Facturier Privacy Policy
Last updated: 28 May 2026
Effective date: 28 May 2026
1. Introduction
This Privacy Policy explains how Facturier (“we”, “us”, “our”) collects, uses, stores, shares, and protects personal data when you visit our website at https://facturier.app, install or use the Facturier application on Shopify (the “App”), or interact with Facturier-powered features in Shopify Admin, Checkout, Customer Account, or Shopify POS.
Facturier is a Shopify embedded app for Romanian and EU e-commerce merchants. It helps merchants generate fiscal documents (invoices, proformas, credit notes), create shipping labels (AWBs), manage pickup points, sync inventory, and related operational workflows by connecting Shopify with billing, logistics, and geo-validation providers.
If you do not agree with this Privacy Policy, do not install or use the App.
2. Who we are (Data Controller)
For personal data relating to our operation of the App (for example merchant staff authentication, support requests, platform logs, and billing of the App subscription), we act as an independent data controller under the EU General Data Protection Regulation (“GDPR”) and applicable national law.
| Field | Details |
|---|---|
| Trade name / product | Facturier |
| Legal entity | CORE ELEVATING MEDIA S.R.L. |
| Registered address | Str. Barcaului nr. 92, Municipiul Oradea, Județul Bihor, Cod poștal 410257, România |
| Trade Register No. | J05/292/2019 |
| Unique Registration Code (CUI / CIF) | 40481264 |
| EUID | ROONRC.J5/292/2019 |
| Main activity (CAEN) | 6311 — Prelucrarea datelor, administrarea paginilor web și activități conexe |
| Contact email | support@facturier.app |
| Website | https://facturier.app |
| Data Protection contact | support@facturier.app (subject: “Data Protection”) |
3. Roles under GDPR
Depending on the data and context, different roles apply:
| Context | Typical role of Facturier | Typical role of merchant |
|---|---|---|
| Merchant staff using the embedded App in Shopify Admin or POS | Controller | — |
| End customers of the merchant (order, shipping, invoice, pickup-point data processed to deliver App features) | Processor (processing on the merchant’s instructions) | Controller |
| Shopify platform data accessed via granted API scopes | Processor (for merchant customer/order data) / Controller (for our own session and operational records) | Controller (for store and buyer data in Shopify) |
When we act as a processor, the merchant’s privacy policy and terms govern the merchant–customer relationship. Merchants are responsible for providing lawful bases, notices, and rights mechanisms to their customers. We process merchant customer data only to provide the App and as documented here and in our agreement with the merchant (Shopify’s Partner Program terms and the merchant’s use of the App).
4. What personal data we process
We process only the personal data reasonably necessary to operate the App. We do not sell personal data.
4.1 Merchant and staff data
When a merchant installs the App or staff open it in Shopify Admin or POS, we may process:
- Shopify shop domain and shop identifier
- OAuth access tokens and session metadata (stored in our database)
- Staff user identifier, name, email, locale, and account role flags provided by Shopify during authentication
- App settings and integration credentials the merchant configures (billing provider keys, courier credentials, sender locations, notification preferences)
- Support messages submitted through the in-app contact form (email address, subject, message, shop domain)
- Subscription and entitlement information via Shopify App Pricing / Partner API
4.2 Order, fulfillment, and customer data (merchant end customers)
To generate invoices, AWBs, pickup-point flows, returns, inventory updates, and related features, we access and process Shopify order and customer data permitted by the scopes the merchant grants, including where applicable:
- Customer name, email, phone number
- Billing and shipping addresses
- Company name and tax identifiers (for example VAT/CIF, CNP where provided for Romanian fiscal compliance)
- Order line items, totals, currency, payment and fulfillment status
- Pickup point / locker selection and shipping method metadata
- Customs declaration information for export shipments
- Fulfillment and tracking identifiers (AWB numbers, label URLs, courier metadata)
Much of this operational output is written back to Shopify order and fulfillment metafields under the app.facturier namespace (invoice numbers, document URLs, billing status, AWB data, mirrored fiscal identifiers, reminder state, etc.). Business records therefore remain primarily in the merchant’s Shopify store.
