Effective date: [fill at launch]
Safora is a Shopify application operated by [SRL legal name once formed] ("we", "us"). We are based in Romania and act as a data controller for the limited data described below, and as a data processor for product data we read on your instructions through the Shopify Admin API.
For questions, e-mail safora@tandor.eu.
your-store.myshopify.com)We never receive the store owner's password, payment method, or banking information.
Through the Shopify Admin API, Safora reads:
gpsr namespaceSafora does not read or request customer data, order information, or payment information. The Shopify scopes Safora requests reflect this: write_products only.
When you use the AI auto-fill feature, the following is sent to Anthropic, PBC:
Personal data is never sent to the AI. See Anthropic's policies at anthropic.com/legal/privacy.
When you save GPSR fields, Safora writes them as product metafields in your store, under the gpsr namespace. This data is yours and lives in your Shopify store — we do not maintain a separate copy.
We do not process special-category personal data and do not engage in automated decision-making with legal effect on data subjects.
| Sub-processor | Purpose | Location |
|---|---|---|
| Shopify | Hosting our API session, billing | Canada / Ireland |
| Anthropic | AI auto-fill | United States |
| Fly.io | App backend hosting | Frankfurt, EU |
Anthropic is based in the United States. Product title + description data sent to Anthropic is transferred under the EU Standard Contractual Clauses incorporated into our sub-processor agreement.
| Data | Retention |
|---|---|
| Shop session record | Until uninstall, then deleted within 48h |
| GPSR metafields | Stored in your Shopify store; we keep no separate copy |
| AI request logs | Up to 30 days for debugging, then purged |
| Billing records | As required by Shopify and Romanian tax law (typically 10 years) |
You can:
To exercise these rights, e-mail safora@tandor.eu. We respond within 30 days.
For security incidents, contact safora@tandor.eu.
Safora is a B2B tool. We do not knowingly collect data from anyone under 16.
customers/data_request — responds immediately with no content (Safora stores no customer data)customers/redact — responds immediately with no contentshop/redact — deletes the session record and all shop-tied dataWe may update this Privacy Policy. Material changes will be announced with 30 days' notice.
[Legal entity once SRL formed]
E-mail: safora@tandor.eu
Romanian DPA: dataprotection.ro