Legal information
ComplyDock Privacy Policy
This policy explains how personal data is collected, used, stored, disclosed, and deleted when merchants, suppliers, and website visitors use ComplyDock.
Controller and service operator
From 10 August 2026
Efstathios TsanidisSole proprietor (Einzelunternehmer), trading as TsanDev
Luhnenstraße 7
30559 Hannover
Germany
Email: tsan-dev@outlook.com
In this policy, “ComplyDock”, “TsanDev”, “we”, “us”, and “our” refer to Efstathios Tsanidis, trading as TsanDev.
1. What ComplyDock does
ComplyDock helps Shopify merchants collect, organise, review, approve, and publish product-compliance information received from suppliers. Merchants can use it to:
- Synchronise selected Shopify product information.
- Create supplier records and assign products.
- Send secure, expiring information requests to suppliers.
- Collect manufacturer, responsible-person, warning, instruction, custom-field, and supporting-document information.
- Review submissions, request corrections, and keep supplier evidence separate from later merchant revisions.
- Publish merchant-approved information to a Shopify storefront and retain source, review, approval, and publication history.
ComplyDock is not designed to collect Shopify customer, order, payment, checkout, or payment-card data.
2. Our role under data-protection law
2.1 TsanDev as controller
TsanDev acts as a controller when it determines why and how data is processed for operating, maintaining, securing, billing, and supporting ComplyDock; preventing abuse; keeping necessary business and security records; handling privacy requests; complying with legal obligations; and operating the public website.
2.2 TsanDev as processor
For supplier contacts, compliance records, documents, submissions, and related communications entered for a merchant’s workflow, the merchant generally determines the purpose of processing and acts as controller. TsanDev generally processes that information as the merchant’s processor to provide ComplyDock according to the merchant’s instructions and applicable service terms.
Merchants are responsible for an appropriate legal basis for the personal data they enter, the suppliers they contact, the information they request, and the information they publish.
The Data Processing Agreement incorporated into the Terms of Servicegoverns this processor relationship where Article 28 GDPR applies.
3. Personal data we process
3.1 Shopify store, installation, and merchant-user information
- Shop domain, store name, Shopify and installation identifiers, installation status, granted scopes, and relevant configuration.
- Authentication and session data, including access credentials stored for authorised Shopify API access.
- Authorised-user name, business email, Shopify user identifier, account-owner status, locale, and actions performed in ComplyDock.
- Subscription plan, Shopify billing status, settings, notification preferences, and activity dates.
Shopify handles subscription payments. ComplyDock does not receive or store merchant payment-card details.
3.2 Shopify product information
- Product title, Shopify identifier, handle, and product type.
- Featured product image URL.
- Variant identifiers and titles, SKUs, and barcodes.
- Whether a variant requires shipping, used to limit synchronisation to physical products.
3.3 Suppliers, manufacturers, and responsible persons
- Company and contact-person names, business email addresses, telephone numbers where provided, merchant notes, product assignments, and request history.
- Manufacturer, importer, distributor, authorised-representative, or responsible-person names, roles, addresses, countries, email addresses, websites, and product assignments where submitted.
Business information can be personal data when it concerns a sole trader, named contact, or individual responsible person.
3.4 Requests, submissions, and review records
- Request identifiers, status, products, requested fields and documents, merchant messages, deadlines, and secure-link events.
- Supplier answers, comments, warnings, instructions, custom-field values, issue and expiry dates, and submitted documents.
- Draft, submission, correction, approval, rejection, merchant revision, replacement, publication, and provenance records.
3.5 Uploaded files
Merchants and suppliers may upload declarations, certificates, test reports, manuals, safety instructions, images, and other supporting records. Files are stored privately and are not automatically published to the storefront.
Users must not upload:
- Personal data unnecessary for the compliance workflow.
- Special-category personal data, government identification, or similarly sensitive material unless legally necessary and expressly supported by ComplyDock.
- Unlawful, malicious, or infringing content.
