operate the app for that shop. It is deleted as described in section 6.
The app processes customer data only for the Right to Repair claim workflow, which exists so a consumer can exercise a statutory right.
When an order is fulfilled, we store exactly seven fields:
| Field | Purpose |
|---|---|
| Order id | Links the record to the order in Shopify |
| Order number | Verifies a repair claim |
| Line item id | Identifies which item a claim concerns |
| Product id | Determines the applicable guarantee and label |
| Variant title | Shows the consumer what they are claiming on |
| Fulfilment date | Calculates when the legal guarantee ends |
| Customer email address | Verifies a repair claim |
We do not store shipping or billing addresses, payment or card data, prices, discounts, taxes, order notes, customer identifiers, or any other part of the order.
A claim additionally records: the remedy chosen (repair or replacement) and when it was chosen, the exact version of the mandated disclosure shown before that choice and when it was shown, the guarantee end date together with every value used to calculate it, and the merchant's own status updates and notes.
Those values are frozen at the moment of the claim and never recalculated afterwards. If the merchant later changes a setting, an existing claim keeps the dates the consumer was actually given, and the figures behind them stay available to check.
A consumer proves a claim is theirs with the order number and the email address on that order. No account or password is required. To protect other people's orders, every failed attempt returns the same generic message and never reveals whether an order number exists.
For customer data, the merchant is the controller and this app is a processor acting on the merchant's instructions. Processing is necessary for compliance with the merchant's legal obligations under Directive (EU) 2024/1799 and Implementing Regulation (EU) 2025/1960, and for the performance of the contract between the merchant and their customer.
All data is stored and processed in the European Union. No personal data leaves the EU.
| Sub-processor | Purpose | Region |
|---|---|---|
| Fly.io | Application hosting | Frankfurt, Germany |
| Neon | PostgreSQL database | European Union |
| Sentry | Error monitoring | European Union |
This applies to staging as well as production. Adding a sub-processor, or moving one outside the EU, requires updating this table first.
Shopify is not a sub-processor of ours. Metafields, uploaded files and order data live in the merchant's own Shopify account, governed by the merchant's agreement with Shopify.
Images of the official notice and label are uploaded to the merchant's own Shopify Files and served from Shopify's CDN. Order confirmation emails therefore never contact our servers.
The storefront never communicates with our servers. Everything a shopper sees is rendered by the merchant's theme from data held in Shopify.
| Data | Retention |
|---|---|
| Merchant shop record and settings | Until uninstall, then purged after 30 days |
| Order records and repair claims | Until the guarantee end date + 12 months + a further 12 months, then permanently deleted |
| Metafields written to the merchant's store | Removed on uninstall |
| Notice and label images in the merchant's Files | Kept indefinitely, including after uninstall — see below |
The images are official EU artwork, not personal data. They are kept because order-confirmation emails already delivered to customers link to them: deleting one would blank the guarantee notice in mail sent for orders that were placed long before. They live in the merchant's own file library and only the merchant can remove them.
The extra periods cover a repair completed on the last day of the guarantee and a dispute raised at the end of the extended period. Deletion is permanent, not a hidden flag.
On a Shopify customers/redact or shop/redact request, the relevant data is
deleted immediately, without waiting for the periods above.
A consumer may ask the merchant for access to, correction of, or deletion of their data, and the merchant can act on that through Shopify's data request and redaction flows, which this app implements. Requests sent directly to us are forwarded to the merchant, since the merchant is the controller.
A consumer in the EU may also complain to the supervisory authority in their own member state.
Material changes will be published here and noted in the app.
Kavero Labs — Enes Ay Eskişehir, Türkiye Support: [email protected]