Privacy Policy — Saal: Sales Agent
Last updated: 28.07.2026
This policy explains what personal data the Saal: Sales Agent Shopify app ("the App") processes, why, and for how long. It applies to merchants who install the App and to the customers of those merchants whose data the App accesses.
1. Who is responsible
Micha Saalmüller
Mittenwalder Straße 32
10961 Berlin, Germany
Email: privacy@michasaalmueller.com
There is no statutory obligation for us to appoint a Data Protection Officer under Art. 37 GDPR. We have assessed this: the App is operated by a single person, does not carry out large-scale processing of special categories of data, and does not perform regular systematic monitoring of individuals. You can contact us directly at the address above for any data protection question.
2. Our role: controller or processor
This distinction matters, because it determines who you contact about what.
For data about merchants (your shop domain, your plan, your billing status, your support emails), we act as the controller. This policy describes that processing.
For data about a merchant's customers (names, email addresses, orders, consent records), we act as a processor on behalf of the merchant. The merchant is the controller and decides why and how that data is used; we only act on their instructions, as set out in our Data Processing Agreement. If you are the customer of a shop using this App and want to exercise your rights, please contact that shop directly — they control your data. We will support them in responding.
3. What data we process
3.1 Merchant and shop data
Collected through Shopify's APIs when you install and use the App:
- Shop domain and myshopify domain
- Shopify API access token (used to act on your behalf)
- Shopify plan tier (to determine which App features are available)
- Subscription and trial status
This data is stored in our database for as long as the App is installed.
3.2 Customer data accessed through Shopify's APIs
To provide the App's core function — letting an authorised sales agent place an order for another customer — the App accesses the following about the merchant's customers:
- Customer ID, display name and email address
- Customer tags (used to determine which customers an agent may act for)
- Company and company location assignments (Shopify Plus B2B only)
- Order data received through the
orders/createwebhook
We do not store this data in our own database. It is read from Shopify, used to complete the requested action, and discarded. The only exception is short-lived technical logging, described in section 3.4.
3.3 Consent records
When a sales agent begins acting for a customer, the App records the consent date, an optional note, and the responsible agent. These records are written to metafields on the customer record inside the merchant's own Shopify account. They are not copied to or retained on our systems. The merchant controls this data and can view, export or delete it in Shopify at any time.
3.4 Technical logs
Our hosting provider generates operational logs for error handling, security and debugging. These may contain shop domain, customer ID and order ID. Logs are retained for approximately 3 days and are then deleted automatically. They are not used for analytics, profiling or any purpose other than keeping the App working correctly.
3.5 Support communication
If you contact us by email, we process your email address and the content of your message in order to answer it.
3.6 Local storage on the storefront
To keep a sales agent's session active while they act for a customer, the App stores a single entry in the browser's local storage on the agent's own device. It contains the identifier and name of the customer being acted for, their company assignment where applicable, and technical flags describing the session (plan tier, country and catalogue settings). This is what allows the storefront to show the agent whose account they are ordering in. It is removed when the agent ends the session.
This storage is strictly necessary to provide the function the agent has explicitly requested, and is therefore exempt from the consent requirement under § 25(2) no. 2 TDDDG. We do not use cookies, local storage or any comparable technology for analytics, advertising or tracking, and we place nothing on the devices of a shop's ordinary customers.
3.7 What we do not do
- We do not track shop visitors or collect browsing behaviour of merchants' customers.
- We do not use any personal data for marketing, advertising, profiling or interest-based segmentation.
- We do not sell or share personal data with third parties for their own purposes.
- We do not use personal data for automated decision-making producing legal or similarly significant effects.
4. Why we process this data, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Providing the App's functionality to the merchant | Art. 6(1)(b) GDPR — performance of a contract |
| Processing customer data on the merchant's behalf | Art. 28 GDPR — processing on documented instructions |
| Security, error diagnosis and abuse prevention | Art. 6(1)(f) GDPR — legitimate interest in a functioning, secure service |
| Billing and subscription management | Art. 6(1)(b) GDPR, and Art. 6(1)(c) for statutory retention |
| Answering support requests | Art. 6(1)(b) or 6(1)(f) GDPR |
We do not process personal data for any purpose other than those listed above.
5. Sub-processors
| Provider | Role | Location |
|---|---|---|
| Cloudflare, Inc. | Application hosting, database, operational logs | Database hosted in Western Europe (EU) |
| Shopify Inc. | Platform on which the App runs; source and destination of the data | Per Shopify's own privacy policy |
Our database is hosted in a Western European region, so merchant data is stored within the EU. Cloudflare, Inc. is established in the United States and access from outside the EEA cannot be entirely excluded, for example for support or maintenance. We have a data processing agreement in place with Cloudflare, and any such transfer is covered by appropriate safeguards under Art. 46 GDPR, including EU Standard Contractual Clauses.
Billing is handled entirely by Shopify. We never receive or process payment card data.
We will update this list before engaging any new sub-processor.
6. How long we keep data
| Data | Retention |
|---|---|
| Shop session and access token | Until the App is uninstalled, then deleted |
| Subscription and billing records | Until uninstall; invoice-related records kept as required by German commercial and tax law |
| Customer data from Shopify APIs | Not stored — processed in memory only |
| Consent records | Stored in the merchant's Shopify account, under the merchant's control |
| Technical logs | Approximately 3 days, then deleted automatically |
| Support emails | 12 months after the request is resolved |
When a merchant uninstalls the App, or when Shopify sends us a shop redaction request, we delete the associated shop data.
7. Shopify's mandatory privacy webhooks
The App implements the three compliance webhooks required by Shopify:
- `customers/data_request` — when a customer asks a merchant for their data, we respond with any data we hold about that customer. In practice this is normally none, as we do not store customer data.
- `customers/redact` — we delete any data held about the specified customer.
- `shop/redact` — 48 hours after a merchant uninstalls the App, we delete that shop's data.
8. Your rights
Under the GDPR you have the right to access your data, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable format. You also have the right to lodge a complaint with a supervisory authority.
To exercise these rights in relation to merchant data, contact us at privacy@michasaalmueller.com. We will respond within one month.
If you are the customer of a shop using this App, the merchant is the controller of your data. Please direct your request to that shop; we will assist them in fulfilling it.
The supervisory authority responsible for us is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59-61, 10555 Berlin
9. Security
- All data is encrypted in transit (TLS) and at rest.
- Access to production systems is limited to the sole developer of the App, protected by unique credentials and two-factor authentication.
- Test and production environments and databases are strictly separated. No live merchant or customer data is used in development.
- We maintain an incident response procedure. In the event of a personal data breach, we will notify the competent supervisory authority within 72 hours where required under Art. 33 GDPR, and affected merchants without undue delay.
10. Changes to this policy
We may update this policy as the App changes. The current version is always available at /sales-agent-privacy-policy, with the date of the last change shown at the top. We will notify merchants of material changes by email.
This policy is also available in German.
11. Contact
Micha Saalmüller
Mittenwalder Straße 32
10961 Berlin, Germany
privacy@michasaalmueller.com