Privacy Policy for the Brand Echo app
This page explains which data the Brand Echo app for Shopify processes, who receives it, how long it is kept and what your rights are.
1. Who is responsible
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Lars WaltherMarienweiher 8
95352 Marktleugast, Germany
Email: support@brand-echo.app
This policy covers the Brand Echo app. The website brand-echo.app has its own privacy policy.
2. What the app can access
The app requests two Shopify permissions: reading products and writing products. It does not access your customers, orders or payment data, and it stores no names or email addresses of your staff.
3. Which data we process
| Data | Details | Where it is kept |
|---|---|---|
| Installation data | Your shop address (myshopify.com domain), the access token Shopify issues for the app, the granted permissions | Our database |
| Your settings | Language, brand voice, example texts and custom rules you enter | Our database |
| Plan and credits | Your plan, credit counters, remaining extra credits and purchase records (Shopify charge ID, number of credits, date) | Our database |
| Product data | Title, vendor, existing description, tags, variant options and, for short descriptions, a small version of the main product image | Read from Shopify when you generate a text. Not stored in our database. |
| Failed products | Product ID and the reason a generation failed. The reason can contain the product title. | Our database |
| Bulk jobs | Shop address, product IDs, your instruction text and progress | Temporary job storage, removed after 7 days at the latest |
| Server logs | Shop address, product titles, technical details and error messages. If a generation fails, the generated text can appear in the log. | Logs of our hosting provider, kept for a limited period |
| Support requests | Your email address and the content of your message | Our mailbox |
4. Purposes and legal bases
- Providing the app and its functions to you: Article 6 (1) (b) GDPR (performance of a contract).
- Billing, preventing repeated use of free credits, security and troubleshooting: Article 6 (1) (f) GDPR. Our legitimate interest is the reliable and fair operation of the app.
- Keeping purchase records: Article 6 (1) (c) GDPR together with the retention duties under German commercial and tax law.
5. Text generation with Google Gemini
To generate texts, the app sends the product data listed in section 3, your brand voice settings, your example texts, your custom rules and your instruction to the Gemini API operated by Google. The name and address of your shop are not part of the request. To detect your brand voice, the app sends up to five of your existing product descriptions.
If a description is empty or very short, or if you ask for it in a quick edit, Google runs a web search as part of the request ("Grounding with Google Search"). The search terms are formed by the model from the product data. According to Google's terms, additional data is collected and used for this feature.
We use the paid Gemini API. According to Google's terms for paid services, Google does not use prompts or responses to improve its products, processes them under its data processing addendum, and logs them for a limited period.
6. Who receives data
| Recipient | Role | Location |
|---|---|---|
| Shopify | Platform through which the app is installed, used and billed. Shopify is responsible for its own processing. | Canada, Ireland and other countries |
| Railway Corporation | Hosting of the app, job storage and server logs | USA |
| Neon, LLC | Database | Data stored in Frankfurt, Germany. The provider is based in the USA. |
| Google LLC and its affiliates | Gemini API for text generation and web search | USA and other countries |
| Zoho Corporation B.V., Beneluxlaan 4B, 3527 HT Utrecht (Netherlands / Niederlande) | Mailbox for support requests | European Union |
Railway, Neon, Google and our email provider act as our processors (Article 28 GDPR). Where data is transferred to the USA, the transfer is based on the EU standard contractual clauses in the providers' data processing terms (Article 46 (2) (c) GDPR) and, where a provider is certified, on the EU-U.S. Data Privacy Framework (Article 45 GDPR). We do not sell data and do not use it for advertising.
7. How long we keep data
- When you uninstall the app, the access token is deleted immediately.
- 48 hours after uninstalling, Shopify asks us to erase your shop's data. We then delete your settings, example texts, custom rules, the list of failed products and remaining bulk jobs.
- What we keep after that: your shop address, your plan and credit counters, your remaining extra credits and your purchase records. We need them to prevent repeated use of free credits, to restore credits you paid for if you install the app again, and for bookkeeping.
- Counters without remaining extra credits are deleted 12 months after uninstalling if you have not installed the app again.
- Purchase records are kept for the retention periods required by German commercial and tax law.
- Bulk job data is removed after 7 days at the latest. Server logs are kept by our hosting provider for a limited period.
You can ask us to delete your data earlier at any time by writing to support@brand-echo.app. We then delete everything we are not legally required to keep.
8. Data of your customers
The app does not store data of your customers. Shopify's requests to export or erase customer data therefore find nothing to return or delete on our side.
9. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Article 15)
- have inaccurate data corrected (Article 16)
- have your data erased (Article 17)
- have the processing restricted (Article 18)
- receive your data in a portable format (Article 20)
- object to processing that is based on our legitimate interests (Article 21)
To exercise these rights, write to support@brand-echo.app. You also have the right to lodge a complaint with a data protection supervisory authority (Article 77 GDPR). The authority responsible for us is Das Bayrische Landesamt für Datenschutzaufsicht.
10. Further information
The app needs the data in section 3 to work. Without it, the app cannot be used. We do not use automated decision-making or profiling. If the app changes in a way that affects this policy, we update this page and the date at the top.
Datenschutzerklärung für die App Brand Echo
Diese Seite erklärt, welche Daten die App Brand Echo für Shopify verarbeitet, wer sie erhält, wie lange sie gespeichert werden und welche Rechte du hast. Stand: 7. Oktober 2026.
1. Verantwortlicher
Verantwortlicher im Sinne der Datenschutz-Grundverordnung (DSGVO) ist:
Lars WaltherMarienweiher 8
95352 Marktleugast, Deutschland
E-Mail: support@brand-echo.app
Diese Erklärung gilt für die App Brand Echo. Für die Website brand-echo.app gibt es eine eigene Datenschutzerklärung.
2. Worauf die App zugreifen kann
Die App fordert zwei Shopify-Berechtigungen an: Produkte lesen und Produkte schreiben. Sie greift nicht auf Kunden-, Bestell- oder Zahlungsdaten zu und speichert keine Namen oder E-Mail-Adressen deiner Mitarbeiter.
3. Welche Daten wir verarbeiten
| Daten | Einzelheiten | Speicherort |
|---|---|---|
| Installationsdaten | Deine Shop-Adresse (myshopify.com-Domain), das Zugriffstoken, das Shopify für die App ausstellt, die erteilten Berechtigungen | Unsere Datenbank |
| Deine Einstellungen | Sprache, Markenstimme, Beispieltexte und eigene Regeln, die du eingibst | Unsere Datenbank |
| Tarif und Credits | Dein Tarif, Credit-Zähler, verbleibende Extra-Credits und Kaufbelege (Shopify-Charge-ID, Anzahl der Credits, Datum) | Unsere Datenbank |
| Produktdaten | Titel, Hersteller, vorhandene Beschreibung, Tags, Variantenoptionen und bei kurzen Beschreibungen eine verkleinerte Fassung des Hauptbilds | Werden beim Generieren aus Shopify gelesen. Keine Speicherung in unserer Datenbank. |
| Fehlgeschlagene Produkte | Produkt-ID und der Grund, warum eine Generierung scheiterte. Der Grund kann den Produkttitel enthalten. | Unsere Datenbank |
| Bulk-Aufträge | Shop-Adresse, Produkt-IDs, dein Anweisungstext und der Fortschritt | Temporärer Auftragsspeicher, Löschung nach spätestens 7 Tagen |
| Server-Logs | Shop-Adresse, Produkttitel, technische Angaben und Fehlermeldungen. Scheitert eine Generierung, kann der erzeugte Text im Log stehen. | Logs unseres Hosting-Anbieters, begrenzte Aufbewahrung |
| Support-Anfragen | Deine E-Mail-Adresse und der Inhalt deiner Nachricht | Unser Postfach |
4. Zwecke und Rechtsgrundlagen
- Bereitstellung der App und ihrer Funktionen: Art. 6 Abs. 1 lit. b DSGVO (Vertragserfüllung).
- Abrechnung, Schutz vor mehrfacher Nutzung kostenloser Credits, Sicherheit und Fehlersuche: Art. 6 Abs. 1 lit. f DSGVO. Unser berechtigtes Interesse ist der zuverlässige und faire Betrieb der App.
- Aufbewahrung von Kaufbelegen: Art. 6 Abs. 1 lit. c DSGVO in Verbindung mit den handels- und steuerrechtlichen Aufbewahrungspflichten.
5. Texterstellung mit Google Gemini
Zum Erzeugen von Texten sendet die App die in Abschnitt 3 genannten Produktdaten, deine Einstellungen zur Markenstimme, deine Beispieltexte, deine eigenen Regeln und deine Anweisung an die Gemini API von Google. Name und Adresse deines Shops sind nicht Teil der Anfrage. Für die Erkennung deiner Markenstimme sendet die App bis zu fünf deiner vorhandenen Produktbeschreibungen.
Ist eine Beschreibung leer oder sehr kurz, oder verlangst du es in einer Schnellbearbeitung, führt Google im Rahmen der Anfrage eine Websuche aus („Grounding with Google Search“). Die Suchbegriffe bildet das Modell aus den Produktdaten. Nach den Bedingungen von Google werden für diese Funktion zusätzliche Daten erhoben und verwendet.
