Privacy policy — Kaderlab EU Compliance Kit

Version 1.0 · Effective 16 September 2026 · Questions: support@kaderlab.com

1. Who we are

Kaderlab EU Compliance Kit is built and operated by AVS Digital, a Dutch one-person business (eenmanszaak) trading as Kaderlab, KvK 67123783, Amsterdam, the Netherlands.

Write to support@kaderlab.com about anything in this document, including a request to see, correct or erase what the app holds about your shop.

Kaderlab is one person plus automation, and says so. This app is built and operated day to day with the help of AI automation. No part of the app talks to a shopper, and nothing in it generates text that a shopper reads: the words in every storefront notice are the merchant's own.

2. Which app this is about

This document covers the Shopify app Kaderlab EU Compliance Kit and the Cloudflare Worker behind it. It does not cover a merchant's own shop, their theme, or anything else Kaderlab publishes.

3. What the app stores

The app stores shop-level data only. It identifies no shopper, and there is no column anywhere in its database for a customer id, an e-mail address, an order id or a hash of either.

A shop domain such as demo.myshopify.com is a business identifier. Where a merchant is a sole trader (eenmanszaak), data about their shop can relate to them as a natural person, so the app treats everything below as if it were personal data: one lawful basis per purpose, one retention term per record, and an erasure that actually erases.

3.1 The install record — table shops

FieldWhat it isWhy it is stored
shop_domainThe shop's .myshopify.com domainIdentifies the shop whose data this is
installed_atWhen the app was first installedSupport, and the start of the relationship
updated_atWhen the record was last writtenSupport; a re-install issues a new token
currencyThe shop's currency codeA price history is meaningless without it
scopesThe access scopes Shopify grantedSo the app knows what it may ask Shopify for
access_token_sealedThe Shopify access token, encryptedCalling Shopify on the shop's behalf

The token is sealed with AES-256-GCM under a key derived from the app's own API secret, which lives in the Worker's secret store and not in the database. A copy of the database is therefore not a set of live credentials for anybody's shop.

The app asks Shopify for currencyCode and nothing else. Shopify's shop resource also carries email, shopOwnerName, phone and an address. None of them is requested, so none of them can be stored by accident.

The app holds one access scope: read_products. It reads product prices, which is what an Omnibus prior price is computed from. It asks for no scope that reaches customers or orders, so there is no version of this app that could read them.

3.2 The notice history — table notice_changes

FieldWhat it is
change_idAn id derived from the event that caused the change
recorded_atWhen the change was recorded
shop_domainThe shop
noticeWhich notice this is about
activeWhether it was switched on or off
sourceWhat caused the change

This is the evidence log: which EU information notices a shop had active on its storefront, and when that changed. It is append-only and shop-level, and no shopper appears in it.

3.3 The price history — table price_points

FieldWhat it is
price_point_idAn id derived from the event that carried the price
observed_atWhen the price was observed
shop_domainThe shop
variant_idA product variant — a product, never a person
currencyThe currency the price is in
amount_centsThe price in integer minor units
sourceWhich event carried it

This is product data. It exists because the Omnibus prior-price rule (Directive (EU) 2019/2161 art. 6a) asks what the lowest price was in the 30 days before a reduction, and that is answerable only from a record of what the price was.

3.4 The delivery log — table webhook_deliveries

FieldWhat it is
webhook_idShopify's delivery id
received_atWhen it arrived
topicWhich webhook topic it was
shop_domainThe shop
outcomeWhat the app did with it: handled or ignored
order_countHow many orders a data request concerned — a number, never an order
noteWhat the app did, in one line

Every webhook Shopify sends is recorded here, including the three mandatory privacy topics. This is the record that an erasure request arrived and was carried out.

The app subscribes to five topics and no others: customers/data_request, customers/redact and shop/redact, which Shopify requires of every app; products/update, which carries the price changes the Omnibus history is made of; and app/uninstalled, which is how the app knows to delete a shop's credential the moment it stops being valid.

4. What reaches the app and is not stored

5. Why the app stores it, and under which lawful basis

PurposeDataLawful basis (GDPR art. 6)
Running the app for the merchant who installed itThe install recordPerformance of a contract, art. 6(1)(b)
Keeping the evidence log the merchant asked forThe notice historyPerformance of a contract, art. 6(1)(b)
Computing an Omnibus prior priceThe price historyPerformance of a contract, art. 6(1)(b)
Showing that a privacy webhook arrived and was carried outThe delivery logLegal obligation, art. 6(1)(c), and Shopify's own platform requirement

The app does no profiling, no automated decision-making with legal effect, no advertising and no analytics of any kind. It sets no cookie: the app's own page and the storefront badge store nothing in a visitor's browser.

6. Who else sees it

WhoWhat forWhere
CloudflareHosting: the Worker that runs the app and the D1 database that stores the tables in §3EU jurisdiction

That is the whole list. The app makes no other outbound call: no e-mail provider, no analytics service, no AI API and no payment processor is involved in running it. Payments for a paid plan are handled by Shopify through its Billing API, so no payment data reaches Kaderlab at all.

Shopify is the platform the merchant already has their own agreement with; this app receives data from Shopify because the merchant installed it.

The processor register Kaderlab keeps under GDPR art. 30 lives in the holding repository at docs/legal/processor-register.md, and a processor is added to it in the same change that starts using them.

7. How long it is kept

8. Your rights

A merchant — or a person whose data is in the app because their shop is a sole trader — may ask for access, correction, erasure, restriction or a copy of their data, and may object to processing. Write to support@kaderlab.com. An answer follows within 30 days.

A complaint can be made to the Dutch data protection authority, the Autoriteit Persoonsgegevens.

9. Security

10. What this app does not do

It gives a merchant structure and a record. It does not tell them, and cannot tell them, whether their shop meets an EU information duty: that is for a qualified professional to judge. Nothing in the app issues a verdict on a duty, and nothing in this document should be read as one.

11. Changes to this policy

A change is published on the same page with a new version number. A change that alters what is stored, why, or who sees it arrives in the same change as the code that causes it.