SafetyLoop — Privacy Policy

Last updated: [date of actual publication, not this draft date]

SafetyLoop is a Shopify compliance-audit app, developed and operated by Offsite OÜ (registry code 14061956), Estonia, EU.

Data the app accesses

To audit your store, SafetyLoop reads:

SafetyLoop does not request or store your customers' names, email addresses, phone numbers, shipping addresses or order history. The audit engine's own design confirms this: no customer/order query exists in the codebase (products/eu-compliance/audit.py, confirm.py — no customers or orders API calls). Re-confirmed 2026-10-10 (lane L5) against the real installed app's actual Admin API scopes: lanes/L1/BRIEF.md and the live token (lanes/L1/private/admin_token.json) show scope write_products only (plus the default read_products) — no customer or order scope was requested or granted.

Data you (the merchant) provide

You may upload supplier-provided safety data (manufacturer name and address, responsible-person details, product identifiers, safety warnings) via a CSV or JSON file. This is data about your products and suppliers, not about your customers. SafetyLoop stores your explicit evidence reference for each fact and never invents or guesses a value you did not provide (products/eu-compliance/README.md, "Supplier contract" section).

Data the app stores

Hosting: Fly.io, Frankfurt (EU) region, same organization as HyreKit (eu-app/HOSTING.md, sourced 2026-10-10 from fly.io's own pricing docs) — live: https://eu-compliance-autopilot.fly.dev (L1c part B, deployed and verified 2026-10-10).

How the data is used

Solely to run the compliance audit and show you its results. Never sold, rented or used for advertising. Supplier facts you upload are not used to train any model; today's engine makes zero AI/model calls at all (confirmed by grep, see CLAIMS.md rows 15-16) — if an AI auto-fill feature ships later, this policy must be updated before that feature is turned on, not after.

Subprocessors

Mandatory Shopify compliance webhooks

SafetyLoop automatically answers customers/data_request, customers/redact and shop/redact with a verified HMAC (confirmed live 2026-10-10, lanes/L1c/RESULT.md; eu-app/SUBMISSION-GAP.md row closed). Since this app does not hold customer PII in the first place, data-request/redact responses mostly confirm "nothing held"; shop/redact deletes your shop's audit history and confirmed records.

Retention and deletion

Data is kept while the app is installed. Uninstalling triggers Shopify's shop/redact webhook, which deletes your shop's audit history and confirmed records.

Security

All traffic encrypted in transit (TLS). Stored data accessible only to the app and its operator (Offsite OÜ).

Your rights

Under the EU GDPR, merchants may request access, correction or deletion of data held about them. Contact us and we will respond within one business day (EET/EEST) — same commitment as the HyreKit precedent.

Contact

Offsite OÜ · Estonia, EU · allie@offsite.ee · Registry code 14061956. (A dedicated safetyloop@offsite.ee alias is planned — see SUPPORT.md B.4; until created, use allie@offsite.ee.)