Passerity

Privacy Policy

Effective September 16, 2026

This policy is a good-faith, researched description of what Passerity actually does with data today. It is not legal advice and has not been reviewed by a lawyer. It will be revisited if the business's risk profile changes materially (for example: real revenue at scale, or formal company registration).

What Passerity is

Passerity is a Shopify app that helps merchants draft and publish EU Digital Product Passports (DPP) and GPSR-style compliance information for their products — materials, manufacturer/importer details, care and repair instructions, recyclability, and safety certificates — as a QR-coded public page per product.

We do not request Protected Customer Data

Passerity's Shopify access scopes are limited to read_products and write_products. We never request access to your customers' names, emails, addresses, phone numbers, or order history, and there is no customer record of any kind anywhere in Passerity's database. Nothing about your shoppers passes through Passerity at all — the only audience-facing surface is the public passport page itself, which any visitor (including someone who simply scans the QR code) can view without identifying themselves to us.

What data we do handle

DataSourceWhy
Company / manufacturer & importer details (name, contact email, address) Entered directly by the merchant in Passerity's settings Required content on the published passport page and for GPSR/DPP manufacturer-identification requirements
Product catalog data (title, description, tags) Read from your Shopify store via the Admin API Displayed on the passport page, and used to draft an initial passport with AI autofill (see below)
Safety certificate files you upload Uploaded by the merchant Linked from the published passport page for shopper/regulator verification

We recognize that manufacturer/importer contact details can be personal data when the merchant is a sole proprietor rather than a registered company, even though it is never customer data. We handle it with the same care either way.

AI-assisted passport drafting

When you use Passerity's autofill feature, your product's title, description, and tags — the same information already visible on your public storefront — are sent to Anthropic's Claude API to draft passport text for you to review and edit. No customer data is ever included in this request. You can edit or discard any AI-drafted content before publishing.

Where data is stored and processed

Safety certificate uploads are currently stored on Passerity's own Fly.io application server rather than a third-party storage provider. If we later move certificate storage to a dedicated object-storage provider, that provider will be added to this list and to the Data Processing page.

Data retention and deletion

Uninstalling Passerity from your store deletes your shop's data — company/manufacturer profile and every product passport, including uploaded safety certificates — from our systems. Shopify's mandatory customers/data_request and customers/redact webhooks always report that Passerity holds nothing to export or redact for any given customer, because Passerity never stores customer data in the first place.

Your rights

If you are a merchant using Passerity, you can request a copy of, or the deletion of, the data described above at any time by contacting us — see below. If you are a shopper who scanned a passport QR code, remember that the passport page itself does not collect any information from you.

Contact

Questions about this policy or how Passerity handles data: support@passerity.com.