Privacy Policy
As of: 19/07/2026
1. Overview
Protecting your data matters to us. Konforma is built deliberately data-lean: the Shopify app processes no customer data from your shop and requests no scopes for it. This policy explains the processing of personal data when you visit this website (konforma.app).
2. Controller
The controller within the meaning of the GDPR is:
Konforma
Email: [email protected]
Please direct any data-protection enquiry, including the data-subject rights listed under point 8, to that address. We respond within the statutory period of one month (Art. 12 (3) GDPR).
3. Hosting
This website is hosted by Cloudflare (Cloudflare, Inc.). When the pages are accessed, the host processes technically necessary access data. Processing is based on our legitimate interest in secure and efficient provision (Art. 6 (1) (f) GDPR). Where data is transferred to third countries, this is based on the EU standard contractual clauses.
4. Server log files
On each access, information transmitted by your browser is automatically recorded (including IP address, date and time, page requested, referrer, browser type). This data serves technical provision and security and is not merged with other data sources. The legal basis is Art. 6 (1) (f) GDPR.
5. Cookies & analytics
This website sets no cookies, uses no advertising tracking, and currently runs no analytics. Nothing is stored on or read from your device beyond what is strictly necessary to operate the site (§ 25 (2) TDDDG, transposing Art. 5(3) ePrivacy). Fonts are self-hosted and no third-party services are embedded.
If we introduce reach measurement in future, it will be named here along with its legal basis.
6. Contact
If you contact us by email, we process your details to handle the enquiry (Art. 6 (1) (b) or (f) GDPR). The data is deleted once it is no longer required.
7. The Konforma app
The Shopify app Konforma requires no customer-data scopes and processes no personal data of your customers. It renders mandatory disclosures (legal-guarantee notice, GARAN label) and scans your storefront copy (products, collections, pages and blogs) for green claims, without access to order or customer data.
On your explicit action, the app writes changes back to your own shop: the text you approve into the relevant storefront copy (products, collections, pages or blogs), and the GARAN and compliance-seal data as app-owned metafields. Only store and product data is ever written, never customer data.
To operate, the app stores per-shop configuration, the findings of its green-claims scans, any substantiation you attach to a claim (a note, a link and an expiry date) and dated snapshots of your own published copy. This is store and product data, not personal data of your customers. It is hosted on Fly.io (application and database) in the EU (Frankfurt).
On the Pro plan, the app sends notification emails (new-risk-phrase and evidence-expiry alerts) to your store’s contact or account-owner address. These are delivered via Resend (an EU sub-processor, Ireland). The legal basis is performance of the app contract (Art. 6 (1) (b) GDPR).
8. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). You also have the right to lodge a complaint with a data-protection supervisory authority.
9. Changes
We update this privacy policy as the legal situation or our processing changes. The current version published here applies (see date above).