Privacy Policy
preg — packaging reporting for German EPR (VerpackG / VerpackDG). Last updated 26 August 2026.
What preg is for
preg calculates how much packaging, by statutory material fraction, a merchant placed on the German market in a reporting period. It does this by multiplying units shipped to German delivery addresses by the packaging the merchant has described for each product and parcel.
What preg reads from a store
- Order data: the delivery country of each order, whether the order was a test or was cancelled, its processed and fulfillment dates, and for each line item the quantity, whether it requires shipping, and which product variant it refers to.
- Product data: product and variant titles, SKUs, and whether a variant requires shipping.
- Packaging profiles that the merchant creates in preg.
What preg does not read or store
preg does not read or store customer names, email addresses, phone numbers, or street addresses. From a delivery address it reads only the two-letter country code, because that is the only part relevant to deciding whether goods were placed on the German market.
preg does not sell data, does not share it with third parties for their own purposes, does not use it for advertising or profiling, and does not make automated decisions about individual people.
What preg stores, and where
- A session record per shop — the shop domain and the OAuth access token Shopify issues. Held in a PostgreSQL database hosted by Supabase in the EU (Ireland), encrypted at rest and in transit.
- Packaging profiles — stored as metafields inside the merchant’s own Shopify store, not on preg’s servers.
Order data is read when a report is generated and used to compute totals. The resulting report shows aggregate weights by material, which are not personal data.
Retention
The session record is deleted when the app is uninstalled. Because preg stores no customer personal data, there is nothing further to retain or erase.
Sub-processors
- Supabase — managed PostgreSQL, EU (Ireland), for session storage.
- Shopify — the source of the data and the host of the merchant’s metafields.
Requests from merchants and their customers
preg implements Shopify’s mandatory compliance webhooks. Because it holds no customer personal data, a customer data request returns nothing and a redaction request has nothing to erase. Shop redaction removes the session record.
Contact
Questions about this policy or about data handling can be sent to the address listed on preg’s Shopify App Store listing.
preg computes figures for reporting. It does not file anything with LUCID or a dual system, and it is not legal advice.