Privacy Policy
Last updated: August 18, 2026
1. Who we are
PassportAudit is a Shopify application that helps merchants generate and audit EU Digital Product Passports (DPP) in compliance with EU Regulation 2024/1781 (ESPR — Ecodesign for Sustainable Products Regulation). PassportAudit is operated by Eyal Taibert ("we", "our", or "us").
Contact: eyaltaibert@gmail.com
2. What data we collect
PassportAudit collects only the data necessary to provide the service. We do not collect any personal data from your store's customers or buyers.
From Shopify's API (when you install the app):
- Your store domain (e.g. yourstore.myshopify.com)
- Shopify OAuth access token (used to read your product data)
- Product titles, descriptions, types, vendors, SKUs, and images
From you directly (when you fill in passport fields):
- Manufacturer name, address, and contact information
- Materials composition, fiber content, recycled content percentage
- Carbon footprint, durability, repairability information
- Certifications and compliance declarations
- Any other product sustainability data you enter into passport fields
Automatically generated:
- Audit results (pass/fail status per ESPR field)
- Job logs (sync and audit activity records)
- Billing plan status (free or pro)
We do not collect: customer names, emails, addresses, payment information, browsing behavior, or any personal data belonging to your store's end customers.
3. How we use your data
We use the data we collect solely to provide PassportAudit's services:
- To sync your Shopify products into our system for auditing
- To run ESPR compliance audits and show you which fields pass or fail
- To generate and host Digital Product Passport pages on your behalf
- To display audit results and passport status in your dashboard
- To manage your billing plan via Shopify's billing API
We do not use your data for advertising, marketing profiling, or any purpose other than providing the PassportAudit service.
4. What data is made public
When you publish a Digital Product Passport, the passport fields you have filled in become publicly accessible at a unique URL (e.g. passportaudit.app/p/[passport-id]). This is the intended purpose of the EU Digital Product Passport — to allow consumers and regulators to verify product compliance data.
You control what data appears on the public passport page. Only fields you explicitly fill in and choose to publish are shown. Draft passports are never publicly accessible.
5. Data storage and security
Your data is stored in the following systems:
- Supabase (database) — hosted in the EU West region (Paris, France). Data does not leave the EU.
- Vercel (hosting) — our application server. Functions run in the nearest region to the user.
Your Shopify access token is stored encrypted at rest in Supabase. We use HTTPS for all data in transit. We do not store payment card details — billing is handled entirely by Shopify.
6. Data retention
We retain your data for as long as your store has PassportAudit installed. If you uninstall the app and request deletion, we will delete all your store data including products, passports, audit results, and job logs within 30 days of the request.
You can request deletion by emailing eyaltaibert@gmail.com or by triggering the shop/redact webhook through Shopify's data deletion process.
7. Third-party services
PassportAudit uses the following third-party services to operate:
- Shopify — the platform our app runs on. Shopify's privacy policy applies to data processed by Shopify: shopify.com/legal/privacy
- Supabase — our database provider, hosted in Paris EU. Privacy policy: supabase.com/privacy
- Vercel — our hosting provider. Privacy policy: vercel.com/legal/privacy-policy
- api.qrserver.com — used to generate QR code images for published passports. No personal data is sent.
We do not share your data with any other third parties, and we do not sell your data.
8. Your rights (GDPR)
If you are located in the European Economic Area, you have the following rights regarding your personal data:
- Right of access — you can request a copy of the data we hold about you
- Right to rectification — you can ask us to correct inaccurate data
- Right to erasure — you can ask us to delete your data
- Right to restriction — you can ask us to limit how we process your data
- Right to data portability — you can request your data in a machine-readable format
- Right to object — you can object to our processing of your data
To exercise any of these rights, contact us at eyaltaibert@gmail.com. We will respond within 30 days.
9. Cookies
PassportAudit uses a single HTTP-only session cookie named shop to identify your store after OAuth. This cookie is strictly necessary for the app to function and does not track you across other websites. No advertising or analytics cookies are used.
10. Changes to this policy
We may update this privacy policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of PassportAudit after changes constitutes acceptance of the updated policy.
11. Contact
For any privacy-related questions or requests, contact:
Eyal Taibert
Email: eyaltaibert@gmail.com
This privacy policy was written specifically for PassportAudit and reflects what data we actually collect and process. It is not a generic template.