eTechflow LLC · Supplement SafetyOps

Privacy Policy

Last updated: 5 September 2026  ·  Version 1.0

1.Who we are and what this policy covers

Supplement SafetyOps is software used by merchants who sell dietary supplements to receive, investigate and report product-safety complaints and adverse events. It is operated by eTechflow LLC.

This policy explains how we handle personal information in two different roles:

If you are a consumer who reported a problem to a brand, that brand controls your information and its own privacy policy governs. Our software helps that brand meet its legal obligations. Please contact the brand directly — see section 9.

Supplement SafetyOps is designed primarily for United States dietary-supplement brands and US FDA workflows. It is not presented as providing complete legal coverage for every country.

2.Information we process on behalf of merchants

Where a consumer reports a product-safety concern, we may process:

Information reaches us either because the reporter submitted it, or because the merchant connected their Shopify store and we retrieved the order and customer record that the report relates to.

3.Why we process it

Solely so that a merchant can operate a lawful product-safety process: identify what was purchased and by whom; investigate the complaint; request missing information; assess seriousness; meet reporting obligations, including the duty to report serious adverse events within 15 business days; identify other consumers who may have received an affected lot; conduct safety or recall communication; and retain records as required by law.

We do not use this information for anything else. It is never used for marketing, advertising, remarketing, segmentation, profiling, scoring, sale, or training AI models. It is never shared with a merchant's marketing systems.

4.Legal bases for processing

SafetyOps processes health-related information on behalf of merchant customers. Each merchant is responsible for identifying and documenting an applicable lawful basis under Article 6 GDPR and a separate special-category condition under Article 9 GDPR. Where required and no statutory condition applies, explicit consent under Article 9(2)(a) will be obtained. The public-health condition under Article 9(2)(i) will only be relied upon where processing is specifically authorised by applicable EU or Member State law and the required safeguards are satisfied.

By jurisdiction

Legal bases are not identical everywhere, and should not be presented as though they were.

JurisdictionBasis relied on
United StatesCompliance with FDA adverse-event reporting and recordkeeping requirements; performance of merchant contracts; and legitimate business purposes such as product-safety investigations.
EU / EEAContract, legitimate interests or applicable legal obligations under Article 6, plus an appropriate Article 9 condition for health data — normally explicit consent unless a specific statutory condition applies.
United KingdomContract, legitimate interests or applicable legal obligations under UK GDPR, plus an Article 9 condition and, where required, a condition under Schedule 1 of the Data Protection Act 2018.
Other countriesThe merchant must identify the applicable local legal basis before using SafetyOps to process health information there.

5.Automated decision-making

We do not make automated decisions that produce legal or similarly significant effects.

We use AI to help safety staff work faster — reading an unstructured message and suggesting structured fields, and flagging text that may describe a serious event so that it is reviewed sooner. These are suggestions to a person, never decisions.

Every regulatory determination — whether an event is serious, whether it is reportable, whether a case may be closed — is made by a trained, authorised person, recorded with a written rationale, and attributed to a named individual. No AI output modifies a record or triggers any communication or external action on its own.

Before any AI provider is used, we assess whether data is used for model training, how long it is retained, where it is held, and what contractual controls apply. Identifying details are removed before text is sent for AI processing, and merchants can switch off external AI processing entirely for sensitive documents.

6.Who we share information with

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

7.How long we keep it

Product-safety records are retained for a minimum of six years from the date the report is received, because merchants are legally required to hold them — whether or not a report was ever submitted to a regulator. Merchants may configure longer periods.

Ordinary commerce data that is not part of a safety record — such as imported order history with no linked complaint — is kept only as long as needed for the app to function, and is deleted on schedule.

InformationRetention
Mandatory adverse-event recordsSix years from receipt of the report
Merchant account data after a deletion requestOrdinarily deleted within 30 days
Imported order data not linked to a case24 months rolling
All store data after the merchant uninstallsDeleted as Shopify requires — see section 8
Security and audit logs12–24 months, unless attached to a regulatory case
Encrypted backupsDeleted through the normal backup cycle, ordinarily within 90 days

8.Deletion requests and mandatory retention

We will honour verified deletion requests unless the relevant information must be retained to comply with applicable legal, regulatory, safety, fraud-prevention, dispute-resolution or legal-claims requirements.

