DULDUL.PL - Radosław Dul, a sole trader registered in Poland. Tax identification number (NIP) 6282163301, statistical number (REGON) 122519615 — both resolve to the full entry in the public Polish business registers. For anything about personal data, write to app@ddapps.pl.
This app is a tool for merchants using Shopify. For the personal data of a merchant's own buyers, the merchant remains the controller and we act on their instructions.
Only what the app has been granted, and only what the feed needs. The app does not request access to customers or orders, and has no way to read them.
| Access | What for |
|---|---|
read_products | Titles, descriptions, prices, images, identifiers and variant options — the content of the feed itself. |
read_inventory | Stock levels, which decide an offer's availability value. |
Worth saying first what we do not store: no data about a merchant's buyers, because the app cannot read any. The merchant's own email address is read from Shopify at the moment a notification is sent and is not written down.
| Data | Kept |
|---|---|
| Shop domain, plan, feed settings and category mappings | Until the app is uninstalled and Shopify asks us to erase the shop |
| Feed run history: time, duration, number of products and offers, errors | 90 days |
| List of products left out of a feed, with their titles at the time | 90 days, with the run it belongs to |
| The generated feed file | Until the next generation replaces it |
| Shopify access token | For as long as the app is installed |
| Server logs | 30 days, then rotated out |
Ceneo.pl reads the generated feed from an address the merchant gives them. We do not send anything to Ceneo ourselves — the merchant decides whether to hand over the address, and the feed contains product data, not personal data.
| Processor | Role | Where |
|---|---|---|
| Hetzner Online GmbH | Hosting of the app and its database | Germany (EEA) |
Data is not transferred outside the European Economic Area.
We answer the three requests Shopify forwards on a buyer's or merchant's behalf:
The app can place the following in the storefront, each only when the merchant turns it on:
| What | Why | Cookies | Consent |
|---|---|---|---|
| Ceneo widget (ssl.ceneo.pl/shops/sw.js) | Shows the shop's Ceneo rating as a badge. Placed only when the merchant turns it on in the app and enables the app embed in their theme. | ceneo_cid — a visitor identifier set by Ceneo | Marketing. By default the script waits for consent; the merchant can turn that off in the app settings. |
All traffic runs over TLS. Access tokens are held only in Shopify's session mechanism and are never written to logs. Access to the server is limited to the operator named above.
The effective date at the top changes with the text. Changes that affect what we collect or who receives it are announced in the app before they take effect.
app@ddapps.pl
DULDUL.PL - Radosław Dul, jednoosobowa działalność gospodarcza. NIP 6282163301, REGON 122519615 — oba prowadzą do pełnego wpisu w publicznych rejestrach. W sprawach danych osobowych: app@ddapps.pl.
Aplikacja jest narzędziem dla sprzedawców korzystających z Shopify. W zakresie danych kupujących w sklepie sprzedawcy administratorem pozostaje sprzedawca, a my działamy na jego zlecenie.
Tylko te, na które aplikacja ma uprawnienia, i tylko te, których potrzebuje feed. Aplikacja nie prosi o dostęp do klientów ani zamówień i nie ma możliwości ich odczytania.
| Uprawnienie | Po co |
|---|---|
read_products | Nazwy, opisy, ceny, zdjęcia, identyfikatory i opcje wariantów — czyli treść feedu. |
read_inventory | Stany magazynowe, które decydują o dostępności oferty. |
Warto zacząć od tego, czego nie przechowujemy: żadnych danych kupujących w sklepie sprzedawcy, bo aplikacja nie może ich odczytać. Adres e-mail samego sprzedawcy pobieramy z Shopify w chwili wysyłki powiadomienia i nie zapisujemy go.
| Dane | Okres |
|---|---|
| Domena sklepu, plan, ustawienia feedu i mapowania kategorii | Do odinstalowania i żądania usunięcia danych sklepu |
| Historia uruchomień: czas, długość, liczba produktów i ofert, błędy | 90 dni |
| Lista produktów pominiętych w feedzie, z nazwami z chwili generowania | 90 dni, razem z uruchomieniem |
| Wygenerowany plik feedu | Do następnego wygenerowania |
| Token dostępu Shopify | Na czas, gdy aplikacja jest zainstalowana |
| Logi serwera | 30 dni, potem rotowane |
Ceneo.pl pobiera wygenerowany feed spod adresu, który sprzedawca im podaje. Sami niczego do Ceneo nie wysyłamy — o przekazaniu adresu decyduje sprzedawca, a feed zawiera dane produktów, nie dane osobowe.
| Podwykonawca | Rola | Gdzie |
|---|---|---|
| Hetzner Online GmbH | Hosting aplikacji i bazy danych | Niemcy (EOG) |
Dane nie opuszczają Europejskiego Obszaru Gospodarczego.
Obsługujemy trzy żądania przekazywane przez Shopify:
Aplikacja może umieścić w sklepie poniższe elementy — każdy dopiero wtedy, gdy sprzedawca go włączy:
| Co | Po co | Pliki cookie | Zgoda |
|---|---|---|---|
| Ceneo widget (ssl.ceneo.pl/shops/sw.js) | Pokazuje ocenę sklepu w Ceneo jako plakietkę. Umieszczany tylko wtedy, gdy sprzedawca włączy go w aplikacji i włączy blok w motywie. | ceneo_cid — identyfikator odwiedzającego, ustawiany przez Ceneo | Marketing. Domyślnie skrypt czeka na zgodę; sprzedawca może to wyłączyć w ustawieniach aplikacji. |
Cały ruch idzie po TLS. Tokeny dostępu przechowuje wyłącznie mechanizm sesji Shopify i nigdy nie trafiają do logów. Dostęp do serwera ma wyłącznie podmiot wskazany wyżej.
Data u góry zmienia się razem z tekstem. Zmiany dotyczące tego, co zbieramy albo kto otrzymuje dane, ogłaszamy w aplikacji, zanim zaczną obowiązywać.
app@ddapps.pl