Privacy policy
1. Introduction
Welcome to xConnector. This Privacy Policy explains how Infoquest SRL, a company registered in Romania (Trade Registry No. J2003000464092, VAT ID: RO15538750), with registered office at Calea Calarasilor 319, Braila, Romania ("xConnector", "we", "us", "our"), collects, uses, stores, shares, and protects personal information when you use our Shopify application and related services (the "App").
This Privacy Policy applies to:
- Shopify merchants who install and use the App ("Merchants");
- Customers of Merchants whose data is processed through the App ("End Customers");
- Visitors to our website at about.xconnector.app ("Website Visitors").
By installing, accessing, or using the App, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the App.
This Privacy Policy should be read together with our Terms of Service and Data Processing Addendum (DPA).
2. Who We Are
xConnector is a software connector (middleware) that automates data exchange between Shopify and third-party services such as courier platforms, ERP/invoicing systems, and cloud printing services.
Data Controller: For data we collect directly (Website Visitors, Merchant account data), Infoquest SRL acts as the Data Controller.
Data Processor: For End Customer data processed through the App on behalf of Merchants, Infoquest SRL acts as the Data Processor. The Merchant is the Data Controller for their customers' data. The terms of this processing relationship are set out in our Data Processing Addendum (DPA).
Contact:
- Email: privacy@xconnector.app
- Support: support@xconnector.app
- Registered office: Calea Calarasilor 319, Braila, Romania
3. What Data We Collect
3.1 Merchant Data (We Are the Controller)
When you install and use the App, we collect:
- Account information: Shopify store name, store URL, owner name, email address
- Authentication data: OAuth tokens provided by Shopify for API access
- Configuration data: App settings, preferences, connected services, courier credentials, ERP credentials
- Usage data: Features used, actions performed, timestamps, error logs
- Billing data: Subscription status, plan type (billing is handled by Shopify; we do not collect payment card details)
- Support data: Communications with our support team, including email address and message content
3.2 End Customer Data (We Are the Processor)
When Merchants use the App to process orders, we process the following data on their behalf:
Order and Shipping Data:
- Full name (first name, last name, company name)
- Shipping and billing addresses (street, city, county/province, postal code, country)
- Phone number(s)
- Email address
- Order contents (products, quantities, prices)
- Cash-on-delivery (COD) amounts
- Package weight and dimensions
- Delivery instructions or notes
Invoice and Fiscal Data:
- Customer name and address (as invoiced)
- Fiscal identification codes (CUI/CIF, CNP where applicable)
- VAT registration numbers
- Bank account details (where provided for B2B invoicing)
Operational Data:
- Shopify order IDs and internal reference numbers
- AWB (tracking) numbers
- Fulfillment status and history
3.3 Website Visitor Data
When you visit our website, we may collect:
- Technical data: IP address, browser type and version, operating system, device type
- Usage data: Pages visited, time spent, referral source
- Cookie data: As described in Section 9 of this Privacy Policy
3.4 Special Categories of Data
We do not intentionally collect or process special categories of personal data as defined in GDPR Article 9 (e.g., health data, biometric data, data revealing racial or ethnic origin, political opinions, religious beliefs). Merchants must not submit special category data through the App.
4. How We Collect Data
We collect personal data through the following means:
- Directly from you: When you install the App, configure settings, or contact support.
- From Shopify: Through the Shopify API, when you authorize the App to access your store data (orders, customers, products, fulfillments).
- From third-party services: When courier platforms or ERP systems return data in response to App operations (e.g., AWB numbers, invoice numbers, tracking updates).
- Automatically: Through cookies and similar technologies when you visit our website, and through application logs when you use the App.
5. Legal Basis for Processing
We process personal data based on the following legal grounds under GDPR Article 6(1):
PurposeLegal BasisProviding the App's functionalityPerformance of a contract (Art. 6(1)(b))Processing End Customer data on behalf of MerchantsPerformance of a contract with the Merchant / Legitimate interest (Art. 6(1)(b)/(f))Sending service-related communicationsPerformance of a contract (Art. 6(1)(b))Maintaining security and preventing fraudLegitimate interest (Art. 6(1)(f))Improving the App and developing new featuresLegitimate interest (Art. 6(1)(f))Complying with legal obligations (e.g., fiscal retention)Legal obligation (Art. 6(1)(c))Website analyticsConsent (Art. 6(1)(a)) or Legitimate interest (Art. 6(1)(f))
Where we rely on legitimate interest, we have conducted a balancing test to ensure that our interests do not override your fundamental rights and freedoms.
