GARAN Privacy Policy
Last updated: 6 August 2026
This Privacy Policy explains what data the GARAN Shopify app ("GARAN", "the App", "we") collects, why, and how it's handled. GARAN is built and operated by Optimmerce ("we", "us").
Who this applies to
This policy covers data collected from merchants who install GARAN on their Shopify store. GARAN does not collect, access, or store any data about a merchant's customers.
What GARAN does
GARAN helps merchants display the EU's harmonised legal-guarantee notice and the GARAN durability label required under Regulation (EU) 2024/825 and Commission Implementing Regulation (EU) 2025/1960. It renders these as storefront theme blocks and lets merchants enter product-specific durability/guarantee data.
Data we collect
Shop access token
When a merchant installs GARAN, Shopify issues us an offline access token for that store, which we store so the app continues to function without the merchant re-authenticating on every visit. This token is tied to the store, not to any individual staff member — GARAN does not request "online" (per-user) access, so we never receive or store the name, email, or other details of the person who installed the app.
This is the only data GARAN stores in its own database.
Product/guarantee data
The durability and guarantee information a merchant enters (duration, brand, model identifier) is written directly to metafields on that merchant's own Shopify store — it is Shopify-hosted data that belongs to the merchant, not a separate copy held by us. We read and write it via the Shopify Admin API to render the storefront blocks and power the bulk editor; we do not copy, log, or retain it in any database of our own.
Billing information
Subscription plan selection (Free/Pro) is handled entirely by Shopify's own hosted billing pages. We never see or store payment details — Shopify manages that relationship directly with the merchant.
Customer data
GARAN does not access, process, or store any data about a merchant's customers (shoppers). The storefront blocks it renders are static, publicly-visible content (the legal notice and label) and do not collect any visitor information.
Mandatory privacy webhooks
As required by Shopify for all public apps, GARAN implements the customers/data_request, customers/redact, and shop/redact webhooks. Because GARAN never stores customer data, the first two are no-ops. shop/redact deletes the store's access token from our database.
Data retention
The shop access token is retained for as long as the app remains installed, and deleted when the merchant uninstalls it (or immediately, on request via shop/redact).
Subprocessors / where data lives
Application hosting and database provider details will be added here once the app's production deployment is finalized.
Your rights
Merchants can request deletion of their store's data at any time by uninstalling the app, or by contacting us at the email below.
Contact
Questions about this policy or your data: hello@optimmercehq.com
Changes to this policy
We'll update the "last updated" date above if this policy changes, and post the updated version at this same location.