Legal
Last updated: July 23, 2026
BatchProof is a Shopify app that helps supplement, CBD, and cosmetics brands manage Certificates of Analysis (COAs) — the lab reports that back up product batch testing — and publish them for customer lookup. This policy explains what data BatchProof collects when a merchant installs the app, and how that data is stored, used, and deleted.
Questions about this policy or your data can be sent to support@batchproof.app.
When a merchant installs BatchProof, we store the data needed to run the app on their store:
On the Shopify side, BatchProof requests a single access scope: write_products. It is used to let merchants pick products from their catalog and to display product titles next to batches inside the app. BatchProof does not request access to customers, orders, or any other store data.
BatchProof's public batch lookup page is used by a merchant's end customers to look up a COA by batch number. We do not collect or store any personal information from these visitors. Specifically, a public lookup records only an internal shop id, an internal batch id, and a timestamp — never an IP address, cookie, email address, name, or any other identifier of the person looking it up.
Batch metadata, audit logs, and shop records are stored in a managed Postgres database (Neon, hosted on AWS in the eu-central-1 region, Frankfurt). COA PDFs and merchant logo files are stored in Cloudflare R2 object storage, provisioned in the EU jurisdiction. All data in transit between a merchant's browser, Shopify, and our servers is encrypted with TLS. Shopify session data (used for authenticating the embedded admin app) is handled through Shopify's official application libraries.
We rely on a small number of infrastructure providers to run BatchProof:
We do not sell merchant or shop data to any third party, and we do not use stored COA content to train models.
Data is kept for as long as the app remains installed on a shop. When a merchant uninstalls BatchProof, Shopify sends an app-uninstalled notification followed by a shop/redact webhook approximately 48 hours later; on receiving it, we erase all data associated with that shop — database rows, stored COA PDFs, and any uploaded logo. Merchants can also delete individual batches (and their COA files) at any time from within the app, without waiting for uninstall.
BatchProof also acknowledges Shopify's customers/data_request and customers/redact GDPR webhooks. Since we do not store any personal data about a merchant's end customers (see Section 3), there is no customer data for us to export or delete in response to these requests.
If you are a merchant using BatchProof, you can view or delete your batch data at any time via the app's batch list, and uninstalling the app triggers full deletion as described above. If you believe BatchProof holds data about you that shouldn't be there, or you have any question about this policy, contact us at support@batchproof.app and we will respond promptly.
Merchants in the EU/EEA and other jurisdictions with data protection laws (such as GDPR) have rights to access, correct, and erase their data — the mechanisms above (in-app deletion and the uninstall/redact flow) are how those rights are fulfilled for BatchProof.
Separately from the Shopify app, the marketing site at batchproof.app uses cookieless, privacy-friendly analytics (GoatCounter), which is not connected to the Shopify app's data. If you joined our pre-launch waitlist (processed via Formspree), we keep your email address only to send launch and founding-pricing announcements; to have it deleted, email support@batchproof.app.
If we make material changes to this policy, we will update the "Last updated" date above. Continued use of the app after a change means you accept the updated policy.