Rechtliches
Datenschutz ConsentGate
Diese Erklärung gilt für die Shopify-App ConsentGate. Sie richtet sich an Händlerinnen und Händler, die die App installieren, und beschreibt außerdem, welche Daten von Shop-Besucherinnen und -Besuchern über das Cookie-Banner verarbeitet werden.
Die Datenschutzerklärung der Website wiedenroth.tech bleibt daneben gültig. Nutzungsbedingungen: https://consentgate.de/agb. Stand: 1. September 2026.
Verantwortliche Stelle
Wiedenroth Technologies GmbH
Speicherstraße 9
31134 Hildesheim
Deutschland
E-Mail: info@wiedenroth-technologies.com
Telefon: +49 5121 9289929
Geschäftsführer: Jan Ole Wiedenroth
Handelsregister: Amtsgericht Hildesheim, HRB 208795
USt-IdNr.: DE361687340
Impressum: https://wiedenroth.tech/impressum
Ein betrieblicher Datenschutzbeauftragter ist nicht bestellt. Anfragen zum Datenschutz bitte an die oben genannte E-Mail.
Worum es geht
ConsentGate ist eine Einwilligungs-App für Shopify-Shops. Sie zeigt ein Cookie-Banner, blockiert nicht notwendige Tracker bis zur Zustimmung und schreibt die Wahl an die Shopify Customer Privacy API sowie — soweit eingerichtet — an den Google Consent Mode.
Gegenüber dem Händler sind wir Verantwortliche für die Daten der App-Installation und der Admin-Nutzung. Für die Einwilligungsdaten der Shop-Besucher handelt der Händler als Verantwortlicher; wir verarbeiten diese Daten in seinem Auftrag (Art. 28 DSGVO).
Daten der Händler (App-Installation und Admin)
Wenn Sie ConsentGate im Shopify-Admin installieren oder öffnen, verarbeiten wir:
- Shop-Domain (z. B. ihr-shop.myshopify.com) und den gewählten Plan
- Zugriffs-Token und erteilte Berechtigungen (OAuth / Session), damit die App mit Shopify sprechen kann
- bei Online-Sitzungen: Shopify-Nutzer-ID, Name, E-Mail, Locale und Rolle der Person, die die App öffnet
- Banner-Einstellungen, Texte, Farben, Kategorien und die Liste der erkannten Dienste
- technische Server-Logs (Zeitpunkt, aufgerufene Route, Statuscode), soweit unser Hosting sie schreibt
Rechtsgrundlage ist Art. 6 Abs. 1 lit. b DSGVO (Vertrag über die App-Nutzung) und Art. 6 Abs. 1 lit. f DSGVO (Betrieb, Sicherheit, Missbrauchsabwehr).
Die App-Konfiguration für das Banner liegt zusätzlich als Metafeld bei Shopify. Shopify ist Empfänger dieser Daten.
Daten der Shop-Besucher (Cookie-Banner)
Im Shop selbst speichert das Banner im Browser der Besucherin oder des Besuchers (First-Party, Domain des Händlers):
- eine zufällige Kennung (
consentgate.vidim Local Storage) - die getroffene Auswahl und den Zeitpunkt (
consentgate.v1im Local Storage)
Über den Shopify App-Proxy sendet das Banner uns die Wahl zur Ablage im Auftrag des Händlers:
- die zufällige Kennung (kein Name, keine E-Mail, keine Kunden-ID)
- Entscheidung (alle annehmen / alle ablehnen / eigene Auswahl)
- Kategorien: notwendig, Statistik, Marketing, Präferenzen
- Banner-Version und Sprache
- optional ein Länder- oder Regionskürzel aus der Shopify Customer Privacy API — keine IP-Adresse
- Zeitpunkt
Wir speichern keine IP-Adresse, keine Kundennamen und keine Shopify-Kunden-IDs. Die Einträge dienen dem Händler als Nachweis der Einwilligung (Art. 7 Abs. 1 DSGVO). Rechtsgrundlage beim Händler ist in der Regel Art. 6 Abs. 1 lit. c und lit. f DSGVO; für das Setzen nicht notwendiger Cookies Art. 6 Abs. 1 lit. a DSGVO i. V. m. § 25 TDDDG.
