PriceCalc Pro – Shopify App
Provider: Janine Fabienne Eicker, Unnersberger Allee 10, 42659 Solingen, Germany
Contact: support@jrmedia.software
1. Controller
The controller responsible for processing personal data in connection with the PriceCalc Pro app within the meaning of the General Data Protection Regulation (GDPR) is:
Janine Fabienne Eicker
Unnersberger Allee 10
42659 Solingen
Deutschland
E-Mail: support@jrmedia.software
A data protection officer has not been appointed, as the requirements under Art. 37 GDPR in conjunction with § 38 BDSG (German Federal Data Protection Act) are not met.
2. Overview of Data Processed
PriceCalc Pro is a B2B app embedded in the Shopify Admin, used exclusively by Shopify merchants (businesses or sole traders). The app processes the following categories of data:
2.1 Product and Price Data (via Shopify API)
The app retrieves the following data via the Shopify Admin GraphQL API:
- Shop ID and shop currency
- Product and variant data (product title, variant, SKU, purchase price/unit cost, selling price)
- Collections, vendors, and tags
- Custom metafields (namespace
custom): calculation factor, procurement costs, handling costs, profit margin, buffer, VAT key, reference price
The app writes modified prices and metafields back to the merchant's Shopify store. This product and price data is not permanently stored on the Provider's servers; it is processed at runtime only and held in the user's browser.
This data generally does not constitute personal data under the GDPR, as it relates to the merchant's business data (products, prices).
2.2 Shop Master Data (Server-Side Storage)
In order to associate subscription, usage quota and support requests with the correct shop, the Provider stores the following shop master data transmitted by Shopify in the app database (operated by Gadget, see section 4.2):
- Shop ID, myshopify domain and shop domain
- Shop name and name of the shop owner
- Shop email address
- Shop country
- Shopify plan of the shop and shop creation date
This data is captured on installation and kept up to date via the Shopify shop/update webhook. Because it may contain the name and email address of a natural person — particularly in the case of sole traders — the Provider treats it as personal data. The shop's postal address, phone number and geolocation are expressly not stored.
2.3 Billing and Subscription Data
Billing for paid plans is processed exclusively via the Shopify Billing API. Payment data is processed by Shopify; the Provider has no access to credit card or bank account details. The Provider stores only plan status, subscription identifier, term end date and usage counters.
2.4 Usage and Administration Data (Abuse Prevention)
To enforce plan quotas and prevent misuse, the Provider stores the following metrics per shop:
- Number of calculation and API calls in the current billing period
- Number of webhooks received and number of quota overruns
- Timestamp of the last activity in the app
- Administrative status of the shop (active, flagged or blocked) including the reason for and time of any flag
These metrics are visible only to the Provider in an internal administration area that is technically restricted to designated administrator shops. On this basis, the Provider may block a shop or remove the app in cases of significant misuse. Automatic flagging of conspicuous shops serves only as an internal review signal; the decision to block is always taken manually (see section 10). Counters are reset monthly. If the number of requests exceeds a multiple of the usual value, the app temporarily suspends write operations for the shop concerned in order to protect availability for all users (see section 10).
2.5 App Settings and Access to Terminal Equipment Storage
User settings (autosave, price rounding, language, backup preferences) and work sessions are stored in the browser's localStorage. This data remains local to the user's browser and is not transmitted to the Provider's servers.
When a supplier price list is imported, the unfinished assignment for that list is stored there as well: the file name, the supplier's article numbers and the decisions made about them. This serves only to let interrupted work be resumed, never leaves the user's browser, and is removed automatically after 30 days; the “Discard” button deletes it immediately at any time.
In addition, Shopify and the Gadget platform set strictly necessary session cookies to authenticate the embedded app session. Access to terminal equipment storage (localStorage and session cookies) is strictly necessary to provide the service explicitly requested by the user and therefore does not require consent under § 25(2) no. 2 TDDDG. No analytics, tracking or advertising cookies are used.
2.6 Backup Files (Local Downloads)
Exported backup files (JSON) are downloaded directly to the user's device and are not stored on the Provider's servers.
2.7 No Processing of End-Customer Data
PriceCalc Pro does not process any personal data of the Shopify merchant's end customers. The app requests permissions from Shopify for products, inventory, locations and locales only; access to orders, customer names, addresses or other customer data is technically impossible.
