Privacy Policy

GreenClaims ("we", "our", "us") builds a compliance tool for Shopify merchants that scans a store's product and content copy for environmental marketing claims that may present risk under the EU Empowering Consumers for the Green Transition Directive (EmpCo, Directive (EU) 2024/825). This policy explains what data we access, how we use it, who we share it with, and the choices merchants have. We follow Shopify's Partner Program requirements and the principle of least privilege.

1. Data we access

With the merchant's consent during install, GreenClaims requests only these Shopify Admin API scopes:

  • read_products - to read product titles, descriptions, and related fields so we can scan them for environmental claims.
  • read_content - to read store content (pages, blog articles) for the same claim scanning.
  • read_locales - to read which languages your storefront publishes, so we know which translations to scan.
  • read_translations - to read the translated versions of your product and content text (e.g. from Translate & Adapt) for the same claim scanning, on plans that include multilingual scanning.

GreenClaims is read-only: it holds no write scopes and never modifies your products, content, or any other part of your store. We do not request or access customer data, orders, or financial records.

These scopes can technically expose some store-owner and author metadata that Shopify attaches to the content they cover — for example, the author name on a blog article. GreenClaims reads only the marketing text it scans and deliberately ignores those author and personal metadata fields. The only data we store are the flagged claims, the scan and audit records they produce, and any evidence you choose to attach — never author or personal metadata.

2. How we use the data

  • To scan your product and content text and flag environmental claims that may be restricted under EmpCo.
  • To draft lower-risk alternatives and let you build an evidence-backed registry of your claims.
  • To maintain an audit trail and, on paid plans, tamper-evident audit snapshots and monitoring of changes over time.
  • To send the alert and digest emails you opt into (see Subprocessors).

3. Data we do not collect

  • Customer personal data
  • Order history or financial data
  • Payment information

We run no third-party web analytics, no session recording, and no advertising trackers against your store or its data.

4. Storage, region, and retention

Session credentials, scan results, claims, and audit records are stored in a database on Amazon Web Services in the United States (US East region). All data is encrypted in transit over TLS, and access to production data is limited to the smallest number of personnel necessary.

We retain your scan results, claims, evidence, and audit snapshots for as long as GreenClaims is installed, so your history is available to you. On uninstall we stop all processing and delete your store's data when Shopify sends the shop/redact signal, which typically arrives about 48 hours later; you can request earlier deletion at any time. The short-lived cache we use to avoid re-analyzing unchanged text expires within 30 days.

5. Subprocessors

We rely on the following vetted subprocessors to operate the service:

  • Anthropic (Claude API) - when a claim needs to be judged in context or rewritten, the relevant product/content text is sent to Anthropic's API for analysis. Only that text is sent - never customer, order, or payment data. Anthropic does not use API inputs or outputs to train its models by default; under its standard API terms, inputs and outputs may be retained for up to 30 days unless a zero-data-retention arrangement applies (Anthropic Privacy Policy).
  • Amazon Web Services (SES) - sends the alert and weekly digest emails you enable, to the notification address you provide in settings.
  • Amazon Web Services (hosting) - application hosting, database, and background job processing.
  • Shopify - the platform your store and our embedded app run on.

6. Email notifications

If you enable alerts, we store the notification email address you enter in settings and use it solely to send compliance alerts and digests via Amazon SES. Every email includes an unsubscribe link, and you can change or remove the address at any time in the app's settings.

7. GDPR webhooks

GreenClaims processes Shopify's mandatory compliance webhooks: customers/data_request, customers/redact, and shop/redact. Because we do not store customer data, customers/data_request and customers/redact are acknowledged with no records to return or redact. On shop/redact (sent by Shopify after uninstall), we delete all data associated with that shop.

8. Uninstall and data deletion

You can uninstall GreenClaims at any time from your Shopify admin. On uninstall we stop all processing for your store and delete its data on Shopify's shop/redact signal. To request deletion sooner, email support@bulksheet.app.

9. Contact

Questions about this policy or your data: support@bulksheet.app.