Mora Boost ApS · Legal
Privacy Policy
Last updated: 11 September 2026 · Applies to all Shopify applications published by Mora Boost ApS under the Aveus brand
This Privacy Policy explains how Mora Boost ApS ("we", "us", "our") collects, uses, and protects personal data in connection with the Shopify applications we publish under the Aveus brand (each an "App", together the "Apps" or the "Services"). It is provided in compliance with the General Data Protection Regulation (GDPR, Regulation EU 2016/679), Art. 13, and, where applicable, the EU Data Act (Regulation EU 2023/2854).
The document has three parts. Part A applies to every App. Part B contains one section per App with the exact data that App handles, why, for how long, and with which sub-processors. Part C explains how new Apps are added. Where Part B is more specific than Part A, Part B prevails for that App.
| B.1 | Aveus AI — EU AI Act and GDPR compliance auditor for Shopify stores |
| B.2 | Aveus: AI Label — automatic labelling of AI-generated product images (EU AI Act Art. 50) |
Part A — Provisions common to all Apps
A.1 Data Controller
| Legal name | Mora Boost ApS |
| CVR number | 46 17 19 77 |
| Registered address | Rantzausgade 11, 2. 6., 2200 København N, Denmark |
| Jurisdiction | European Union (Denmark — EU Member State) |
| Contact email | contact@aveus.ai |
| Supervisory authority | Datatilsynet (Danish Data Protection Agency) — datatilsynet.dk |
A.2 Our Role Under GDPR and Yours
With respect to your merchant data (store domain, access tokens, audit records and the App-specific data listed in Part B), Mora Boost ApS acts as an independent Data Controller.
With respect to your end customers' data, Mora Boost ApS acts, where an App touches such data at all, as a Data Processor under GDPR Art. 28, acting on the instructions delivered through Shopify's mandatory privacy webhooks (customers/data_request, customers/redact, shop/redact). You remain the Data Controller for your customers and for your store, including the lawfulness of the data you collect from them, the notices you give them and the third-party services you install. Nothing in this Policy transfers those responsibilities to us.
A.3 What We Never Do
- We never sell, rent or trade your data, and we never share it with data brokers or advertisers.
- We never use your data, your store content or your customers’ data to train artificial-intelligence models, ours or anyone else’s.
- We never place analytics, advertising or tracking code on your storefront. Where an App adds code to your storefront (for example a label or a banner), Part B says exactly what it does and it never reads or transmits your visitors’ personal data to us.
- We never collect personal data from your end customers on our own initiative. An App only receives customer identifiers when Shopify sends them to us through its mandatory webhooks, and Part B states what happens to them.
- We never move data outside the European Economic Area except under the safeguards described in A.4.
- We never keep data longer than the retention period stated for it in Part B.
A.4 Data Recipients and International Transfers
Every App relies on the following core sub-processors. Part B lists any additional sub-processor a specific App uses.
| Sub-processor | Purpose | Location |
|---|---|---|
| Shopify International Limited (Ireland) / Shopify Inc. | The platform on which the Apps run: authentication, Admin API access to your store, delivery of the mandatory privacy webhooks | EU/Canada — Shopify Data Processing Addendum |
| Supabase Inc. (supabase.com) | PostgreSQL database hosting (encrypted at rest, per-store row-level isolation) | EU — AWS eu-central-1 (Frankfurt) |
| Vercel Inc. (vercel.com) | Application hosting and serverless runtime | EU — Frankfurt (fra1). Edge routing and rate limiting execute at the Vercel edge location nearest the visitor. |
Supabase and Vercel are US-incorporated companies whose EU infrastructure may be supported by personnel outside the EEA. Any such residual access is covered by the Standard Contractual Clauses pursuant to GDPR Art. 46.2.c, incorporated into each provider's Data Processing Addendum. No personal data is transferred outside the EEA without these safeguards.
A.5 Security Measures
We implement technical and organisational measures appropriate to the risk, including: AES-256-GCM encryption of Shopify access tokens at rest, Row Level Security (RLS) so that one store can never read another store's rows, HMAC signature verification of every Shopify webhook, TLS in transit, append-only audit logs, dependency and secret scanning in our build pipeline, and regular security reviews against the OWASP Top 10. No system is perfectly secure; if we become aware of a personal-data breach affecting you, we will notify you and, where required, the supervisory authority within the periods set by GDPR Art. 33–34.
