Privacy Policy

Gulbrandsen Apps ENK · Version 1.0 · 29 August 2026

Version 1.0, in force. This document describes the service as built. Scheduled for external legal review before public launch.

1. Who we are

WarrantyBridge is operated by Gulbrandsen Apps ENK, a sole proprietorship registered in Norway in August 2026, organisation number 938 324 484.

For personal data belonging to a merchant's customers, the merchant is the data controller and WarrantyBridge is the data processor. We process that data only on the merchant's documented instructions, which are set out in our Data Processing Agreement.

2. What we collect

We deliberately collect the minimum needed to issue a warranty card and handle a claim.

DataWhy
Email addressDeliver the warranty card and transactional claim updates on the merchant's behalf
First and last nameIdentify the purchaser on their card and in the merchant's claim inbox
Country (two-letter code)Determine which statutory guarantee period applies
Order and product detailsOrder reference, product title, SKU, quantity, purchase and fulfilment dates

We also store claim contents a customer submits: claim type, description, and any photographs they attach.

What we never collect

We do not request, receive, or store telephone numbers, street addresses, cities, postal codes, payment card details, or financial information. Only the country portion of an address is read; the rest is discarded and never written to our systems.

3. Where the data lives

All personal data is stored in Microsoft Azure, North Europe region (Ireland), within the European Union. Data is not transferred outside the EU or EEA in the ordinary course of operating the service.

4. How long we keep it

Personal data is not kept longer than needed (GDPR Article 5(1)(e)). Warranty records are retained until the later of:

A record connected to a warranty claim is retained until at least 24 months after that claim is closed. Where no coverage end date exists, a refunded purchase is retained for 24 months from purchase, and any other such record for the longer of 24 months or the country period above.

Once that period passes, an automated nightly process removes the personal data: the order reference is redacted and the customer's name and email are erased. The warranty record itself — product, dates, status — is kept in anonymised form. Nothing is retained indefinitely.

5. Rights

Because the merchant is the controller, requests are normally made to the merchant, who passes them to us through Shopify. We act on them regardless of route.

Erasure and deletion requests always take precedence over the retention schedule above.

6. Who else sees the data

PartyRoleLocation
ShopifySource of order and customer data; the merchant's platformPer Shopify's own terms
Microsoft AzureHosting and databaseEU (North Europe)

We do not sell personal data, share it for advertising, use it for profiling or automated decision-making, or use it to train machine-learning models. A transactional email provider will be added when the warranty card email is enabled; this page will be updated to name it before any customer email is sent.

7. Marketing

WarrantyBridge sends no marketing email. Warranty cards and claim updates are transactional. Optional warranty-expiry reminders are disabled by default, enabled only at a merchant's choice, and carry an unsubscribe link.

8. Security

Data is encrypted in transit and at rest, access to personal data is logged, and access is restricted to a single operator. Details are in our Security and Incident Response policy.

9. Contact and complaints

privacy@warrantybridge.app

If you are in the EEA and believe your data has been handled improperly, you may complain to your national supervisory authority. In Norway this is Datatilsynet.