Facturier
AboutIntegrationsCapabilitiesFeaturesPricingFAQ
PrivacyInstall Facturier
AboutIntegrationsCapabilitiesFeaturesPricingFAQPrivacy PolicyInstall Facturier

Facturier Privacy Policy

Last updated: 28 May 2026
Effective date: 28 May 2026


1. Introduction

This Privacy Policy explains how Facturier (“we”, “us”, “our”) collects, uses, stores, shares, and protects personal data when you visit our website at https://facturier.app, install or use the Facturier application on Shopify (the “App”), or interact with Facturier-powered features in Shopify Admin, Checkout, Customer Account, or Shopify POS.

Facturier is a Shopify embedded app for Romanian and EU e-commerce merchants. It helps merchants generate fiscal documents (invoices, proformas, credit notes), create shipping labels (AWBs), manage pickup points, sync inventory, and related operational workflows by connecting Shopify with billing, logistics, and geo-validation providers.

If you do not agree with this Privacy Policy, do not install or use the App.


2. Who we are (Data Controller)

For personal data relating to our operation of the App (for example merchant staff authentication, support requests, platform logs, and billing of the App subscription), we act as an independent data controller under the EU General Data Protection Regulation (“GDPR”) and applicable national law.

FieldDetails
Trade name / productFacturier
Legal entityCORE ELEVATING MEDIA S.R.L.
Registered addressStr. Barcaului nr. 92, Municipiul Oradea, Județul Bihor, Cod poștal 410257, România
Trade Register No.J05/292/2019
Unique Registration Code (CUI / CIF)40481264
EUIDROONRC.J5/292/2019
Main activity (CAEN)6311 — Prelucrarea datelor, administrarea paginilor web și activități conexe
Contact emailsupport@facturier.app
Websitehttps://facturier.app
Data Protection contactsupport@facturier.app (subject: “Data Protection”)

3. Roles under GDPR

Depending on the data and context, different roles apply:

ContextTypical role of FacturierTypical role of merchant
Merchant staff using the embedded App in Shopify Admin or POSController—
End customers of the merchant (order, shipping, invoice, pickup-point data processed to deliver App features)Processor (processing on the merchant’s instructions)Controller
Shopify platform data accessed via granted API scopesProcessor (for merchant customer/order data) / Controller (for our own session and operational records)Controller (for store and buyer data in Shopify)

When we act as a processor, the merchant’s privacy policy and terms govern the merchant–customer relationship. Merchants are responsible for providing lawful bases, notices, and rights mechanisms to their customers. We process merchant customer data only to provide the App and as documented here and in our agreement with the merchant (Shopify’s Partner Program terms and the merchant’s use of the App).


4. What personal data we process

We process only the personal data reasonably necessary to operate the App. We do not sell personal data.

4.1 Merchant and staff data

When a merchant installs the App or staff open it in Shopify Admin or POS, we may process:

  • Shopify shop domain and shop identifier
  • OAuth access tokens and session metadata (stored in our database)
  • Staff user identifier, name, email, locale, and account role flags provided by Shopify during authentication
  • App settings and integration credentials the merchant configures (billing provider keys, courier credentials, sender locations, notification preferences)
  • Support messages submitted through the in-app contact form (email address, subject, message, shop domain)
  • Subscription and entitlement information via Shopify App Pricing / Partner API

4.2 Order, fulfillment, and customer data (merchant end customers)

To generate invoices, AWBs, pickup-point flows, returns, inventory updates, and related features, we access and process Shopify order and customer data permitted by the scopes the merchant grants, including where applicable:

  • Customer name, email, phone number
  • Billing and shipping addresses
  • Company name and tax identifiers (for example VAT/CIF, CNP where provided for Romanian fiscal compliance)
  • Order line items, totals, currency, payment and fulfillment status
  • Pickup point / locker selection and shipping method metadata
  • Customs declaration information for export shipments
  • Fulfillment and tracking identifiers (AWB numbers, label URLs, courier metadata)

Much of this operational output is written back to Shopify order and fulfillment metafields under the app.facturier namespace (invoice numbers, document URLs, billing status, AWB data, mirrored fiscal identifiers, reminder state, etc.). Business records therefore remain primarily in the merchant’s Shopify store.

