Datenschutzerklärung (Privacy Policy)

Last updated: 29 July 2026
Applies to: the website fashionbits.de and the Shopify app “Fashionbits EDI” (the “App”)


1. Who we are

The controller responsible for the processing described in this policy is:

Eichler.tech GmbH
Rohdestr. 8
81245 München, Germany

Managing Director: Felix Eichler

Data protection contact: Felix Eichler - info@fashionbits.de

We have not appointed a Data Protection Officer, as we are not required to do so under Art. 37 GDPR. Please direct all privacy enquiries to the address above.

2. In short

Fashionbits EDI imports EDI messages from your suppliers - product catalogues (PRICAT) and delivery notes (DESADV) - into your Shopify store. The data we handle is overwhelmingly business data: article numbers, EANs, sizes, colours, prices, quantities, GLNs and company details. We do not need, want, or ask for the personal data of your end customers.

Some personal data is unavoidable: your name and email address as our customer, the sender addresses on the EDI emails we read on your behalf, and standard technical log data. This policy explains what we do with it.

We do not sell personal data, and we do not use your data to train AI models.

3. Our two roles

Data protection law distinguishes between a controller (who decides why and how data is processed) and a processor (who processes data on someone else’s instructions). Both apply to us, in different parts of the service:

SituationOur role
Data inside your Shopify store and your EDI messages, processed so the App can do its jobProcessor - you (the merchant) are the controller; we act on your instructions
Your account, billing, support, our website and product analyticsController - we decide on this processing ourselves

Where we act as a processor, our processing is governed by a Data Processing Agreement (DPA) under Art. 28 GDPR, which forms part of our terms and is available at fashionbits.de/dpa or on request from info@fashionbits.de. If the DPA and this policy conflict on processor matters, the DPA prevails.

4. What we process as your processor (App data)

When you install and use the App, we process the following on your behalf:

Store and installation data

Shop domain, store name, store ID, plan, currency, locations, time zone, and the access token issued to us by Shopify. Source: the Shopify Admin API, with the scopes you approve at install.

Product and inventory data

Products, variants, SKUs, barcodes/EANs, prices, stock levels and locations - read from and written to your store so that catalogue imports and goods receipts work.

EDI message data

The content of the EDI messages you receive from your trading partners (PRICAT, DESADV, and later ORDRSP, SLSRPT, INVRPT), including GLNs, partner company names and addresses, article and delivery data, plus the raw message files themselves and the validation results we generate.

Email transport data (only if you connect a mailbox)

The App can read EDI messages directly from a mailbox you connect (e.g. Microsoft 365). In that case we access the messages in the connected folder(s) and process sender and recipient addresses, subject lines, timestamps and attachments. We use this access solely to find, retrieve and process EDI messages - we do not read, index or store unrelated correspondence beyond what is technically necessary to identify a message as relevant. You can revoke this access at any time in your Microsoft account or in the App settings.

Users of the App

Name, email address and role of the store users who work with the App, plus their in-app actions (e.g. who approved an import) for audit purposes.

Personal data of your end customers is not part of the App’s purpose. If such data nevertheless reaches us - for example because a delivery note contains a named contact person, or a message contains an unexpected field - we process it only as part of the message and delete it with that message under our retention rules.

Legal basis: as a processor we rely on your instructions; your own legal basis for this processing is typically Art. 6(1)(b) or (f) GDPR.

5. What we process as controller

5.1 Account and contract

Name, business email address, company, shop domain, billing status and the correspondence we exchange with you. Purpose: providing the service, invoicing, and administration.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract), Art. 6(1)(c) GDPR for statutory retention of invoicing records.

Note: billing for Shopify apps runs through Shopify Billing. We do not receive or store your payment card or bank details.

5.2 Support

Whatever you send us in a support request - email content, screenshots, log excerpts, and where relevant a short-lived copy of the message that failed.
Legal basis: Art. 6(1)(b) and Art. 6(1)(f) GDPR (our legitimate interest in providing support and improving the product).

5.3 Website

When you visit fashionbits.de, our hosting provider processes standard server data: IP address, date and time, requested page, referrer, browser and operating system. This is necessary to deliver the site and to protect it against attacks.
Legal basis: Art. 6(1)(f) GDPR. Retention: server logs are deleted or anonymised after 30 days.

