Privacy Policy
Effective date: 2026-07-23
Who we are
Makeready ("the app") is a Shopify app operated by Keoma Kindl, based in Austria, EU. Keoma Kindl is the data controller for the direct relationship with you, the merchant. For any question about your data or this policy, or to exercise your rights, contact us at support@keomakindl.at. Given the scope of our processing we are not required to appoint a Data Protection Officer; support@keomakindl.at reaches the person responsible.
What this policy covers and our role
This policy explains what personal data the app processes when you install it on your Shopify store, why, and on what legal basis.
Two roles apply. For your customers' personal data, you (the store owner) are the controller and we act as your processor under Article 28 GDPR, processing that data only on your instructions to provide the app. For our direct relationship with you as a merchant, we are the controller.
Data we process
Store and account data: your store domain, a Shopify access token, and the configuration you create in the app.
Order data: for captured orders (by default every new order; the merchant's Order detection settings can limit this to made-to-order orders only), we receive and store the order number, customer name and email, order total and currency, number of line items, financial and fulfillment status, whether the order is for pickup or delivery, order date, and the personalization properties entered at checkout. We do not collect the customer's address, phone number, or any payment or card data.
Content you add: internal notes, attachments (stored in your Shopify Files and referenced by link), materials, recipes and settings.
Legal basis for processing
Providing the app to you: Article 6(1)(b) GDPR, performance of our contract with you as a merchant, covering the production dashboard, order tracking, material and cost tracking, and reporting.
Processing your customers' personal data: we do this only as your processor, on your documented instructions under Article 28 GDPR; your own legal basis as the controller governs that data.
Keeping the service safe: Article 6(1)(f) GDPR, our legitimate interest in security, abuse prevention and rate limiting, balanced against your and your customers' rights.
Legal obligations: Article 6(1)(c) GDPR, for example when we act on Shopify's mandatory privacy webhooks.
How we use it
We use this data solely to provide the app's features: the production dashboard, due dates, material and cost tracking, reporting, and the customer order-tracking page. We do not use your data for advertising, and we do not sell or share it.
The customer tracking page
Each order receives a private, unguessable link that shows that customer their own status. A self-service lookup requires the order number plus the matching email. This page never shows costs or materials, and never shows an internal note unless you explicitly mark that specific note or photo as an update to share with the customer.
Cookies and local storage
The app uses only what it needs to function. Inside the Shopify admin, a strictly necessary session cookie keeps you signed in to the app. In your browser we use local storage to remember your preferences: your chosen language, your onboarding progress, and which in-app tips you have dismissed.
The customer tracking page sets no tracking cookies. We do not use advertising cookies, cross-site trackers, or any third-party analytics.
Storage, security and encryption
Your data is stored in a managed PostgreSQL database. The customer's name and email are encrypted at rest with AES-256-GCM, as are the Shopify access and refresh tokens that let the app act on your behalf. We also store a one-way hash (a blind index) of the customer email that cannot be reversed, used solely to locate a customer's orders when a privacy request comes in.
Data in transit is protected with TLS. Access to production data is limited to what is needed to operate and support the service.
Where your data is stored and international transfers
We store your data on infrastructure located in the European Union (a managed database in Frankfurt, Germany, and application hosting in an EU region). We do not transfer your data outside the EU ourselves.
Shopify, as the platform your store runs on, may process data outside the EU under its own data processing terms and the European Commission's Standard Contractual Clauses, which you accepted when you started using Shopify.
Sub-processors
We use a small number of carefully chosen sub-processors, each bound by a data processing agreement: Shopify (the platform your store and orders live on), Neon (our managed PostgreSQL database provider, hosting data in the EU) and Railway (our application hosting provider, running in an EU region). We do not share your data with any other third parties, and we never sell or rent it.
Retention
We keep your data for as long as the app is installed. When you uninstall, Shopify sends a shop-redaction request about 48 hours later and we permanently delete all your data. When a customer redaction request arrives, we erase that customer's name and email from your orders while keeping the order record as your production history. You can also contact us at support@keomakindl.at to request earlier deletion.
Your rights
Under the GDPR you and your customers have the right to access, rectify, erase, restrict and object to the processing of personal data, and to data portability. You can trigger full deletion by uninstalling the app. Customer access and deletion requests flow through Shopify's standard privacy webhooks, which we honor automatically; you can also contact support@keomakindl.at to exercise any right directly.
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects. If you believe we have handled your data unlawfully, you have the right to lodge a complaint with a data protection supervisory authority in the EU, in particular in the country where you live, work, or where the alleged infringement took place.
Children's data
The app is a business tool for merchants and is not directed at children. We do not knowingly process the personal data of children.
Changes to this policy
We may update this policy. The effective date above always reflects the current version, and we will reflect any material change here.