Privacy Policy Codixio Back in Stock

1. Overview and purpose of this policy

Codixio Back in Stock is an extension for Shopware 6 that allows end customers to be notified as soon as an unavailable product is back in stock. This policy describes which personal data is processed, for which purpose and on which legal basis, how long it is stored, and which rights data subjects have.

The policy addresses two groups: merchants who use the app in their shop, and end customers who sign up for notifications through the form in the shop.

2. Controller

Matthias Jakisch, Hauptstr. 34, OT Etingen, 39359 Oebisfelde-Weferlingen, Germany. Phone +49 39059 974988. E-mail general support@codixio.com, e-mail data protection and legal legal@codixio.com. Legal form: sole proprietorship (no commercial register entry), operating under the trade name Codixio. VAT identification number pursuant to Sec. 27a UStG: DE296346917. Tax status: small business under Sec. 19 UStG.

3. Allocation of roles

For the operation of the app within the merchant's shop, the merchant is the controller within the meaning of Art. 4 no. 7 GDPR. Codixio acts as a processor pursuant to Art. 28 GDPR. The details are governed by the data processing agreement available at https://legal.codixio.com/apps/back-in-stock-shopware/dpa.

The app additionally provides two publicly reachable pages on the Codixio infrastructure which end customers open directly from an e-mail without any technical involvement of the merchant's shop: the confirmation page of the sign-up procedure and the unsubscribe page. The submission of the sign-up form is likewise sent directly from the end customer's browser to the Codixio backend. For these requests the merchant remains the controller, because they serve exclusively the purpose commissioned by the merchant and Codixio pursues no purposes of its own. Codixio does not collect any data beyond the processing on behalf of the merchant in the course of these requests, does not evaluate them and does not use them for any purpose of its own.

4. Data processed in detail

4.1 Sign-up for notification (end customers)

When a person submits the sign-up form on a product page, the following details are transmitted to the Codixio backend and stored there: the e-mail address entered, the product identifier, the sales channel identifier, the shop identifier, the optionally stated desired quantity, the language of the shop page and a technical check value of the confirmation link. In addition, timestamps for creation, for sending the confirmation e-mail, for confirmation and for notification are stored, as well as the processing status of the sign-up.

Product name, product image and product link are not taken from the browser but are retrieved by the backend directly from the merchant's shop at the moment the respective e-mail is sent.

The purpose is exclusively to send the requested notification for precisely this product. The legal basis is consent pursuant to Art. 6 (1) (a) GDPR, obtained by way of the confirmed sign-up procedure (see section 5).

4.2 Merchant notification address

From the Pro plan onwards, merchants may store an e-mail address to which a message is sent as soon as a new sign-up has been confirmed. This address is stored for as long as the setting exists. The purpose is the notification requested by the merchant; the processing takes place as processing on behalf of the merchant.

4.3 IP address for abuse prevention

When the sign-up form is submitted, the sender's IP address is used to limit the number of sign-ups per sender and shop within a time window. The IP address is held exclusively and transiently in a cache whose entries expire after the time window of one minute. It is not stored in the database, not written to logs and not linked to the sign-up. The purpose is to prevent automated bulk sign-ups and abuse; the processing takes place as processing on behalf of the merchant and at the same time protects data subjects against unwanted use of their addresses.

The form additionally contains a field invisible to humans which is filled in only by automated programs. If it is filled in, the sign-up is discarded without any data being stored.

4.4 Technical operating data

In order to process incoming stock messages from the shop, the backend stores the identifier of the respective event, the shop identifier and the time of receipt so that the same message is not processed more than once. Furthermore, it is recorded which type of e-mail was sent for which sign-up at which time, so that no duplicate deliveries occur. Neither data set contains e-mail addresses.

The merchant's settings (thresholds, stock basis, templates, reminder period, domain list, product-level switches) are stored for as long as the app is installed in the shop.

4.5 Logs

The application logs of the backend contain no e-mail addresses, no confirmation links and no IP addresses. Only technical identifiers, event names, counts and error messages are recorded.

5. Confirmed sign-up procedure

After the form has been submitted, the sign-up is initially unconfirmed. An e-mail containing a confirmation link is sent; only once this link has been opened is consent deemed to have been given and notifications may be delivered. An unconfirmed sign-up receives no notification.

The confirmation link expires after seven days. If the sign-up is not confirmed, it is deleted in full after fourteen days at the latest.

