WarrantyBridge is operated by Gulbrandsen Apps ENK, a sole proprietorship registered in Norway in August 2026, organisation number 938 324 484.
For personal data belonging to a merchant's customers, the merchant is the data controller and WarrantyBridge is the data processor. We process that data only on the merchant's documented instructions, which are set out in our Data Processing Agreement.
We deliberately collect the minimum needed to issue a warranty card and handle a claim.
| Data | Why |
|---|---|
| Email address | Deliver the warranty card and transactional claim updates on the merchant's behalf |
| First and last name | Identify the purchaser on their card and in the merchant's claim inbox |
| Country (two-letter code) | Determine which statutory guarantee period applies |
| Order and product details | Order reference, product title, SKU, quantity, purchase and fulfilment dates |
We also store claim contents a customer submits: claim type, description, and any photographs they attach.
We do not request, receive, or store telephone numbers, street addresses, cities, postal codes, payment card details, or financial information. Only the country portion of an address is read; the rest is discarded and never written to our systems.
All personal data is stored in Microsoft Azure, North Europe region (Ireland), within the European Union. Data is not transferred outside the EU or EEA in the ordinary course of operating the service.
Personal data is not kept longer than needed (GDPR Article 5(1)(e)). Warranty records are retained until the later of:
A record connected to a warranty claim is retained until at least 24 months after that claim is closed. Where no coverage end date exists, a refunded purchase is retained for 24 months from purchase, and any other such record for the longer of 24 months or the country period above.
Once that period passes, an automated nightly process removes the personal data: the order reference is redacted and the customer's name and email are erased. The warranty record itself — product, dates, status — is kept in anonymised form. Nothing is retained indefinitely.
Because the merchant is the controller, requests are normally made to the merchant, who passes them to us through Shopify. We act on them regardless of route.
Erasure and deletion requests always take precedence over the retention schedule above.
| Party | Role | Location |
|---|---|---|
| Shopify | Source of order and customer data; the merchant's platform | Per Shopify's own terms |
| Microsoft Azure | Hosting and database | EU (North Europe) |
We do not sell personal data, share it for advertising, use it for profiling or automated decision-making, or use it to train machine-learning models. A transactional email provider will be added when the warranty card email is enabled; this page will be updated to name it before any customer email is sent.
WarrantyBridge sends no marketing email. Warranty cards and claim updates are transactional. Optional warranty-expiry reminders are disabled by default, enabled only at a merchant's choice, and carry an unsubscribe link.
Data is encrypted in transit and at rest, access to personal data is logged, and access is restricted to a single operator. Details are in our Security and Incident Response policy.
If you are in the EEA and believe your data has been handled improperly, you may complain to your national supervisory authority. In Norway this is Datatilsynet.