3.6 Technical, security, and audit information
We and our infrastructure providers may process IP address, browser and device information, operating system, routes and actions, timestamps, authentication and access events, request and webhook identifiers, errors, delivery events, failed attempts, document format-validation results, and audit records.
3.7 Public website and contact enquiries
Website infrastructure may process standard request information, including IP address, browser details, requested page, response status, and access time. A local browser preference may remember the selected appearance mode.
The contact form processes the name, email address, user role, selected topic, optional store domain or request reference, message, privacy acknowledgement, and Turnstile verification token supplied with the enquiry. Messages are delivered to the support inbox and are not saved in the ComplyDock application database. Attachments are not accepted through the contact form. The Turnstile token is validated server-side and is not saved in the ComplyDock application database.
3.8 Shopify App Store analytics and attribution
We may configure Google Analytics 4 and Meta Pixel for the ComplyDock listing hosted by the Shopify App Store. When a merchant views that listing, interacts with it, clicks Install, or completes an installation, Shopify may send listing analytics and attribution events to our Google Analytics and Meta accounts.
Depending on the event and the configuration, this information may include the ComplyDock app identifier, listing and Install-button interactions, referral or discovery source, Shopify App Store surface and search information, selected locale, technical and device information, shop identifier, shop name, and shop domain. Shopify may send completed-installation events through Google Analytics Measurement Protocol and Meta Conversions API.
These listing integrations do not send merchant compliance records, supplier submissions, uploaded documents, product-compliance information, or supplier contact information to Google Analytics or Meta.
3.9 Public website analytics
If a visitor gives consent, the public ComplyDock website loads Google Analytics 4 to help us understand how the website is used and improve its content and usability. Depending on enabled measurement settings, Google Analytics may process page paths, navigation and interaction events, referral or acquisition source, approximate location derived from network information, and technical, browser, device, and language information.
Google Analytics is not loaded and public-website analytics data is not sent until the visitor selects “Allow analytics”. This website analytics integration is not loaded in the embedded merchant app, supplier portal, authentication, internal, webhook, or download routes. The visitor’s choice is stored locally in the browser and can be changed through “Analytics settings” in the public footer.
We do not intentionally send contact-form content, names, email addresses, shop domains, supplier-access tokens, request references, merchant compliance records, supplier submissions, or uploaded documents to the public-website Google Analytics stream.
4. How information is collected
- From merchants: when they install or configure ComplyDock, manage suppliers and products, create requests, upload or review records, publish, export, change settings, or contact support.
- From Shopify: through authentication, APIs, billing, and webhooks after the merchant grants access.
- From suppliers: when an invited supplier opens a secure link, saves progress, or submits requested information and documents. No ComplyDock account is required.
- Automatically: when technical, security, delivery, request, audit, consented public-website analytics, and Shopify App Store listing analytics or attribution events are generated through use of the service, website, or listing.
5. Why we process personal data
We process personal data as necessary to:
- Authenticate merchants and provide, maintain, and secure ComplyDock.
- Synchronise selected products and operate supplier, request, submission, document, review, correction, approval, revision, publication, and export workflows.
- Maintain source, activity, security, delivery, billing, and audit records.
- Send transactional emails, provide support, troubleshoot errors, prevent misuse, and improve service reliability and usability.
- Validate uploaded file size, type, and content signature and respond to valid legal, regulatory, and authority requests.
- Measure Shopify App Store listing traffic, listing interactions, installation conversions, acquisition sources, and marketing effectiveness.
- With consent, measure use of the public website so we can improve its content, navigation, reliability, and usability.
- Establish, exercise, or defend legal claims.
We do not sell personal data or use merchant compliance records, supplier submissions, uploaded documents, product-compliance information, or supplier contact information for third-party behavioural advertising. We do not use merchant, supplier, document, or compliance data to train public artificial-intelligence models. Consented public-website analytics and analytics and attribution data relating to the Shopify App Store listing may be processed by Google, and listing attribution data may be processed by Meta, as described in this policy.
