GetPPWR
Privacy policy
What personal data GetPPWR processes, why, how long it is kept, and who to contact about it.
Last updated 2 September 2026
Who we are
GetPPWR is operated by Påster (business ID 2205201-2), Betaniankatu 12, 20810 Turku, Finland.
For questions about this policy or about personal data, write to hello@getppwr.com.
Our two roles
For the order data of a merchant's store, the merchant is the data controller and we are the processor. The merchant decides that packaging reports are needed; we produce them on their instruction and for no other purpose.
For the merchant's own account data — the name and email address of the Shopify user who installs and uses the app — we are the controller.
What we process, and what we do not
GetPPWR calculates statutory EU packaging reports (EPR / Regulation (EU) 2025/40) from a store's fulfilled orders. To do that it reads and stores, for each fulfilled order:
- The Shopify order ID and fulfilment ID
- The date the order was fulfilled
- The destination country code of the shipment (country only — no street address, city or postcode)
- The product ID, quantity and unit weight of each fulfilled line
Data we never request
The app does not ask Shopify for, and does not store, any of the following. This is a property of the code, not only a promise: the order query requests the destination country code and nothing else from the shipping address.
- Customer names
- Email addresses
- Phone numbers
- Street addresses, cities or postcodes
- Shopify customer IDs
- Payment details of any kind
Merchant account data
When the app is installed, Shopify provides the name, email address and locale of the Shopify user, together with an access token. These are stored to keep the merchant signed in and to identify the store. They are deleted when the app is uninstalled.
Why we process it, and on what basis
The sole purpose is to calculate and produce packaging reports that the merchant is legally required to file with national EPR registers, and to show the merchant which of their products still lack packaging data.
For order data, the basis is the performance of our contract with the merchant and the merchant's own legal obligation to report packaging placed on the market. We do not use order data for analytics about individuals, advertising, profiling, or any automated decision-making, and we do not sell data to anyone.
How long we keep it
Fulfilled-order records are kept for the current reporting year and the five preceding years, and are deleted automatically once older than that. Records of orders fulfilled before 2021-01-01 are no longer held. All records for a shop are deleted when the app is uninstalled, regardless of age.
The period is the current reporting year plus the five before it, because EPR record-keeping obligations across the EU commonly run to five years and a register may query a filed report after the fact. When order records pass that age they are deleted automatically. Reports already calculated are aggregate weights per material and contain no order identifiers, so a report that has been filed remains available for download after the underlying orders are gone — but it can no longer be recalculated.
Who else processes it
We use the following sub-processors. We do not share personal data with anyone else.
- Railway Corp. (United States) — hosting of the application server
- Supabase Inc. (United States) — hosting of the PostgreSQL database, in the EU region configured for this app
- Shopify Inc. (Canada) — the source of the order data, and the platform the app runs inside
Security
Data is encrypted in transit using TLS and encrypted at rest by our hosting provider. Access to production data is limited to the people who need it to operate and support the app. Access tokens are stored so that they cannot be read from the application interface.
Your rights
A merchant may ask us at any time to provide, correct or delete the data we hold about them, and may withdraw from the service by uninstalling the app — which deletes all of that store's data.
Because we hold no customer names, emails, phone numbers or addresses, a request from a merchant's customer for their personal data will find nothing to return; Shopify's mandatory customer data request and redaction webhooks are implemented and answer accordingly.
If you believe we have handled personal data unlawfully, you may complain to the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), Finland — tietosuoja.fi.
Changes to this policy
If we change what we process or why, we will update this page and change the date below the title before the change takes effect in the app.