2.8 Feedback Responses
If the user answers a feedback question inside the app — for example about the reason for a cancellation or about satisfaction with the app — the Provider stores the answer in the app database: the rating, the selected reason, an optional free-text comment, the subscribed plan, along with the shop identifier, myshopify domain and timestamp. Answering is voluntary; the app can be used and uninstalled without answering, and no benefit is granted in return for an answer. Upon receipt of the shop/redact webhook, the shop reference and the free text are deleted; rating, reason and timestamp remain as an anonymous figure without any link to a shop. Feedback requests are never sent by email.
3. Purpose and Legal Basis of Processing
| Purpose | Legal Basis |
|---|---|
| Providing app features (reading and writing product and price data) | Art. 6(1)(b) GDPR – Performance of a contract |
| Subscription management and usage tracking | Art. 6(1)(b) GDPR – Performance of a contract |
| Temporary suspension of write operations at a multiple of the usual number of requests (sections 2.4 and 10) | Art. 6(1)(f) GDPR – legitimate interests of the Provider in the availability of the service for all users |
| Security and error correction | Art. 6(1)(f) GDPR – Legitimate interests of the Provider |
| Abuse prevention, enforcement of usage quotas and blocking of conspicuous shops (section 2.4) | Art. 6(1)(f) GDPR – Legitimate interests of the Provider |
| Evaluation of voluntary feedback responses to improve the app (section 2.8) | Art. 6(1)(f) GDPR – Legitimate interests of the Provider |
| Compliance with Shopify GDPR requirements (GDPR webhooks) | Art. 6(1)(c) GDPR – Legal obligation |
The Provider's legitimate interest (Art. 6(1)(f)) consists in ensuring stable and secure operation of the app, preventing misuse and improving the app based on voluntary feedback.
4. Processors and Third-Party Providers
4.1 Shopify Inc.
The app is embedded in the Shopify Admin and accesses shop data via the Shopify Admin API. Shopify acts as an independent controller for the processing of merchant data under its own privacy terms: shopify.com/legal/privacy
4.2 Gadget Software Inc. (Hosting and Platform)
The app is hosted and operated on the Gadget platform (Gadget Software Inc., Vancouver, Canada). Gadget processes app data retrieved via the Shopify API as a data processor.
Gadget stores data in Canada (EU adequacy decision in place) and in the USA via sub-processors (including Google Cloud and Cloudflare). For transfers to the USA, Gadget relies on Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR.
A Data Processing Addendum (DPA) between the Provider and Gadget was concluded on 1 August 2026 in accordance with Gadget Software Inc.'s requirements. It incorporates the EU Standard Contractual Clauses (Modules 2 and 3); the competent supervisory authority for the purposes of those clauses is the Data Protection Commission of Ireland. Further information: gadget.dev/privacy and gadget.dev/data-processing-addendum
Gadget in turn engages the sub-processors listed below. The table reflects the list published by Gadget as at the last update of this Privacy Policy; the current list is published by Gadget at gadget.dev/privacy. Status of this table: 26 August 2026.
| Service Provider | Function | Location |
|---|---|---|
| Google Cloud | Infrastructure and data hosting (all data collected by Gadget) | USA |
| Cloudflare (incl. Cloudflare Analytics) | CDN / Security / Web activity logs | USA |
| Crunchy Data | Database operations and logs | USA |
| Axiom | Product and operational logs | USA |
| Humio | Operational logs / Web activity logs | USA |
| HubSpot | Email marketing (email address and name of the Provider account) | USA |
| LaunchDarkly | Feature flags (email address of the Provider account) | USA |
| Fivetran | Business intelligence and warehousing (all data collected by Gadget) | USA |
HubSpot and LaunchDarkly process only the contact details of the Provider's Gadget account (email address and name). No merchant data, shop data or end-customer data is transmitted to these two services; the statement in section 4.4 regarding marketing services within the app remains unaffected.
4.3 Shopify CDN
The app loads the App Bridge and Polaris libraries provided by Shopify directly from Shopify's servers (cdn.shopify.com). This transmits the user's IP address to Shopify. As the app runs exclusively within the Shopify Admin, this connection to Shopify exists in any event.
4.4 No Other Services
Beyond the services listed above, no further processors are engaged. In particular, the app integrates no analytics, tracking, advertising or email marketing services, and no data is transmitted to such services.
5. Transfers to Third Countries
App data may be transferred to the USA and Canada as part of hosting by Gadget Software Inc. Canada benefits from an EU adequacy decision issued by the European Commission. For transfers to the USA, Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR are used as appropriate safeguards.
