Privacy policy

Last updated 28 July 2026

What Passa is

Passa helps Shopify merchants create Digital Product Passports required under Regulation (EU) 2024/1781 (ESPR), publish them as public pages, and generate the QR codes that link a physical product to its passport.

What we store

What we do not store

We store no customer personal data. Passports are keyed by product identifier, batch and serial — never by a customer. Public passport pages are served without login and we do not log or profile the person scanning a code. When Shopify sends the customers/data_request or customers/redact webhooks we have nothing to return or erase, and we say so rather than pretending otherwise.

What is public

A passport page is public by design: that is the point of the regulation. Not every field is public, though. Each field carries an audience, and data intended for repairers, recyclers or market surveillance authorities is not shown on the public page.

Retention, including after you uninstall

When you uninstall, Shopify sends a shop/redact request 48 hours later. On receiving it we delete your session, your operator contact details, and every passport that was never registered with the EU DPP Registry.

Passports already registered with the EU DPP Registry are retained. ESPR and EN 18221 require a registered passport to remain reachable for the product's lifetime — a consumer scanning a QR code on a product years from now must still reach it. Retained records are detached from your shop identity and contain no personal data. This is a legal obligation attached to the product, not to your subscription.

Sub-processors

Your rights

You can view, correct, export and delete your data from within the app at any time. Export produces a CSV of everything we hold for your shop. For anything else, contact us and we will respond within 30 days.

Contact

Email support@p4ssa.com.