What is stored
Recorded
- Timestamp of the consent decision
- Visitor region (country code)
- Categories chosen — analytics, marketing, preferences
- Applied consent model
- Banner language
- Policy version ID shown to the visitor
- Consent identifier returned by Shopify's Customer Privacy API
- Shop settings — policy URLs, and custom labels on the Pro plan
Never recorded
- Customer names
- Email addresses
- Postal addresses
- Order data
- Any other contact detail
Admin permissions
LangKamel requests one Shopify Admin API permission beyond the standard session context every embedded app receives: the ability to read whether your store's own native cookie-consent banner (Settings → Customer privacy → Cookie banner) is currently turned on.
This is used only during onboarding, to warn you if Shopify's own banner and LangKamel's banner would both show to the same visitor, and to point you at the setting to turn Shopify's off. LangKamel never writes to or changes that setting on your behalf — disabling it stays a manual step you take yourself in your own Shopify admin.
Cookies and identifiers
LangKamel sets no tracking cookies of its own and generates no visitor-tracking identifiers of its own.
The consent identifier stored with each record is received from Shopify's Customer Privacy API. Its nature and behaviour are defined by Shopify; LangKamel neither generates nor controls it.
Retention and erasure
Consent records are append-only. When the app is uninstalled from a store, Shopify's shop redaction webhook erases all of that store's records within the 48-hour window defined by Shopify's GDPR webhooks.
Hosting
Data is hosted on Neon Postgres in the EU region (Frankfurt, Germany).
Integrity
Consent records are append-only and protected from modification at the application level. They are not tamper-proof, and LangKamel makes no such claim.
Contact
Questions about this page, or a request concerning data held for your store: support@langkamel.com.