5.4 Product analytics

We use PostHog (EU hosting) to understand how the App and the website are used - which screens are opened, which imports fail, where people get stuck. We configure PostHog to avoid unnecessary personal data (IP addresses are truncated or not stored, and we do not use cross-site tracking or advertising features).
Legal basis: Art. 6(1)(f) GDPR, or your consent under Art. 6(1)(a) GDPR and § 25(1) TDDDG where cookies or comparable technologies requiring consent are used. You can withdraw consent at any time via the cookie settings on our website.

5.5 Email to you

We send service emails (import failures, security notices, billing and product changes) via Brevo. These are necessary to operate the service - Art. 6(1)(b) and (f) GDPR - and cannot be unsubscribed from while you hold an account.

Any marketing email is sent only with your consent (Art. 6(1)(a) GDPR) or under § 7(3) UWG to existing customers for similar products. Every marketing email carries an unsubscribe link; unsubscribing has no effect on your use of the App.

5.6 Security and abuse prevention

Application logs, error traces, rate-limiting data and audit trails, kept to keep the service stable and secure.
Legal basis: Art. 6(1)(f) GDPR.

6. Cookies and similar technologies

The App uses only cookies that are strictly necessary - session, authentication and security cookies. These do not require consent.

On our website we additionally use analytics as described in 5.4. Where consent is required, we ask for it before setting the relevant cookies and you can change or withdraw your choice at any time via the cookie settings link in the footer.

7. Subprocessors and service providers

We use the following providers. Each is bound by a data processing agreement under Art. 28 GDPR, and each processes data only on our instructions.

ProviderPurposePrimary location
Google Cloud (Google Cloud EMEA Ltd., Ireland)Application hosting, databases, storage, backupsEU (europe-west region)
Vercel Inc. (USA)Hosting of the website fashionbits.de (the App itself does not run on Vercel)EU edge locations; company in the USA
PostHog (EU Cloud)Product analyticsEU (Germany)
Shopify International Ltd. / Shopify Inc.The platform the App runs on; app distribution and billingIreland / Canada
Microsoft Ireland Operations Ltd.Mailbox access via Microsoft 365, only if you connect a mailboxEU
Brevo (Sendinblue GmbH / Brevo SA)Transactional and, where applicable, marketing emailEU (France/Germany)

We may add or replace subprocessors as the service develops. Where we act as your processor, we will inform you of any intended change in good time and you may object on reasonable data protection grounds, as set out in the DPA. The current list is always the one published here.

8. Transfers outside the EU/EEA

We deliberately host in the EU. Some providers are nevertheless established in third countries or may access data from there for support purposes.

Where that happens, the transfer is covered by one or more of the following safeguards:

You can request a copy of the relevant safeguards from info@fashionbits.de.

9. How long we keep data

All App data - EDI messages, mapping configurations and account data - is retained for the life of your installation and deleted 90 days after uninstall.

10. Security

We apply technical and organisational measures appropriate to the risk, including: TLS encryption for all data in transit, encryption at rest, tenant separation between merchants, least-privilege access with multi-factor authentication for our team, the minimum Shopify API scopes needed for the App’s functions, regular backups, and dependency and vulnerability monitoring. Access to production data is limited to those who need it for operations or support and is logged.

If a personal data breach occurs, we will notify the competent supervisory authority within 72 hours where required, and notify you without undue delay where the breach affects data we process on your behalf.

11. Automated decision-making

We do not carry out automated decision-making producing legal or similarly significant effects within the meaning of Art. 22 GDPR. Validation and matching rules in the App are deterministic and always allow manual review and correction.

12. Your rights

Under the GDPR you have the right to:

To exercise any of these, write to info@fashionbits.de. We answer within one month.

If you are an end customer of one of our merchants, please address your request to that merchant - they are the controller for that data. We will forward any request that reaches us.

You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), for example the authority for our registered office:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany

13. Is providing data mandatory?

Providing the data described in sections 4 and 5.1 is necessary to enter into and perform the contract. Without it we cannot provide the App. Analytics and marketing are optional and refusing them has no effect on your use of the service.

14. Children

The App is a business tool and is not directed at children. We do not knowingly process data of persons under 16.

15. Changes to this policy

We update this policy when the service changes. The current version always applies and is published at fashionbits.de/privacy with the date of the last update at the top. Where a change materially affects you, we will notify you by email or in the App before it takes effect.


Questions? Reach out to info@fashionbits.de.