Privacy Policy — Saal: Sales Agent

Last updated: 28.07.2026

DE

This policy explains what personal data the Saal: Sales Agent Shopify app ("the App") processes, why, and for how long. It applies to merchants who install the App and to the customers of those merchants whose data the App accesses.

1. Who is responsible

Micha Saalmüller
Mittenwalder Straße 32
10961 Berlin, Germany
Email: privacy@michasaalmueller.com

There is no statutory obligation for us to appoint a Data Protection Officer under Art. 37 GDPR. We have assessed this: the App is operated by a single person, does not carry out large-scale processing of special categories of data, and does not perform regular systematic monitoring of individuals. You can contact us directly at the address above for any data protection question.

2. Our role: controller or processor

This distinction matters, because it determines who you contact about what.

For data about merchants (your shop domain, your plan, your billing status, your support emails), we act as the controller. This policy describes that processing.

For data about a merchant's customers (names, email addresses, orders, consent records), we act as a processor on behalf of the merchant. The merchant is the controller and decides why and how that data is used; we only act on their instructions, as set out in our Data Processing Agreement. If you are the customer of a shop using this App and want to exercise your rights, please contact that shop directly — they control your data. We will support them in responding.

3. What data we process

3.1 Merchant and shop data

Collected through Shopify's APIs when you install and use the App:

  • Shop domain and myshopify domain
  • Shopify API access token (used to act on your behalf)
  • Shopify plan tier (to determine which App features are available)
  • Subscription and trial status

This data is stored in our database for as long as the App is installed.

3.2 Customer data accessed through Shopify's APIs

To provide the App's core function — letting an authorised sales agent place an order for another customer — the App accesses the following about the merchant's customers:

  • Customer ID, display name and email address
  • Customer tags (used to determine which customers an agent may act for)
  • Company and company location assignments (Shopify Plus B2B only)
  • Order data received through the orders/create webhook

We do not store this data in our own database. It is read from Shopify, used to complete the requested action, and discarded. The only exception is short-lived technical logging, described in section 3.4.

3.3 Consent records

When a sales agent begins acting for a customer, the App records the consent date, an optional note, and the responsible agent. These records are written to metafields on the customer record inside the merchant's own Shopify account. They are not copied to or retained on our systems. The merchant controls this data and can view, export or delete it in Shopify at any time.

3.4 Technical logs

Our hosting provider generates operational logs for error handling, security and debugging. These may contain shop domain, customer ID and order ID. Logs are retained for approximately 3 days and are then deleted automatically. They are not used for analytics, profiling or any purpose other than keeping the App working correctly.

3.5 Support communication

If you contact us by email, we process your email address and the content of your message in order to answer it.

3.6 Local storage on the storefront

To keep a sales agent's session active while they act for a customer, the App stores a single entry in the browser's local storage on the agent's own device. It contains the identifier and name of the customer being acted for, their company assignment where applicable, and technical flags describing the session (plan tier, country and catalogue settings). This is what allows the storefront to show the agent whose account they are ordering in. It is removed when the agent ends the session.

This storage is strictly necessary to provide the function the agent has explicitly requested, and is therefore exempt from the consent requirement under § 25(2) no. 2 TDDDG. We do not use cookies, local storage or any comparable technology for analytics, advertising or tracking, and we place nothing on the devices of a shop's ordinary customers.

3.7 What we do not do

  • We do not track shop visitors or collect browsing behaviour of merchants' customers.
  • We do not use any personal data for marketing, advertising, profiling or interest-based segmentation.
  • We do not sell or share personal data with third parties for their own purposes.
  • We do not use personal data for automated decision-making producing legal or similarly significant effects.

4. Why we process this data, and on what legal basis

PurposeLegal basis
Providing the App's functionality to the merchantArt. 6(1)(b) GDPR — performance of a contract
Processing customer data on the merchant's behalfArt. 28 GDPR — processing on documented instructions
Security, error diagnosis and abuse preventionArt. 6(1)(f) GDPR — legitimate interest in a functioning, secure service
Billing and subscription managementArt. 6(1)(b) GDPR, and Art. 6(1)(c) for statutory retention
Answering support requestsArt. 6(1)(b) or 6(1)(f) GDPR

We do not process personal data for any purpose other than those listed above.

5. Sub-processors

ProviderRoleLocation
Cloudflare, Inc.Application hosting, database, operational logsDatabase hosted in Western Europe (EU)
Shopify Inc.Platform on which the App runs; source and destination of the dataPer Shopify's own privacy policy

Our database is hosted in a Western European region, so merchant data is stored within the EU. Cloudflare, Inc. is established in the United States and access from outside the EEA cannot be entirely excluded, for example for support or maintenance. We have a data processing agreement in place with Cloudflare, and any such transfer is covered by appropriate safeguards under Art. 46 GDPR, including EU Standard Contractual Clauses.

Billing is handled entirely by Shopify. We never receive or process payment card data.

We will update this list before engaging any new sub-processor.

6. How long we keep data

DataRetention
Shop session and access tokenUntil the App is uninstalled, then deleted
Subscription and billing recordsUntil uninstall; invoice-related records kept as required by German commercial and tax law
Customer data from Shopify APIsNot stored — processed in memory only
Consent recordsStored in the merchant's Shopify account, under the merchant's control
Technical logsApproximately 3 days, then deleted automatically
Support emails12 months after the request is resolved

When a merchant uninstalls the App, or when Shopify sends us a shop redaction request, we delete the associated shop data.

7. Shopify's mandatory privacy webhooks

The App implements the three compliance webhooks required by Shopify:

  • `customers/data_request` — when a customer asks a merchant for their data, we respond with any data we hold about that customer. In practice this is normally none, as we do not store customer data.
  • `customers/redact` — we delete any data held about the specified customer.
  • `shop/redact` — 48 hours after a merchant uninstalls the App, we delete that shop's data.

8. Your rights

Under the GDPR you have the right to access your data, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable format. You also have the right to lodge a complaint with a supervisory authority.

To exercise these rights in relation to merchant data, contact us at privacy@michasaalmueller.com. We will respond within one month.

If you are the customer of a shop using this App, the merchant is the controller of your data. Please direct your request to that shop; we will assist them in fulfilling it.

The supervisory authority responsible for us is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59-61, 10555 Berlin

9. Security

  • All data is encrypted in transit (TLS) and at rest.
  • Access to production systems is limited to the sole developer of the App, protected by unique credentials and two-factor authentication.
  • Test and production environments and databases are strictly separated. No live merchant or customer data is used in development.
  • We maintain an incident response procedure. In the event of a personal data breach, we will notify the competent supervisory authority within 72 hours where required under Art. 33 GDPR, and affected merchants without undue delay.

10. Changes to this policy

We may update this policy as the App changes. The current version is always available at /sales-agent-privacy-policy, with the date of the last change shown at the top. We will notify merchants of material changes by email.

This policy is also available in German.

11. Contact

Micha Saalmüller
Mittenwalder Straße 32
10961 Berlin, Germany
privacy@michasaalmueller.com