Privacy Policy
Last updated: 11 July 2026
1. Controller
The controller responsible for data processing under the General Data Protection Regulation (GDPR) is:
Suplify UG (haftungsbeschränkt)
Alte Weseler Straße 18
46569 Hünxe, Germany
Email: info@suplify.app
This privacy policy applies to the use of the website www.suplify.app and the Suplify app within the Shopify ecosystem.
2. General Information on Data Processing
Protecting your personal data is important to us. We process your data confidentially and in accordance with the applicable data protection laws, especially the GDPR and the German Telecommunications and Telemedia Data Protection Act (TDDDG).
3. Data Collection on the Website
When visiting our website, the web server automatically collects information transmitted by your browser (so-called server log files). This includes the browser type and version, the operating system used, the referrer URL, the hostname of the accessing device, and the time of the server request. The processing is based on Art. 6 (1) lit. f GDPR to ensure technical stability and security.
4. Cookies and Tracking Technologies
Until you consent, no optional service listed below is loaded. You can consent separately to Analytics (Clarity/Vercel), Marketing (Google Ads/Klaviyo), and Functionality (Wistia/Crisp), or reject all optional services. No category is preselected and only services in enabled categories receive data.
Consent preference (strictly necessary): we store the first-party cookie “suplify_cookie_consent” for up to 12 months. It records which of the Analytics, Marketing, and Functionality categories you enabled, without a visitor identifier. Legacy “all” and “necessary” choices remain respected. Access is necessary to provide your requested privacy settings (§ 25(2) no. 2 TDDDG); related processing is based on Art. 6(1)(c) and (f) GDPR. Server logs may contain IP address, request time, URL, referrer, browser/device information and response status for security and delivery; they are not combined with marketing profiles.
Optional services are activated only on the basis of your consent under Art. 6(1)(a) GDPR and, where information is stored on or read from your device, § 25(1) TDDDG. Providers may receive data in the USA. Transfers are based, where available, on an EU adequacy decision under the EU–US Data Privacy Framework (Art. 45 GDPR) and otherwise on EU Standard Contractual Clauses (Art. 46 GDPR).
- Google Ads conversion tracking (Google tag AW-17848889113): Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; possible recipient Google LLC, USA. After consent, Google may process IP address, browser/device data, page URL, referrer, timestamps, ad-click identifiers (for example GCLID) and conversion/interactions data to attribute and measure advertising and, if enabled in the Google account, personalize ads. Google may set “_gcl_” cookies for up to 90 days. Google Ads account/reporting data is retained according to Google’s configured and published retention rules. Provider privacy notice
- Microsoft Clarity: Provider for EU users: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland; Microsoft affiliates in the USA may receive data. After consent, Clarity records page views and interaction data such as clicks, scrolling, pointer movement, navigation, approximate location, IP address and browser/device data to create session replays and heatmaps and improve usability. Sensitive page content should be masked. Clarity uses pseudonymous identifiers including “_clck” and “_clsk”. Playback data is normally retained for 30 days; click/heatmap and favorited or labeled session data may be retained for 13 months. Provider privacy notice
- Vercel Web Analytics: Provider: Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. After consent, Vercel processes page URL and route, filtered query parameters, referrer, timestamp, approximate location, operating system, browser and device type for aggregated traffic statistics. Vercel states that it uses no tracking cookies, does not store IP addresses or persistent cross-site identifiers, and discards the temporary visitor hash after 24 hours. Provider privacy notice
- Wistia video player: Provider: Wistia, Inc., 17 Tudor Street, Cambridge, MA 02139, USA. The player is not loaded before consent. When loaded, Wistia receives IP address, browser/device and request data and video events such as start, pause, viewing duration and completion to deliver the video and measure engagement. The player can use local storage; optional integrations may use identifiers. Wistia states that logs of unknown users are generally retained for 30 days; data linked to known users or customer media may be retained longer under its policy. Provider privacy notice
- Crisp support chat: Provider: Crisp IM SAS, France. The chat is loaded only after consent and may process IP address, page URL, browser/device identifiers and usage events. If you send a request, we additionally process the information you voluntarily provide, such as name, email address and message, to answer it (Art. 6(1)(b) GDPR for pre-contractual requests or Art. 6(1)(f) GDPR for efficient support). Support data is retained only as long as required for the request, contractual/legal duties and the provider’s documented retention rules. Provider privacy notice
- Klaviyo onsite marketing: Provider: Klaviyo, Inc., 125 Summer Street, Boston, MA 02110, USA. After consent, Klaviyo may process IP address, browser/device and referral data, pages viewed, active-on-site and form interactions, and—once you identify yourself by submitting a form or following a Klaviyo message link—email/phone and profile-linked browsing events for newsletter forms, campaign measurement and marketing personalization. The “__kla_id” identifier may last up to two years; optional anonymous activity may be held in browser storage for up to 14 days before identification. Provider privacy notice
You may change or withdraw any category at any time through “Cookies” in the footer. Withdrawal is as easy as granting consent and does not affect prior lawful processing. If an enabled category is disabled, the site reloads to terminate its third-party code. The website remains usable without optional services.
