Datenschutz
Liquiflow
MRR Labs GmbH
Neckarstraße 122, 70190 Stuttgart
Deutschland
HRB 796773
Amtsgericht Stuttgart
phone: +49 711 50455717
E-Mail: info@liquiflow.app
Datenschutzerklärung — EU-Gewährleistungslabel (Shopify-App)
Stand: 6. September 2026
1. Verantwortlicher
MRR Labs GmbH
Neckarstraße 122, 70190 Stuttgart, Deutschland
HRB 796773, Amtsgericht Stuttgart
E-Mail: info@liquiflow.app
2. Gegenstand dieser Erklärung
Diese Erklärung gilt für die Shopify-App EU-Gewährleistungslabel. Für die Website liquiflow.app gilt die dort veröffentlichte Datenschutzerklärung; die darin beschriebenen Dienste (Analyse, Videos, Newsletter) kommen in dieser App nicht vor.
Die App hilft Shopify-Händlern, die ab dem 27. September 2026 vorgeschriebenen Angaben zur gesetzlichen Gewährleistung und zur Herstellergarantie in ihrem Shop anzuzeigen. Nutzer der App ist der Händler. Besucher seines Shops sehen die Anzeige, treten dabei aber nicht mit uns in Verbindung; siehe Abschnitt 5.
3. Welche Daten verarbeitet werden
Shop-Domain
Shopify bei der InstallationZuordnung aller Daten zum Shop
Zugriffstoken
Shopify (OAuth)Zugriff auf die Shopify-API im Auftrag des Händlers
Einstellungen der App
Eingabe des HändlersDarstellung im Shop
Herstellerstammdaten
Eingabe des HändlersPflichtangaben der Garantieerklärung nach § 479 BGB
Zuordnung Produkt und Garantie
Eingabe des HändlersErzeugung und Pflege der Labels
Protokoll der Aktionen
Nutzung der App: Nachweis, welche Angabe wann veröffentlicht wurde
Die Herstellerstammdaten enthalten Name und Anschrift des Garantiegebers. Ist der Garantiegeber eine natürliche Person, sind das personenbezogene Daten. Sie werden gespeichert, weil die Garantieerklärung sie nach § 479 Absatz 1 BGB zwingend enthalten muss.
Das Protokoll speichert zu jeder Aktion die Shopify-Nutzerkennung, sofern die Aktion aus dem Admin ausgelöst wurde. Kein Name, keine E-Mail-Adresse.
Die App fordert von Shopify ausschliesslich diese Berechtigungen an: read_products, write_products, write_files, read_themes, read_locales. Produkte werden gelesen und um Metafelder ergänzt, Dateien werden für die amtlichen Grafiken hochgeladen, Themes und Sprachen werden nur gelesen.
4. Welche Daten ausdrücklich nicht verarbeitet werden
- Keine Kundendaten. Die App fordert weder
read_customersnochread_ordersan und beantragt keinen Zugriff auf Protected Customer Data. - Keine Bestelldaten.
- Keine Namen oder E-Mail-Adressen von Mitarbeitenden des Händlers. Die App arbeitet ausschliesslich mit Offline-Sitzungen; die Felder, die das Sitzungsschema dafür vorsieht, bleiben leer.
- Kein Tracking, keine Analyse, keine Werbe-Cookies, weder im Admin noch im Shop des Händlers.
Die Garantieerklärung erreicht den Kunden über die Bestellbestätigung von Shopify. Der dafür eingefügte Liquid-Baustein wird von Shopify verarbeitet; die App bekommt weder Empfänger noch Inhalt der Mail zu sehen. Genau deshalb ist dieser Weg gewählt worden und nicht ein eigener Mailversand.
5. Besucher des Shops
Was im Shop erscheint, wird vollständig vom Shopify-CDN ausgeliefert: die amtlichen Grafiken liegen in den Shopify-Dateien des Händlers, das Skript und die Stilangaben gehören zur Theme-Erweiterung und liegen ebenfalls bei Shopify. Ein Shop-Besucher baut deshalb keine Verbindung zu einem Server der App auf. Es werden dabei keine Cookies gesetzt und keine Zugriffe protokolliert.
6. Rechtsgrundlage
- Für die Verarbeitung der Händler- und Herstellerdaten: Erfüllung des Vertrags über die Nutzung der App, Artikel 6 Absatz 1 Buchstabe b DSGVO.
- Für das Protokoll: berechtigtes Interesse an der Nachvollziehbarkeit gesetzlich vorgeschriebener Angaben, Artikel 6 Absatz 1 Buchstabe f DSGVO.
7. Empfänger
- Shopify International Limited als Plattform, auf der Shop und App laufen.
- Hetzner Online GmbH, Serverstandort Deutschland, als Auftragsverarbeiter für Anwendung und Datenbank.
Eine Übermittlung in Drittländer findet durch die App nicht statt.
8. Speicherdauer
Bei Deinstallation der App werden die Sitzungen des Shops sofort gelöscht.
