Last update: 1 September, 2026
Who we are
This app ("bKlug FAQ Audit", the "App") is provided by MENSAGENS ELÍPTICAS - LDA. (trading as "bKlug"), a company registered in Portugal, Tax Identification Number PT517467739, with registered address at Rua Sousa Martins, nº 15, 5, 1050-217 Lisbon, Portugal.
For the data this App processes, bKlug acts as a data processor on behalf of the merchant (the Shopify store owner), who is the data controller for their store.
What the App does
The App reads store content the merchant selects, compares it against the shipping and delivery settings actually configured in Shopify, and reports where the two contradict each other. It then helps the merchant write the answers and produces a report they can download.
The App has read-only access to Shopify. It cannot and does not edit the merchant's pages, policies, settings or any other part of their store. Corrections a merchant makes while working through their report change the report, not their Shopify content.
Data we collect
From the merchant's store
With the merchant's permission, and only for the sources they tick before starting an audit, the App reads: store policies (refund, privacy, terms, shipping, contact, legal notice), Online Store pages, shipping and delivery profiles, metaobjects, the markets the store sells to, and the store's languages. It also reads the store's myshopify domain and basic identification, and an access token used to authenticate the App with Shopify.
The App does not request access to, and cannot read, products, orders, customers, or any other protected customer data. There is no scope in the App's configuration that would permit it, and no code path that would use one.
A merchant may also paste the address of a public page on their own storefront. The App then fetches that page as any visitor would, and reads only what the page publicly shows.
From the merchant
The store owner's email address, read from Shopify at install and editable in the App, so that monitoring results can be sent where the merchant wants them. Monitoring emails can be switched off in the App, individually, at any time.
The answers, decisions and notes the merchant writes while working through their report.
From store visitors (shoppers)
None. The App has no storefront component, sets no cookies on the merchant's storefront, and never runs on a shopper's device. It is used entirely inside the Shopify admin by the merchant.
How the content is analysed
The store content selected for an audit is sent to a large language model to find contradictions between pages and to draft answers. The model is operated by Microsoft under the Azure OpenAI Service, which does not use the content sent to it to train models.
What is sent is the merchant's own published store content and their Shopify shipping configuration. Quotations kept in the report are reproduced exactly as they appear on the merchant's own pages, because a quotation the merchant cannot check against their own page is not evidence.
Why we process this data (legal basis)
We process the data above to provide the App the merchant installed and to keep it functioning. The legal basis is the performance of a contract and our legitimate interest in operating the service under the GDPR.
Sub-processors
Shopify Inc. provides the app platform, authentication, billing, and the Admin API the App reads through. Vercel Inc. hosts the App's admin interface and runs its scheduled jobs. Railway Corp. hosts the audit service, its PostgreSQL database and its job queue, and is where audits and reports are stored. Microsoft Corporation provides the Azure OpenAI Service that analyses the store content. Twilio Inc. (SendGrid) delivers monitoring emails. Functional Software, Inc. (Sentry) receives application error reports.
Vercel, Railway, SendGrid and Sentry operate in the United States. Each processes data only as needed to provide its service.
Payments
All charges are made through Shopify's own billing, and appear on the merchant's Shopify invoice. bKlug never sees, receives or stores card or bank details.
Data retention
Audits, reports and the monitoring baseline are retained while the App is installed, so that a merchant keeps access to reports they have paid for. Uninstalling the App stops all processing immediately: monitoring checks end and the App's access to the store is revoked by Shopify.
When Shopify sends the shop data-erasure request that follows an uninstall, we delete that store's audits, stored reports and monitoring data outright rather than flagging them, because a stored report contains the merchant's own policy text.
Data subject rights
Store visitors: the App collects no visitor personal data, so there is no visitor data for us to access, correct or delete.
Merchants and individuals whose data we process may request access, correction, deletion or portability, and may object to or restrict processing, by contacting us at contact@bklug.ai.
We respond to Shopify's mandatory data-request, customer-redact and shop-redact webhooks. Because the App holds no shopper personal data, our response to the customer-data and customer-redact requests confirms that no such data is held.
International transfers
Data may be processed in the European Union and in other countries where our sub-processors operate. Where data leaves the EU or EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
Security
We use industry-standard measures to protect the data we process, including encrypted transport (HTTPS) throughout, signed and time-limited authentication between the App and the audit service, and access controls on our hosting environments.
Changes to this policy
We may update this policy as the App changes. The "Last update" date above reflects the latest version. Material changes affecting how we process data will be communicated through the App listing.
Contact
Questions about this policy, or a request about your data, can be sent to contact@bklug.ai.