Privacy Policy

Last updated: 10 July 2026

Creditio ("the app") is a Shopify app that enforces B2B credit limits and payment-terms rules on the Shopify checkout. It is operated by Talivio Technology OÜ (registry code 16991406), Ahtri tn 12, Kesklinna linnaosa, Tallinn, Harju maakond, 15551, Estonia ("we", "us"). This policy explains what data we process, why, on what legal basis, and the rights you have.

1. Our role: controller and processor

For the merchant's own data (store details, app settings, billing and support communication) we are the data controller. For the data of a merchant's B2B customers — company records, contact emails, credit limits, balances and payment reminders — the merchant is the data controller and we act as the merchant's processor: we handle that data only to provide the app to the merchant, under the merchant's configuration and instructions. We will, on request, enter into a GDPR Article 28 data processing agreement with the merchant; our standard DPA is available at [email protected].

The merchant alone determines the credit and checkout rules the app applies. The GDPR does not apply to decisions about legal persons (Recital 14), and the app's credit rules concern companies. To the extent any checkout decision constitutes automated individual decision-making under Article 22 GDPR about a natural person, the merchant, as controller, is responsible for the lawful basis and safeguards, including human intervention; the app provides a manual override so the merchant can review or reverse any decision.

2. What data we process

3. Why we process it and our legal basis

Where we are the controller, we process data on the following legal bases under Article 6(1) GDPR: to perform our contract with the merchant — providing, billing and supporting the app (Article 6(1)(b)); to comply with legal obligations such as accounting law (Article 6(1)(c)); and for our legitimate interest in keeping the service secure and reliable (Article 6(1)(f)). Where we act as the merchant's processor (section 1), the merchant is responsible for having a legal basis, and we process the data only on the merchant's behalf.

We do not use any of this data for marketing, advertising or profiling, and we do not perform creditworthiness scoring: the app applies the credit limits and rules the merchant itself configures.

4. Payment reminder emails

If the merchant enables payment reminders (dunning), we send reminder emails about overdue invoices to the company contact email on the merchant's behalf, in the language and with the reply-to address the merchant configures. These emails are part of the merchant's own receivables process; the merchant is the controller for them and decides whether and when they are sent.

5. Who we share it with

We do not sell merchant or customer data, and we do not share it with third parties for their own purposes. Data is shared only with the recipients needed to run the service:

6. Data retention and deletion

Data is retained only while the app is installed on the merchant's store. When a merchant uninstalls the app, we delete the store's data — including all company, invoice and reminder records — upon receiving Shopify's shop/redact webhook, which Shopify sends approximately 48 hours after uninstallation. We also honour Shopify's customers/redact webhook (deleting data about a specific customer at the merchant's request) and customers/data_request webhook (when Shopify forwards a customer's data request, we review the data we hold about that customer and make it available to the merchant so the merchant can respond). Any residual personal data not removed by the redact webhooks is deleted or anonymised within 90 days of uninstallation, unless a longer statutory retention applies. Server logs are kept for up to 90 days. Accounting and invoicing records are retained for 7 years from the end of the financial year, as required by the Estonian Accounting Act (a legal exception to erasure under Article 17(3)(b) GDPR). Backups are cleared within our ordinary backup rotation.

7. Your rights

Under the GDPR you can request access to your data, correction, erasure, portability, restriction of processing and object to processing. You may lodge a complaint with a supervisory authority — for us that is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), but you may also contact the authority in your own country. To exercise a right, email us at the address below. If you are a B2B customer of a store that uses Creditio, the store (merchant) is the controller of your data — we will forward your request to the merchant, or you can contact the merchant directly.

8. Security

All data in transit between Shopify, our servers and merchants is encrypted via TLS/HTTPS. Company contact email addresses are encrypted at rest at the application level, and the database tables holding company and invoice data are encrypted at rest. Access to production systems is restricted to the app's operator. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your data.

9. Cookies

The app runs embedded in the Shopify admin and uses only essential first-party cookies: a session cookie and a CSRF cookie that protect the embedded app against abuse. We do not use analytics or advertising cookies. This page itself sets no cookies beyond those.

10. Changes to this policy

We may update this policy from time to time. The date at the top shows when it last changed; material changes will be communicated where appropriate.

Contact

Questions about this policy or a request regarding your data can be sent to [email protected].