4.3 Checkout and Customer Account extension data

When enabled, Facturier UI extensions in Checkout and Customer Account may:

  • Display pickup-point selection interfaces (including map-based selection when the merchant configures Google Maps)
  • Read order/shipping context needed to save a pickup point to the order
  • Expose invoice download links on the order status page

These extensions authenticate using Shopify session tokens. They do not bypass Shopify checkout or create standalone buyer accounts on our servers.

4.4 Transactional emails to end customers

If the merchant enables pickup-point reminder emails, Facturier may send one transactional email per eligible order to the customer’s order email address via our email provider (Resend), using merchant-configurable subject and body templates. Reply-To may be set to a merchant-provided address. We do not use this channel for marketing newsletters.

4.5 Technical, security, and performance data

We process limited technical data to secure and operate the App:

  • Request identifiers, timestamps, HTTP metadata
  • Application logs with automatic redaction of common personal data fields (emails, phone numbers, CNP, CIF/VAT patterns, names, addresses in structured log context)
  • Aggregated admin performance metrics (Web Vitals) and carrier rate-callback latency statistics stored in Redis
  • Webhook delivery metadata and HMAC verification results
  • Privacy compliance webhook records (customers/data_request, customers/redact, shop/redact)

We do not operate third-party advertising or cross-site tracking for merchant end customers through the App.


5. Purposes and legal bases (GDPR Article 6)

PurposeData involvedLegal basis
Provide the App (invoicing, logistics, pickup points, inventory, returns, extensions)Order, customer, fulfillment, settings, credentialsPerformance of contract with the merchant (Art. 6(1)(b)); where end-customer data is involved, processing is on the merchant’s documented instructions as processor
Authenticate merchants/staff and maintain sessionsSession tokens, staff profile fieldsPerformance of contract (Art. 6(1)(b)); Legitimate interests in secure access (Art. 6(1)(f))
Connect to billing and courier providers chosen by the merchantOrder/customer/shipment data, API credentialsPerformance of contract (Art. 6(1)(b))
Send optional pickup-point reminder emails when enabledCustomer email, order name, shop name, status page URLPerformance of contract with merchant / merchant’s legitimate interests in completing delivery (Art. 6(1)(b)/(f)); merchant must ensure appropriate customer notice
Romanian fiscal validation (e.g. ANAF CIF checks when enabled)VAT/CIF identifiersLegal obligation / Performance of contract depending on merchant configuration (Art. 6(1)(c)/(b))
Handle support requestsContact details, message content, shop domainPerformance of contract; Legitimate interests in support (Art. 6(1)(b)/(f))
Security, fraud prevention, debugging, service reliabilityLogs, webhook metadata, telemetry aggregatesLegitimate interests (Art. 6(1)(f))
Comply with law and Shopify mandatory privacy webhooksRedaction/data-request recordsLegal obligation (Art. 6(1)(c))
App subscription billing via ShopifyShop identifier, plan/entitlement dataPerformance of contract (Art. 6(1)(b))

Where we rely on legitimate interests, we balance those interests against data subjects’ rights and implement minimization and retention limits described below.


6. Where data is stored

StorageWhat is storedNotes
Shopify (merchant store)App settings metafields, order/fulfillment metafields, order additional details for pickup pointsPrimary business record; survives typical App database cleanup
PostgreSQL (self-hosted)Shopify OAuth sessions; privacy webhook action audit recordsOnly persistent database tables; no separate business datastore
Redis (self-hosted)Job queues, geo-resolution cache, integration token cache (AuthVault), short-lived signed links to PDFs/labels (~90 seconds), aggregated telemetryEphemeral / operational
Application logsRedacted operational logsHot rotation on server; optional cold archives (~30 days default)
Third-party providers (see §7)Data transmitted to generate documents, labels, or emailsGoverned by merchant configuration and provider terms

Production infrastructure is hosted on a VPS in the EU (currently Hetzner per our deployment architecture), with TLS encryption in transit.


7. Recipients and sub-processors

We share personal data only as needed to operate the App:

7.1 Shopify

Shopify hosts the merchant store, Admin, Checkout, APIs, and extension runtime. Data flows through Shopify APIs under the merchant’s granted scopes and Shopify’s terms.

