Home Legal Wording for your own policy

Wording for your own policy

Copy-and-adapt wording for a merchant's own privacy policy and cookie notice, covering the item register, what a scan sends, and what you need not say.

Last updated 11 August 2026 · Applies to the Provenance Shopify app

You are the controller of your customers' information. We are your processor. That means your own privacy policy should mention this app, even though it holds less about your customers than almost anything else you have installed.

Below is wording you can copy and adapt. It is a starting point written by people who know what the app does, not legal advice, and it is not a substitute for someone who knows your business and your jurisdiction. Read it, change what does not match how you use the app, and delete what does not apply.

Replace anything in square brackets.

1. For your privacy policy

The short version, which is enough for most stores.

Item records and verification

Some of our products carry a unique identifier, printed on a card or label as a QR code. Scanning it opens a page on this website that shows what the item is: the model, the colourway, when it was made, its edition number if it has one, and its current status.

That lookup is provided by Provenance, an app made by Monochrome, which we use to keep our register of individual items. The record describes the object, not its owner. We do not record who owns an item, and no name, email address, order number or price is stored against an identifier.

When somebody scans a card, the technical details of that request, including an IP address, reach Monochrome and are kept in their operational logs for 30 days. Their privacy policy is at https://provenance.monochrome.digital/legal/privacy/.

2. If you want the longer version

For a store whose customers ask, or a policy that is thorough elsewhere and would look thin here.

Item records and verification

We keep a register of the individual items we make. Each one has a unique identifier, which is printed on the card or label that ships with it. The register records what that item is: [product, variant, the date it was made, its edition number, its status]. It does not record anything about the person who owns it.

The register is held in two places. A copy sits in our own Shopify admin, under our control. The system of record is a database in the European Union, operated by Monochrome, the makers of the Provenance app we use to manage it.

When a card is scanned. The identifier travels in the part of the web address after the #, which browsers do not send to a server, and the page then asks Monochrome's service what that identifier names. Monochrome receives the identifier and the technical details of the request, including an IP address and the type of browser. These sit in their hosting providers' operational logs for a short period, are used to run the service and to detect abuse, and are not used to build a profile or to advertise. No cookie is set by the lookup.

What a lookup means. It returns what we recorded about an item. It is not a guarantee of authenticity and it is not a valuation. If something you are holding does not match what the record says, [contact us at your address].

Monochrome's privacy policy is at https://provenance.monochrome.digital/legal/privacy/. We have a data processing agreement with them.

Probably nothing, and that is not a mistake.

The verification page sets no cookies of its own and runs no analytics of its own. If your theme sets cookies, or if you run analytics across your storefront, the verification page is a page of your storefront like any other and your existing wording already covers it. Nothing needs adding on account of this app.

If your notice lists categories and you want to be explicit:

The item verification page on this site sets no cookies of its own. Any cookies present there are the ones described elsewhere in this notice, set by our store.

4. For your terms, if you make claims

Only if you are recording claims about materials, origin or dates on the register, and worth thinking about if you are.

A record is a statement you have made to your customer. It is treated as one by a consumer protection regulator, and it is the kind of statement that gets read back to you two years later by somebody reselling the item. Recording "Adria leather" when you are not certain whether a particular hide was Adria or nappa is a copy problem on a product page and something worse on a certificate.

About our item records. The information shown when you scan one of our cards is recorded by us and reflects our own records of that item. We keep it accurate to the best of our knowledge. If you believe a record is wrong, [contact us at your address] and we will look into it.

There is no wording that makes an inaccurate claim safe. The only safe move is to leave a field blank rather than fill it with a guess.

5. What you do not need to say

Listed so you do not write it out of caution.

  • You do not need consent for the lookup. It sets no cookies and stores nothing on the device. Consent is about storage and access on a device, and neither happens here.
  • You do not need to name Monochrome as receiving customer data, because it does not receive any. It receives an identifier and the technical details of a web request.
  • You do not need a separate agreement with us. The Data Processing Addendum is already in force.

6. If your lawyer asks for something else

Write to hello@monochrome.digital. We would rather answer a question from your counsel than have you publish wording that describes an app we do not make.