6. Whether information is required
Some information is necessary for requested functions. Shopify authentication is required to use the embedded app; a supplier email address is required to send a request; required compliance fields may need to be completed before review or publication; and technical information is necessary to secure the service. Optional fields do not need to be provided, but missing required information can make a related function unavailable.
7. Legal bases for processing
Where the GDPR applies and TsanDev acts as controller, processing is based, as applicable, on:
- Contract — Article 6(1)(b) GDPR: providing the service, managing installation and subscription access, delivering requested functionality, and supporting merchants.
- Legitimate interests — Article 6(1)(f) GDPR:operating, securing, improving, troubleshooting, preventing abuse, maintaining necessary records, answering enquiries, handling legal claims, and carrying out limited listing-performance and installation-attribution measurement where permitted, after considering affected rights and interests. This basis does not override consent requirements that apply to non-essential technologies.
- Legal obligations — Article 6(1)(c) GDPR:complying with applicable legal, tax, accounting, regulatory, court, and law-enforcement duties.
- Consent — Article 6(1)(a) GDPR: only where consent is legally required for a particular activity, including non-essential analytics, advertising, or similar tracking technologies. Consent may be withdrawn for the future.
Where TsanDev acts as processor, the merchant determines and documents the applicable legal basis.
8. Secure supplier links
Supplier links are request-specific, scoped to selected products, may expire, and may be revoked or replaced. They must not be shared outside the supplier’s authorised team. Suppliers should submit only accurate and relevant information, avoid unnecessary personal data, and contact the merchant if a link was received by mistake. ComplyDock may record access, submission, and security events to protect the request and preserve workflow integrity.
9. Storefront publishing and public information
Only information explicitly approved and published by the merchant is intended to reach the ComplyDock storefront integration. Supporting documents remain private and are not published through the current storefront integration.
Published information can be viewed, cached, indexed, copied, or stored by third parties outside TsanDev’s control. Approved values may be transferred to Shopify product metafields used for storefront display and are also subject to the merchant’s Shopify settings and Shopify’s policies.
Merchants are responsible for reviewing, lawfully publishing, correcting, and removing information. ComplyDock does not certify products, determine applicable law, provide legal advice, or guarantee regulatory compliance.
10. Service providers and other recipients
The following providers receive information where necessary to operate ComplyDock. Depending on the processing, they may act as processors, subprocessors, or independent controllers under their own terms and notices.
- Shopify: app distribution, authentication, APIs, webhooks, embedded-app functionality, billing, metafields, and storefront integration.
- Vercel: hosting, serverless infrastructure, content delivery, deployment, technical logging, and private file storage through Vercel Blob.
- Neon: managed PostgreSQL database infrastructure.
- Resend: transactional email delivery and related recipient, message, identifier, delivery, bounce, and error data.
- Microsoft Outlook: receipt and handling of public contact-form and support communications in the monitored support mailbox.
- Cloudflare Turnstile: contact-form abuse prevention using browser, device, network, and challenge signals and server-side token verification.
- Google Analytics: consented analytics for the public website and analytics and attribution for the Shopify App Store listing. Public-website analytics may include page, interaction, acquisition, approximate-location, and technical device information. Listing analytics may include listing views, Install-button activity, completed-installation events and, depending on the event Shopify sends, shop identifier, name, and domain information. Google processes this information under its applicable terms and privacy documentation. Further information is available in the Google Privacy Policy.
- Meta: Meta Pixel and Conversions API analytics and attribution for the Shopify App Store listing, including listing views, Install-button activity, completed installations, and marketing performance. Depending on the event, Meta may process technical and listing-event information and shop name and domain information under its applicable terms and privacy documentation. Further information is available in the Meta Privacy Policy.
Information may also be disclosed to professional advisers, insurers, courts, regulators, tax authorities, or law-enforcement authorities where required or permitted by law or reasonably necessary for legal claims. Relevant information may be disclosed under appropriate safeguards during a prospective or completed financing, sale, merger, or reorganisation.
