Skip to content

Privacy Policy

for the Shopify app “Recall Monitor” · Last updated: October 2026 · Deutsche Fassung

1. Controller

SyncVentura, owner Igor Savostjanow, Bettina-von-Arnim-Str. 68, 28857 Syke, Germany
Email: info@syncventura.de

2. What this is about

The app checks a Shopify store’s products against official recall alerts. It is installed through Shopify, runs in the merchant’s Shopify admin and only works with products, not with customers, orders or payments.

3. Data processed

Store access. On installation, Shopify transmits the store address (myshopify domain) and an access token that lets the app access the merchant’s products on their behalf. Where Shopify provides it at sign-in, the app also stores the ID, first and last name, email address and locale of the signed-in staff member.

Product data. The app reads products through Shopify’s API. Only for stores with more than 1,000 products does it keep a copy of the product data (ID, title, handle, vendor, product type, tags, status, image URL, SKU, barcode and the app’s fields) in its database, so that its pages load quickly.

Recall matches. When an official alert matches a product, the app stores the match: product ID and title, the alert, what matched (barcode, model number or brand) and your assessment. The app fetches the alerts from the authorities’ public pages (EU Safety Gate, CPSC, GOV.UK, Health Canada, lebensmittelwarnung.de, FDA, FSA, CFIA, FSANZ, NHTSA); no data from your store is sent there.

Check log and watchlist. For every check the app stores the time, type (daily, manual, instant), the number of products checked, alerts and matches, and the sources with their status – this is the basis of the check record. Terms you add to the watchlist and the alerts found for them are stored as well.

Email on new matches. The app stores the recipient addresses you enter in the settings. If you enter none, it reads the store’s email address from Shopify when sending, without storing it. The email contains product titles and the matching official alerts.

Actions in your store. Recall pages (on request) and the “Draft” status and tag (if you turn them on) are created in your store at Shopify. With Pro, new matches are sent to Shopify Flow in your store. This content is stored at Shopify.

Subscription. Whether a store has already used the free trial is stored as a non-reversible key (HMAC) of the store address with the date.

Server logs. When pages are requested, the server processes the IP address, time, requested URL and user agent.

Light or dark mode. Only if you switch between light and dark mode on the public pages does a cookie (“thema”, value “hell” or “dunkel”, one year) store your choice. It is strictly necessary for that (Section 25 (2) no. 2 TDDDG) and contains no personal data. There are no analytics or advertising cookies.

4. Purposes and legal bases

Providing the app to the merchant, including the email on new matches and the check log: Art. 6(1)(b) GDPR (contract). Trial note and server logs: Art. 6(1)(f) GDPR (preventing abuse, secure operation). Emails to us: Art. 6(1)(b) or (f) GDPR.

5. Recipients

The app and its data stay in the EU. Only emails to us may also be processed by Google in the USA; Google LLC is certified under the EU-U.S. Data Privacy Framework (EU Commission adequacy decision, Art. 45 GDPR).

6. Retention

7. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object (Art. 21). An email to info@syncventura.de is sufficient. You may also lodge a complaint with a supervisory authority (Art. 77 GDPR); the competent authority is the Data Protection Commissioner of Lower Saxony, Prinzenstraße 5, 30159 Hannover, Germany.