Privacy Policy
This policy is written to be read, not skimmed past. It is short because the app is built to know as little as possible.
1. Who we are
JINGA SIA ("we") is a software studio registered in Riga, Latvia. We make Energy Label Autopilot, a Shopify app that helps merchants show EU energy labels on their stores. We are the data controller for the processing described here. Contact: support@jinga.dev.
2. What this policy covers
The Energy Label Autopilot app, and this website (jinga.dev).
3. What the app processes
- Store and account data. When you install the app, Shopify sends us your shop's
.myshopify.comdomain and an API access token, which we store to operate the app. When a staff member opens the app in the Shopify admin, Shopify's sign-in may also provide that person's name, email address and language, which are stored as part of the session. - Product data. To match products against EPREL, the app reads product titles, vendors, SKUs, barcodes, tags and descriptions through Shopify's API. Results are written back into your own store as product metafields (EPREL registration number, energy class, product group and related fields). We do not keep a copy of your catalogue on our servers.
- Billing status. Your plan and any charges are handled by Shopify's Billing API. We see which plan your store is on. We never see a payment method.
- Support email. If you write to us, we receive what you send, and keep it as ordinary correspondence.
4. What the app never processes
Data about your customers. The app does not request access to customers, orders, or any personal data of your shoppers, and Shopify's permission system prevents it from reading them. This is deliberate, and the app is built to depend on it: if a future version ever needed more access, Shopify would ask you to approve the new permission, and this policy would change first.
5. Why we process it, and on what legal basis
To provide the service you asked for by installing the app — auditing your catalogue's label coverage, matching products against EPREL, writing and maintaining label metafields, revalidating them nightly, and answering support. The legal basis is performance of a contract (Art. 6(1)(b) GDPR). We do not use your data for advertising, we do not profile anyone, and we do not sell or share data with third parties for their own purposes.
6. Where your data lives
The app and its database run on Render in Frankfurt, Germany. Support email is hosted by Zoho in their EU data centres. Our providers are bound by data-processing agreements; where a provider's corporate group is outside the EU, transfers are covered by EU standard contractual clauses.
7. How long we keep it
- Access token and session data: until you uninstall. Shopify notifies us of the uninstall and we delete them.
- Label metafields: they live in your store, not on our servers, and Shopify removes the app's metafields when the app is uninstalled.
- Support correspondence: kept as ordinary business email.
The app implements Shopify's three mandatory privacy webhooks. Because we hold no data about your customers, a customer data request or customer redaction finds nothing in our systems to return or erase; the shop redaction notice that follows an uninstall arrives after the deletions above have already happened.
8. Who else is involved
- Shopify — the platform the app runs on; it processes your store's data under its own terms and policy.
- Render — hosting and database, Frankfurt region.
- Zoho — support email, EU data centres.
- EPREL (the EU's public product registry, run by the European Commission) — we build our matching index from EPREL's published data files; nothing about you or your store is ever sent to it by our servers. One storefront exception: when a shopper opens the energy label, their browser loads the official label image and product information sheet directly from eprel.ec.europa.eu, the same way any image on a web page is loaded. That request goes from the shopper's browser to EPREL and never passes through our servers.
9. This website
jinga.dev sets no cookies and runs no analytics or tracking of any kind. Our host processes standard server logs (IP address, requested URL, user agent) to deliver and secure the site.
10. Your rights
Under the GDPR you can ask for access to, correction of, or deletion of your personal data, ask us to restrict or object to processing, and ask for a portable copy. Write to support@jinga.dev and we will answer within a month. You can also complain to a supervisory authority — in Latvia, the Data State Inspectorate (Datu valsts inspekcija, dvi.gov.lv), or the authority in your own country.
11. Changes
If this policy changes, the new version appears here with a new effective date. A change that matters to you — anything beyond wording — will be announced inside the app before it takes effect.