euroB2B — App Privacy Policy
Effective date: 25 August 2026
This Privacy Policy explains how CodeThat M.Siekmann & D.Siekmann
GbR ("CodeThat", "we", "us", or "our") collects, uses, discloses, and
protects personal data in connection with the euroB2B
application (the "App"), a Shopify app that adds a B2B wholesale ordering area
to a merchant's Shopify store. The App is served from
app.eurob2b.app and, on the merchant's storefront, under the
path /apps/eurob2b (Shopify app proxy). We process personal data in
accordance with the EU General Data Protection Regulation (GDPR), the UK GDPR,
the California Consumer Privacy Act as amended (CCPA/CPRA), and Shopify's
requirements for apps that handle protected customer data.
1. Scope of this Policy
This Policy applies only to the euroB2B Shopify app and the data we access and process when a merchant installs and uses the App on their Shopify store. It does not cover our marketing websites (eurob2b.de / euro-b2b.com), which have their own privacy notice, nor any third-party services (including Shopify itself) that operate under their own privacy policies.
The App provides B2B (wholesale) features on top of Shopify: a business registration form for the merchant's storefront with optional approval workflow, VAT-ID (USt-IdNr / VIES) validation, company and company-location management, customer-group net pricing and price lists, a quick-order matrix, EU VAT and reverse-charge handling, draft-order and order processing, and optional order document uploads.
2. Who We Are — Data Controller
The party responsible for the App is:
CodeThat M.Siekmann & D.Siekmann GbR
Rathenaustraße 39
44869 Bochum
Germany
VAT-ID (USt-IdNr): DE360588533
Phone: +49 2327 36 99 126
Email: hi@code-that.com
For any privacy-related question or request, contact us by email at hi@code-that.com with "Privacy" in the subject line, or by post or phone using the details above. We respond within the timeframes required by applicable law.
3. Our Role: Controller and Processor
(a) Merchant account data — we act as controller. For data relating to the merchant, their store, and their staff that we use to provide, secure, support, and bill for the App, we determine the purposes and means of processing and are therefore the data controller.
(b) The merchant's customer data — we act as processor. When the App processes personal data about a merchant's own (business) customers — for example company records, contact names, email addresses, VAT IDs, addresses, and orders — in order to deliver the B2B features to that merchant, we do so on behalf of and under the instructions of the merchant. In that context the merchant is the controller and we are the processor. Merchants are responsible for having a lawful basis and for providing appropriate privacy notices to their own customers. A Data Processing Agreement (Art. 28 GDPR) is available from us on request.
4. What Data the App Accesses and Processes
The App accesses only the data necessary to provide its functionality (data minimisation). Depending on the features a merchant enables, this includes:
(a) Merchant / store data
Store name, myshopify domain and primary domain, store country, Shopify plan, billing/plan status of the App subscription, App settings and configuration, installation and uninstallation timestamps, and the name, email address and locale of staff members who install, configure, or operate the App (as provided by Shopify during authentication).
(b) The merchant's customer data (processed on the merchant's behalf)
Registration data submitted through the B2B registration form on the merchant's storefront: company name, first and last name, email address, billing address (street, postcode, city, country), VAT identification number and the result of its validation, and any additional custom fields the merchant has configured for the form. Company and contact records in Shopify: company name, company locations, contact names, email addresses, roles, and the assignment of companies to price lists / catalogs and B2B markets. Order data: draft orders and orders placed through the B2B area, including line items, quantities, prices, tax and reverse-charge treatment, payment terms, and shipping/billing addresses. Order documents (only if the merchant enables this feature): files uploaded in connection with an order, such as purchase orders.
(c) Data accessed via the Shopify APIs
The App reads from and writes to the merchant's store through the Shopify Admin API, the Customer Account API, and Shopify webhooks. The access scopes the merchant approves at installation cover: customers (read/write, incl. protected customer data such as name, email address, phone number and address), companies and company locations (read/write), orders and draft orders (read/write), products, publications, files and content (read/write), markets, discounts, delivery, payment and validation customizations (read/write), payment terms (read/write), and the app proxy. We use these scopes solely to provide and support the App's B2B features described in this Policy, and for no other purpose.