We do not make decisions producing legal or similarly significant effects about website visitors solely by automated means under Art. 22 GDPR.
5. Contacting Us via Website
When using our contact form or support chat, we process the personal data you provide (e.g., name, email address, message) to handle your inquiry. The legal basis is Art. 6 (1) lit. b GDPR (pre-contractual measures) or lit. f (legitimate interest in effective communication).
6. Use of the Suplify App (Shopify)
When installing and using the Suplify app, we process the following data of Shopify store owners: company name, business address, contact details, Shopify store domain, and billing information via the Shopify Billing API. This data is necessary for providing and billing the app. Legal basis: Art. 6 (1) lit. b GDPR.
7. Processing End Customer Data (via the App)
When using the app, Suplify also processes personal data of the end customers of the respective Shopify stores (e.g., name, address, phone number, order details) in order to forward orders to our production and logistics partner for manufacturing, packaging, and shipping. Suplify acts as the controller under Art. 4 (7) GDPR in this regard.
8. Data Sharing with Third Parties and International Transfers
Personal data is only shared in accordance with legal requirements and to fulfill contractual obligations. This includes the following recipients:
- Manufacturing and fulfillment partners (EU)
- Hosting providers (EU)
- Payment processors (EU/USA with appropriate safeguards)
- Shipping providers (EU)
- Marketing and analytics services (only with consent, EU/USA with appropriate safeguards)
- Customer support tools (EU/USA with appropriate safeguards)
For providers based outside the EU (e.g., USA), data is transferred under the standard contractual clauses pursuant to Art. 46 (2) lit. c GDPR or based on the EU-US Data Privacy Framework if the provider is certified.
9. Data Retention
We retain personal data only as long as necessary for the respective purposes or as required by law. Contact data is deleted once the request is resolved. Data relevant for tax or commercial law is stored for 6 or 10 years in accordance with §§ 147 AO and 257 HGB.
10. Data Subject Rights
You have the right to request access to your data (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and to object to processing (Art. 21). If you have given consent to processing, you may withdraw it at any time with future effect. You also have the right to lodge a complaint with a data protection authority under Art. 77 GDPR.
11. a. Data Security
We implement appropriate technical and organizational security measures to protect your personal data against manipulation, loss, destruction, or unauthorized access. Our website and app use SSL encryption.
11. b. Security Incidents and Data Breaches
We maintain a documented Security Incident Response Policy that governs the detection, containment, investigation, and notification of security incidents. If a confirmed breach of security leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data ("Data Breach"), we will:
- Detect & Assess – Immediately identify the incident and assess risks to the confidentiality, integrity, and availability of the data concerned.
- Contain & Remediate – Take prompt actions to limit impact and restore system security.
- Notify Supervisory Authority – Where legally required, report the breach without undue delay and, in any event, within 72 hours of becoming aware of it, in accordance with Art. 33 GDPR.
- Inform Affected Individuals – Notify data subjects without undue delay if the breach is likely to result in a high risk to their rights and freedoms (Art. 34 GDPR).
- Document & Prevent – Log every incident and response step, and implement corrective measures to prevent recurrence.
- Contact – Questions regarding security incidents can be directed to info@suplify.app.
12. Updates to this Privacy Policy
We reserve the right to update this privacy policy at any time. The current version is always available on our website.