Privacy Policy

Last updated: 22 April 2026 · Operator: HOST GATE SRL (Romania), trading as Shopgate.

This Privacy Policy explains how Shopgate("we", "our", the "App"), operated by HOST GATE SRL, a Romanian limited-liability company, processes personal data when Shopify merchants ("Merchants") install and use the App and when the App handles data of the Merchant's customers ("End Customers").

The App is a merchant-operations SaaS for Romanian Shopify stores. Its core functions are (a) generating shipping labels (AWB) via Romanian courier APIs, (b) issuing legally-compliant fiscal invoices (facturi fiscale), and (c) automating related order-fulfillment workflows.

Role under GDPR. For data of End Customers, the Merchant is the data controller and Shopgate is the data processor. Processing is governed by our Terms of Service, which include a Data Processing Agreement (DPA). See /terms.

1. Who we are & how to contact us

2. Categories of personal data we process

The data we process falls into two layers: data about the Merchant (our direct customer) and data about End Customers (accessed on behalf of the Merchant through the Shopify Admin API).

2.1 Merchant data

2.2 End Customer data

End Customer data is fetched on-demand from the Shopify Admin GraphQL API (version 2026-01) when the Merchant triggers a specific operation. We do not bulk-export, poll or pre-cache End Customer data. The fields used are:

3. Purposes & legal basis

PurposeData usedLegal basis (GDPR)
Operate the Merchant's accountMerchant data §2.1Art. 6(1)(b) — contract performance
Generate AWB shipping labelsEnd Customer name, address, phoneArt. 6(1)(b) — contract (Merchant↔Shopgate)
Issue fiscal invoices (facturi fiscale)End Customer name, billing address, email, company CUI (if applicable)Art. 6(1)(c) — legal obligation (Codul Fiscal Art. 319; Legea Contabilității 82/1991)
Send tracking notificationsEnd Customer email, order tracking dataArt. 6(1)(b) — contract
Retain fiscal records for tax auditBuyer name, CUI, registered address (in OrderFiscalBuyerCache), invoice PDFsArt. 6(1)(c) — legal obligation (10-year retention under Legea 82/1991)
Security, fraud prevention, incident handlingAudit log, IP addresses, request metadataArt. 6(1)(f) — legitimate interests

4. Retention periods

5. Subprocessors

We share End Customer PII only with the following third parties, and only when the Merchant explicitly enables them in their tenant settings:

SubprocessorPurposeData shared
SamedayAWB generation (courier)Name, shipping address, phone
CargusAWB generation (courier)Name, shipping address, phone
Fan CourierAWB generation (courier)Name, shipping address, phone
DPD RomaniaAWB generation (courier)Name, shipping address, phone
SmartBillFiscal invoice issuance (optional — only when Merchant enables it)Name, billing address, email, CUI (if company customer)
ANAF (Romanian tax authority)Public registry lookup of Romanian company identification (CUI only — not personal data)Company tax code (CUI)
Merchant's own SMTP serverTransactional email deliveryRecipient email, message body
Hosting infrastructure (EU, Romania)Server and database hostingAll data at rest (encrypted)

We do not share data with advertising networks, data brokers, analytics providers, AI/ML training pipelines or any party not contracted by the Merchant.

6. International transfers

All primary processing takes place on infrastructure located in the European Union (Romania). Subprocessors listed above are Romania-based entities (EU). Where a subprocessor transfers data outside the EU, the transfer is covered by the EU Standard Contractual Clauses (SCCs) or an adequacy decision.

7. Security measures

8. Your rights (End Customers & Merchants)

Under GDPR, you have the right to:

How to exercise rights. End Customers should first contact the Merchant (data controller) from whom they purchased. Merchants can contact us directly at dpo@shopgate.ro.

We also process requests that arrive through Shopify's standard GDPR webhook channel (customers/data_request, customers/redact, shop/redact), fulfilling data export within 30 days and erasure immediately (non-fiscal data), as required.

9. Automated decision-making & profiling

We do not perform automated decision-making with legal or similarly significant effects. We do not profile End Customers. No AI/ML is applied to End Customer data.

10. Children's data

The App is a business-to-business service. We do not knowingly process data of children under 16. Any incidental End Customer data handled via the App is processed under the Merchant's own privacy notice to End Customers.

11. Data breach notification

We will notify affected Merchants within 72 hours of becoming aware of a personal-data breach that is likely to result in risk to individuals, in line with GDPR Art. 33. Merchants, as data controllers, are then responsible for notifying their End Customers and the supervisory authority, where applicable.

12. Changes to this policy

We may update this Privacy Policy. Material changes will be announced to active Merchants by email at least 30 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.

13. Contact

Questions about this Privacy Policy or about how we process personal data: