SafetyMark Privacy Policy

Last updated: July 22, 2026

SafetyMark is a Shopify app published by Sizzle (“Sizzle,” “we,” “us,” or “our”). This policy explains what information the app accesses, how we store and use it, and the choices you have. It applies to merchants who install SafetyMark on their Shopify store.

SafetyMark helps merchants display the product-safety information the European Union’s General Product Safety Regulation (GPSR, Article 19) asks a product listing to show — the manufacturer, an EU Responsible Person, a product identifier, and safety warnings — and it flags which products are still missing required information. You decide what the details say; SafetyMark provides the fields, the storage, the on-page display, and the checklist.

Summary

In short: SafetyMark works with your products and their safety details and nothing about your shoppers. We request no customer or order permissions, so we never access shopper names, emails, addresses, or orders. The safety content you enter is stored inside your own Shopify store, not on our servers — the only data we keep is a secure session and a small record of whether we’ve shown you the in-app review prompt. Our data is stored in the United States, we use only three service providers (Neon, Netlify, and Shopify), and we run no tracking or advertising cookies. When you uninstall, everything is removed cleanly.

Information we access

To do its job, SafetyMark connects to your store through Shopify’s API and works with:

  • Your store domain and a Shopify access token: used to connect securely to your store and make Shopify API calls on your behalf. The token is never shared.
  • Your products and their safety details: read and saved so you can record each product’s manufacturer, EU Responsible Person, product identifier, safety warnings, pictogram images, and whether the product is out of GPSR scope — and so the app can check which products are missing required information.
  • Your files: to attach the safety pictogram images you choose (for example CE, age, WEEE, or hazard symbols) to a product.
  • Your markets and translations: so safety warnings can be shown in the buyer’s language.
  • Your theme: read-only, to confirm the Product Safety block is turned on so the details appear on your product pages.

What we store, and where

SafetyMark deliberately keeps almost nothing on its own servers.

  • Your safety content stays in your store. All of the product-safety content you enter — manufacturer and Responsible Person records, warnings, identifiers, pictograms, and exemptions — is stored inside your own Shopify store as metaobjects and metafields, not on our servers. It stays with your store and is removed with the app when you uninstall.
  • On our servers we keep only two things: the secure session that lets the app communicate with your store, and a single small record noting whether we have shown you the in-app “leave a review” prompt (so we don’t ask repeatedly). Neither of these contains customer information.

Information we do not collect

SafetyMark does not access, process, or store any customer or shopper personal data. The app requests no customer or order permissions from Shopify, so it has no API access to shopper names, email addresses, mailing addresses, payment details, or order records. We do not run analytics or profiling, and we do not sell or share data for advertising.

Shopify permissions we request

SafetyMark requests only the permissions it needs to store, display, and audit your products’ safety information, and it includes no customer or order scopes:

  • read_products, write_products — to read your products and save each one’s safety details, and to check which are missing required information.
  • write_metaobjects, write_metaobject_definitions — to create and manage the reusable Manufacturer and Responsible Person records in your store.
  • write_files — to attach the safety pictogram images you choose to a product.
  • read_markets, write_translations — to show safety warnings in the language of each market you sell into.
  • read_themes — read-only, to confirm the Product Safety block is enabled on your product pages.

How we use your information

We use the information described above only to provide the SafetyMark service: to store the safety details you enter, to display them on your product pages through a theme block, to audit your catalog for missing required information, to show warnings in the right language, and to manage your subscription status. We do not use your data for any other purpose.

Cookies and your storefront

SafetyMark is a standard embedded Shopify app built with Remix, Polaris, and App Bridge. It sets only the functional session cookies required by Shopify’s authentication and embedded app framework. It uses no analytics, advertising, or tracking cookies.

The app is used only by you inside the Shopify admin. The safety information it shows on your storefront is a theme app block served by Shopify — it collects no personal information about your shoppers, and Shopify removes it automatically if you uninstall.

Where your data is stored

The session and review records described above are stored and processed in the United States (AWS US East, us-east-1), in a Neon Postgres database, and the application runs on Netlify. Your product-safety content is stored by Shopify as part of your store.

Service providers

We keep our list of service providers small. The following third parties process data on our behalf or as part of delivering the service:

  • Neon: the Postgres database that stores the app session and review record.
  • Netlify: application hosting and serverless functions.
  • Shopify: the source of your store data, the store of your product-safety content, and the processor of all billing through the Shopify Billing API.

We use no other subprocessors. There is no separate analytics, error tracking, email, advertising, or payment provider.

Billing

Billing for SafetyMark is handled entirely through Shopify using the Shopify Billing API (Managed Pricing). We do not use an external payment processor, and we do not receive or store your payment card details.

Data retention and deletion

When you uninstall SafetyMark, your session and access token are deleted immediately. Shopify then sends a shop redaction request about 48 hours after uninstall, at which point we permanently erase the remaining session and review records we hold for your store. Effective retention after uninstall is therefore about 48 hours, followed by complete deletion. You can also request deletion at any time by contacting us.

Your product-safety content itself lives in your store’s own Shopify metaobjects and metafields, so it is removed together with the app when you uninstall — nothing is left behind in your theme.

Shopify compliance webhooks

SafetyMark implements all three of Shopify’s mandatory privacy webhooks:

  • customers/data_request: because we store no customer data, there is nothing to return. We log the request.
  • customers/redact: no operation, since there is no customer data to redact. We log the request.
  • shop/redact: we actively purge the session and review records for the shop as described above.

Your rights

Because the safety details SafetyMark works with are your own store’s content, you remain in control of them. You can review and edit them at any time inside the app, and you can trigger deletion of the records we hold by uninstalling SafetyMark, which leads to complete erasure about 48 hours later through Shopify’s shop redaction process.

Depending on where you or your customers are located, data protection laws such as the GDPR and the CCPA may give additional rights, such as the right to access, correct, or delete personal data. Since SafetyMark does not collect shopper personal data, these requests are limited in scope, but you can contact us at any time and we will assist.

Security

We take reasonable measures to protect the data we store. Data is held on managed infrastructure provided by Neon and Netlify, and access is limited to the app’s own functions. No method of storage or transmission is completely secure, so while we work to protect your data we cannot guarantee absolute security.

International users

SafetyMark stores and processes its session and review records in the United States. If you install the app from outside the United States, you understand that this data will be transferred to and processed in the United States.

Children

SafetyMark is a business tool for Shopify merchants and is not directed to children. We do not knowingly collect personal information from children.

Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the date at the top of this page. Your continued use of SafetyMark after an update means you accept the revised policy.

Contact

If you have questions about this policy or how SafetyMark handles data, contact us atcontact@sizzle.so.