Privacy Notice — MatchAudit for Shopify
Effective date: August 27, 2026
This Privacy Notice explains how MatchAudit processes personal data in connection with the MatchAudit app distributed via the Shopify App Store. It explains the distinction between data MatchAudit processes as controller and data processed on behalf of Shopify merchants.
1. Who We Are
MatchAudit UG (haftungsbeschränkt) ("MatchAudit", "we", "us", or "our") provides a sanctions-screening and compliance-evidence application distributed through the Shopify App Store.
MatchAudit is a German company. If you interact with MatchAudit through the App Store listing, our website, contact forms, or support channels, MatchAudit is generally the controller of the personal data processed for those purposes.
MatchAudit UG (haftungsbeschränkt) is located at Turmstrasse 7, 65611 Brechen, Germany, and is represented by Managing Director Emmi Jose. The company is registered in the commercial register under Amtsgericht Limburg a.d. Lahn, HRB 7665.
2. Important Distinction: Controller vs Processor
The App receives order, customer, and fulfillment data from a merchant's Shopify store through the Shopify Admin API and webhooks, at the merchant's instruction (by installing and configuring the App). Two different data-protection roles apply.
- Shop Data received from a merchant's Shopify store. Where the App receives billing/shipping names, addresses, order records, or related identifiers from a merchant's Shop for screening, the merchant generally acts as controller and MatchAudit generally acts as processor on the merchant's behalf.
- MatchAudit business and platform data. For MatchAudit's own account administration with the merchant, billing records held for MatchAudit's own legal obligations, support, security logging, abuse prevention, and legal compliance, MatchAudit generally acts as controller.
If a merchant requires a data processing agreement under Article 28 GDPR, MatchAudit provides a DPA covering the processor activities described above; installing the App and accepting the Terms of Use constitutes agreement to it.
3. Categories of Data We Process as Controller
- Merchant account and Shop data: Shopify shop domain, shop contact details made available during installation, shop-level settings, installed-plan and subscription status, and staff identifiers used to attribute decisions (see Section 5).
- Commercial and billing data: subscription tier, billing interval, usage-record history, processed exclusively through the Shopify Billing API — MatchAudit does not independently collect payment card or bank data.
- Website and support data: contact-form submissions, support communications, and related records where a merchant contacts MatchAudit directly.
- Security and audit data: webhook delivery logs, job-queue records, administrative changes, and similar operational records needed to run the App reliably.
4. Categories of Data We Process on Behalf of Merchants (Shop Data)
Depending on which modules a merchant enables, the App receives from the merchant's Shopify store:
- billing and shipping party names, and company names where present, from orders;
- customer records (name, and where applicable other identifiers exposed via the
customers/create/customers/updatewebhooks); - order and fulfillment identifiers and status needed to place or release a Fulfillment Hold;
- for the merchant-requested free retroactive report: order date and amount, currency, test/cancel/refund status, payment-gateway name, customer name, email and phone where Shopify supplies them, billing and shipping names and postal addresses, company name, country code, and checkout IP address where available;
- for retrospective review of a non-clear historical result: the reviewer identity, action timestamp, review rationale, and any external case or authority-report reference the reviewer chooses to enter;
- for a merchant-uploaded historical-record CSV: merchant-supplied reference ID, order date and status, amount and currency, customer or company name, postal address, country code, email, and phone where included by the merchant;
- Directory metadata that links repeated screenings of the same customer or order party, including screening status, count, and last-screened or last-decision time;
- where evidence records are enabled: decision rationale, policy acknowledgement, and periodic review records created by the merchant's staff, optionally assisted by AI-drafted rationale.
Ongoing screening queries request names and postal-address fields needed for identity and country-risk screening. The one-time retroactive report also processes the contact, payment-gateway, order-state, and checkout-IP fields listed above so a finding can be identified and evidenced. It does not request payment-card data, bank data, passwords, or customer-account credentials. Shopify may redact fields that have not been approved through its protected-customer-data review.
The App also stores limited data from public sanctions sources, such as listed names, aliases, nationality, date of birth, addresses, source identifiers, source versions, and checksums. This public-source information is used only to explain and evidence a possible match; a listed person's attributes are not treated as attributes of the merchant's customer unless the Merchant independently verifies them.
For this category of data, the merchant is responsible for determining the legal basis, purpose, and scope of processing (this is data about the merchant's own customers, collected under the merchant's own relationship with them). MatchAudit processes such data only to provide the App, in accordance with the merchant's configuration and instructions, applicable law, and the DPA.
Sensitive data. The App is not designed to process special-category data (Art. 9 GDPR) or criminal-offence data (Art. 10 GDPR) — screening is limited to identity/name/address matching against sanctions and export-control lists, and does not include adverse-media or criminal-records screening.
5. Reviewer Identity
Where a merchant's staff member records a screening decision, acknowledges a policy, or completes a periodic review, the App attributes that action to the specific staff member identified by Shopify's own verified session token — never to a value submitted through a form field. This is a data-integrity control, not merely a UI label: the underlying database enforces that a decision record cannot be created without this attribution.
6. Purposes and Legal Bases
Where MatchAudit acts as controller, we process personal data only where we have an applicable legal basis under the GDPR, including performance of a contract (App provisioning, Shopify Billing administration), compliance with legal obligations (tax, accounting, regulatory), legitimate interests (securing the App, preventing abuse, responding to inquiries, defending legal claims), and consent where required for a specific activity.
MatchAudit does not sell Shop Data, share it for cross-context behavioral advertising, or use Customer Data obtained through Shopify to train generalized AI or machine-learning models. We do not use the App for advertising profiling. Service telemetry may be used to maintain and improve the App only in aggregated or de-identified form that cannot reasonably identify a merchant or customer.