A.6 Your Rights as a Data Subject
Under GDPR Chapter III, you have the following rights regarding your merchant data:
- Right of access (Art. 15) — Request a copy of the data we hold about your Shopify store.
- Right to rectification (Art. 16) — Request correction of inaccurate data.
- Right to erasure (Art. 17) — Request deletion of your data. What a verified erasure request purges, and what uninstalling the App purges automatically, is stated per App in Part B.
- Right to data portability (Art. 20) — Request your data in a machine-readable format.
- Right to restrict processing (Art. 18) — Request that we limit how we use your data in certain circumstances.
- Right to object (Art. 21) — Object to processing based on legitimate interests.
To exercise any of these rights, contact us at contact@aveus.ai from the e-mail address associated with your Shopify store, or through the Shopify privacy webhooks. We will respond within 30 days (GDPR Art. 12). We may ask you to verify that you control the store concerned before acting on a request.
A.7 Right to Lodge a Complaint
You have the right to lodge a complaint with the competent supervisory authority:
| Authority | Datatilsynet (Danish Data Protection Agency) |
| Website | datatilsynet.dk |
| Address | Carl Jacobsens Vej 35, 2500 Valby, Denmark |
| Phone | +45 33 19 32 00 |
A.8 Retention Principles
Each data category in Part B is deleted automatically once its retention period expires. Periods are upper limits, not minimums: we do not keep data beyond the purpose that justifies it (GDPR Art. 5.1.e — storage limitation). Where a category is kept after uninstallation, Part B says so and why. Records that document that we honoured a legal request (for example the entry proving that a shop/redact webhook was processed) are kept as evidence of compliance under GDPR Art. 5.2 (accountability) and Art. 17.3.e (defence of legal claims) and are pseudonymised where possible.
A.9 Scope of the Apps and Relationship with the Terms of Service
The Apps are software tools. Their outputs — compliance classifications, risk scores, image labels, certificates, generated documents and similar — are produced automatically from the data available to the App at the time and may be incomplete or inaccurate. They are provided to assist you and do not constitute legal advice; you remain solely responsible for reviewing them and for your store's compliance with the EU AI Act, the GDPR and any other law that applies to you. Our liability, warranties, the governing law and the forum for disputes are governed exclusively by our Terms of Service, which you accept when you install an App. This Policy describes how we handle data; it does not create obligations beyond those required by data-protection law.
A.10 Changes to This Policy
We may update this Privacy Policy, including by adding a section to Part B for a new App or amending an existing section when an App changes what it does with data. We will notify you by updating the "Last updated" date at the top of this page. Continued use of an App after changes constitutes acceptance. Material changes will be communicated via the Shopify admin notification system.
Part B — App-specific provisions
B.1 Aveus AI — EU AI Act and GDPR compliance auditor
Aveus AI is a B2B RegTech platform serving Shopify merchants. We collect the minimum data necessary to provide compliance auditing services (GDPR Art. 5.1.c — data minimisation). We do not collect, store, or process Personally Identifiable Information (PII) from your end customers (consumers).
