Back to Home

GDPR Compliance

Attributify is committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR).

Our Commitment to GDPR

As a Shopify app that processes merchant data, we take our responsibilities under GDPR seriously. We have implemented technical and organizational measures to ensure compliance with data protection regulations.

Punde Commerce LLC acts as a data processor when handling your store data on behalf of you (the data controller). For our own business operations, we act as a data controller.

Data We Process

Data We Collect

  • Product information (titles, handles, vendors, options, tags)
  • Attribute mappings you configure
  • Mapping rules you create
  • Filter configurations
  • Audit logs of app activity

Data We Do NOT Collect

  • Customer personal information
  • Payment or financial data
  • Order details or transactions
  • Customer browsing behavior
  • Marketing or tracking data

Legal Basis for Processing

We process your data based on the following legal grounds:

  • Contract Performance: Processing necessary to provide our services as agreed when you install and subscribe to Attributify.
  • Legitimate Interests: Processing necessary for our legitimate business interests, such as improving our services and ensuring security.
  • Legal Obligations: Processing required to comply with applicable laws and regulations.

Your Rights Under GDPR

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights:

Right to Access

Request a copy of all personal data we hold about you and your store.

Right to Rectification

Request correction of any inaccurate or incomplete personal data.

Right to Erasure

Request deletion of your personal data ("right to be forgotten").

Right to Portability

Receive your data in a structured, machine-readable format.

Right to Object

Object to processing of your personal data for certain purposes.

Right to Restrict

Request restriction of processing under certain circumstances.

Shopify Mandatory Compliance Webhooks

We comply with Shopify's mandatory privacy webhooks to handle data subject requests:

customers/data_request

When a customer requests their data, we provide all relevant information to the store owner.

customers/redact

When a customer's data must be deleted, we remove any customer-related information from our systems.

shop/redact

Within 48 hours of app uninstallation, we receive this webhook and delete all store data within 30 days.

Data Security Measures

We implement appropriate technical and organizational measures to protect your data:

  • Encryption in transit (TLS 1.2+) and at rest
  • Data isolation between merchants
  • Regular security audits and vulnerability assessments
  • Access controls and authentication requirements
  • Secure cloud infrastructure with compliance certifications

International Data Transfers

Our services are deployed across multiple regions to ensure low latency and reliability:

  • US East (Virginia) - North America
  • Frankfurt - Europe
  • Mumbai - South Asia
  • Sydney - Oceania
  • São Paulo - South America

If you are located in the EEA, UK, or Switzerland, your data may be transferred to and processed in other regions based on routing.

We ensure appropriate safeguards are in place for international transfers, including Standard Contractual Clauses (SCCs) where required by applicable law.

Data Retention

We retain your data only for as long as necessary:

  • Active accounts: Data is retained while your app subscription is active.
  • After uninstallation: All data is deleted within 30 days of receiving the shop/redact webhook.
  • Legal requirements: Some data may be retained longer if required by law (e.g., billing records).

Exercise Your Rights

To exercise any of your GDPR rights or if you have questions about our data practices, please contact our privacy team.

We will respond to your request within 30 days as required by GDPR.