Speicherdauer der Server-Einträge: vom Händler einstellbar, mindestens 30 Tage, höchstens 7 Jahre, Standard 365 Tage. Ältere Einträge werden automatisch gelöscht. Die Browser-Daten bleiben, bis die Besucherin oder der Besucher sie löscht oder die Auswahl ändert.
Shop-Prüfung (Scan)
Wenn der Händler den Shop prüft, lädt ConsentGate die öffentliche Storefront und wertet Theme, App-Einbettungen und sichtbare Skripte aus. Dabei können URLs, Hostnamen und Cookie-Namen als Nachweis landen, damit Dienste zugeordnet werden. Das dient nur der Einrichtung der App (Art. 6 Abs. 1 lit. b DSGVO).
Empfänger und Auftragsverarbeitung
- Shopify Inc. / Shopify International Ltd. — Installation, Login, Admin-API, App-Proxy, Webhooks, Metafelder. Shopify sitzt in Kanada und Irland; Übermittlungen stützen sich auf den Angemessenheitsbeschluss für Kanada bzw. die Standardvertragsklauseln von Shopify.
- Unser Hosting — die App und die Einwilligungsdaten liegen auf von uns betriebenen bzw. beauftragten Servern. Soweit ein externer Hoster eingesetzt wird, geschieht das in der EU und auf Grundlage eines Vertrags nach Art. 28 DSGVO.
Wir verkaufen die Daten nicht und nutzen sie nicht für Werbung auf eigene Rechnung.
Pflicht-Webhooks von Shopify
Shopify verlangt die Bearbeitung dieser Ereignisse:
- App deinstalliert / Shop gelöscht: Wir löschen Shop-Daten, Banner, erkannte Dienste, Einwilligungsprotokolle und Sitzungen.
- Kundenauskunft / Kundenlöschung: ConsentGate speichert keine Shopify-Kundenkonten. Eine Zuordnung zu einer Kundin oder einem Kunden ist nicht möglich; wir bestätigen das gegenüber Shopify.
Speicherdauer (Händlerdaten)
Sessions bleiben, solange die App installiert ist bzw. das Token gültig ist. Shop-Einstellungen bleiben bis zur Deinstallation. Nach der Deinstallation löschen wir die genannten Daten, sobald der Shopify-Webhook eintrifft. Backups können wenige Tage länger existieren und werden dann überschrieben.
Ihre Rechte
Betroffene Personen haben das Recht auf Auskunft, Berichtigung, Löschung, Einschränkung, Datenübertragbarkeit und Widerspruch, soweit die gesetzlichen Voraussetzungen vorliegen. Außerdem besteht ein Beschwerderecht bei einer Aufsichtsbehörde, für uns zuständig:
Die Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5
30159 Hannover
https://lfd.niedersachsen.de
Shop-Besucherinnen und -Besucher wenden sich zuerst an den Händler. Über das Cookie-Banner oder „Cookie-Einstellungen“ können sie ihre Wahl selbst ändern.
Pflicht zur Bereitstellung
Ohne Shop-Domain und Zugriffstoken können wir die App nicht betreiben. Die Einwilligungsprotokolle sind für den Nachweis der Wahl nötig, wenn der Händler das Banner nutzt. Andere Angaben sind freiwillig.
Automatisierte Entscheidungen
Es findet keine automatisierte Entscheidungsfindung im Sinn von Art. 22 DSGVO statt.
Aktualisierung
Wenn sich die App oder die Verarbeitung ändert, passen wir diese Erklärung an und setzen das Datum neu. Stand: September 2026.
The website privacy policy at wiedenroth.tech remains in force alongside this notice. Terms of use: https://consentgate.de/agb. Effective: 1 September 2026.
Controller
Wiedenroth Technologies GmbH
Speicherstraße 9
31134 Hildesheim
Deutschland
Email: info@wiedenroth-technologies.com
Phone: +49 5121 9289929
Managing director: Jan Ole Wiedenroth
Commercial register: Amtsgericht Hildesheim, HRB 208795
VAT ID: DE361687340
Legal notice: https://wiedenroth.tech/impressum
We have not appointed a data protection officer. Privacy requests should go to the email above.
