This policy explains what personal information Tasdeek handles, why, who else sees it and how long it is kept. It covers the Tasdeek app for Shopify and this website, tasdeek.com.
1. Who we are
Tasdeek is an app for Shopify stores. It gives each physical product unit its own serial number and record, and it provides pages where a store's customers can register a product, check that it is genuine, file a warranty claim, pass the product to a new owner and read a digital product passport.
Tasdeek is run by [LEGAL OWNER NAME], based in [COUNTRY] ("we", "us"). You can reach us at support@tasdeek.com.
Our role and the store's role
The stores that install Tasdeek are called merchants in this policy. When a merchant's customer registers a product or files a claim, the merchant decides what customer information is collected through their store and what it is used for. Tasdeek processes that information for the merchant, on the merchant's instructions. In data protection terms the merchant is usually the controller and we are its processor.
If you bought a product from a store that uses Tasdeek, the store's own privacy policy also applies to you, and the store is your first point of contact about your information.
We decide how information is used, and are responsible for it, in two cases: information about merchants and their staff who use the app, and information sent to us through this website.
2. What we collect
From merchants and their staff
- Store details from Shopify when the app is installed: the store's Shopify address, its main language and time zone, and which Tasdeek plan it is on.
- Details Shopify provides when a staff member opens the app: name, email address and language, and the access tokens the app needs to work with the store.
- Settings the merchant enters, such as a brand name, a support email address, the details of the merchant's own mail server if they choose to use one, a Klaviyo key if they connect Klaviyo, and addresses for webhooks. Mail server passwords and Klaviyo keys are stored encrypted. API keys are stored only in a hashed form that cannot be turned back into the key.
- Store data needed to run the service: products and variants, serial numbers, the orders and order lines that serial numbers are linked to, warranty rules and any product passport information the merchant publishes.
About a store's customers, for the merchant
- Product registration: email address, first and last name, phone number if given, where and when the product was bought, a link to a receipt if given, language, whether the customer agreed to receive marketing (with the time and the wording they agreed to), and a link to the matching customer record in the merchant's Shopify store.
- Order check: to confirm that a registration matches a purchase, Tasdeek reads the email address on the Shopify order the serial number was sold with.
- Ownership: the email address of the current owner, of the previous owner after a transfer, and of the person a transfer link was sent to.
- Warranty claims: contact email address, the description of the problem, photos, videos, documents or links the customer adds, language, and the messages on the claim.
- Sign-in links: customers see their products on a "My products" page by asking for a sign-in link by email. There are no passwords. We keep a short record that a link has been used so it cannot be used twice.
When someone checks a serial number
When anyone scans a label or checks a serial number on the authenticity page, Tasdeek records the serial number, the time, the browser and device type the browser reports, the country when the hosting network supplies it, and a hashed form of the IP address combined with a value that changes every day. We do not store the IP address itself and we do not record precise location. We use these records to spot a serial number that is checked from many different places, which can point to a copied label.
Tasdeek itself does not set cookies or use browser storage on these customer pages. The pages are shown inside the merchant's online store, so the store's own cookies and settings still apply there.
On this website
- Early access form: the email address you enter. We use it only to reply to you about early access. The form sends your address to our support inbox by email; this website does not keep it in a database.
- This website sets no cookies, has no analytics or tracking, and loads nothing from other websites. Cloudflare, which runs this website, handles technical information such as IP addresses to deliver pages and to protect the site from abuse. The early access form limits how often one IP address can send it, using short-lived counters.
3. How we use it
- To provide the service to the merchant: create serial numbers and labels, link serial numbers to orders when they are fulfilled, register products, track warranties, handle claims, transfer ownership, show authenticity results and publish product passports.
- To keep the merchant's Shopify store up to date: when a customer registers, Tasdeek finds or creates the matching customer in the store, adds a tag to it, and, if the customer agreed to marketing, records that consent in Shopify. It also lists the serial numbers of a fulfilled order on that order.
- To send service emails for the merchant: registration confirmations, sign-in links, claim status updates and transfer links.
- To pass data to tools the merchant chooses to connect: Shopify Flow, Klaviyo, the merchant's own webhooks and the merchant's use of the Tasdeek API.
- To keep the service safe and working: limiting request rates, flagging serial numbers checked from many places and investigating errors. Tasdeek's own request logs record which page was requested and the result, without the query part of the address, so email addresses and links in addresses are not written to them.
- For merchant accounts and this website: to answer questions, handle early access requests and run billing through Shopify.
We do not sell personal information, we do not use a store's customer information for our own marketing, and we do not use it for advertising.
Where data protection law such as the GDPR applies, we rely on these legal bases: for information we process for a merchant, the merchant's own legal basis and our contract with the merchant; for merchant accounts, our contract with the merchant and our legitimate interest in running a secure service; for the early access form, your request to hear from us. [LEGAL BASES TO BE CONFIRMED]
5. How long we keep it
- While the store uses Tasdeek: registrations, ownership records, claims, attachments, scan records and passports are kept while the merchant has Tasdeek installed, unless the merchant deletes them sooner.
- When a store uninstalls Tasdeek: staff sign-in sessions are deleted straight away. Shopify then sends us a request to delete the store's data, usually 48 hours after the app is uninstalled. When it arrives we delete all of that store's Tasdeek data, including registrations, claims and their files, scan records, passports, settings and API keys.
- When a customer asks for their data to be erased: the merchant receives the request through Shopify and Shopify passes it to us. We then remove the customer's name, email address, phone number, receipt link and consent details from their registrations, remove their email address from ownership records, cancel transfer links sent to them, delete the files they attached to claims, remove the text they wrote on claims and delete delivery logs that contain their email address. We keep the product unit record itself (serial number, product and the order it was sold with), because it is part of the merchant's own stock records, and we keep notes that the merchant's staff wrote on claims.
- Activity log: 180 days, or longer while it relates to a claim that is still open.
- Delivery logs for webhooks and connected tools, which can contain customer email addresses: 30 days after delivery ends.
- Sign-in links stop working after one hour and transfer links after 72 hours.
- Early access emails sent through this website: kept in our support inbox for [EARLY ACCESS EMAIL RETENTION PERIOD], then deleted.
6. Your rights
Depending on where you live, you may have the right to ask for a copy of your personal information, to have it corrected or deleted, to restrict or object to how it is used, to receive it in a portable format, and to withdraw consent you gave. You can also complain to your data protection authority.
If you are a customer of a store that uses Tasdeek
Please contact the store first, because the store decides how your information is used. The store can see and export your registration details and can ask Shopify to erase your data, which removes it from Tasdeek as described above. If you contact us instead, we will pass your request to the store and help the store answer it.
If you agreed to marketing when you registered a product, you can change your mind at any time using the unsubscribe link in the store's marketing emails or by contacting the store.
If you are a merchant or used our early access form
Email support@tasdeek.com and we will help. You can ask us to delete your early access request at any time.
7. Contact
Questions about this policy or your information: support@tasdeek.com.
Postal address: [LEGAL OWNER NAME], [POSTAL ADDRESS], [COUNTRY].
If we change this policy, we will update the date at the top of this page. If a change is significant, we will also tell merchants who use Tasdeek.