6. How We Use Your Data
We use the data we collect for the following purposes:
- Service delivery: To provide, maintain, and improve the App's functionality, including order processing, shipping label generation, invoice creation, inventory synchronization, and fulfillment management.
- Third-party integrations: To transmit data to courier platforms, ERP/invoicing systems, and printing services as configured by the Merchant.
- Customer support: To respond to inquiries, troubleshoot issues, and provide technical assistance.
- Service communications: To send important notices about the App, including updates, security alerts, and changes to our terms.
- Security: To detect, prevent, and address technical issues, fraud, and security threats.
- Analytics: To understand how the App is used and to improve our services (using aggregated and anonymized data where possible).
- Legal compliance: To comply with applicable laws, regulations, and legal processes.
We do not use personal data for:
- Automated decision-making or profiling that produces legal effects;
- Marketing or advertising to End Customers;
- Selling personal data to third parties.
7. Data Sharing and Sub-processors
7.1 When We Share Data
We share personal data only in the following circumstances:
- With third-party services configured by the Merchant: When the Merchant connects a courier, ERP, or printing service through the App, we transmit the necessary data to that service as instructed by the Merchant. The specific services are determined entirely by the Merchant's configuration.
- With Shopify: As part of the normal operation of the App within the Shopify platform.
- With infrastructure providers: For hosting and operating the App (see Sub-processors below).
- For legal compliance: When required by law, regulation, or legal process, or to protect our rights, privacy, safety, or property.
7.2 Sub-processors
We use the following categories of sub-processors:
CategoryPurposeData ProcessedCloud Infrastructure (Hetzner, AWS)Hosting, storage, computeAll data stored in the AppShopify Inc.E-commerce platform, order sourceOrder data, customer dataCourier Platforms (Sameday, FanCourier, Cargus, DPD, GLS, and others)Shipping label generation, trackingRecipient name, address, phone, package detailsERP/Invoicing Systems (SmartBill, Oblio, Nexus ERP, and others)Invoice generationCustomer name, address, fiscal ID, order amountsPrinting Services (PrintNode, where enabled)Cloud printingDocument content (labels, invoices)
The specific courier and ERP sub-processors used are determined by each Merchant's own configuration. We transmit data only to services actively connected by the Merchant.
A current list of sub-processors is available upon request at privacy@xconnector.app. Changes to sub-processors are communicated in accordance with our DPA.
7.3 No Selling of Data
We do not sell, rent, or trade personal data to third parties for their marketing or commercial purposes.
8. International Data Transfers
8.1 Processing Location
We primarily process and store personal data within the European Economic Area (EEA). Our infrastructure is hosted in data centers located in Germany (EU).
8.2 Transfers Outside the EEA
Some data transfers outside the EEA may occur when:
- Shopify processes data in Canada and the United States (covered by Shopify's own data processing terms and adequacy decisions/SCCs);
- Merchant-configured services operate outside the EEA (the Merchant is responsible for ensuring adequate safeguards for these transfers).
Where we transfer data outside the EEA, we ensure that appropriate safeguards are in place, including:
- Transfers to countries recognized by the European Commission as providing adequate protection;
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- Other applicable derogations under GDPR Article 49.
9. Cookies and Tracking Technologies
9.1 What Are Cookies
Cookies are small text files placed on your device when you visit a website. They help the website remember your preferences and understand how you interact with it.
9.2 Cookies We Use
TypePurposeDurationStrictly necessaryEssential for website functionality (e.g., session management)SessionAnalyticsTo understand website usage patterns and improve our contentUp to 2 yearsFunctionalTo remember your preferencesUp to 1 year
9.3 Managing Cookies
You can control cookies through your browser settings. Most browsers allow you to refuse or delete cookies. Please note that disabling strictly necessary cookies may affect website functionality.