7. Merchant Responsibilities for Shop Data
Merchants using the App to screen order and customer data remain responsible for ensuring a lawful basis exists for that processing under their own relationship with their end customers, providing legally required notices to those customers, and responding to data subject rights requests concerning their own customers (except where the App's Shopify privacy-compliance webhook handling applies — see Section 9).
8. Recipients and Service Providers
MatchAudit may disclose or make personal data available to service providers and subprocessors where necessary to operate the App:
- Fly.io (application hosting, Frankfurt, EU);
- Supabase (database and file storage, EU-region project dedicated to this App, separate from MatchAudit's core product database);
- OpenAI Ireland Ltd., where an optional AI-assisted case explanation is requested. The current case-analysis payload is designed to exclude Shopify customer names, street addresses, order IDs, and customer IDs. It can include country, match scores, public sanctions-list names or aliases, public-source identifiers, and other limited evidence needed to explain the case. API requests disable response storage where supported; provider abuse-monitoring retention may still apply under the provider's terms;
- Shopify itself, to the extent Shopify's own platform necessarily receives responses from the App (e.g., Flow trigger payloads, fulfillment-hold API calls) as part of normal API interaction — this is not a subprocessor relationship in the traditional sense, since Shopify is the merchant's own platform, not a vendor MatchAudit selected on the merchant's behalf;
- professional advisers such as lawyers, auditors, and accountants;
- competent authorities, regulators, courts, or law enforcement where legally required.
See our Subprocessors page for details.
9. Shopify Privacy-Compliance Webhooks
The App implements Shopify's three mandatory compliance webhook topics:
customers/data_request— MatchAudit assembles the Shop Data held about the named customer for delivery to the merchant.customers/redact— MatchAudit erases or irreversibly de-identifies the named customer's personal data held in Shop Data, while preserving non-identifying evidence-chain integrity data where necessary.shop/redact— Shopify sends this request after its post-uninstallation waiting period. MatchAudit then erases or irreversibly de-identifies the shop's Shop Data within the period required by Shopify and applicable law, unless a documented legal obligation requires limited retention.
MatchAudit acknowledges valid compliance webhooks promptly and completes the required access or redaction action within 30 days of receipt, unless applicable law requires retention.
10. International Transfers
Primary App compute is configured for Fly.io Frankfurt, and the dedicated Supabase project is configured for an EU region. Vendors and their own subprocessors may provide support, security, routing, backup, or optional AI processing from other countries. Where personal data is transferred outside the EEA without an adequacy decision, MatchAudit uses an applicable transfer mechanism, such as the European Commission's Standard Contractual Clauses, together with supplementary measures where required.
11. Retention
- Free retroactive reports use the merchant-selected retention period (7, 30, 90, or 365 days). For records without sanctions findings, MatchAudit stores only report metadata, a source reference, and a keyed digest rather than a full record copy. The minimum party/contact/address/IP detail required for a sanctions finding is encrypted at rest. Raw uploaded CSV files are parsed in memory and are not retained; accepted rows are encrypted while queued and removed after processing, while rejected rows retain only row number and validation reasons. The scheduled retention process deletes the entire report at expiry, and uninstall handling deletes retroactive reports immediately.
- Shop Data (screenings, Directory metadata, decisions, and evidence records) is retained while the App remains installed so the Merchant can review decisions, re-screen relevant parties, and create evidence exports.
- Private evidence-export files are retained while the App is installed unless removed earlier under an applicable request or retention process. Download links expire after five minutes; expiry of a link does not itself delete the underlying private file.
- Shopify sends
shop/redactafter its post-uninstallation waiting period. MatchAudit completes the authenticated shop-erasure workflow within 30 days of receiving that request, subject to documented legal-retention obligations. - Evidence-chain structure may remain in irreversibly de-identified form where necessary to preserve integrity, but direct Shopify identifiers and encrypted customer name/address data are erased or de-identified through the applicable redaction workflow.
- Controller-side billing, security, and legal-claim records may be retained for the period required by tax, accounting, security, or limitation laws and are then deleted or anonymized.
12. Security
MatchAudit implements technical and organizational measures designed to protect personal data, including row-level security enforced at the database layer keyed to each merchant's shop, AES-256-GCM application-layer encryption of stored customer identity fields and Shopify offline access tokens, encrypted transport, a dedicated low-privilege database role for App runtime queries, authenticated webhook handling, and short-lived signed URLs for evidence-export files stored in a private bucket. No system can guarantee absolute security, but these measures are designed to be appropriate to the nature of the App and the risks involved.
13. Data Subject Rights
Where MatchAudit acts as controller, individuals may have rights under applicable data protection law, including access, rectification, erasure, restriction, objection, or portability, subject to applicable legal limits.
Where MatchAudit acts as processor for Shop Data, requests from a merchant's end customer should generally be directed to the merchant. MatchAudit supports such requests to the extent required by applicable law and the DPA, including through the mandatory webhook handling described in Section 9.
Individuals may also lodge a complaint with a competent data-protection supervisory authority. Exercising a right is subject to identity verification and the exceptions provided by applicable law.
14. Changes to This Notice
MatchAudit may update this Privacy Notice where required by changes in law, Shopify's own requirements, or App design. Material updates will be published with an updated effective date.
15. Contact
MatchAudit UG (haftungsbeschränkt) Turmstrasse 7, 65611 Brechen, Germany Commercial register: Amtsgericht Limburg a.d. Lahn, HRB 7665
Privacy-related inquiries: info@matchaudit.io