Silens Shopify cookie consent

Privacy Policy — Silens

Last updated: 31 July 2026

Data controller

The Silens app, distributed on the Shopify App Store, is published by Sylvain Balas, a natural person established in France, acting in an individual capacity.

Contact: deozwrecker@gmail.com

These contact details allow you to exercise all the rights described below. Any written request sent to this address receives an answer within the period stated under "Your rights".

No data protection officer has been appointed: the activity does not fall within any of the cases making such an appointment mandatory under Article 37 of the GDPR.

In short

This app collects, stores and transmits no personal data about the visitors of the stores where it is installed.

The consent collected by the banner is recorded by Shopify, within Shopify's own system, under an anonymous identifier provided by Shopify. We have no access to it and keep no copy of it.

We store no IP address, no email address, no name, no browser fingerprint and no advertising identifier.

The only data we retain temporarily is the domain name of the stores that install the app, in our technical logs. Where the merchant trades as a sole trader, that domain name may constitute personal data relating to them: this policy applies to it in full.

In what capacity we act

For the technical logs described below, we act as data controller.

For everything else we act neither as controller nor as processor, since no processing takes place on our side: the reads performed in the admin happen directly between the merchant's browser and Shopify, without passing through our systems.

Visitor consent is processed by Shopify on the merchant's behalf. We play no part in that relationship.

What we read through Shopify's APIs

At the merchant's request, and only while they are using the admin interface, the app reads:

These reads happen directly from the merchant's browser to Shopify. The results are displayed on screen and disappear when the page is closed. None of this information is sent to our servers or retained.

What we collect from the merchant

Nothing, apart from what Shopify passes to us at installation (the store's domain name) so the app can function.

What we collect from the merchant's customers

Nothing.

The consent banner shown to visitors passes their choice to Shopify's Customer Privacy API. We neither receive nor store that choice.

The banner stores a single piece of information in the visitor's browser: the date on which they answered, so it knows when to ask again. That date stays on their device and is never sent to us.

Technical logs

Our compliance webhook endpoint, hosted on Cloudflare, records two pieces of information for each call received from Shopify: the domain name of the store concerned and the type of request.

Purposes. Technical diagnosis, service security, and evidence that compliance requests forwarded by Shopify were properly handled.

Legal basis. Article 6(1)(f) of the GDPR, legitimate interests: keeping the service running and secure. That interest is balanced against the rights of data subjects, the recording being reduced to the strict minimum and its duration to three days. Handling the compliance requests themselves also rests on Article 6(1)(c), compliance with a legal obligation.

Retention. Three days at most, the retention period applied by Cloudflare Workers on the plan we use. After that, logs are deleted automatically and permanently.

They contain no data relating to the merchant's customers.

Recipients and processors

We sell no data, share none with any third party for commercial purposes, and use none for advertising.

Two providers are involved:

webhooks to us and hosts the consent system.

for three days.

There are no other recipients. We have no ad network, no analytics tool and no third-party messaging service connected to the app.

Transfers outside the European Union

The Cloudflare network has points of presence distributed worldwide, so technical logs may be processed outside the European Union.

These transfers are governed by Cloudflare's data processing addendum, which incorporates the standard contractual clauses adopted by the European Commission. The same applies to processing carried out by Shopify, governed by its own data processing addendum.

Security

Every webhook received is authenticated by verifying its HMAC SHA-256 signature, compared in constant time so the secret is not exposed through response timing. A call with an invalid signature is rejected without processing. The shared secret is stored in no file of the project.

The app has no database: its exposure surface is limited to that single endpoint.

How long we keep data

We keep no data beyond the technical logs described above, deleted after three days. There is no database associated with this app.

Automated decision-making and profiling

The app performs no automated decision-making producing legal effects, and no profiling, within the meaning of Article 22 of the GDPR.

Minors

The app is aimed at professional merchants and knowingly collects no data relating to minors.

Your rights

The GDPR grants you rights of access, rectification, erasure, restriction and objection regarding your personal data, as well as a right to portability. Since the processing rests on legitimate interests, you also have the right to object to it at any time on grounds relating to your particular situation.

Given the nature and duration of the data involved, we hold almost nothing about you in practice, and nothing beyond three days. You may nonetheless write to us at any time at deozwrecker@gmail.com to exercise these rights. We answer within one month, as provided by Article 12(3) of the GDPR.

You have the right to lodge a complaint with the Commission nationale de l'informatique et des libertés (CNIL), the French supervisory authority, at cnil.fr.

Data subject requests forwarded by Shopify

As required by Shopify, the app answers the three compliance webhooks: customer data request, customer data erasure, and shop data erasure after uninstall.

Since we hold no data attached to an identified customer, we have nothing to return or erase for the first two. For a shop erasure, we delete the technical logs concerning that shop.

Changes

Any change to this policy will be published on this page, with the date at the top updated accordingly. Substantial changes will be signalled to merchant users through the means available to us on the Shopify platform.