Privacy Policy
1. Who we are
Genius Nutrition SRL, VAT ID RO35355847, located at Tamasi 20, Buftea, Ilfov 070000, România, operates SGR România.
Privacy questions can be sent to gdpr@obsedia.ai.
2. Data we process
- Shop domain, Shopify identifiers, approved API scopes, installation and authentication session data.
- Merchant administrator name, email, locale, and role details supplied by Shopify for authorized sessions.
- Product and variant identifiers, titles, SKU, barcode, SGR selection, and packaging weights entered by the merchant.
- Order, line-item, refund, and cancellation identifiers and quantities required to build monthly SGR records and optionally fulfill technical deposit lines.
- Current SGR line amounts after discounts, source timestamps and Shopify financial status. These are not cash-receipt records.
- Explicit creation and readback of new drafts, without buyer contact fields. Locally retained idempotency hashes and operation status prevent duplicate creation; draft IDs and customer contacts are not persisted by this feature.
- Subscription status, plan, price, currency, and technical security or audit events.
We do not request or store customer payment details. Monthly reports query Shopify when requested. The App retains a derived, pseudonymous SGR event ledger containing Shopify order, product and variant identifiers, quantities, and lifecycle timestamps. It does not persist raw order payloads, names, delivery addresses, phone numbers, or buyer email addresses.
3. Purposes and legal bases
We process data to provide the App, authenticate authorized users, configure SGR behavior, prepare reports, manage Shopify billing, provide support, secure the service, and comply with legal obligations. Processing is based on performance of the merchant agreement, legitimate interests in security and service reliability, and legal obligations where applicable.
For buyer data processed on a merchant's instructions, the merchant is normally the controller and we act as processor.
4. Sharing and subprocessors
We do not sell personal data and do not use merchant or buyer data for behavioral advertising. Data is shared only as needed with:
- Shopify, for installation, authentication, billing, Admin API, and webhook delivery.
- Railway Corporation, which hosts the application and PostgreSQL database in the United States for the current production environment.
- Professional advisers or authorities when required by law or necessary to protect legal rights and service security.
Railway provides a Data Processing Addendum incorporating transfer safeguards such as Standard Contractual Clauses where applicable. Railway DPA.
5. Retention and deletion
- Technical webhook records: up to 90 days.
- Security and operational audit records: up to 24 months.
- Minimal pseudonymous SGR order-line identity (no customer contact data): while the installation is active, solely to map later refunds/returns after catalog deletion; removed by the associated customer or shop deletion request.
- Derived SGR sale/reversal ledger rows and current line-value snapshots: up to 24 months.
- After shop deletion, a non-reversible HMAC of the shop domain and the deleted AppInstallation ID are retained only as a security fence until a different verified installation consumes it.
- Hashed identifiers of explicitly redacted orders: for the active installation, solely to prevent delayed Shopify webhooks from recreating erased records.
- Expired Shopify sessions: deleted after a 7-day operational grace period.
- Customer data-request exports and completion receipts: up to 30 days after completion.
- Pending or failed privacy requests: retained and retried until completed or manually resolved under an applicable legal exception; they are never silently discarded at an attempt threshold.
- Store configuration, selected variants, and subscription projection: while the App remains installed, then deleted when Shopify sends the mandatory shop/redact request, subject to legal obligations.
Customer deletion requests remove the limited related operational records. A shop deletion request removes sessions, configuration, subscriptions, webhook records, order-line snapshots, derived SGR ledger rows, and audit records for that shop; only the non-identifying lifecycle security fence described above remains.
6. Security
Data is transmitted over HTTPS. Shopify access and refresh tokens are encrypted at rest using authenticated AES-256-GCM encryption. Webhooks are verified using Shopify HMAC signatures, and database access is restricted to the application environment.
7. Your rights
Depending on applicable law, individuals may request access, correction, deletion, restriction, objection, or portability and may complain to a supervisory authority. Buyer requests should normally be submitted first to the merchant that controls the Shopify store. We cooperate through Shopify's mandatory privacy webhooks; data-access exports are made available only inside the authenticated Shopify Admin for that merchant.
8. Changes
We may update this policy when the App or legal requirements change. The effective date above identifies the current version.
The App is not affiliated with RetuRO and does not automatically submit declarations. Merchants review and submit generated records themselves.