B.1.1 What data we collect and why
| Data | Purpose | Legal Basis (GDPR Art. 6) |
|---|---|---|
| Shopify store domain (shop_domain) | Tenant identification, RLS isolation, audit scoping | Art. 6.1.b — Contract performance |
| Shopify Offline Access Token (encrypted AES-256-GCM) | Authenticate API calls to your Shopify Admin GraphQL API to scan scripts and pixels | Art. 6.1.b — Contract performance |
| Script and pixel metadata (name, src URL, provider domain) | EU AI Act compliance classification and risk scoring | Art. 6.1.b — Contract performance |
| Compliance audit results (risk level, violations, legal justification) | Stored in your compliance ledger as evidence of due diligence | Art. 6.1.b — Contract / Art. 6.1.f — Legitimate interests |
| GDPR request queue entries (shop_domain, customer_id from Shopify webhook, status) | Processing Shopify-mandated privacy webhook events (customers/redact, customers/data_request, shop/redact) | Art. 6.1.c — Legal obligation |
| Compliance ledger entries (operation, before/after snapshot, timestamp) | Immutable record-keeping required under EU AI Act Art. 12 | Art. 6.1.c — Legal obligation |
| Audit log entries (action, timestamp, performed_by) | Security and operational traceability of actions taken on your store | Art. 6.1.f — Legitimate interests |
| AI cost telemetry (store domain, AI route, model, token counts, estimated cost, and the identifier of the few items that consumed the most tokens — a theme file path such as assets/custom.js) | Controlling our AI spend, detecting abuse and denial-of-wallet attacks, and diagnosing cost anomalies. We store counters and item identifiers only — never product descriptions, customer data, or any content submitted to the model. | Art. 6.1.f — Legitimate interests |
B.1.2 Data Retention
| Data Category | Retention Period | Basis |
|---|---|---|
| AI inventory (script audit results) | Until app uninstallation or explicit deletion request | Art. 6.1.b — Contract |
| Compliance ledger (immutable audit trail) | 1095 days (3 years) from the entry date, then automatically deleted | EU AI Act automated log-keeping (6-month floor) extended to the Danish 3-year limitation period for contractual claims — Art. 17.3.e GDPR (defence of legal claims) |
| Audit logs (security and operational events) | 730 days | Art. 6.1.f — Legitimate interest (security monitoring) |
| AI cost telemetry (route, model, token counts, estimated cost) | 365 days | Art. 6.1.f — Legitimate interest (cost control, abuse prevention) |
| GDPR request queue (data_portability_requests) | 90 days after completion (Art. 12 GDPR — 30-day processing window + buffer) | Art. 6.1.c — Legal obligation |
| Operational error events (pseudonymised, hashed tenant) | 90 days | Art. 6.1.f — Legitimate interest |
| AI spend ledger (degraded-mode budget counters) | 90 days | Art. 6.1.f — Legitimate interest |
| Scan performance telemetry (one row per scan run: duration and result counters) | 90 days | Art. 6.1.f — Legitimate interest (service reliability) |
| Synthetic media flags, detected vendors | Until app uninstallation or explicit deletion request | Art. 6.1.b — Contract |
| Compliance certificates | Until a verified erasure request. Certificates deliberately survive uninstallation so that an already-issued QR code keeps resolving on our public /verify page. | Art. 6.1.b — Contract / Art. 6.1.f — Legitimate interests |
| Operational notifications and storefront scan history | 90 days (these are not removed on uninstallation — only by a verified erasure request or by this retention period) | Art. 6.1.f — Legitimate interests |
| Shopify access token (encrypted) | Until app uninstallation or token revocation | Art. 6.1.b — Contract |
B.1.3 Additional sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Cloud EMEA Limited (Ireland) — Vertex AI | AI classification of store scripts, pixels, theme code, product copy and public vendor documentation | EU — Vertex AI "eu" multi-region (ML processing stays in the EU) |
| Upstash, Inc. | Redis: rate limiting, AI spend budget and webhook idempotency (store domain, hashed IP — no end-customer data) | EU region |
| Google Ireland Limited (Google Workspace / Gmail) | Operational error alerting to our engineering mailbox (error message, stack trace, request path) | EU/US — Google DPA and SCCs |
AI classification runs on Google Cloud Vertex AI, pinned to the EU multi-region endpoint and restricted to generally available models, so that the ML processing of the content submitted for analysis takes place within the European Union. We authenticate with short-lived credentials issued through Workload Identity Federation — no long-lived Google Cloud service-account key exists in our runtime. Processing is governed by the Google Cloud Data Processing Addendum (GDPR Art. 28). We do not send your end customers' personal data to the model: what is analysed is store code, configuration, product copy and publicly available vendor documentation. Google Cloud EMEA Limited may rely on Google LLC (USA) and other Google affiliates as its own sub-processors for limited support, engineering access and abuse monitoring, under the Standard Contractual Clauses described in A.4.
B.1.4 Erasure and uninstallation
A verified erasure request purges your AI inventory, compliance ledger, audit logs, sessions, detected vendors, synthetic media flags, certificates, AI cost telemetry, spend counters, scan performance telemetry, operational notifications, storefront scan history and pseudonymised error records. Uninstalling the app automatically purges your AI inventory, synthetic media flags, detected vendors and session data; the remaining categories are removed by a verified erasure request or when their retention period expires.
B.2 Aveus: AI Label — labelling of AI-generated product images
Aveus: AI Label reads the metadata of your product images to find Content Credentials (C2PA) and other provenance markers, and labels the images it identifies as AI-generated so that your storefront can disclose them (EU AI Act Art. 50). It is a free App and holds no customer personal data: it never reads your orders, your customers or your visitors.
