Datenschutzerklärung (Privacy Policy)
Last updated: 29 July 2026
Applies to: the website fashionbits.de and the Shopify app “Fashionbits EDI” (the “App”)
1. Who we are
The controller responsible for the processing described in this policy is:
Eichler.tech GmbH
Rohdestr. 8
81245 München, Germany
Managing Director: Felix Eichler
Data protection contact: Felix Eichler - info@fashionbits.de
We have not appointed a Data Protection Officer, as we are not required to do so under Art. 37 GDPR. Please direct all privacy enquiries to the address above.
2. In short
Fashionbits EDI imports EDI messages from your suppliers - product catalogues (PRICAT) and delivery notes (DESADV) - into your Shopify store. The data we handle is overwhelmingly business data: article numbers, EANs, sizes, colours, prices, quantities, GLNs and company details. We do not need, want, or ask for the personal data of your end customers.
Some personal data is unavoidable: your name and email address as our customer, the sender addresses on the EDI emails we read on your behalf, and standard technical log data. This policy explains what we do with it.
We do not sell personal data, and we do not use your data to train AI models.
3. Our two roles
Data protection law distinguishes between a controller (who decides why and how data is processed) and a processor (who processes data on someone else’s instructions). Both apply to us, in different parts of the service:
| Situation | Our role |
|---|---|
| Data inside your Shopify store and your EDI messages, processed so the App can do its job | Processor - you (the merchant) are the controller; we act on your instructions |
| Your account, billing, support, our website and product analytics | Controller - we decide on this processing ourselves |
Where we act as a processor, our processing is governed by a Data Processing Agreement (DPA) under Art. 28 GDPR, which forms part of our terms and is available at fashionbits.de/dpa or on request from info@fashionbits.de. If the DPA and this policy conflict on processor matters, the DPA prevails.
4. What we process as your processor (App data)
When you install and use the App, we process the following on your behalf:
Store and installation data
Shop domain, store name, store ID, plan, currency, locations, time zone, and the access token issued to us by Shopify. Source: the Shopify Admin API, with the scopes you approve at install.
Product and inventory data
Products, variants, SKUs, barcodes/EANs, prices, stock levels and locations - read from and written to your store so that catalogue imports and goods receipts work.
EDI message data
The content of the EDI messages you receive from your trading partners (PRICAT, DESADV, and later ORDRSP, SLSRPT, INVRPT), including GLNs, partner company names and addresses, article and delivery data, plus the raw message files themselves and the validation results we generate.
Email transport data (only if you connect a mailbox)
The App can read EDI messages directly from a mailbox you connect (e.g. Microsoft 365). In that case we access the messages in the connected folder(s) and process sender and recipient addresses, subject lines, timestamps and attachments. We use this access solely to find, retrieve and process EDI messages - we do not read, index or store unrelated correspondence beyond what is technically necessary to identify a message as relevant. You can revoke this access at any time in your Microsoft account or in the App settings.
Users of the App
Name, email address and role of the store users who work with the App, plus their in-app actions (e.g. who approved an import) for audit purposes.
Personal data of your end customers is not part of the App’s purpose. If such data nevertheless reaches us - for example because a delivery note contains a named contact person, or a message contains an unexpected field - we process it only as part of the message and delete it with that message under our retention rules.
Legal basis: as a processor we rely on your instructions; your own legal basis for this processing is typically Art. 6(1)(b) or (f) GDPR.
5. What we process as controller
5.1 Account and contract
Name, business email address, company, shop domain, billing status and the correspondence we exchange with you. Purpose: providing the service, invoicing, and administration.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract), Art. 6(1)(c) GDPR for statutory retention of invoicing records.
Note: billing for Shopify apps runs through Shopify Billing. We do not receive or store your payment card or bank details.
5.2 Support
Whatever you send us in a support request - email content, screenshots, log excerpts, and where relevant a short-lived copy of the message that failed.
Legal basis: Art. 6(1)(b) and Art. 6(1)(f) GDPR (our legitimate interest in providing support and improving the product).
5.3 Website
When you visit fashionbits.de, our hosting provider processes standard server data: IP address, date and time, requested page, referrer, browser and operating system. This is necessary to deliver the site and to protect it against attacks.
Legal basis: Art. 6(1)(f) GDPR. Retention: server logs are deleted or anonymised after 30 days.
5.4 Product analytics
We use PostHog (EU hosting) to understand how the App and the website are used - which screens are opened, which imports fail, where people get stuck. We configure PostHog to avoid unnecessary personal data (IP addresses are truncated or not stored, and we do not use cross-site tracking or advertising features).
Legal basis: Art. 6(1)(f) GDPR, or your consent under Art. 6(1)(a) GDPR and § 25(1) TDDDG where cookies or comparable technologies requiring consent are used. You can withdraw consent at any time via the cookie settings on our website.
