Terms of Service
Last updated: 22 April 2026 · Provider: HOST GATE SRL (Romania), trading as Shopgate.
These Terms of Service (the "Terms") govern your use of the Shopgate application and related services (the "App", "Service"), provided by HOST GATE SRL, a Romanian limited-liability company ("Shopgate", "we", "us"). By installing the App on a Shopify store, creating an account, or otherwise using the Service, you (the "Merchant") agree to these Terms.
The App is a merchant-operations platform for Romanian Shopify stores. It generates AWB shipping labels via Romanian courier APIs, issues fiscal invoices (facturi fiscale) compliant with Romanian tax law, and automates related order-fulfillment workflows.
Data Processing Agreement (DPA).Part II of these Terms is a Data Processing Agreement that forms an integral part of the contract between the Merchant and Shopgate. It governs the processing of personal data of the Merchant's end customers ("End Customers") under GDPR.
Part I — Service Terms
1. Account & eligibility
- The Service is offered to businesses only. By registering, you represent that you act on behalf of a business lawfully established in the European Union (primarily Romania) and that you have authority to bind that business to these Terms.
- You must maintain accurate business identification data (legal name, tax code / CUI, registered address) as this data appears on fiscal invoices you issue through the Service.
- You are responsible for safeguarding your account credentials and for all activity under your account.
2. Shopify integration
- The App is installed on a Shopify store via OAuth. By installing, the Merchant authorizes Shopgate to call the Shopify Admin API with the scopes listed at install time.
- The Merchant may uninstall at any time from the Shopify admin. Uninstall triggers the
app/uninstalledwebhook and marks the shop connection as inactive. Shopify subsequently sends ashop/redactwebhook ~48h later, triggering deletion of non-fiscal data (see DPA §8). - The App version and scopes in effect at any time are those released through Shopify's app-version mechanism.
3. Merchant responsibilities
- You are solely responsible for your compliance with applicable laws — including tax, consumer-protection and data-protection laws — in the jurisdictions where you sell.
- You are responsible for ensuring that your privacy notice to End Customers accurately describes your use of Shopgate as a data processor and lists the subprocessors downstream (couriers, SmartBill, etc.) where applicable.
- You are responsible for the accuracy of the courier and fiscal-service credentials that you configure in the Service. Shopgate will transmit data to those third parties as instructed by you.
- You must not use the Service to process data of persons under 16 without a lawful basis, or to process special-category data (GDPR Art. 9) without explicit consent and appropriate safeguards.
4. Fees & billing
- Fees and payment terms are as agreed between the Merchant and Shopgate at sign-up or via the in-app billing page. Unless otherwise specified, fees are charged in advance on a monthly basis.
- Taxes: fees are exclusive of VAT. Romanian VAT is added where applicable.
- Non-payment: Shopgate may suspend access to the Service after 15 days of overdue payment, with prior written notice. Fiscal records already produced remain retrievable by the Merchant for the statutory retention period.
5. Service availability
We aim for high availability but do not guarantee uninterrupted service. Scheduled maintenance is announced in advance where possible. We are not liable for downtime caused by Shopify, courier APIs, SmartBill, ANAF or other third-party services.
6. Intellectual property
- The Service and all underlying software, designs and documentation are owned by HOST GATE SRL and licensed to the Merchant on a non-exclusive, non-transferable basis for the duration of the subscription.
- The Merchant retains all rights to its own business data and to data uploaded to or generated within the Service.
7. Warranties & disclaimers
The Service is provided "as is". We make no warranty that it will be error-free or that generated fiscal documents and shipping labels will be accepted by every third party in every scenario. The Merchant is solely responsible for reviewing generated documents before use.
8. Limitation of liability
To the maximum extent permitted by law, Shopgate's aggregate liability arising out of or in connection with the Service — whether in contract, tort (including negligence) or otherwise — shall not exceed the fees paid by the Merchant to Shopgate in the 12 months preceding the event giving rise to the claim. This limitation does not apply to (a) death or personal injury caused by our negligence, (b) fraud or willful misconduct, or (c) liabilities that cannot lawfully be limited.
9. Term & termination
- The Terms remain in force while the Merchant has an active account. Either party may terminate for convenience with 30 days' notice.
- Shopgate may terminate immediately if the Merchant materially breaches the Terms or applicable law.
- On termination, the DPA obligations regarding data return/deletion apply (see DPA §8).