Wir nutzen die kostenpflichtige Gemini API. Nach den Bedingungen von Google für kostenpflichtige Dienste verwendet Google Eingaben und Ausgaben nicht zur Verbesserung seiner Produkte, verarbeitet sie auf Grundlage seines Auftragsverarbeitungsvertrags und protokolliert sie für einen begrenzten Zeitraum.
6. Wer Daten erhält
| Empfänger | Rolle | Ort |
|---|---|---|
| Shopify | Plattform, über die die App installiert, genutzt und abgerechnet wird. Shopify ist für die eigene Verarbeitung selbst verantwortlich. | Kanada, Irland und weitere Länder |
| Railway Corporation | Hosting der App, Auftragsspeicher und Server-Logs | USA |
| Neon, LLC | Datenbank | Speicherung in Frankfurt, Deutschland. Der Anbieter hat seinen Sitz in den USA. |
| Google LLC und verbundene Unternehmen | Gemini API für Texterstellung und Websuche | USA und weitere Länder |
| Zoho Corporation B.V., Beneluxlaan 4B, 3527 HT Utrecht (Netherlands / Niederlande) | Postfach für Support-Anfragen | Europäische Union |
Railway, Neon, Google und unser E-Mail-Anbieter sind unsere Auftragsverarbeiter (Art. 28 DSGVO). Soweit Daten in die USA übermittelt werden, beruht das auf den EU-Standardvertragsklauseln in den Auftragsverarbeitungsbedingungen der Anbieter (Art. 46 Abs. 2 lit. c DSGVO) und, soweit ein Anbieter zertifiziert ist, auf dem EU-U.S. Data Privacy Framework (Art. 45 DSGVO). Wir verkaufen keine Daten und nutzen sie nicht für Werbung.
7. Wie lange wir Daten speichern
- Bei der Deinstallation wird das Zugriffstoken sofort gelöscht.
- 48 Stunden nach der Deinstallation fordert Shopify uns auf, die Daten deines Shops zu löschen. Wir löschen dann deine Einstellungen, Beispieltexte, eigenen Regeln, die Liste fehlgeschlagener Produkte und verbliebene Bulk-Aufträge.
- Was danach bleibt: deine Shop-Adresse, dein Tarif und die Credit-Zähler, deine verbleibenden Extra-Credits und deine Kaufbelege. Wir brauchen sie, um die mehrfache Nutzung kostenloser Credits zu verhindern, bezahlte Credits bei einer Neuinstallation wiederherzustellen und für die Buchhaltung.
- Zähler ohne verbleibende Extra-Credits werden 12 Monate nach der Deinstallation gelöscht, wenn du die App nicht erneut installiert hast.
- Kaufbelege bewahren wir für die handels- und steuerrechtlichen Aufbewahrungsfristen auf.
- Daten zu Bulk-Aufträgen werden nach spätestens 7 Tagen entfernt. Server-Logs bewahrt unser Hosting-Anbieter für einen begrenzten Zeitraum auf.
Du kannst jederzeit eine frühere Löschung verlangen, indem du an support@brand-echo.app schreibst. Wir löschen dann alles, was wir nicht gesetzlich aufbewahren müssen.
8. Daten deiner Kunden
Die App speichert keine Daten deiner Kunden. Anfragen von Shopify zur Auskunft über Kundendaten oder zu deren Löschung finden bei uns deshalb nichts, was herauszugeben oder zu löschen wäre.
9. Deine Rechte
Nach der DSGVO hast du das Recht auf:
- Auskunft über die zu dir gespeicherten Daten (Art. 15)
- Berichtigung unrichtiger Daten (Art. 16)
- Löschung deiner Daten (Art. 17)
- Einschränkung der Verarbeitung (Art. 18)
- Datenübertragbarkeit (Art. 20)
- Widerspruch gegen eine Verarbeitung, die auf unserem berechtigten Interesse beruht (Art. 21)
Um diese Rechte auszuüben, schreib an support@brand-echo.app. Du hast außerdem das Recht, dich bei einer Datenschutzaufsichtsbehörde zu beschweren (Art. 77 DSGVO). Die für uns zuständige Behörde ist Das Bayrische Landesamt für Datenschutzaufsicht.
10. Weitere Hinweise
Die App benötigt die Daten aus Abschnitt 3, um zu funktionieren. Ohne sie kann die App nicht genutzt werden. Eine automatisierte Entscheidungsfindung oder ein Profiling findet nicht statt. Ändert sich die App so, dass es diese Erklärung betrifft, aktualisieren wir diese Seite und das Datum oben.