Our audit process: how we produce a PPWR compliance package

Transparency about how every number is computed — and why gaps are shown, not hidden.

What the audit package is

The PPWR Compliance app turns your Shopify store data into a verifiable packaging audit: which countries you have producer-responsibility obligations in, how many kilograms of which materials you ship into each, what evidence is missing, and what to hand to which service provider.

Every number carries its calculation trail: which BOM (bill of materials) version, where the data came from, and when it was generated. When a regulator asks "how was this number computed?", the package answers it.

Not legal advice: conclusions needing professional judgment are marked "pending confirmation". Every export ends with a fixed statement of this boundary.

Three ways in, one aggregation path

Your data enters the app by any of three routes — and all three feed the same pipeline:

  1. CSV paste — export an Orders CSV from your Shopify admin and paste it in.
  2. "Sync from Shopify" — one click pulls your last 12 months via the GraphQL Admin API.
  3. Webhook (automatic) — new orders arrive in real time, HMAC-verified.
Parse → validate → normalize fulfillment status → join to BOMs by SKU → aggregate by destination country × order status × material → idempotent upsert (same order + material = one row; re-imports overwrite)

Excluded orders, honestly counted: orders removed by rules (test orders, cancelled status) are tallied. The audit package shows the real exclusion count from your most recent import — or "unknown" if you've never imported. We never write 0 when we mean "we don't know".

What the package contains

SectionWhat it shows
Country totalsWeight (g) and order count per destination country × material × order status
BOM detailEach SKU's packaging layers: material code (PAP 20, LDPE 04…), weight, source. Estimated weights must carry their estimation basis — recomputable
Evidence gapsSKUs without BOMs, unmatched order lines, missing registrations, countries outside rule coverage — exposed, not hidden
Registration statusRegistry entries you've recorded (LUCID, IDU, CONAI) with number + verification timestamp
Rule versionsWhich rules version participated — trace every figure back
Excluded ordersCount + import timestamp; "unknown" ≠ 0

Frozen at generation: content is frozen with a SHA-256 checksum at the moment you generate it. CSV / PDF / ZIP downloads are all derived from that same frozen content — "what was delivered when" is reproducible. The ZIP adds a manifest with per-section hashes so the recipient can verify nothing was altered.

Version safety: legacy packages are detected by content fingerprint; if one would rebuild inaccurately, the download refuses it and asks you to regenerate — we don't hand over numbers we can't stand behind.

Evidence gaps: we show what we don't know

GapMeaning
Missing weightA packaging layer lacks its weight — flagged, not guessed
Missing material codeA layer lacks its material code
Order without BOMLine can't be recomputed — exposed rather than silently zeroed
Registration missingA destination country has an obligation but no registration record
Rule not readyNo reviewed active rule — degrades to "awaiting rules", never asserts
Country not coveredListed for manual confirmation; never silently treated as "no obligation"

Gaps disappear dynamically as you fill data in — add a BOM or a registration and the gap vanishes.

The service-provider handoff package

After the audit, the app can generate a handoff package pre-filled to what each EPR provider asks for. Provider field specs come from first-hand verification of the providers' own websites — including which fields we produce, which you must supply (e.g. your LUCID number), and which need confirmation.

Handoff follows a strict state machine: generated → handed over → submitted → receipt — no skipping; the last states are advanced by you (we record, we don't advance).

What we ask of you

The app aggregates what you supply — it cannot verify supplier statements or registry records on your behalf. Our responsibility: every computation reproducible, every gap visible. Your responsibility: accuracy of what you enter. For binding regulatory guidance, rely on official sources and your own advisors.

Pricing (billed through Shopify)

One-time audit packages — no subscription, no automatic renewal:

PackageIncludesLimit
Basic — $29Responsibility conclusion, packaging inventory, order-country aggregation≤ 50 SKUs
Full — $59Basic + evidence gap list + registration status≤ 200 SKUs
Handoff — $99Full + service-provider handoff + 30-min review call≤ 200 SKUs

Additional SKUs $0.10 each; more than 3 destination countries quoted separately before any charge. Every charge requires your explicit confirmation in Shopify checkout.

Ready to see it on your own store? Install from the Shopify App Store — browsing the workspace is free.