5.5 Email to you
We send service emails (import failures, security notices, billing and product changes) via Brevo. These are necessary to operate the service - Art. 6(1)(b) and (f) GDPR - and cannot be unsubscribed from while you hold an account.
Any marketing email is sent only with your consent (Art. 6(1)(a) GDPR) or under § 7(3) UWG to existing customers for similar products. Every marketing email carries an unsubscribe link; unsubscribing has no effect on your use of the App.
5.6 Security and abuse prevention
Application logs, error traces, rate-limiting data and audit trails, kept to keep the service stable and secure.
Legal basis: Art. 6(1)(f) GDPR.
6. Cookies and similar technologies
The App uses only cookies that are strictly necessary - session, authentication and security cookies. These do not require consent.
On our website we additionally use analytics as described in 5.4. Where consent is required, we ask for it before setting the relevant cookies and you can change or withdraw your choice at any time via the cookie settings link in the footer.
7. Subprocessors and service providers
We use the following providers. Each is bound by a data processing agreement under Art. 28 GDPR, and each processes data only on our instructions.
| Provider | Purpose | Primary location |
|---|---|---|
| Google Cloud (Google Cloud EMEA Ltd., Ireland) | Application hosting, databases, storage, backups | EU (europe-west region) |
| Vercel Inc. (USA) | Hosting of the website fashionbits.de (the App itself does not run on Vercel) | EU edge locations; company in the USA |
| PostHog (EU Cloud) | Product analytics | EU (Germany) |
| Shopify International Ltd. / Shopify Inc. | The platform the App runs on; app distribution and billing | Ireland / Canada |
| Microsoft Ireland Operations Ltd. | Mailbox access via Microsoft 365, only if you connect a mailbox | EU |
| Brevo (Sendinblue GmbH / Brevo SA) | Transactional and, where applicable, marketing email | EU (France/Germany) |
We may add or replace subprocessors as the service develops. Where we act as your processor, we will inform you of any intended change in good time and you may object on reasonable data protection grounds, as set out in the DPA. The current list is always the one published here.
8. Transfers outside the EU/EEA
We deliberately host in the EU. Some providers are nevertheless established in third countries or may access data from there for support purposes.
Where that happens, the transfer is covered by one or more of the following safeguards:
- an adequacy decision of the European Commission (this covers, for example, transfers to Canada in the case of Shopify);
- the provider’s certification under the EU–U.S. Data Privacy Framework, where applicable;
- the European Commission’s Standard Contractual Clauses (Art. 46(2)(c) GDPR), together with supplementary technical and organisational measures such as encryption in transit and at rest.
You can request a copy of the relevant safeguards from info@fashionbits.de.
9. How long we keep data
All App data - EDI messages, mapping configurations and account data - is retained for the life of your installation and deleted 90 days after uninstall.
10. Security
We apply technical and organisational measures appropriate to the risk, including: TLS encryption for all data in transit, encryption at rest, tenant separation between merchants, least-privilege access with multi-factor authentication for our team, the minimum Shopify API scopes needed for the App’s functions, regular backups, and dependency and vulnerability monitoring. Access to production data is limited to those who need it for operations or support and is logged.
If a personal data breach occurs, we will notify the competent supervisory authority within 72 hours where required, and notify you without undue delay where the breach affects data we process on your behalf.
11. Automated decision-making
We do not carry out automated decision-making producing legal or similarly significant effects within the meaning of Art. 22 GDPR. Validation and matching rules in the App are deterministic and always allow manual review and correction.
12. Your rights
Under the GDPR you have the right to:
- access your data (Art. 15) and receive a copy;
- have inaccurate data corrected (Art. 16);
- have data deleted (Art. 17);
- have processing restricted (Art. 18);
- receive your data in a portable format (Art. 20);
- object to processing based on legitimate interests, on grounds relating to your particular situation (Art. 21) - including, at any time and without giving reasons, to direct marketing;
- withdraw consent at any time, without affecting the lawfulness of processing before the withdrawal (Art. 7(3)).
To exercise any of these, write to info@fashionbits.de. We answer within one month.
If you are an end customer of one of our merchants, please address your request to that merchant - they are the controller for that data. We will forward any request that reaches us.
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), for example the authority for our registered office:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany
13. Is providing data mandatory?
Providing the data described in sections 4 and 5.1 is necessary to enter into and perform the contract. Without it we cannot provide the App. Analytics and marketing are optional and refusing them has no effect on your use of the service.
14. Children
The App is a business tool and is not directed at children. We do not knowingly process data of persons under 16.
15. Changes to this policy
We update this policy when the service changes. The current version always applies and is published at fashionbits.de/privacy with the date of the last update at the top. Where a change materially affects you, we will notify you by email or in the App before it takes effect.
Questions? Reach out to info@fashionbits.de.