10. Governing law & jurisdiction
These Terms are governed by Romanian law. Disputes will be submitted to the competent courts of the registered office of HOST GATE SRL, without prejudice to any mandatory consumer-protection provisions.
11. Changes to Terms
We may update these Terms. Material changes will be announced by email at least 30 days before they take effect. Continued use of the Service after the effective date constitutes acceptance.
Part II — Data Processing Agreement (DPA)
This DPA forms an integral part of the Terms and applies when Shopgate processes personal data on behalf of the Merchant within the meaning of GDPR (Regulation (EU) 2016/679).
DPA.1 Roles
- Merchant = data controller for personal data of its End Customers.
- Shopgate = data processor, acting on documented instructions from the Merchant.
DPA.2 Subject-matter, duration, nature & purpose
- Subject-matter: processing of End Customer personal data to deliver the Service (AWB generation, fiscal invoicing, order fulfillment).
- Duration:for the term of the Merchant's subscription, plus any legally-mandated retention (notably fiscal records — 10 years under Romanian law).
- Nature & purpose: storage (tokens, audit log, fiscal records), transmission (to couriers, SmartBill, SMTP), generation of documents (invoice PDF, AWB).
DPA.3 Categories of data & data subjects
Categories of personal data and of data subjects are described in our Privacy Policy, §2 and §3. In summary:
- Data subjects: the Merchant's End Customers; the Merchant's staff users.
- Personal data: name, email, phone, shipping and billing addresses, order metadata, and Merchant-business identification.
DPA.4 Processor obligations
Shopgate shall:
- Process personal data only on the Merchant's documented instructions, including the instructions embedded in the configuration of the Service (e.g., which courier is enabled, whether SmartBill is used).
- Ensure that personnel with access to personal data are bound by confidentiality obligations.
- Implement the technical and organizational measures described in the Privacy Policy §7 (encryption at rest and in transit, encrypted backups, webhook HMAC verification, tenant isolation, access logging, rate-limiting, secure credential management).
- Assist the Merchant in responding to End Customer rights requests under GDPR Chapter III, where the Merchant cannot respond alone using its own Shopify admin.
- Notify the Merchant without undue delay (and in any case within 72 hours) after becoming aware of a personal-data breach affecting personal data processed under this DPA.
- At the Merchant's choice, delete or return personal data at the end of the Service, subject to legal-retention exceptions (fiscal records).
- Make available to the Merchant information necessary to demonstrate compliance, and allow for and contribute to audits (see DPA.7).
DPA.5 Subprocessors
The Merchant grants Shopgate general written authorization to engage subprocessors. The current list of subprocessors is published at /privacy §5. We will inform Merchants of intended changes (addition or replacement) by email and/or in-app notice at least 30 days in advance. The Merchant may object for demonstrated data-protection reasons; if no acceptable alternative can be agreed, the Merchant may terminate the Service without penalty.
Shopgate imposes on each subprocessor data-protection obligations no less protective than those set out in this DPA.
DPA.6 International transfers
Where personal data is transferred outside the European Economic Area, Shopgate ensures appropriate safeguards (Standard Contractual Clauses or adequacy decisions) are in place with the receiving party.
DPA.7 Audit rights
Upon reasonable written request, and no more than once per calendar year (except where legally required or following a security incident), Shopgate will provide the Merchant with a summary of the technical and organizational measures in place. On-site audits may be performed by an independent auditor bound by confidentiality, during business hours, with at least 30 days' notice, and at the Merchant's cost.
DPA.8 Return or deletion on termination
On termination of the Service:
- Shopify access tokens and merchant credentials are deleted within 48 hours of receipt of the Shopify
shop/redactwebhook, or on direct written instruction from the Merchant, whichever is earlier. - Non-fiscal End Customer data is deleted on the same timeline.
- Fiscal records (
OrderFiscalBuyerCache, fiscal invoice PDFs) are retained for 10 years as required by Romanian tax law (Legea Contabilității 82/1991, Art. 25), after which they are deleted. This retention is a legal obligation of the Merchant as issuer of the invoice; Shopgate performs it on the Merchant's behalf. GDPR Art. 17(3)(b) expressly allows this retention against erasure requests. - On request, Shopgate will export the Merchant's data in a structured, commonly-used format before deletion.
DPA.9 Liability & order of precedence
In case of conflict between these Terms and the DPA, the DPA prevails for matters relating to the processing of personal data. Liability under the DPA is subject to the overall limitation set out in Part I §8.
DPA.10 Contact
- Data protection: dpo@shopgate.ro
- Security incidents: security@shopgate.ro