batchready

Privacy Policy

Effective date: 2026-07-20


Who we are

Batchready ("the app") is a Shopify app operated by Keoma Kindl, based in Austria, EU. Keoma Kindl is the data controller for the direct relationship with you, the merchant. For any question about your data or this policy, or to exercise your rights, contact us at support@keomakindl.at. Given the scope of our processing we are not required to appoint a Data Protection Officer; support@keomakindl.at reaches the person responsible.

What this policy covers and our role

This policy explains what personal data the app processes when you install it on your Shopify store, why, and on what legal basis.

Two roles apply. For any order data we access on your behalf, you (the store owner) are the controller and we act as your processor under Article 28 GDPR, processing that data only on your instructions to provide the app. For our direct relationship with you as a merchant, we are the controller.

Data we process

Store and account data: your store domain, a Shopify access token, and the configuration you create in the app.

Order references: for orders you assign to a production batch, we store the order's Shopify id, its order number and the id of the order line the quantity came from, linking your production to fulfillment. The batch history keeps the order number on the assignment event as well. We do not receive or store the customer's name, email, address, phone number, or any payment or card data.

Product references: product and variant ids and cached titles for the products your batches make and your recipes target. When you open a batch we also read the product's lowest variant price and its featured image, to show what the run is worth and to offer the product photo as the batch photo; the image link is stored only if you keep it.

Content you add: your batches, material use, stock corrections, materials, recipes, settings and the batch history that records what happened to each batch.

Images you upload: if you add a photo to a batch's public Passport, we save it to your own Shopify Files and keep only the resulting image link on the batch. These images are your content and are not customer personal data.

Requests to your public pages: the Batch Passport and the batch lookup are served under your own store domain through a Shopify app proxy. Shopify forwards each of those requests to us together with the visitor's IP address and browser information. We process the IP address transiently, in memory only, to rate-limit lookups, and we do not store it, log it, or link it to anything else. Nothing about a visitor is written to our database.

Legal basis for processing

Providing the app to you: Article 6(1)(b) GDPR, performance of our contract with you as a merchant, covering batch tracking, material use, and linking orders to batches.

Order data we access: we do this only as your processor, on your documented instructions under Article 28 GDPR; your own legal basis as the controller governs that data.

Keeping the service safe: Article 6(1)(f) GDPR, our legitimate interest in security, abuse prevention and rate limiting, balanced against your and your customers' rights.

Legal obligations: Article 6(1)(c) GDPR, for example when we act on Shopify's mandatory privacy webhooks.

How we use it

We use this data solely to provide the app's features: creating production batches, tracking their material use, generating batch labels, linking orders to the batch they came from, writing that batch's batch number back onto the order as a tag, and, when you upload one, saving a photo to a batch's public Passport in your own Shopify Files. We do not use your data for advertising, and we do not sell or share it.

The visitor IP addresses that reach us with public-page requests are used for one purpose only, limiting how many batch lookups a single source can make per minute, so that batch numbers cannot be enumerated. They serve no other purpose.

Cookies and local storage

The app uses only what it needs to function. Inside the Shopify admin, a strictly necessary session cookie keeps you signed in to the app. In your browser we use local storage to remember your preferences: your chosen language and which in-app tips you have dismissed.

The app sets no tracking cookies. We do not use advertising cookies, cross-site trackers, or any third-party analytics.

The public Batch Passport and batch lookup pages set no cookies at all and load no third-party resources, fonts included. A custom font, if you configure one, is served from your own Shopify Files. Those pages are also marked noindex and are served with no-store, so they are neither indexed by search engines nor cached.

Storage, security and encryption

Your data is stored in a managed PostgreSQL database. The Shopify access and refresh tokens that let the app act on your behalf are encrypted at rest with AES-256-GCM.

Data in transit is protected with TLS. Access to production data is limited to what is needed to operate and support the service.

Where your data is stored and international transfers

We store your data on infrastructure located in the European Union (a managed database in Frankfurt, Germany, and application hosting in an EU region). We do not transfer your data outside the EU ourselves.

Shopify, as the platform your store runs on, may process data outside the EU under its own data processing terms and the European Commission's Standard Contractual Clauses, which you accepted when you started using Shopify.

Sub-processors

We use a small number of carefully chosen sub-processors, each bound by a data processing agreement: Shopify (the platform your store and orders live on), Neon (our managed PostgreSQL database provider, hosting data in the EU) and Railway (our application hosting provider, running in an EU region). We do not share your data with any other third parties, and we never sell or rent it.

Retention

We keep your data for as long as the app is installed. When you uninstall, Shopify sends a shop-redaction request about 48 hours later and we permanently delete all your data. Because we store no customer personal data, a customer redaction request has nothing to erase. You can also contact us at support@keomakindl.at to request earlier deletion.

Your rights

Under the GDPR you and your customers have the right to access, rectify, erase, restrict and object to the processing of personal data, and to data portability. You can trigger full deletion by uninstalling the app. Customer access and deletion requests flow through Shopify's standard privacy webhooks, which we honor automatically; since we hold no customer personal data, there is nothing for us to return or erase. You can also contact support@keomakindl.at to exercise any right directly.

We do not carry out automated decision-making or profiling that produces legal or similarly significant effects. If you believe we have handled your data unlawfully, you have the right to lodge a complaint with a data protection supervisory authority in the EU, in particular in the country where you live, work, or where the alleged infringement took place.

Children's data

The app is a business tool for merchants and is not directed at children. We do not knowingly process the personal data of children.

Changes to this policy

We may update this policy. The effective date above always reflects the current version, and we will reflect any material change here.