11. International data transfers
Some providers and their subprocessors may process information outside Germany or the European Economic Area. Where required, transfers rely on an applicable adequacy decision, valid EU–U.S. Data Privacy Framework certification, European Commission Standard Contractual Clauses, supplementary safeguards, or another legally recognised mechanism. Contact us for information about safeguards relevant to your data.
12. Retention and deletion
Personal data is retained only while needed for the purposes in this policy, the merchant’s active service, security and dispute handling, or applicable legal duties.
12.1 Active installations and uninstallation
During an active installation, ComplyDock generally retains the merchant settings, product snapshots, suppliers, requests, submissions, documents, review and publication history, audit data, and service records needed to provide the app. After uninstall, sessions and app access credentials are removed promptly and the merchant dataset and private files receive a deletion deadline currently configured for 30 days after the first recorded uninstall. Deletion jobs may complete after that deadline when a provider operation fails and must be retried; pending data is not restored to ordinary use while deletion is being retried. A valid Shopify shop-redact request accelerates the deadline and is handled within Shopify's required period unless continued retention is legally required.
Reinstallation before purge completion may cancel pending deletion where technically and legally permitted. Limited information may be kept longer where required by law, necessary for a dispute, claim, fraud or security investigation, validly agreed, or irreversibly anonymised.
12.2 Documents, links, and submissions
Accepted files are generally retained while the installation is active until deleted by the merchant or purged with the shop data. File content rejected during file validation or merchant review is deleted; limited non-content audit metadata may remain. Secure links remain usable until expiry, revocation, replacement, or deletion of the related dataset. Submission and review history may remain during the active installation for traceability.
12.3 Email, support, logs, and statutory records
Application email-delivery records are kept as reasonably necessary for delivery, failure investigation, duplicate prevention, security, and audit, and are generally removed with the merchant dataset. Providers retain their own service records under their contracts and legal obligations. Support mailbox communications are retained while an enquiry is active and afterwards only as reasonably necessary for support, disputes, and legal claims. Technical and security logs are retained according to operational, incident, provider, and legal requirements. Tax, accounting, and business records may be retained for statutory periods.
12.4 Public website and App Store listing analytics
Consented public-website analytics and Shopify App Store listing analytics and attribution data within our Google Analytics and Meta accounts are retained according to the retention controls configured in those services and only for as long as reasonably necessary to improve the website, measure acquisition and installation performance, evaluate marketing, resolve attribution issues, or meet legal obligations. Aggregated reports and records retained by Shopify, Google, or Meta under their own terms may follow different retention periods.
12.5 Backups and residual copies
Deleted information may temporarily remain in restricted backups, disaster-recovery systems, or provider replicas until the applicable cycle expires or data is overwritten. Residual copies are not used for ordinary business purposes.
13. Shopify privacy and compliance requests
ComplyDock handles Shopify’s mandatory privacy webhooks for applicable access, customer-deletion, and shop-deletion requests. The app is not designed to collect Shopify customer or order data; customer-related requests may therefore complete without locating customer records while still being recorded for operational integrity. Individuals may also contact us directly.
14. Data security
Measures used to protect information may include:
- HTTPS encryption in transit and Shopify session authentication.
- Tenant-scoped access controls and restricted system access.
- Private file storage, randomised storage keys, and expiring, revocable supplier links.
- File-size, extension, media-type, and content-signature validation for supported document formats. This validation does not constitute antivirus or malware scanning.
- Audit and security logging, environment separation, testing, database controls, and deletion jobs with retry handling.
No system can guarantee absolute security. Users must protect their devices, Shopify and email accounts, passwords, and secure links. We assess and notify personal-data breaches where legally required.
15. Cookies, analytics, and similar technologies
ComplyDock uses technologies reasonably necessary to authenticate, secure, operate, and remember settings for the service. These may include Shopify session mechanisms, security tokens, Cloudflare Turnstile challenge technology, and local browser storage for the selected appearance, notification read state, and public-website analytics consent choice.