9.4 The App
The xConnector App itself operates within the Shopify Admin environment and does not place cookies on End Customers' devices. Any cookies used in the Shopify Admin are governed by Shopify's own cookie policy.
10. Data Retention
10.1 Merchant Data
We retain Merchant data for the duration of the Merchant's use of the App. Upon uninstallation:
- We cease processing data for the Merchant's purposes;
- We delete the Merchant's data within 90 days of termination, except where retention is required by law;
- Backup data is deleted within 30 days after primary data deletion.
10.2 End Customer Data
End Customer data (orders, shipping information, invoices) is retained for the duration of the Merchant's use of the App. Merchants may delete individual records through the App where such functionality is available.
10.3 Legal Retention
We may retain certain data beyond the periods above where required by law, including:
- Fiscal records: Up to 10 years as required by Romanian fiscal legislation;
- Legal proceedings: For the duration of any legal claim or dispute;
- Regulatory requirements: As required by applicable data protection or other regulatory authorities.
10.4 Anonymized Data
We may retain anonymized or aggregated data that can no longer be associated with any individual, indefinitely, for statistical and analytical purposes.
11. Data Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit (TLS/SSL) and at rest;
- Access controls with role-based permissions and API key management;
- Network security including firewalls and network segmentation;
- Monitoring and logging of access to systems containing personal data;
- Regular testing of the effectiveness of security measures;
- Secure development practices in our software development lifecycle;
- Incident response procedures for detecting and responding to security incidents.
While we strive to protect your data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security but commit to promptly addressing any security incidents in accordance with our obligations under GDPR and our DPA.
12. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Article 15): You have the right to obtain confirmation of whether we process your personal data and to access a copy of that data.
- Right to rectification (Article 16): You have the right to request correction of inaccurate personal data or completion of incomplete data.
- Right to erasure (Article 17): You have the right to request deletion of your personal data in certain circumstances (e.g., when the data is no longer necessary for the purposes for which it was collected).
- Right to restriction (Article 18): You have the right to request restriction of processing in certain circumstances (e.g., while we verify the accuracy of your data).
- Right to data portability (Article 20): You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit it to another controller.
- Right to object (Article 21): You have the right to object to processing based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds.
- Right to withdraw consent (Article 7(3)): Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
- Right to lodge a complaint: You have the right to lodge a complaint with a supervisory authority (see Section 14).
How to Exercise Your Rights
- Merchants: Contact us at privacy@xconnector.app with your request. We will respond within 30 days.
- End Customers: If you are a customer of a Merchant using xConnector, please contact the Merchant directly (as the Data Controller) to exercise your rights. The Merchant will coordinate with us as needed. If you contact us directly, we will redirect you to the relevant Merchant.
We may request proof of identity before processing your request to ensure the security of your data.
13. Children's Privacy
The App is designed for use by businesses (Shopify merchants) and is not directed at children under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 16, we will take steps to delete it promptly.
14. Supervisory Authority
If you believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority.
The relevant supervisory authority for Infoquest SRL is:
Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP) B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336, Bucuresti, Romania Website: www.dataprotection.ro Email: anspdcp@dataprotection.ro
You may also lodge a complaint with the supervisory authority in the EU Member State of your habitual residence or place of work.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or regulatory guidance. When we make material changes:
- We will update the "Last modified" date at the top of this page;
- We will notify Merchants through email or in-app notification at least 30 days before significant changes take effect;
- We will post the updated Privacy Policy on our website.
We encourage you to review this Privacy Policy periodically. Continued use of the App after the effective date of changes constitutes acceptance of the updated Privacy Policy.
16. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices:
- Data Protection Contact: privacy@xconnector.app
- General Support: support@xconnector.app
- Company: Infoquest SRL
- Registered office: Calea Calarasilor 319, Braila, Romania
- Trade Registry: J2003000464092
- VAT ID: RO15538750
We aim to respond to all privacy-related inquiries within 30 days.
This Privacy Policy was last reviewed on 29.06.2026.