Last updated: August 2026
When you create a CircularID account, we collect your name, email address, and the organisation details you provide. When you use the platform, we store the product and Digital Product Passport data you create — names, SKUs, materials, supply chain information, certifications, and any images you upload.
When a customer scans a published passport's QR code, we record the view (approximate country derived from IP address, device type, and referrer) to power the Analytics section of your dashboard. We do not store the scanning customer's IP address beyond what's needed to resolve their country, and published passport pages are viewable without any account or login.
If you connect Shopify or WooCommerce, we store the access credentials needed to read your product catalog and create products on your behalf, scoped to your organisation only. We never share these credentials with any other organisation using CircularID.
Data is stored on servers within the EU/hosting infrastructure used to operate CircularID Cloud. Passwords are hashed, third-party integration tokens are encrypted at rest, and access to your organisation's data is restricted to members you've invited.
You can request a copy of your data, correction of inaccurate data, or deletion of your account and associated data at any time by contacting us. Published passports are public by design once you publish them — unpublishing or archiving a passport removes it from public view.
The dashboard uses a session cookie to keep you signed in — it's cleared automatically after 60 minutes of inactivity or when you close your browser. We don't use third-party advertising or tracking cookies.
Questions about this policy or your data can be sent to the contact address listed on your CircularID account, or via circularid.trikagency.com.