7.2 Billing integrators (merchant-configured)

When connected by the merchant, order and customer data needed for fiscal documents may be sent to:

  • SmartBill
  • FGO
  • Oblio

7.3 Courier / logistics providers (merchant-configured)

When connected by the merchant, shipment and recipient data may be sent to one or more of:

  • Fan Courier
  • Cargus
  • Sameday
  • Packeta
  • DPD
  • MyGLS
  • Dragon Star Courier (DSC)

Geo-resolution caches may store normalized city/street identifiers to satisfy provider API requirements.

7.4 Other service providers

ProviderPurpose
ResendTransactional email delivery (pickup reminders, support routing)
Google Maps PlatformMap display in pickup-point selector when the merchant supplies an API key
ANAF (Romanian tax authority APIs)Optional VAT/CIF validation when enabled by the merchant
Hosting / infrastructure (e.g. Hetzner, Docker runtime)Application hosting

Merchants choose which integrations to enable. We do not send data to a billing or courier provider unless that integration is configured for their shop.

We may disclose data if required by law, court order, or to protect rights, safety, and security.


8. International transfers

Some sub-processors (for example Shopify, Resend, or Google) may process data outside the European Economic Area (EEA). Where required, we rely on appropriate safeguards such as Standard Contractual Clauses, adequacy decisions, or equivalent mechanisms offered by those providers.

Merchants should review their chosen integrators’ privacy documentation for transfer details.


9. Retention

We retain personal data only as long as necessary for the purposes above:

Data categoryRetention period
Shopify OAuth sessionsUntil session expiry, App uninstall, or successful shop/redact handling (sessions deleted on uninstall)
Integration tokens (AuthVault)Until integration disconnect, credential rotation, or shop redaction
Short-lived document/label links (Redis)~90 seconds
Geo cache entriesCached for operational efficiency; not a permanent archive
Application logsHot log rotation on server; cold archives typically ~30 days (configurable)
Privacy webhook recordsRecorded with a 30-day action window aligned with Shopify compliance requirements; retained as audit trail thereafter only as long as needed for compliance evidence
Order/fulfillment metafields in ShopifyControlled by merchant and legal/fiscal retention obligations (Romanian/EU tax and shipping records may require longer retention); redacted or anonymized when legally permissible and when Shopify sends customers/redact / shop/redact
Customs declaration metafieldsDeleted or anonymized after export/legal retention expires

When retention ends, we delete or anonymize data in our systems. Data written to Shopify metafields may remain in the merchant store until the merchant or Shopify deletes it, subject to legal holds.


10. Security measures

We implement technical and organizational measures appropriate to the risk, including:

  • Encryption in transit (HTTPS/TLS for all App endpoints)
  • Access controls and Shopify OAuth session tokens for Admin/API access
  • Webhook HMAC verification for Shopify webhooks
  • Credential vaulting for provider tokens (Redis AuthVault)
  • Structured logging with PII redaction in application logs
  • Infrastructure isolation between staging and production environments
  • Least-privilege API scopes required for App functionality

No method of transmission or storage is 100% secure. Merchants must protect their Shopify accounts and integration credentials.


11. Shopify mandatory privacy webhooks

Facturier subscribes to Shopify’s mandatory compliance webhooks:

WebhookOur response
customers/data_requestWe record the request and provide merchant customer data we hold in our systems within 30 days, or explain if data exists only in Shopify/metafields or with a third-party integrator
customers/redactWe record the request and delete or anonymize personal data in our systems associated with the specified customer/orders within 30 days, except where retention is legally required
shop/redactWe record the request and delete shop-associated data in our database (sessions, cached tokens, operational records) within 30 days, except where retention is legally required

Fiscal and shipping records mirrored in Shopify order metafields may need to be retained by the merchant under tax or commercial law even after redaction requests. In those cases we document the legal basis for retention in our internal compliance records.

On App uninstall, we delete OAuth sessions for that shop from our database. Merchants should also request Shopify shop/redact after uninstall for full cleanup of compliance-tracked actions.


12. Your rights (GDPR)

If we act as controller of your personal data (for example you are merchant staff or you contact support), you have the following rights, subject to conditions in GDPR:

  • Access — request confirmation and a copy of your data
  • Rectification — correct inaccurate data
  • Erasure — request deletion where applicable
  • Restriction — request limited processing
  • Portability — receive data you provided in a structured format where applicable
  • Objection — object to processing based on legitimate interests
  • Withdraw consent — where processing is consent-based (not typically the primary basis for core App features)

To exercise these rights, email support@facturier.app with subject “Data Protection Request”. We may need to verify your identity. We respond within one month, extendable where permitted by law.

