Privacy: Spicca - sidrene cijene.

This covers the Shopify app Spicca - sidrene cijene. It works with your products and prices, not with your customers, and it cannot read your orders.

Details

Who I am
Damir Medić, trading as Spicca, a sole trader (obrt) registered in Zagreb, Croatia. I build and run the app. info@spicca.com.hr
What the app does
It shows the anchor price (sidrena cijena) next to every price in your Shopify store and publishes your daily price list (cjenik) in CSV and XML on your store's own domain, as Croatian decisions NN 101/2026 require.
What it reads from your store
Only what the price list needs: your products and their variants (title, vendor, tags, status, publish date, SKU, barcode, price, compare-at price, unit price and availability), and your store's name, domain, currency and tax setting. The app asks Shopify for product access and nothing else, so it cannot read orders, customers, staff or payments.
What it writes to your store
Three fields on each product variant: the anchor price, its date and how it was set. They are ordinary metafields in your store, and you can view and change them in your Shopify admin. The app also saves your list of outlets where your theme can read it, so the price list block can link to each one.
What it keeps on its own servers
A copy of the product data above, refreshed every morning, because the price list is built from it. A record of each variant's price changes over time. The settings you enter in the app: your outlet's type, address and label, your store name, and your answers during setup. The price lists it has published. A short technical record of recent product updates and daily runs, used to find faults. And the access key Shopify gives the app to read and write your products.
Your customers and visitors
The app does not collect or store anything about your customers or the people who visit your store. Its storefront part sets no cookies and writes nothing to a visitor's browser. The option to show anchor prices only to visitors from Croatia uses the country Shopify has already chosen for the page, so no visitor location reaches the app. Some anchor prices are fetched from the app's server through Shopify. Like any web request, that request carries technical data such as an IP address, and Shopify adds a signed-in customer's ID number to it, as it does for every app. The app does not use or store either. They appear only in Cloudflare's short-lived request logs.
What is public
The price lists. Publishing them is what the law asks for, so anyone can open them at your store's /apps/cjenik address. They contain what your store already shows publicly: product names, codes, prices, anchor prices and your outlet's address and label.
Billing
Shopify bills you for the app. The app only checks with Shopify whether your store has an active plan and when a trial ends. It never sees card or payment details.
Where it is kept
The app runs on Cloudflare (Workers, Durable Objects and KV storage), which stores the data above on my behalf and may process it in data centres outside the EU under its data processing terms. Cloudflare keeps technical request logs for a few days. I read them when something is broken and not otherwise. Monitoring uses two outside services: healthchecks.io receives a short summary of each morning's run, which names your store's myshopify address only if its price list failed to publish, and UptimeRobot receives only counts. Nothing is sold, shared for marketing or used to train anything.
How long I keep it
While the app is installed. Each published price list stays public for 30 days, as the decision requires, and is deleted automatically the day after. Records of product updates are deleted after 7 days. When you uninstall, the access key and the copy of your products are deleted at once. Shopify then sends a deletion request 48 hours later, and everything else for your store is deleted: settings, price history and price lists. The anchor price fields in your store stay there, because they are your store's data. You can delete them in your Shopify admin.
Why I may use it
To provide the app you installed and subscribed to (GDPR Article 6(1)(b)). It is used for nothing else.
Your rights under GDPR
Access, correction, deletion, and a copy of anything I hold. Email me and you'll have it within a working week. You can also complain to the Croatian data protection authority, AZOP (azop.hr).
Changes
If this changes, the new version goes on this page with a new date. Last updated 5 October 2026.