The Shopify-hosted ComplyDock App Store listing may additionally use Google Analytics 4 and Meta Pixel configured by us through Shopify. These technologies may measure listing views and interactions, Install-button activity, acquisition sources, completed installations, and marketing performance. Shopify may also transmit installation and attribution events server-side through Google Analytics Measurement Protocol and Meta Conversions API.
On the public ComplyDock website, Google Analytics 4 remains off unless the visitor selects “Allow analytics”. Rejecting analytics does not prevent use of the public website. A visitor can reopen “Analytics settings” in the public footer and change the choice for future activity. Google Analytics is never loaded by this integration in the embedded application or supplier portal, and Meta Pixel is not added to the public website by this integration. Separate controls may apply to the Shopify-hosted App Store listing.
Merchant compliance records, supplier submissions, uploaded documents, product-compliance information, and supplier contact information are not used for behavioural advertising.
16. Data-subject rights
Subject to legal conditions and exceptions, individuals may:
- Request access, correction, deletion, or restriction.
- Object to processing based on legitimate interests.
- Receive eligible data in a structured, commonly used, machine-readable format.
- Withdraw consent where consent is the legal basis.
- Complain to a competent data-protection authority.
- Request information about international-transfer safeguards.
16.1 Merchant-controlled information
Where a merchant controls information submitted for its compliance workflow, the individual should normally contact that merchant first. Where TsanDev acts as processor, we provide reasonable assistance to the merchant with valid requests.
16.2 TsanDev-controlled information
Requests about information controlled by TsanDev may be sent to tsan-dev@outlook.com. We may request proportionate identity verification before fulfilling a request.
17. Right to object
An individual may object, for reasons relating to their particular situation, to processing based on legitimate interests. We will stop the relevant processing unless compelling legitimate grounds override the individual’s interests, rights, and freedoms, or the processing is needed for legal claims. Individuals may object at any time to direct marketing. ComplyDock does not currently use merchant, supplier, or compliance data for third-party direct marketing.
18. Complaints and supervisory authority
Individuals may complain to a competent data-protection supervisory authority, particularly where they live, work, or believe an infringement occurred. The authority responsible for TsanDev’s establishment in Lower Saxony is:
Der Landesbeauftragte für den Datenschutz NiedersachsenPrinzenstraße 5
30159 Hannover, Germany
Email: poststelle@lfd.niedersachsen.de
Telephone: +49 511 120-4500
Website: www.lfd.niedersachsen.de
We encourage individuals to contact us first where appropriate.
19. Automated decision-making
ComplyDock does not use personal data for solely automated decisions that produce legal or similarly significant effects. Status, missing-information, expiry, completeness, and readiness indicators organise work; they are not legal certification or final compliance determinations.
20. Children’s data
ComplyDock is a business service for merchants, suppliers, manufacturers, and professional users. It is not directed at children, and we do not knowingly collect children’s personal data through the service.
21. Third-party links and independent services
ComplyDock may link to Shopify and other independent services that operate under their own terms and privacy policies. TsanDev is not responsible for an independent third party’s processing where that party determines its own purposes and means.
22. Merchant responsibilities
Merchants are responsible for:
- Giving suppliers and other affected individuals appropriate privacy information and having a valid legal basis.
- Avoiding excessive collection, keeping information accurate, and controlling access to their Shopify account.
- Reviewing information before publication and responding to data-subject requests where the merchant is controller.
- Informing TsanDev of relevant instructions or restrictions and complying with applicable data-protection, ecommerce, advertising, and product laws.
23. Changes to this policy
We may update this policy when functionality, providers, processing, law, security, or operations change. The revised policy will show a new “Last updated” date. We will provide additional notice where a material change requires it.
24. Contact
Efstathios TsanidisSole proprietor (Einzelunternehmer), trading as TsanDev
Luhnenstraße 7
30559 Hannover
Germany
Email: tsan-dev@outlook.com