TesseratesseraInstall on Shopify

Privacy Policy

Last updated: May 1, 2026

1. Data Controller

Tessera (“we”, “us”, “our”) is the data controller for the personal data processed through this website (tessra.eu). For questions about this policy, contact us at hello@tsera.io.

2. Data We Collect

This website uses Google Analytics (GA4) to understand how visitors interact with our pages. Google Analytics uses cookies to collect anonymized usage data such as pages visited, session duration, and referral source. This data is processed by Google LLC under their privacy policy. We do not collect personal data through forms. If you contact us via email, we process only the information you provide (name, email address, message content) for the purpose of responding to your inquiry.

3. Age Verification Processing

EU Age Gate verifies a customer's age on behalf of the Shopify merchant who installed the app (we act as data processor). The privacy-preserving design of the OpenID4VP protocol means we only receive the specific claim we request — a boolean age_over_18 value from the customer's EU Digital Identity Wallet — not a full identity document. No name, birthdate, or other personal data is collected or stored.

4. Legal Basis

We process personal data under Article 6(1)(f) GDPR (legitimate interest — responding to inquiries) and Article 6(1)(b) GDPR (performance of a contract — when you become a customer).

5. Data Retention

Email correspondence is retained for the duration of our business relationship and for up to 3 years after the last contact for legitimate business purposes.

6. Your Rights

Under GDPR, you have the right to access, rectify, erase, restrict, and port your personal data. You also have the right to object to processing and to lodge a complaint with your national data protection authority. To exercise these rights, contact hello@tsera.io.

7. Hosting and Security

This website is hosted on Vercel's global edge network. All connections are encrypted via TLS. We implement security headers including HSTS, Content-Security-Policy, and X-Frame-Options to protect against common web vulnerabilities.

8. Changes to This Policy

We may update this policy to reflect changes in our practices or legal requirements. The “last updated” date at the top indicates the most recent revision.