6. Shopify GDPR Webhooks
As a Shopify Partner, the Provider is required to receive and process the following GDPR webhooks from Shopify:
- customers/data_request: Requests to report stored customer data. As the app does not process end-customer data, these requests are responded to accordingly.
- customers/redact: Requests to delete end-customer data. As no such data is stored, no deletion is necessary.
- shop/redact: Request to delete shop data, received 48 hours after the app is uninstalled. Upon receipt, the Provider automatically deletes all shop master data stored (shop name, owner name, email address, domain, country), all billing and usage data, and all administration and abuse metrics under section 2.4. Only a technical record without any personal content remains (shop ID and myshopify domain) so that a later reinstallation can be correctly identified.
7. Retention and Deletion
| Data Category | Retention Period |
|---|---|
| Product and price data (metafields in Shopify) | Remain in the merchant's Shopify store; no permanent server-side storage by the Provider |
| Shop master data (section 2.2) | For the duration of the installation; deleted automatically upon receipt of the shop/redact webhook (48 hours after uninstallation) |
| Billing and subscription data (section 2.3) | For the duration of the installation; deleted automatically upon the shop/redact webhook. Invoices and payment records are created exclusively by Shopify and retained there for the applicable statutory periods; the Provider keeps no accounting records within the app |
| Usage and administration data (section 2.4) | Counters are reset monthly; fully deleted upon the shop/redact webhook |
| Browser settings (localStorage) | Stored locally in the user's browser; deleted when the user clears browser storage or uninstalls the app. Unfinished price-list assignments additionally expire automatically after 30 days |
| Feedback responses (section 2.8) | Shop reference and free text are deleted upon the shop/redact webhook; rating, reason and timestamp remain as an anonymous figure without any shop reference |
| Log data | Pursuant to Gadget Software Inc.'s retention policies (typically 30–90 days) |
8. Data Security
The Provider implements appropriate technical and organisational measures pursuant to Art. 32 GDPR:
- All transmission between browser, app and Shopify is encrypted via HTTPS/TLS.
- Access to shop data is authenticated through the Shopify session and restricted to the user's own shop by tenant-scoped access rules; access to other shops' data is excluded.
- The internal administration area (section 2.4) is technically restricted to designated administrator shops.
- The app requests only the permissions required for operation (read and write products and inventory, read locations and locales).
- The infrastructure is operated by Gadget Software Inc. in accordance with its security standards.
9. Data Subject Rights
As a data subject, you have the following rights:
- Right of access (Art. 15 GDPR): You may request information about the personal data stored about you.
- Right to rectification (Art. 16 GDPR): You may request correction of inaccurate data.
- Right to erasure (Art. 17 GDPR): You may request deletion of your data, to the extent no statutory retention obligations apply.
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR): You may object to processing based on Art. 6(1)(f) GDPR.
- Right to lodge a complaint (Art. 77 GDPR): You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement.
To exercise your rights, please contact: support@jrmedia.software
10. Automated Decision-Making
No automated decision-making or profiling within the meaning of Art. 22 GDPR takes place. The automatic flagging of conspicuous shops described in section 2.4 serves solely as an internal review signal and has no legal effect in itself; the Provider always decides on blocking or removal of the app after a manual review of the individual case. Data subjects may object to such a measure using the contact details given in section 9.
This must be distinguished from a technical protective measure: if a shop reaches a multiple of the usual number of requests, the app temporarily suspends write operations for that shop. Read access remains available. Only a counter is compared against a fixed threshold; no assessment of personal aspects and no profiling takes place. The measure ends automatically with the next billing period and is lifted without delay on request.
11. Relationship between Merchant and Provider
The Provider processes the data described above as an independent controller for the purpose of performing the usage agreement with the merchant. As PriceCalc Pro does not process any personal data of the merchant's end customers (see section 2.7), a data processing agreement (DPA) under Art. 28 GDPR between merchant and Provider is not required. The Provider will nevertheless make such an agreement available to merchants on request. The template is available at pricecalcpro.de/en/dpa.html; merchants can obtain a signed copy via support@jrmedia.software
12. No Affiliation with Shopify
PriceCalc Pro is an independent third-party app and is not officially affiliated with, endorsed by, or connected to Shopify Inc. in any way. Shopify® is a registered trademark of Shopify Inc.
13. Changes to This Privacy Policy
The Provider reserves the right to update this Privacy Policy when required by changes in law, app features, or data processing practices. The current version is accessible within the app. Users will be notified of material changes where reasonably possible.