You may lodge a complaint with your local supervisory authority. In Romania, this is the ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal) — https://www.dataprotection.ro.

End customers of merchants

If you are a buyer of a store using Facturier, contact the merchant (store owner) first to exercise your privacy rights. The merchant is usually the controller of your order data. We will assist the merchant as processor when required.


13. Cookies and similar technologies

13.1 Merchant Admin / embedded App

The App runs embedded in Shopify Admin and uses Shopify session tokens for authentication (not third-party advertising cookies). Shopify’s own cookies and policies apply to the Admin experience.

13.2 Checkout / Customer Account extensions

Extensions run in Shopify-controlled checkout and customer account surfaces. Facturier does not set standalone marketing cookies on buyers through these extensions.

13.3 Google Maps (optional)

If the merchant enables map-based pickup selection, Google Maps Platform may process technical data according to Google’s policies and the merchant’s Google Cloud configuration.

13.4 We do not use

  • Cross-merchant buyer profiling
  • Third-party ad networks in the App backend
  • Sale of personal data

14. Automated decision-making

Facturier does not make legal or similarly significant decisions about individuals solely by automated means without human involvement. Optional ANAF VAT validation may block invoice generation when a tax identifier fails validation rules configured by the merchant, but fiscal document issuance remains under merchant control.


15. Children’s data

The App is intended for merchants conducting commercial transactions. We do not knowingly collect personal data from children under 16 (or the applicable age in your jurisdiction) for our own marketing purposes. Merchants must comply with applicable rules when selling to minors.


16. Merchant responsibilities

Merchants using Facturier agree to:

  1. Provide accurate privacy information to their customers about invoicing, shipping, pickup points, and related processing
  2. Establish lawful bases for processing buyer personal data
  3. Configure only integrations they are authorized to use
  4. Protect API credentials and staff access to Shopify Admin
  5. Respond to customer privacy requests for data the merchant controls in Shopify
  6. Comply with Romanian/EU fiscal and consumer rules when generating and storing invoices and AWBs

17. Changes to this Privacy Policy

We may update this Privacy Policy to reflect product, legal, or regulatory changes. We will revise the “Last updated” date at the top. Material changes may be communicated through the App, our website, or email where appropriate. Continued use of the App after the effective date constitutes acceptance of the updated policy.


18. Contact

Facturier — Privacy & Data Protection
CORE ELEVATING MEDIA S.R.L. · CUI 40481264 · J05/292/2019
Str. Barcaului nr. 92, 410257 Oradea, Bihor, România
Website: https://facturier.app
Email: support@facturier.app


Appendix A — Shopify API scopes

The App requests Shopify API access needed for its features, including:

read_orders, write_orders, read_customers, read_products, read_fulfillments, write_fulfillments, merchant-managed and assigned fulfillment order scopes, third-party fulfillment order scopes, read_inventory, write_inventory, read_locations, read_shipping, write_shipping.

Scopes are granted by the merchant at install time and can be reviewed in Shopify Admin.


Appendix B — Summary of data storage

The table below summarizes where Facturier stores or processes data and what typically happens when Shopify sends a customer or shop redaction request.

StorageExamplesTypical action on redact
Shopify metafields (app.facturier.*)Invoice/AWB ledger, fiscal identifiers, customs JSONLegal retention may apply; otherwise anonymize or delete where feasible
Short-lived access linksPDF/label share tokensExpire automatically (~90 seconds)
App sessionsOAuth tokens, staff name/emailDelete
Integration credentialsCourier and billing provider tokensDelete
Privacy compliance recordsAudit trail of data requests and redactionsRetained only as long as needed for compliance evidence
Facturier

Automate your Shopify operations — invoicing, proforma invoices, and shipping labels in one app.

Product

IntegrationsFeaturesPricing

Resources

FAQSetup GuideSupportPrivacy Policy

© 2026 Facturier. All rights reserved. Privacy Policy

Shopify is a trademark of Shopify Inc. Facturier is an independent app built for Shopify merchants and is not endorsed by Shopify.