This policy explains what personal data the TraceOps app processes when it is installed on a Shopify store, how and why we process it, how long we keep it, and how it is deleted.
TraceOps is operated by DiLight Entertainment UG (haftungsbeschränkt) ("TraceOps", "we", "us"). For questions about this policy or about the data we process, contact us at privacy@dilight.website.
When TraceOps is installed on a merchant's Shopify store, the merchant is the data controller for their customers' personal data, and TraceOps acts as a data processor on the merchant's behalf, processing store data only to provide the app's traceability features. For our own account and billing records, we act as the controller.
TraceOps adds lot, batch and serial-level traceability to a Shopify store. It reads store data from Shopify on demand (per request, using the merchant's session) rather than keeping a background copy, and it persistently stores only the trace records it creates plus a small cache needed to render public pages. The data involved:
.myshopify.com domain, the OAuth access token
issued at install (stored encrypted and never shown to us in plain text in the UI), your locations, plan and
billing status, and your trace configuration (which products are traced, how sold units are assigned, and
per-product exposure settings for public pages).write_products).We do not process payment card details. Access to store data is limited to the Shopify scopes granted at
install (read_customers, read_fulfillments, read_inventory,
read_locations, read_orders, read_products, write_products).
Where the GDPR applies, we process data on the basis of performance of a contract (Art. 6(1)(b)) with the merchant and our legitimate interest (Art. 6(1)(f)) in providing, securing and protecting the integrity of the service (including anti-counterfeit scan detection). For customer personal data, the merchant's own privacy policy and legal basis govern the underlying processing; we act only on the merchant's documented instructions.
We do not sell personal data. We share data only with the providers needed to run the service:
Recall exports (CSV) are generated only when a merchant triggers them and are delivered to that merchant; they are the only customer-data egress from the app.
We keep store data only for as long as it is needed to provide the service to the merchant. Trace records
(lots, serials, assignments, trace events, scans and recalls) are retained while the app is installed so the
store's traceability history stays intact. When the app is uninstalled, or on a Shopify shop/redact
request, we purge the store's data as described below. Aggregated, non-identifying statistics may be kept longer.
TraceOps implements Shopify's mandatory compliance webhooks (verified by HMAC signature before any action):
customers/data_request — we record the subject-access request so the merchant (the controller)
can fulfil it; the data cannot be returned inline in the webhook response.customers/redact — we anonymize the identified customer's personal data across the store's
trace records.shop/redact — sent by Shopify roughly 48 hours after uninstall, we purge all of the store's
data (trace configuration, lots, serials, trace events, assignments, scans, recalls, inventory shadow, cached
product titles/images and billing records) and revoke the stored install.Store customers should direct data-subject requests to the merchant (the controller). Merchants can reach us at privacy@dilight.website for assistance.
The app uses Shopify's OAuth for install and stores access tokens encrypted. Inbound webhooks are verified with HMAC signatures, and public App Proxy pages are verified with a signed request check. Public trace pages are read-only, exposure-gated per product, rate-limited and served with a strict content-security policy. Scan telemetry is stored only as salted hashes, all reads and writes are scoped to the individual store, and all traffic is served over TLS.
The embedded admin relies on Shopify App Bridge session tokens rather than tracking cookies. These marketing pages may set a small preference cookie to remember your chosen language. We do not use advertising cookies.
We may update this policy as the app evolves. Material changes will be reflected on this page with a new "Last updated" date.
DiLight Entertainment UG (haftungsbeschränkt) · privacy@dilight.website · dilight.website