SelmoreCompliance

Last updated 20 July 2026

Privacy Policy

This policy explains how data is processed on compliance.selmore.io and in the Selmore Compliance Shopify public app.

1. Controller

EGC Mentaris GmbH, Goethestraße 50, 74613 Öhringen, Germany
Email: datenschutz@egc-mentaris.de

2. Roles when using the Shopify app

EGC Mentaris GmbH is the controller for merchant contract, billing, support and security data. For withdrawal, order and communication data concerning a merchant's customers, EGC Mentaris GmbH generally acts as a processor on the merchant's documented instructions. A versioned Data Processing Agreement under Article 28 GDPR is available in the app for acceptance and download.

3. Visiting this website

Technically necessary connection data is processed when this website is accessed, including IP address, time, requested address, transferred data volume, referrer, browser and operating system. This is required for secure delivery, error analysis and protection against attacks. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and stable operation of the service.

The public website does not use analytics or marketing cookies. The embedded Shopify app uses only the mechanisms required for Shopify authentication and secure sessions.

4. Contact requests

When you contact us, we process sender details, contact details, message content and time. The legal basis is Article 6(1)(b) GDPR where the request concerns a contract and otherwise Article 6(1)(f) GDPR. Data is deleted once the request is resolved unless statutory retention duties apply.

5. Installation and use by merchants

We process shop domain, shop and contact details, selected settings, plan and billing status, Shopify session data, permissions, theme placements, verification status, support information and audit data. Processing is required to provide and bill for the app under Article 6(1)(b) GDPR. Security and abuse logs are additionally based on Article 6(1)(f) GDPR.

6. Processing customer data on behalf of merchants

Depending on merchant configuration, Selmore processes names, email addresses, order identifiers, order and delivery dates, country, selected items and quantities, withdrawal details, status, timestamps, email events and technical evidence. Plain-text data is shown only in protected detail views. Lists, audit records and exports use references and hashes where possible.

Each merchant, as controller, determines the legal basis and fulfils information duties towards affected customers. Selmore processes this data only under the DPA and documented configuration.

7. Product information, benefits and recommendations

Product information, optional upgrades, loyalty benefits and referral offers are sent only after the merchant's express consent under Article 6(1)(a) GDPR. We process the selected address and language, consent and unsubscribe times, delivery status, campaign identifier, and personal referral or benefit codes. Recipient addresses are stored encrypted and delivery logs contain only a non-reversible hash. We do not use invisible tracking pixels.

Consent can be withdrawn at any time in the app or via the unsubscribe link in each email. Required service, billing and security messages are unaffected. Referral data is processed to prevent abuse and settle benefits; self-referrals and multiple assignments are excluded.

8. Shopify interfaces

The app uses only Shopify permissions required for activated features, including reading orders and products, managing returns, providing an app proxy, and setting up online-store pages and navigation. Shopify processes data under its own contractual and privacy terms. Paid plans use Shopify App Billing.

9. Email delivery

Transactional messages are sent through the configured Selmore email infrastructure by default. Replies are routed via Reply-To to the address stored by the merchant. Merchants may alternatively configure their own SMTP server. Credentials are stored encrypted and are never displayed in plain text. Delivery status, provider identifiers and content checksums are logged as evidence.

10. Recipients and subprocessors

ProviderPurposeProcessing location
Fly.io, Inc.App hosting, database and encrypted infrastructurePrimary region Frankfurt am Main; possible US transfer subject to appropriate safeguards
one.com Group ABTransactional email delivery through Selmore default deliveryEuropean Union / European Economic Area
Shopify International Limited / Shopify Inc.Shop platform, app authentication, app proxy, order and return interfaces, and billingEU/EEA and other Shopify-documented locations subject to appropriate safeguards

If a merchant configures its own SMTP service, that provider is an additional recipient under the merchant's responsibility.

11. International transfers

The app is primarily operated in Frankfurt am Main, Germany. Where a provider processes data in a third country, the transfer is based on an adequacy decision or appropriate safeguards, in particular EU Standard Contractual Clauses and supplementary measures.

12. Retention and deletion

Merchants choose a retention period in the app. Automated anonymisation can be configured after 6 or 12 months or after 3 or 10 years. Personal withdrawal data is then deleted or anonymised. Non-reversible evidence hashes may remain for integrity verification. Contract, billing and commercial records are retained for statutory periods. Shopify's mandatory privacy webhooks additionally handle access and deletion after uninstall.

13. Security

We use tenant isolation, TLS, encrypted secrets and personal fields, restrictive Shopify scopes, signed storefront and download requests, rate limits, PII-minimised logs, integrity hashes, backups and controlled deletion processes.

14. Data subject rights

Subject to the GDPR, individuals have rights of access, rectification, erasure, restriction, portability and objection. Consent may be withdrawn at any time for the future. A merchant's customers should first contact that merchant regarding their withdrawal data; we assist the merchant under the DPA.

15. Complaints and automated decisions

You may lodge a complaint with a data protection supervisory authority. The competent authority for us is in particular the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg. Selmore does not make solely automated decisions that have legal or similarly significant effects.

16. Changes

We update this policy when processing activities or legal requirements change. The current version remains available on this page.