Consent may be withdrawn at any time with effect for the future. Every e-mail sent by the app contains an unsubscribe link for this purpose. The lawfulness of the processing carried out up to the withdrawal remains unaffected.

6. Storage period and deletion

An upper limit of 24 months applies: sign-ups are deleted in full no later than 24 months after their creation, irrespective of their processing status. Shorter periods apply within this limit:

Deletion is carried out by an automatically recurring run; it is a final removal of the record, not a mere flag.

If the merchant uninstalls the app, all data of that shop is deleted in full: the sign-ups including the e-mail addresses, the dispatch records, the settings including the notification address, the product-level switches, the technical event data as well as the registration and plan data of the shop. If Shopware expressly requests the retention of the data during uninstallation, deletion does not take place; in that case the periods stated above continue to apply.

7. Recipients and transfers

The app transfers data exclusively to the shop of the respective merchant. All e-mails are sent through the interface of the merchant's shop and thus through the merchant's own mail infrastructure; the e-mail address is returned to the merchant's shop for this purpose. In addition, the backend retrieves product data from the merchant's shop, writes the determined plan into the shop configuration and, where used by the merchant, triggers events for the Flow Builder.

No external dispatch service provider is used. No service for analytics, statistics or reach measurement is used. No fonts, scripts, images or other resources are loaded from third-party servers in the shop storefront.

In order to verify the signature of the plan confirmation, the backend retrieves the public signature keys from Shopware AG. No personal data is transmitted in this process.

No personal data is transferred to a third country outside the European Economic Area.

8. Processors

The following provider is used to operate the application servers and the database: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Activity: hosting provider for application servers and Postgres database. Place of processing: data centres Falkenstein (Germany) and Nuremberg (Germany). Third country transfer: no. In addition, Coolify is used as self-operated open source container orchestration on this infrastructure; this is not an external service provider.

There are no further sub-processors.

9. Storage on the terminal device

The app sets no cookies. It does not read any information from the terminal device beyond what is strictly necessary to provide the service expressly requested.

The sign-up form uses one entry in the browser session storage holding the value of a simple flag, in order not to display the input form again on the same page after a sign-up has been submitted successfully. The entry is written exclusively after a deliberate submission by the user and exists only for the lifetime of the browser tab. It contains no personal data, allows no recognition across pages or sessions, and serves no purpose of reach measurement or advertising. This storage is strictly necessary to provide the service expressly requested within the meaning of Sec. 25 (2) no. 2 TDDDG and therefore does not require consent. When a product page is merely viewed, the app only checks whether such an entry exists; nothing is written in that case.

10. Artificial intelligence and automated decisions

The app does not use artificial intelligence. There is no transmission to providers of artificial intelligence systems and no content is generated by such systems; a transparency obligation under Art. 50 of Regulation (EU) 2024/1689 therefore does not apply.

There is no automated decision-making in individual cases, including profiling, within the meaning of Art. 22 GDPR. The checks that exist (limiting sign-ups per sender, detecting automated entries, optional restriction to certain e-mail domains) are simple rule-based technical checks without any evaluation of personal characteristics. Their only effect is whether a sign-up for notification is accepted.

11. Rights of data subjects

Data subjects have the right of access (Art. 15 GDPR), to rectification (Art. 16 GDPR), to erasure (Art. 17 GDPR), to restriction of processing (Art. 18 GDPR), to data portability (Art. 20 GDPR) and to withdraw consent given with effect for the future (Art. 7 (3) GDPR).

The merchant in whose shop the sign-up took place is responsible for handling these rights, as that merchant is the controller. Requests may also be addressed to legal@codixio.com; they are forwarded to the responsible merchant or handled on that merchant's instructions.

The simplest way to end the processing is the unsubscribe link contained in every e-mail sent by the app. Following unsubscription, the record is deleted in full after thirty days at the latest.

12. Right to lodge a complaint

Data subjects have the right to lodge a complaint with a supervisory authority. The competent authority for Codixio is: Landesbeauftragter für den Datenschutz Sachsen-Anhalt, Leiterstraße 9, 39104 Magdeburg, Germany. Phone +49 391 81803-0. E-mail poststelle@lfd.sachsen-anhalt.de. Website datenschutz.sachsen-anhalt.de.

13. Further documents

Data processing agreement: https://legal.codixio.com/apps/back-in-stock-shopware/dpa.en General terms and conditions: https://legal.codixio.com/apps/back-in-stock-shopware/terms.en This privacy policy: https://legal.codixio.com/apps/back-in-stock-shopware/privacy.en