Privacy Policy

Hrvatska Pošta Generate Labels — a Shopify app that creates Hrvatska Pošta return labels for orders.

Last updated: 3 August 2026

This policy explains what data the Hrvatska Pošta Generate Labels app (“the App”) collects when a merchant installs it on their Shopify store, why it is collected, who it is shared with, and how long it is kept. It covers the App only — not Shopify, not Hrvatska pošta d.d., and not the merchant’s own store, each of which has its own privacy policy.

1. Who is responsible

ProviderEnum Software j.d.o.o.
Emaildevelopers@enum.hr
AddressBranitelja Dubrovnika 15
20000 Dubrovnik
Croatia

For personal data belonging to the merchant’s customers, the merchant is the data controller and Enum Software j.d.o.o. acts as a processor, handling that data only to produce and track the return labels the merchant asks for. For the merchant’s own account and configuration data, Enum Software j.d.o.o. is the controller.

2. What the App collects

2.1 Store and account data

2.2 Merchant-entered configuration

2.3 Order and customer data

Orders are read live from the Shopify Admin API each time the merchant opens the App. They are not copied into a local database and are not retained after the request completes.

When the merchant creates a return label, the data needed for that shipment — the customer’s name, address, postcode, city, and where provided phone number and email — is sent to Hrvatska pošta to register the shipment. The App then stores a record of the label:

No payment details, no product-level order contents beyond what is needed to address the parcel, and no customer accounts or marketing data are stored.

2.4 Technical data

The App sets no cookies and uses no advertising, analytics or tracking scripts. Inside the Shopify admin it authenticates with short-lived Shopify session tokens held in memory for the duration of a page view.

3. Why the data is used

PurposeData usedLegal basis (GDPR Art. 6)
Creating and tracking return labels Order, recipient and label data Performance of a contract with the merchant; processing on the merchant’s documented instructions
Authenticating the store and keeping the app installed Shop domain, access and refresh tokens Performance of a contract
Enforcing plan quotas and billing Subscription state, count of labels created in the month Performance of a contract
Security, abuse prevention and troubleshooting Server logs, webhook records Legitimate interests in running a reliable, secure service

Data is never sold, rented, or used to train machine-learning models.

4. Who the data is shared with

RecipientWhat they receiveWhy
Shopify Inc. API requests made on the merchant’s behalf The App runs on Shopify and reads the merchant’s orders from it
Hrvatska pošta d.d. (Croatia) Sender and recipient details for each shipment: name, address, postcode, city, phone, email Registering the return shipment and producing the label — this is the purpose of the App
Hosting and database provider (Render, EU region) Everything the App stores, as the underlying infrastructure Running the service

Data is otherwise disclosed only where required by law. Data is stored on servers in the European Union (Frankfurt, Germany); Shopify and Hrvatska pošta process data under their own terms and safeguards.

5. How long data is kept

6. Security

No system is perfectly secure. If a breach affecting personal data occurs, affected merchants and the competent supervisory authority will be notified as required by law.

7. Your rights

Under the GDPR you may request access to your personal data, and its correction, deletion, restriction or portability, and you may object to processing based on legitimate interests.

You also have the right to lodge a complaint with your local data protection authority — in Croatia, the Agencija za zaštitu osobnih podataka (AZOP).

8. Children

The App is a business tool sold to merchants and is not directed at children. It does not knowingly collect data from anyone under 16 other than incidentally, where such a person is the recipient of a parcel addressed by a merchant.

9. Changes to this policy

This policy may be updated as the App changes. The date at the top reflects the current version; material changes will be communicated to installed merchants.

10. Contact

Questions about this policy or about data the App holds: developers@enum.hr.