4.3 Checkout and Customer Account extension data
When enabled, Facturier UI extensions in Checkout and Customer Account may:
- Display pickup-point selection interfaces (including map-based selection when the merchant configures Google Maps)
- Read order/shipping context needed to save a pickup point to the order
- Expose invoice download links on the order status page
These extensions authenticate using Shopify session tokens. They do not bypass Shopify checkout or create standalone buyer accounts on our servers.
4.4 Transactional emails to end customers
If the merchant enables pickup-point reminder emails, Facturier may send one transactional email per eligible order to the customer’s order email address via our email provider (Resend), using merchant-configurable subject and body templates. Reply-To may be set to a merchant-provided address. We do not use this channel for marketing newsletters.
4.5 Technical, security, and performance data
We process limited technical data to secure and operate the App:
- Request identifiers, timestamps, HTTP metadata
- Application logs with automatic redaction of common personal data fields (emails, phone numbers, CNP, CIF/VAT patterns, names, addresses in structured log context)
- Aggregated admin performance metrics (Web Vitals) and carrier rate-callback latency statistics stored in Redis
- Webhook delivery metadata and HMAC verification results
- Privacy compliance webhook records (
customers/data_request,customers/redact,shop/redact)
We do not operate third-party advertising or cross-site tracking for merchant end customers through the App.
5. Purposes and legal bases (GDPR Article 6)
| Purpose | Data involved | Legal basis |
|---|---|---|
| Provide the App (invoicing, logistics, pickup points, inventory, returns, extensions) | Order, customer, fulfillment, settings, credentials | Performance of contract with the merchant (Art. 6(1)(b)); where end-customer data is involved, processing is on the merchant’s documented instructions as processor |
| Authenticate merchants/staff and maintain sessions | Session tokens, staff profile fields | Performance of contract (Art. 6(1)(b)); Legitimate interests in secure access (Art. 6(1)(f)) |
| Connect to billing and courier providers chosen by the merchant | Order/customer/shipment data, API credentials | Performance of contract (Art. 6(1)(b)) |
| Send optional pickup-point reminder emails when enabled | Customer email, order name, shop name, status page URL | Performance of contract with merchant / merchant’s legitimate interests in completing delivery (Art. 6(1)(b)/(f)); merchant must ensure appropriate customer notice |
| Romanian fiscal validation (e.g. ANAF CIF checks when enabled) | VAT/CIF identifiers | Legal obligation / Performance of contract depending on merchant configuration (Art. 6(1)(c)/(b)) |
| Handle support requests | Contact details, message content, shop domain | Performance of contract; Legitimate interests in support (Art. 6(1)(b)/(f)) |
| Security, fraud prevention, debugging, service reliability | Logs, webhook metadata, telemetry aggregates | Legitimate interests (Art. 6(1)(f)) |
| Comply with law and Shopify mandatory privacy webhooks | Redaction/data-request records | Legal obligation (Art. 6(1)(c)) |
| App subscription billing via Shopify | Shop identifier, plan/entitlement data | Performance of contract (Art. 6(1)(b)) |
Where we rely on legitimate interests, we balance those interests against data subjects’ rights and implement minimization and retention limits described below.
6. Where data is stored
| Storage | What is stored | Notes |
|---|---|---|
| Shopify (merchant store) | App settings metafields, order/fulfillment metafields, order additional details for pickup points | Primary business record; survives typical App database cleanup |
| PostgreSQL (self-hosted) | Shopify OAuth sessions; privacy webhook action audit records | Only persistent database tables; no separate business datastore |
| Redis (self-hosted) | Job queues, geo-resolution cache, integration token cache (AuthVault), short-lived signed links to PDFs/labels (~90 seconds), aggregated telemetry | Ephemeral / operational |
| Application logs | Redacted operational logs | Hot rotation on server; optional cold archives (~30 days default) |
| Third-party providers (see §7) | Data transmitted to generate documents, labels, or emails | Governed by merchant configuration and provider terms |
Production infrastructure is hosted on a VPS in the EU (currently Hetzner per our deployment architecture), with TLS encryption in transit.
7. Recipients and sub-processors
We share personal data only as needed to operate the App:
7.1 Shopify
Shopify hosts the merchant store, Admin, Checkout, APIs, and extension runtime. Data flows through Shopify APIs under the merchant’s granted scopes and Shopify’s terms.
