This is a courtesy translation. The German version (Datenschutzerklärung) is the legally binding document.

Privacy Policy

Last updated: February 2026

EULabel ("we", "our" or "the app") is a Shopify application that helps merchants make their food products compliant with EU Food Information Regulation (FIC/LMIV). This privacy policy explains how we handle your data when using our service.

Controller

Controller within the meaning of the GDPR:

Robin Spanier Softwareentwicklung
Cloefstraße 6, 66693 Orscholz, Germany
Email: robin.spanier@robspan.de

A Data Protection Officer is not required pursuant to § 38 BDSG (fewer than 20 persons engaged in automated data processing).

Data We Access

To provide LMIV compliance services, EULabel accesses the following data from your Shopify store:

Important: We only access product data, not customer data. The app does not store any personal data of your customers.

Legal Bases for Processing

We process your data on the following legal bases:

Data We Store

EULabel was designed with privacy in mind. We minimize data storage to the absolute minimum required:

What we store


What we do NOT store

How We Process Data

  1. LMIV data: All nutritional and product information is stored directly in Shopify metafields, not on our servers.
  2. Automatic label scan: When you upload a label image, it is sent to the Google Gemini API to automatically extract nutritional values, ingredients, allergens and other mandatory LMIV information. The image is used exclusively for this one-time processing and is not stored by us. The extracted data is saved as Shopify metafields in your store.
  3. Automatic translation: When using the translation feature, your LMIV text data (ingredients, storage instructions, warnings, etc.) is sent to the Google Gemini API to produce translations into the desired EU languages. The texts are used exclusively for this one-time processing. The translations are stored as metafields in your Shopify store.
  4. Compliance checking: Validation is performed in real time in the browser. No product data is permanently stored on our servers.
  5. Nutri-Score: The calculation is performed client-side based on the entered nutritional data.
  6. Theme blocks: Storefront display is rendered directly via Shopify's Theme Extension system without routing through our servers.
All LMIV data is stored directly in your Shopify store as metafields. You have full control over this data at all times.

AI Processing and Data Quality

Important notice: When using the automatic label scan and the translation feature, your data is processed by AI technology (Google Gemini). This AI processing is subject to inherent limitations:

We accept no responsibility for the accuracy of AI-generated data. All AI results must be manually reviewed before publication. Responsibility for the accuracy of all food information lies with the food business operator under EU Regulation 1169/2011 (LMIV).

For further details on liability, please refer to our Terms of Service.

Data Retention

Your Rights

Under the GDPR, you have the following rights regarding your personal data:


Right to withdraw consent

Where processing is based on consent, you have the right to withdraw that consent at any time. The lawfulness of processing carried out prior to withdrawal remains unaffected.


Right to lodge a complaint (Art. 77 GDPR)

You have the right to lodge a complaint with a supervisory authority. The competent supervisory authority is:

Unabhängiges Datenschutzzentrum Saarland
Fritz-Dobisch-Straße 12, 66111 Saarbrücken, Germany
poststelle@datenschutz.saarland.de


GDPR principles

EULabel is designed to be GDPR-compliant:

Third-Party Services

EULabel uses the following third-party services:

Data transfer to the USA

Data transfer to the USA is based on the European Commission's adequacy decision for the EU-US Data Privacy Framework (Art. 45(1) GDPR). Google LLC is a certified participant in the EU-US Data Privacy Framework. Additionally, Standard Contractual Clauses (Art. 46(2)(c) GDPR) under Google's Data Processing Addendum serve as a supplementary safeguard.

Beyond these service providers, we do not share your data with any other third parties, advertisers, or data brokers.

Automated Decision-Making

No automated decision-making within the meaning of Art. 22 GDPR takes place. The compliance score is purely informational and has no legal effects.

Obligation to Provide Data

Providing data is contractually required to use the app. Without providing shop data, the service cannot be rendered.

Security

We take security seriously:

Deleting Your Data

To delete all data associated with your store:

  1. Navigate to your Shopify admin panel
  2. Go to Settings → Apps and sales channels
  3. Find EULabel and click "Uninstall"

Upon uninstallation, all session and subscription data is immediately and permanently deleted. LMIV metafields remain in your store and can be deleted manually.

Applicable Law

This privacy policy is governed by the laws of the Federal Republic of Germany. Disputes are subject to the jurisdiction of the German courts.

Changes to This Policy

We may update this privacy policy from time to time. In the event of material changes, we will notify you through the app. Continued use of the app after changes constitutes acceptance of the updated policy.

Contact

If you have questions about this privacy policy or how we handle your data, please contact us:

Robin Spanier Softwareentwicklung
Cloefstraße 6, 66693 Orscholz, Germany
Email: robin.spanier@robspan.de

We aim to respond to all privacy-related inquiries within 48 hours.

EULabel — LMIV-Compliance for Shopify