B.2.1 What data we store and why
| Data | Purpose | Legal Basis (GDPR Art. 6) |
|---|---|---|
| Shopify store domain (shop_domain) | Tenant identification and row-level isolation | Art. 6.1.b — Contract performance |
| Shopify Offline Access Token (encrypted AES-256-GCM) | Read your product images and write the label metafields through the Shopify Admin GraphQL API (single scope: write_products) | Art. 6.1.b — Contract performance |
| Product image records (file name, Shopify CDN URL, product and image identifiers, label status, detection method and the provenance signals found) | Remember which images are labelled, avoid re-scanning, and keep the storefront label in sync | Art. 6.1.b — Contract performance |
| Labelling audit log (scan started/finished, image marked or unmarked, by whom, when) | Traceability of every labelling decision on your store; evidence of due diligence | Art. 6.1.f — Legitimate interests / Art. 6.1.c where EU AI Act record-keeping applies |
| Privacy request records (shop_domain, the customer identifier Shopify includes in customers/data_request and customers/redact, status) | Proving that Shopify’s mandatory privacy webhooks were received and honoured | Art. 6.1.c — Legal obligation |
| Webhook idempotency keys (webhook id, topic, store domain) | Rejecting replayed or duplicated webhooks | Art. 6.1.f — Legitimate interests (security) |
B.2.2 Data we read but do not keep
To detect provenance markers the App downloads, for each product image, at most the first 256 KB of the original file as uploaded to Shopify (from Shopify's asset storage, since the CDN copy strips metadata) — or of the CDN copy when the original is not available. The bytes are inspected in memory and discarded immediately. The App never stores, copies, modifies or transmits your images to anyone.
B.2.3 What the App writes to your store
The label lives in your own Shopify store, not on our servers: the App writes a product metafield per labelled image and one shop-wide metafield with the list of labelled file names, both in the App's reserved namespace. A theme app extension that you enable in your theme editor reads that shop-wide metafield and shows the "AI-generated" badge next to the matching images. That storefront script is served from your own Shopify theme, runs entirely in the visitor's browser, makes no network request to us and reads no visitor data. Uninstalling the App does not delete Shopify app-owned metafields automatically; Shopify removes them according to its own platform rules.
B.2.4 Data Retention
| Data Category | Retention Period | Basis |
|---|---|---|
| Product image records and Shopify access token | Deleted automatically the moment Shopify notifies us that you uninstalled the App, or on a verified erasure request | Art. 6.1.b — Contract |
| Labelling audit log | Deleted when Shopify sends the shop/redact webhook (48 hours after uninstallation) or on a verified erasure request | Art. 6.1.f — Legitimate interests |
| Privacy request records | Deleted on shop/redact, except the single record proving that the shop/redact itself was processed, which is kept as evidence of compliance (A.8) | Art. 6.1.c / Art. 5.2 — Accountability |
| Webhook idempotency keys | 30 days | Art. 6.1.f — Legitimate interests (security) |
| Pseudonymised operational log entries not attributable to any store | 90 days | Art. 6.1.f — Legitimate interests |
B.2.5 Sub-processors and third parties
Only the core sub-processors listed in A.4 (Shopify, Supabase in Frankfurt, Vercel in Frankfurt). The App uses no artificial-intelligence provider (detection is done by reading the file's own metadata), no analytics, no advertising and no e-mail service. The App may ask Shopify to show its standard "rate this app" prompt after your first scan; that prompt is rendered by Shopify and no data about you leaves the Shopify admin.
B.2.6 Privacy webhooks
customers/data_request: the App holds no customer data, so there is nothing to return; the request is recorded. customers/redact: recorded; there is nothing to delete. shop/redact: every row belonging to your store is deleted, including earlier privacy request records and webhook events, as described in B.2.4.
Part C — New Apps
C.1 How new Apps are added to this Policy
Before a new Aveus App is published on the Shopify App Store, we add a section to Part B describing the data it handles, following the same structure as B.1 and B.2 (what we store and why, what we read but do not keep, what the App writes to your store, retention, sub-processors, privacy webhooks). The "Last updated" date at the top of this page moves on that day. An App that has no section in Part B is not covered by this Policy and is not published by us.