Privacy policy
Last updated 28 July 2026
What Passa is
Passa helps Shopify merchants create Digital Product Passports required under Regulation (EU) 2024/1781 (ESPR), publish them as public pages, and generate the QR codes that link a physical product to its passport.
What we store
- Shop identity and session. Your myshopify.com domain and the access token Shopify issues when you install the app.
- Economic operator details. Company legal name, operator identifier (VAT, EORI, LEI or GLN), registered address and contact email. Regulation (EU) 2024/1781 requires these to appear on the public passport, so they are published by design.
- Passport data. Product identifiers and the regulatory fields for each product group, plus the passport domain you configure.
What we do not store
We store no customer personal data. Passports are keyed by product identifier, batch and serial — never by a customer. Public passport pages are served without login and we do not log or profile the person scanning a code. When Shopify sends the customers/data_request or customers/redact webhooks we have nothing to return or erase, and we say so rather than pretending otherwise.
What is public
A passport page is public by design: that is the point of the regulation. Not every field is public, though. Each field carries an audience, and data intended for repairers, recyclers or market surveillance authorities is not shown on the public page.
Retention, including after you uninstall
When you uninstall, Shopify sends a shop/redact request 48 hours later. On receiving it we delete your session, your operator contact details, and every passport that was never registered with the EU DPP Registry.
Passports already registered with the EU DPP Registry are retained. ESPR and EN 18221 require a registered passport to remain reachable for the product's lifetime — a consumer scanning a QR code on a product years from now must still reach it. Retained records are detached from your shop identity and contain no personal data. This is a legal obligation attached to the product, not to your subscription.
Sub-processors
- Shopify — authentication, billing and webhooks.
- Cloudflare — hosting and content delivery.
- The EU Digital Product Passport Registry — when you choose to register a passport, we submit its identifier, its URL, your operator identifier and your backup provider identifier. Passport content itself stays with us; the Registry holds pointers only.
Your rights
You can view, correct, export and delete your data from within the app at any time. Export produces a CSV of everything we hold for your shop. For anything else, contact us and we will respond within 30 days.
Contact
Email support@p4ssa.com.