Privacy policy — ClaimFix
Last updated 20 August 2026.
ClaimFix scans a Shopify store’s catalogue content for environmental claims that are restricted under Directive (EU) 2024/825 and, on the merchant’s instruction, corrects that wording. This policy explains exactly what the app reads, what it writes, what it stores, and for how long.
What we do not collect
ClaimFix never accesses customer data. The app requests only content scopes (write_products, write_content, write_online_store_pages). It has no permission to read customers, orders, or payment information. We do not use cookies for tracking, and we do not sell data or share it with anyone beyond the processors listed below.
What we read
- Product titles, descriptions and text metafields
- Collection titles and descriptions
- Online store pages and blog articles
What we write
The app changes catalogue text only when the merchant explicitly applies a fix after seeing a before/after preview. Every change is recorded with its full prior value and can be undone from the app. We never write anywhere else in the store.
What we store
- Your store domain and the access token issued by Shopify at install
- Scan results: the flagged wording, its location (e.g. a product title), severity and the cited legal provision
- Revision history: for every applied fix, the field’s value before and after the change. This is what makes undo possible and serves as the merchant’s audit trail.
- If monitoring is enabled: the alert email address the merchant entered in the app’s settings
Data is held in a PostgreSQL database hosted by Railway (railway.app) in the Netherlands, within the EU, and is transmitted over HTTPS.
Processors
- Railway (railway.app, EU region) — application and database hosting.
- Anthropic (anthropic.com) — only when the merchant requests AI rewording suggestions, the flagged wording and its surrounding sentence are sent to the Claude API to draft a replacement. No store identifiers, customer data or access tokens are included, and the content is not used to train models.
- Resend (resend.com) — only if monitoring is enabled, used to deliver alert emails to the address the merchant provided.
Retention and deletion
Uninstalling the app deletes your session. On a shop/redact request from Shopify — sent 48 hours after uninstall — all scans, findings, revisions and settings for your store are deleted permanently. You can also request deletion at any time by email.
Because we hold no customer data, the customers/data_request and customers/redact webhooks have nothing to return or erase; they are acknowledged and no data changes.
Your rights
Under the GDPR you may request access to, correction of, or deletion of the data described above, and you may lodge a complaint with your supervisory authority.
Who operates this app
Leon Rhein
Algierstrasse 4
8048 Zürich
Switzerland
Contact
Questions or deletion requests: alpineappsolutionsdev@gmail.com. We respond within 30 days.
ClaimFix is a support tool, not legal advice. Its findings and suggestions are indicators, not legal conclusions.