Last updated: 2026-08-19
To deliver Vellona's GPSR (Regulation EU 2023/988) compliance tooling, we process:
Application data is stored in JSON files on our server. Access tokens are encrypted at rest and secrets are never written to logs.
You may request export, correction or deletion of your data. Vellona responds to the Shopify mandatory webhooks customers/data_request, customers/redact and shop/redact, and deletes the shop's data when received. Uninstalling the app also triggers deletion of your shop's data.
We rely on Shopify for OAuth authentication, billing, App Bridge embedding, product images and the Admin API. Data is shared with Shopify only as required to operate these functions.
Questions about this policy: support@joycraft.dev.