7.2 Billing integrators (merchant-configured)
When connected by the merchant, order and customer data needed for fiscal documents may be sent to:
- SmartBill
- FGO
- Oblio
7.3 Courier / logistics providers (merchant-configured)
When connected by the merchant, shipment and recipient data may be sent to one or more of:
- Fan Courier
- Cargus
- Sameday
- Packeta
- DPD
- MyGLS
- Dragon Star Courier (DSC)
Geo-resolution caches may store normalized city/street identifiers to satisfy provider API requirements.
7.4 Other service providers
| Provider | Purpose |
|---|---|
| Resend | Transactional email delivery (pickup reminders, support routing) |
| Google Maps Platform | Map display in pickup-point selector when the merchant supplies an API key |
| ANAF (Romanian tax authority APIs) | Optional VAT/CIF validation when enabled by the merchant |
| Hosting / infrastructure (e.g. Hetzner, Docker runtime) | Application hosting |
Merchants choose which integrations to enable. We do not send data to a billing or courier provider unless that integration is configured for their shop.
We may disclose data if required by law, court order, or to protect rights, safety, and security.
8. International transfers
Some sub-processors (for example Shopify, Resend, or Google) may process data outside the European Economic Area (EEA). Where required, we rely on appropriate safeguards such as Standard Contractual Clauses, adequacy decisions, or equivalent mechanisms offered by those providers.
Merchants should review their chosen integrators’ privacy documentation for transfer details.
9. Retention
We retain personal data only as long as necessary for the purposes above:
| Data category | Retention period |
|---|---|
| Shopify OAuth sessions | Until session expiry, App uninstall, or successful shop/redact handling (sessions deleted on uninstall) |
| Integration tokens (AuthVault) | Until integration disconnect, credential rotation, or shop redaction |
| Short-lived document/label links (Redis) | ~90 seconds |
| Geo cache entries | Cached for operational efficiency; not a permanent archive |
| Application logs | Hot log rotation on server; cold archives typically ~30 days (configurable) |
| Privacy webhook records | Recorded with a 30-day action window aligned with Shopify compliance requirements; retained as audit trail thereafter only as long as needed for compliance evidence |
| Order/fulfillment metafields in Shopify | Controlled by merchant and legal/fiscal retention obligations (Romanian/EU tax and shipping records may require longer retention); redacted or anonymized when legally permissible and when Shopify sends customers/redact / shop/redact |
| Customs declaration metafields | Deleted or anonymized after export/legal retention expires |
When retention ends, we delete or anonymize data in our systems. Data written to Shopify metafields may remain in the merchant store until the merchant or Shopify deletes it, subject to legal holds.
10. Security measures
We implement technical and organizational measures appropriate to the risk, including:
- Encryption in transit (HTTPS/TLS for all App endpoints)
- Access controls and Shopify OAuth session tokens for Admin/API access
- Webhook HMAC verification for Shopify webhooks
- Credential vaulting for provider tokens (Redis AuthVault)
- Structured logging with PII redaction in application logs
- Infrastructure isolation between staging and production environments
- Least-privilege API scopes required for App functionality
No method of transmission or storage is 100% secure. Merchants must protect their Shopify accounts and integration credentials.
11. Shopify mandatory privacy webhooks
Facturier subscribes to Shopify’s mandatory compliance webhooks:
| Webhook | Our response |
|---|---|
customers/data_request | We record the request and provide merchant customer data we hold in our systems within 30 days, or explain if data exists only in Shopify/metafields or with a third-party integrator |
customers/redact | We record the request and delete or anonymize personal data in our systems associated with the specified customer/orders within 30 days, except where retention is legally required |
shop/redact | We record the request and delete shop-associated data in our database (sessions, cached tokens, operational records) within 30 days, except where retention is legally required |
Fiscal and shipping records mirrored in Shopify order metafields may need to be retained by the merchant under tax or commercial law even after redaction requests. In those cases we document the legal basis for retention in our internal compliance records.
On App uninstall, we delete OAuth sessions for that shop from our database. Merchants should also request Shopify shop/redact after uninstall for full cleanup of compliance-tracked actions.
