Privacy Policy
Hrvatska Pošta Generate Labels — a Shopify app that creates Hrvatska Pošta return labels for orders.
This policy explains what data the Hrvatska Pošta Generate Labels app (“the App”) collects when a merchant installs it on their Shopify store, why it is collected, who it is shared with, and how long it is kept. It covers the App only — not Shopify, not Hrvatska pošta d.d., and not the merchant’s own store, each of which has its own privacy policy.
1. Who is responsible
| Provider | Enum Software j.d.o.o. |
|---|---|
| developers@enum.hr | |
| Address | Branitelja Dubrovnika 15 20000 Dubrovnik Croatia |
For personal data belonging to the merchant’s customers, the merchant is the data controller and Enum Software j.d.o.o. acts as a processor, handling that data only to produce and track the return labels the merchant asks for. For the merchant’s own account and configuration data, Enum Software j.d.o.o. is the controller.
2. What the App collects
2.1 Store and account data
- The store’s
myshopify.comdomain. - Shopify access and refresh tokens issued to the App at install, so it can read orders on the merchant’s behalf. These are secrets, never displayed and never shared.
- Subscription state from Shopify Managed Pricing: plan name, status, billing period end and whether the charge is a test charge. Card and payment details are handled entirely by Shopify and are never seen by the App.
2.2 Merchant-entered configuration
- Hrvatska pošta DXWebAPI credentials (username, password and an optional payer CECODE). The password is encrypted at rest with AES-256-GCM and is never sent back to the browser or to any third party other than Hrvatska pošta itself.
- The merchant’s return address and contact details — company name, street, house number, city, postcode, phone and email — which are printed on the label as the recipient.
- Label defaults such as service code, parcel size, weight and pickup type.
2.3 Order and customer data
Orders are read live from the Shopify Admin API each time the merchant opens the App. They are not copied into a local database and are not retained after the request completes.
When the merchant creates a return label, the data needed for that shipment — the customer’s name, address, postcode, city, and where provided phone number and email — is sent to Hrvatska pošta to register the shipment. The App then stores a record of the label:
- Shopify order id and order number;
- the customer’s name;
- the HP barcode, client reference number, service, parcel size, weight and pickup details;
- the generated label PDF, which itself contains the addresses printed on the label;
- the raw response returned by Hrvatska pošta, and the latest tracking scan for the parcel.
No payment details, no product-level order contents beyond what is needed to address the parcel, and no customer accounts or marketing data are stored.
2.4 Technical data
- Identifiers of webhooks received from Shopify (event id, shop, topic, timestamp), kept so the same event is not processed twice.
- Ordinary server logs produced by the hosting platform, which may include IP address, timestamp and the requested URL.
The App sets no cookies and uses no advertising, analytics or tracking scripts. Inside the Shopify admin it authenticates with short-lived Shopify session tokens held in memory for the duration of a page view.
3. Why the data is used
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Creating and tracking return labels | Order, recipient and label data | Performance of a contract with the merchant; processing on the merchant’s documented instructions |
| Authenticating the store and keeping the app installed | Shop domain, access and refresh tokens | Performance of a contract |
| Enforcing plan quotas and billing | Subscription state, count of labels created in the month | Performance of a contract |
| Security, abuse prevention and troubleshooting | Server logs, webhook records | Legitimate interests in running a reliable, secure service |
Data is never sold, rented, or used to train machine-learning models.
4. Who the data is shared with
| Recipient | What they receive | Why |
|---|---|---|
| Shopify Inc. | API requests made on the merchant’s behalf | The App runs on Shopify and reads the merchant’s orders from it |
| Hrvatska pošta d.d. (Croatia) | Sender and recipient details for each shipment: name, address, postcode, city, phone, email | Registering the return shipment and producing the label — this is the purpose of the App |
| Hosting and database provider (Render, EU region) | Everything the App stores, as the underlying infrastructure | Running the service |
Data is otherwise disclosed only where required by law. Data is stored on servers in the European Union (Frankfurt, Germany); Shopify and Hrvatska pošta process data under their own terms and safeguards.
5. How long data is kept
- Return label records and PDFs: kept for as long as the App is installed, so the merchant keeps an archive of the labels they have paid for.
- On uninstall: when Shopify notifies the App that it has been removed, the store’s access tokens, Hrvatska pošta credentials, settings and label archive are deleted.
- On a shop redaction request from Shopify (sent 48 hours after uninstall): all remaining data for that store is deleted.
- On a customer redaction request from Shopify: the customer’s name is removed from the affected label records.
- Server logs: retained short-term by the hosting provider for operations and security.
6. Security
- All traffic is served over HTTPS.
- Hrvatska pošta passwords are encrypted at rest with AES-256-GCM; they are never returned to the browser.
- Every request from the Shopify admin is verified against a signed Shopify session token, scoped to a single store.
- Incoming webhooks are rejected unless their HMAC signature verifies against the app secret.
- Stored data is partitioned per store, so one merchant cannot read another’s orders, labels or credentials.
No system is perfectly secure. If a breach affecting personal data occurs, affected merchants and the competent supervisory authority will be notified as required by law.
7. Your rights
Under the GDPR you may request access to your personal data, and its correction, deletion, restriction or portability, and you may object to processing based on legitimate interests.
- Shoppers: please contact the store you ordered from. That merchant is the controller of your data and can pass a request on; the App answers such requests through Shopify’s data-request channel.
- Merchants: contact developers@enum.hr, or uninstall the App to have its stored data deleted.
You also have the right to lodge a complaint with your local data protection authority — in Croatia, the Agencija za zaštitu osobnih podataka (AZOP).
8. Children
The App is a business tool sold to merchants and is not directed at children. It does not knowingly collect data from anyone under 16 other than incidentally, where such a person is the recipient of a parcel addressed by a merchant.
9. Changes to this policy
This policy may be updated as the App changes. The date at the top reflects the current version; material changes will be communicated to installed merchants.
10. Contact
Questions about this policy or about data the App holds: developers@enum.hr.