1. Controller
Your data is controlled by Vasja Bocko s.p., a sole trader registered in Slovenia. All rights reserved. Contact: hello@hstariff.com.
2. Data we collect
- Email address — used to authenticate you via a one-time code. No password is stored.
- Classification history — every HS code lookup you perform is saved to your account so you can review it later.
- Shopify store data — if you connect a Shopify store, we access your product list and write HS codes and country-of-origin data back to your inventory. We do not store your full product catalogue; only the data required to perform and display classifications.
- Usage data — we track credit consumption per organisation for billing purposes.
- Session data — a session cookie is stored in your browser to keep you signed in.
3. How we use your data
- To authenticate you and maintain your session.
- To provide the classification service and save your results.
- To operate the Shopify integration on your behalf.
- To track usage for credit/billing purposes.
- To send transactional emails (sign-in codes only — no marketing without consent).
4. Third-party services
We use the following sub-processors:
- Resend — transactional email delivery.
- Anthropic / OpenAI / Google — AI model providers used to generate HS code classifications. Product descriptions may be sent to these providers to produce results.
- Fly.io — cloud infrastructure and database hosting.
- Shopify — when you connect your store, data is exchanged via the Shopify API under your authorisation.
We do not sell your data to any third party.
5. Legal basis (GDPR)
We process your personal data on the basis of contract performance (providing the service you signed up for) and legitimate interests (security, fraud prevention, service improvement). Where required, we will seek your consent.
6. Data retention
Your account data and classification history are retained for as long as your account is active. You may request deletion of your account and all associated data at any time by contacting us.
7. Your rights
Under GDPR you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data ("right to be forgotten").
- Object to or restrict processing in certain circumstances.
- Lodge a complaint with the Slovenian Information Commissioner (ip-rs.si).
To exercise any of these rights, contact us at hello@hstariff.com.
8. Cookies
We use a single session cookie (__session) to keep you signed in. No tracking or advertising cookies are used.
9. Changes to this policy
We may update this policy from time to time. We will notify you of significant changes via email. Continued use of the service constitutes acceptance of the updated policy.