Records relating to dietary-supplement adverse-event reports may be retained for at least six years from the date the report is received where required by United States law. During a mandatory retention period, the information will be restricted to authorised compliance, safety and legal purposes and will not be used for unrelated purposes.

Once the applicable retention period expires, the information will be securely deleted or irreversibly anonymised, subject to reasonable backup-deletion cycles.

Where a request cannot be fully honoured, we separate ordinary copied data from regulated records, delete or return what can lawfully be removed, restrict access to and pseudonymise what must be retained, document the recordkeeping reason, and inform the merchant.

If the merchant uninstalls the app

The six-year recordkeeping duty belongs to the merchant, not to us. Shopify instructs us to erase a store's data 48 hours after the app is uninstalled, and we act on that instruction.

So that no merchant loses records they are legally required to hold, a complete compliance archive is downloadable from their dashboard at any time throughout their subscription, they are warned before uninstalling wherever technically possible, and a secure export link is sent automatically when an uninstall is detected.

9.Your rights

Depending on where you live, you may have the right to access your information, correct it, request deletion, restrict or object to processing, receive a portable copy, withdraw consent, and complain to a supervisory authority.

If you reported a problem to a brand, please contact that brand first — they control your information. If you contact us instead, we will pass your request to the relevant merchant and support them in responding.

For information we hold as a controller, contact us at etechflow0@gmail.com. We respond within 30 days, or within any shorter period required by applicable law.

Exercising a right never results in worse treatment.

10.Security

We protect information with encryption in transit and at rest, encrypted backups, role-based access with least privilege, multi-factor authentication for privileged accounts, strict separation of production from test environments, access logging with alerting on unusual access, malware scanning, expiring download links with no public file URLs, and tested backup recovery.

Suspected vulnerabilities can be reported to etechflow0@gmail.com.

We describe our controls as Part 11-supporting. We do not claim to be Part 11 compliant, FDA approved, FDA certified or HIPAA certified — compliance depends on how software and a merchant's own procedures operate together.

11.Where information is held and international transfers

Information is processed in the United States, on Oracle Cloud Infrastructure in Ashburn, Virginia. The database, files, backups and application remain in the US region where possible.

Where personal data is transferred internationally, we use an applicable lawful transfer mechanism, including European Commission Standard Contractual Clauses for transfers governed by EU GDPR, the UK International Data Transfer Addendum or International Data Transfer Agreement for transfers governed by UK GDPR, and an applicable adequacy decision where available. Where required, we also conduct transfer risk assessments and implement supplementary technical and organisational safeguards.

12.Children

The app is not directed at children. Where a report concerns a child, the information is provided by an adult reporter and is handled with the same protections as other health information.

13.Emergencies

Our software is not an emergency service and does not provide medical advice, diagnosis or treatment. If you may be experiencing a medical emergency, contact emergency services or an appropriate healthcare professional.

14.Changes to this policy

We will post material changes on this page and notify merchant account owners. The version and date at the top of this page show the current revision.

15.Subprocessors

We use the following service providers to operate Supplement SafetyOps. Each is assessed before engagement and bound by data protection terms.

ProviderPurposeLocation
Oracle Cloud InfrastructureApplication hostingUnited States
Oracle Cloud InfrastructureDatabase hostingUnited States
Oracle Cloud Object StorageFile and attachment storageUnited States
Shopify Inc.APIs, authentication, billing and merchant-store dataCanada / United States

This list is kept current. We will update this page before engaging any new subprocessor, and merchants can subscribe to notifications of changes by contacting etechflow0@gmail.com.

16.Contact us

For privacy enquiries, security or vulnerability reports, and support:
etechflow0@gmail.com

Registered address

eTechflow LLC
18121 E Hampden Ave, Unit C 1445
Aurora, CO 80013
United States

Mailing address for privacy correspondence

eTechflow LLC
1500 N Grant St, Ste N
Denver, CO 80203
United States

We have not appointed an EU or UK representative or a Data Protection Officer, as Supplement SafetyOps is not currently offered to, and does not monitor, individuals in the EU/EEA or the United Kingdom. We will reassess this before offering the app in those markets.