(d) Technical and usage data
To operate and secure the App, our systems process log data, timestamps, request metadata, webhook delivery records, and error diagnostics. The storefront registration form is rate-limited; for this purpose the App processes the IP address of the requesting client for a short period. Inside the merchant-facing admin interface we may use PostHog product analytics (EU Cloud) to understand which features are used and to improve the App; this is scoped to merchant staff using the admin interface, does not run on the merchant's storefront, and is not used to build advertising profiles.
5. Purposes and Legal Bases (GDPR Art. 6)
Where we act as controller (merchant account data), we rely on the following legal bases under Article 6(1) GDPR:
Performance of a contract (Art. 6(1)(b)): to provide, configure, maintain, and support the App under our agreement with the merchant, and to handle billing through Shopify.
Legal obligation (Art. 6(1)(c)): to comply with legal and regulatory duties, including tax and accounting record-keeping and responding to data-subject and compliance requests.
Legitimate interests (Art. 6(1)(f)): to keep the App secure, prevent fraud and abuse, debug and improve the App, and communicate with merchants about the service. We balance these interests against the rights of the individuals concerned.
Consent (Art. 6(1)(a)): where we specifically ask for it; consent can be withdrawn at any time with future effect.
Where we act as processor for the merchant's customer data, the lawful basis is determined by the merchant (the controller) and we process the data only on the merchant's documented instructions.
6. How Data Is Collected and Stored
Data is collected (i) directly from the merchant when they install and configure the App, (ii) directly from the merchant's customers when they submit the B2B registration form or upload order documents on the merchant's storefront, (iii) through the Shopify APIs and Shopify webhooks for the resources the merchant has authorised, and (iv) automatically as technical and log data when the App is used.
The App and its PostgreSQL database are hosted on infrastructure operated by Railway (see section 8). Order documents, if enabled, are stored in S3-compatible object storage and are made available only through short-lived, signed URLs. Each merchant's data is logically separated by store, so that one merchant's data is never accessible to another merchant.
7. Data Retention and Deletion
We retain personal data only for as long as necessary for the purposes set out in this Policy or as required by law. Specifically:
While the App is installed: merchant and customer data is retained for as long as it is needed to provide the App's features to the merchant. Merchants can delete individual registrations, companies, and order documents from within the App at any time.
After uninstallation: all App data belonging to the store is automatically and permanently deleted from our database 30 days after the App is uninstalled. The grace period exists so that a merchant who reinstalls within that time does not lose their configuration. Access tokens are revoked immediately on uninstallation.
Legal retention: records we are legally required to keep (for example billing records under German commercial and tax law, § 257 HGB / § 147 AO) are retained for the statutory period and then deleted.
We also honour Shopify's mandatory compliance webhooks:
shop/redact: After a merchant uninstalls the App, Shopify
sends a shop/redact request (48 hours after uninstallation). On
receipt we schedule the store's data for deletion; it is erased in line with
the retention period above, subject only to data we are legally required to
retain.
customers/redact: When a merchant (or Shopify on a customer's
behalf) requests deletion of a specific customer's data, Shopify sends a
customers/redact request and we irreversibly anonymise the
corresponding registration, contact and notification records we hold within
30 days.
customers/data_request: When a customer asks a merchant for a
copy of the data held about them, Shopify sends a
customers/data_request and we compile the data we hold about that
customer and provide it to the merchant so the merchant can fulfil the request.
8. Sub-processors and Third Parties
To run the App we rely on a limited set of service providers who process data on our behalf under data-processing terms. They may only use the data to provide their service to us. Our sub-processors are:
Shopify (Shopify International Ltd., Ireland / Shopify Inc., Canada) — the platform on which the App runs, the source of the store and customer data the App accesses, and the billing provider for App subscriptions. Shopify processes data under its own terms and privacy policy.
Railway (Railway Corp., USA) — hosting of the App server and its PostgreSQL database.
S3-compatible object storage — storage of order documents, used only if the merchant enables order document uploads.
Brevo (Sendinblue SAS, France) — transactional email delivery, e.g. registration confirmations, approval/rejection notices, and responses to customer data requests, on behalf of the merchant.