What this covers
ConsentGate is a consent app for Shopify shops. It shows a cookie banner, holds back non-essential trackers until consent, and writes the choice to the Shopify Customer Privacy API and — if configured — to Google Consent Mode.
Towards the merchant we are the controller for app-installation and admin-use data. For shop visitors’ consent records the merchant is the controller; we process those data on the merchant’s behalf (Art. 28 GDPR).
Merchant data (installation and admin)
When you install or open ConsentGate in the Shopify admin, we process:
- shop domain (e.g. your-shop.myshopify.com) and the selected plan
- access tokens and granted scopes (OAuth / session) so the app can talk to Shopify
- for online sessions: Shopify user ID, name, email, locale and role of the person opening the app
- banner settings, copy, colours, categories and the list of detected services
- technical server logs (time, route, status code), if our hosting writes them
Legal basis: Art. 6(1)(b) GDPR (contract for use of the app) and Art. 6(1)(f) GDPR (operation, security, abuse prevention).
Banner configuration is also stored as a Shopify metafield. Shopify is a recipient of those data.
Shop-visitor data (cookie banner)
In the shop itself the banner stores, in the visitor’s browser (first-party, merchant domain):
- a random identifier (
consentgate.vidin local storage) - the choice made and the time (
consentgate.v1in local storage)
Via the Shopify app proxy the banner sends the choice to us for storage on the merchant’s behalf:
- the random identifier (no name, email or customer ID)
- decision (accept all / reject all / custom)
- categories: necessary, statistics, marketing, preferences
- banner version and language
- optionally a country or region code from the Shopify Customer Privacy API — no IP address
- timestamp
We do not store IP addresses, customer names or Shopify customer IDs. The records exist so the merchant can demonstrate consent (Art. 7(1) GDPR). The merchant’s legal basis is typically Art. 6(1)(c) and (f) GDPR; for setting non-essential cookies Art. 6(1)(a) GDPR together with § 25 TDDDG.
Retention of server records: configurable by the merchant, at least 30 days, at most 7 years, default 365 days. Older records are deleted automatically. Browser data remain until the visitor deletes them or changes the choice.
Shop scan
When the merchant scans the shop, ConsentGate loads the public storefront and inspects the theme, app embeds and visible scripts. URLs, hostnames and cookie names may be kept as evidence so services can be matched. This is solely for setting up the app (Art. 6(1)(b) GDPR).
Recipients and processors
- Shopify Inc. / Shopify International Ltd. — installation, login, Admin API, app proxy, webhooks, metafields. Shopify is based in Canada and Ireland; transfers rely on the adequacy decision for Canada or Shopify’s standard contractual clauses.
- Our hosting — the app and consent records sit on servers we operate or commission. Where an external host is used, it is in the EU under an Art. 28 GDPR contract.
We do not sell the data or use them for our own advertising.
Required Shopify webhooks
Shopify requires us to handle these events:
- App uninstalled / shop deleted: we delete shop data, banner, detected services, consent logs and sessions.
- Customer data request / customer deletion: ConsentGate does not store Shopify customer accounts. We cannot match a record to a customer; we confirm that to Shopify.
Retention (merchant data)
Sessions last while the app is installed or the token is valid. Shop settings last until uninstall. After uninstall we delete the data once the Shopify webhook arrives. Backups may exist a few days longer and are then overwritten.
Your rights
Data subjects have the rights of access, rectification, erasure, restriction, portability and objection where the statutory conditions are met. There is also a right to lodge a complaint with a supervisory authority. Ours is:
Die Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5
30159 Hannover
https://lfd.niedersachsen.de
Shop visitors should contact the merchant first. They can change their choice themselves via the cookie banner or “Cookie settings”.
Obligation to provide data
Without a shop domain and access token we cannot operate the app. Consent logs are required to evidence the choice if the merchant uses the banner. Other details are optional.
Automated decisions
There is no automated decision-making within the meaning of Art. 22 GDPR.
Updates
If the app or the processing changes, we update this notice and the date above. Effective: September 2026.