12. Your rights (GDPR)
If we act as controller of your personal data (for example you are merchant staff or you contact support), you have the following rights, subject to conditions in GDPR:
- Access — request confirmation and a copy of your data
- Rectification — correct inaccurate data
- Erasure — request deletion where applicable
- Restriction — request limited processing
- Portability — receive data you provided in a structured format where applicable
- Objection — object to processing based on legitimate interests
- Withdraw consent — where processing is consent-based (not typically the primary basis for core App features)
To exercise these rights, email support@facturier.app with subject “Data Protection Request”. We may need to verify your identity. We respond within one month, extendable where permitted by law.
You may lodge a complaint with your local supervisory authority. In Romania, this is the ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal) — https://www.dataprotection.ro.
End customers of merchants
If you are a buyer of a store using Facturier, contact the merchant (store owner) first to exercise your privacy rights. The merchant is usually the controller of your order data. We will assist the merchant as processor when required.
13. Cookies and similar technologies
13.1 Merchant Admin / embedded App
The App runs embedded in Shopify Admin and uses Shopify session tokens for authentication (not third-party advertising cookies). Shopify’s own cookies and policies apply to the Admin experience.
13.2 Checkout / Customer Account extensions
Extensions run in Shopify-controlled checkout and customer account surfaces. Facturier does not set standalone marketing cookies on buyers through these extensions.
13.3 Google Maps (optional)
If the merchant enables map-based pickup selection, Google Maps Platform may process technical data according to Google’s policies and the merchant’s Google Cloud configuration.
13.4 We do not use
- Cross-merchant buyer profiling
- Third-party ad networks in the App backend
- Sale of personal data
14. Automated decision-making
Facturier does not make legal or similarly significant decisions about individuals solely by automated means without human involvement. Optional ANAF VAT validation may block invoice generation when a tax identifier fails validation rules configured by the merchant, but fiscal document issuance remains under merchant control.
15. Children’s data
The App is intended for merchants conducting commercial transactions. We do not knowingly collect personal data from children under 16 (or the applicable age in your jurisdiction) for our own marketing purposes. Merchants must comply with applicable rules when selling to minors.
16. Merchant responsibilities
Merchants using Facturier agree to:
- Provide accurate privacy information to their customers about invoicing, shipping, pickup points, and related processing
- Establish lawful bases for processing buyer personal data
- Configure only integrations they are authorized to use
- Protect API credentials and staff access to Shopify Admin
- Respond to customer privacy requests for data the merchant controls in Shopify
- Comply with Romanian/EU fiscal and consumer rules when generating and storing invoices and AWBs
17. Changes to this Privacy Policy
We may update this Privacy Policy to reflect product, legal, or regulatory changes. We will revise the “Last updated” date at the top. Material changes may be communicated through the App, our website, or email where appropriate. Continued use of the App after the effective date constitutes acceptance of the updated policy.
18. Contact
Facturier — Privacy & Data Protection
CORE ELEVATING MEDIA S.R.L. · CUI 40481264 · J05/292/2019
Str. Barcaului nr. 92, 410257 Oradea, Bihor, România
Website: https://facturier.app
Email: support@facturier.app
Appendix A — Shopify API scopes
The App requests Shopify API access needed for its features, including:
read_orders, write_orders, read_customers, read_products, read_fulfillments, write_fulfillments, merchant-managed and assigned fulfillment order scopes, third-party fulfillment order scopes, read_inventory, write_inventory, read_locations, read_shipping, write_shipping.
Scopes are granted by the merchant at install time and can be reviewed in Shopify Admin.
Appendix B — Summary of data storage
The table below summarizes where Facturier stores or processes data and what typically happens when Shopify sends a customer or shop redaction request.
| Storage | Examples | Typical action on redact |
|---|---|---|
Shopify metafields (app.facturier.*) | Invoice/AWB ledger, fiscal identifiers, customs JSON | Legal retention may apply; otherwise anonymize or delete where feasible |
| Short-lived access links | PDF/label share tokens | Expire automatically (~90 seconds) |
| App sessions | OAuth tokens, staff name/email | Delete |
| Integration credentials | Courier and billing provider tokens | Delete |
| Privacy compliance records | Audit trail of data requests and redactions | Retained only as long as needed for compliance evidence |