Inngest (Inngest Inc., USA) — orchestration of background jobs (e.g. processing webhooks, approvals and synchronisation). Inngest receives event identifiers and the store domain; personal data itself remains in our database.
Mantle (Heymantle Inc., Canada) — management of App subscription plans and billing status. Receives the store domain and plan / billing information.
Vatstack — validation of VAT identification numbers against the EU VIES system. Receives the VAT ID submitted at registration.
Crisp (Crisp IM SAS, France) — in-app support chat inside the merchant admin interface. Receives the store domain, plan information and any messages the merchant sends us.
PostHog (PostHog Inc., USA; EU Cloud hosted in the EU) — product analytics inside the merchant admin interface, as described in section 4(d).
We do not sell personal data and do not share it with third parties for their own marketing purposes. We may disclose data where required by law or to protect our legal rights. We will update this list when we add or replace a sub-processor.
9. International Data Transfers
We are based in Germany and process personal data primarily within the EU/EEA. Some of our sub-processors (Railway, Inngest, PostHog) are established in the United States and Shopify and Mantle in Canada. Where personal data is transferred to a country outside the EU/EEA, we rely on an EU adequacy decision (Canada; the EU-US Data Privacy Framework where the recipient is certified) and/or the EU Standard Contractual Clauses incorporated into the sub-processor's data-processing agreement, together with supplementary technical measures such as encryption in transit and at rest.
10. Data Security
We take appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These include: TLS encryption of all data in transit; encryption at rest of the database and object storage; Shopify HMAC verification of every webhook; session-token authentication of every admin request; short-lived signed URLs for order documents; rate limiting of the public registration form; separation of staging and production environments; logical separation of merchant data per store; restricted, need-to-know staff access to protected customer data; audit logging of administrative actions inside the App; and an internal process for handling and, where required, notifying security incidents. No method of transmission or storage is completely secure and we cannot guarantee absolute security.
11. Your Rights (Data Subjects)
Subject to applicable law, individuals whose personal data we process as a controller have the right to:
Access — obtain confirmation of, and a copy of, the personal
data we hold about them.
Rectification — have inaccurate or incomplete data
corrected.
Erasure — request deletion of their data where a legal ground
applies.
Restriction — request that we restrict processing in certain
circumstances.
Portability — receive their data in a structured, commonly
used, machine-readable format.
Objection — object to processing based on our legitimate
interests.
Withdraw consent — where processing is based on consent,
withdraw it at any time with future effect.
Lodge a complaint — file a complaint with a supervisory
authority.
To exercise any of these rights, contact us at hi@code-that.com. Where we act as a processor for a merchant's customer data, please direct the request to the relevant merchant (the controller); we will assist the merchant in responding.
Our competent supervisory authority is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2-4, 40213 Düsseldorf, Germany.
California (CCPA/CPRA): We do not sell or "share" personal information as those terms are defined under California law. California consumers have the right to know, delete, and correct their personal information and not to be discriminated against for exercising these rights.
12. Shopify Protected Customer Data Compliance
The App is built to comply with Shopify's Protected Customer Data requirements
and the Shopify Partner Program Agreement. In particular, we: process only the
minimum customer data required to provide the App's functionality; use it only
for the purposes disclosed in this Policy and never for advertising or
profiling; apply the retention and deletion rules in section 7; encrypt data in
transit and at rest; restrict staff access; keep records of processing and
access; and implement the mandatory Shopify compliance webhooks
customers/data_request, customers/redact, and
shop/redact. Merchants remain responsible for informing their
customers about the use of the App in their own privacy notice.
13. Children
The App is a business tool intended for use by merchants and their business customers. It is not directed to children, and we do not knowingly process the personal data of children.
14. Changes to this Policy
We may update this Policy from time to time to reflect changes in the App, our practices, or legal requirements. When we make material changes we will update the effective date above and, where appropriate, notify merchants through the App or by email. The current version is always available at this URL.
15. Contact
For any question about this Policy or our handling of personal data, contact:
CodeThat M.Siekmann & D.Siekmann GbR
Rathenaustraße 39, 44869 Bochum, Germany
Email: hi@code-that.com
Phone: +49 2327 36 99 126