Die übrigen Daten, also Einstellungen, Hersteller, Zuordnungen und Protokoll, bleiben für 48 Stunden erhalten. Der Grund ist die Arbeit des Händlers: eine versehentliche Deinstallation soll nicht sofort vernichten, was er eingetragen hat. Danach fordert Shopify über den Endpunkt shop/redact die Löschung an, und die App löscht alle Daten dieses Shops.
Bleibt diese Anforderung aus, etwa weil ein Shop geschlossen statt die App deinstalliert wurde, werden die Daten spätestens 90 Tage nach der Deinstallation gelöscht. Früher auf Anforderung, siehe Abschnitt 9.
9. Rechte der betroffenen Personen
Auskunft, Berichtigung, Löschung, Einschränkung, Datenübertragbarkeit und Widerspruch nach Artikel 15 bis 21 DSGVO, dazu das Beschwerderecht bei einer Aufsichtsbehörde. Anfragen an info@liquiflow.app.
10. Anfragen über Shopify
Die drei von Shopify vorgeschriebenen Endpunkte sind eingerichtet: customers/data_request, customers/redact und shop/redact. Da über Kunden keine Daten vorliegen, bestätigen und protokollieren sie die Anfrage, statt Daten herauszugeben oder zu löschen, die es nicht gibt. shop/redact löscht die Daten des Shops.
11. Änderungen
Stand: 6. September 2026. Bei Änderungen der App wird diese Erklärung fortgeschrieben.
Privacy Policy — EU Guarantee Label (Shopify app)
Last updated: 6 September 2026
1. Controller
MRR Labs GmbH
Neckarstraße 122, 70190 Stuttgart, Germany
Commercial register HRB 796773, Stuttgart Local Court
Email: info@liquiflow.app
2. Scope
This policy covers the Shopify app EU Guarantee Label. The website liquiflow.app is covered by its own privacy policy; the services described there (analytics, video, newsletter) are not used by this app.
The app helps Shopify merchants display the information on the legal guarantee of conformity and on producer guarantees that becomes mandatory on 27 September 2026. The user of the app is the merchant. Visitors to the merchant's store see the display but do not connect to us; see section 5.
3. Data processed
Shop domain
Shopify at installationAssociating all data with the shop
Access token
Shopify (OAuth)Calling the Shopify API on the merchant's behalf
App settings
Entered by the merchantRendering in the store
Producer master data
Entered by the merchantMandatory content of the guarantee statement under § 479 German Civil Code
Product-to-guarantee assignment
Entered by the merchantGenerating and maintaining the labels
Action log
Use of the appEvidence of which statement was published when
Producer master data contains the name and address of the guarantor. Where the guarantor is a natural person, this is personal data. It is stored because the guarantee statement is legally required to contain it.
The log stores the Shopify user ID for actions triggered from the admin. No name, no email address.
The app requests only these Shopify scopes: read_products, write_products, write_files, read_themes, read_locales.
4. Data explicitly not processed
- No customer data. The app requests neither
read_customersnorread_ordersand does not apply for Protected Customer Data access. - No order data.
- No names or email addresses of the merchant's staff. The app uses offline sessions only; the session fields provided for this remain empty.
- No tracking, no analytics, no advertising cookies, neither in the admin nor in the merchant's store.
The guarantee statement reaches the customer through Shopify's order confirmation. The Liquid snippet used for this is processed by Shopify; the app sees neither the recipient nor the content of the email. This is precisely why this route was chosen over sending mail ourselves.
5. Store visitors
Everything that appears in the store is served by the Shopify CDN: the official artwork sits in the merchant's Shopify Files, and the script and styles belong to the theme app extension and are likewise hosted by Shopify. A store visitor therefore never connects to an app server. No cookies are set and no requests are logged.
6. Legal basis
- Merchant and producer data: performance of the contract for the use of the app, Article 6(1)(b) GDPR.
- Action log: legitimate interest in being able to evidence legally required disclosures, Article 6(1)(f) GDPR.
7. Recipients
- Shopify International Limited, as the platform on which store and app run.
- Hetzner Online GmbH, servers located in Germany, as processor for the application and the database.
The app does not transfer data to third countries.
8. Retention
On uninstall, the shop's sessions are deleted immediately.
The remaining data (settings, producers, assignments, log) is retained for 48 hours, so that an accidental uninstall does not immediately destroy the merchant's work. Shopify then requests erasure through the shop/redact endpoint, and the app deletes all data belonging to that shop.
Where that request does not arrive, for example because a store was closed rather than the app uninstalled, the data is deleted 90 days after uninstallation at the latest. Earlier on request, see section 9.
9. Data subject rights
Access, rectification, erasure, restriction, portability and objection under Articles 15 to 21 GDPR, and the right to lodge a complaint with a supervisory authority. Requests to info@liquiflow.app.
10. Requests via Shopify
The three mandatory endpoints are implemented: customers/data_request, customers/redact and shop/redact. As no customer data exists, the first two acknowledge and log the request rather than producing or erasing data that does not exist. shop/redact deletes the shop's data.
11. Changes
Last updated 6 September 2026. This policy is updated as the app changes.