E
Enstellis
SignalsInsidePricing
Install on Shopify

Privacy

Enstellis privacy policy

This policy explains how the Enstellis website and Shopify app handle personal data. It is written in English for international merchants while reflecting GDPR disclosure expectations for an EU company operating from Romania.

Controller details

Controller
Enstellis SRL
Registered office
Frunzei Street, No. 11, Galati Municipality, Galati County, Romania
Contact email
support@enstellis.com
Romanian Trade Register / ONRC
J2026032702008
Company tax identification code (CUI/CIF)
54719618

What we process

  • Merchant and store identifiers such as shop domain, installation metadata, and plan state
  • Shipping configuration and audit snapshots needed to run the Enstellis workflow
  • Optional alert contact details and support correspondence you provide
  • Technical and security information needed to authenticate requests and operate the service

Sources of personal data

  • Directly from you when you install the app, configure alerts, or contact Enstellis
  • From Shopify when the service reads store configuration, installation context, and billing state
  • From service providers when delivery, infrastructure, or security status is returned to keep the workflow operating

Purposes and legal bases

  • Providing the Shopify app and website: performance of a contract
  • Protecting the service, logs, and abuse prevention: legitimate interests in keeping the service secure, stable, and supportable
  • Accounting, tax, and legal compliance: legal obligation
  • Sending operational alert emails you configure: contract performance or your instructions within the service

Recipients and processors

  • Shopify provides authentication, store configuration access, app context, billing-related data, and mandatory privacy webhooks. See Shopify's privacy policy and legal terms.
  • Fly.io runs the Shopify app runtime. See Fly.io's privacy policy and compliance information.
  • Neon/Databricks provides production database infrastructure and backup/restore history. See Neon's privacy information and data processing terms.
  • Resend processes alert delivery when email alerts or test alerts are enabled. See Resend's privacy policy and data processing addendum.
  • Vercel hosts the public Enstellis website. See Vercel's privacy policy and data processing addendum.
  • Google Workspace handles support email for support@enstellis.com. See Google's privacy policy and Workspace data processing terms.

Current hosting labels: website - Vercel; app - Fly.io and Neon PostgreSQL. Enstellis updates this public list when material subprocessors change.

International transfers

  • Some processors may handle personal data outside the EEA
  • Where this happens, Enstellis relies on an adequacy decision or on appropriate safeguards such as the EU Standard Contractual Clauses

When data is required

  • Basic account, store, and configuration data are required to install and operate the Shopify app
  • If required service data is not provided, Enstellis may not be able to run audits, show billing state, or deliver the requested workflow
  • Optional alert email details are only required if you enable alert delivery

Retention

  • Store-linked app data is kept while the app remains installed, including store domain, encrypted Shopify token, plan state, alert settings, audits, issues, history, simulator scenarios, workspace entries, shared reports, and alert-delivery records
  • When Shopify notifies Enstellis that the app was uninstalled or the shop must be redacted, the store record and related app data are deleted from the app database through the uninstall or shop-redact flow
  • Trial eligibility, Free audit allowance, and paid-access entitlement records may be retained after uninstall for fraud prevention, fair-use enforcement, billing fairness, and restoring already-paid access if the same shop reinstalls before a paid billing period ends; these records contain only a protected shop-domain identifier, the relevant plan or allowance type, the first trial-used date where applicable, the current Free audit window and used count where applicable, and the paid-through date where applicable, not tokens, audits, products, settings, alert emails, or Shopify customer/order data
  • Customer/order records are not stored because Enstellis does not request customer or order scopes; customer data requests and customer redaction webhooks are acknowledged without deleting customer records from Enstellis
  • Rate-limit windows are short-lived and normally removed within about 24 hours; they are not part of audit history
  • Fly.io runtime logs for the Shopify app are provider-managed, short-retention operational logs, and Enstellis does not export them to a separate logging service
  • Vercel runtime logs for the public website are provider-managed according to the active Vercel plan and configuration
  • Neon database backup or point-in-time-restore history may retain deleted rows until the provider backup or history window expires
  • Support correspondence, billing, tax, security, or legal records may be retained only as long as needed to answer requests, comply with law, or establish, exercise, or defend legal claims

Your rights

  • Access, rectification, erasure, restriction, objection, and portability rights
  • The right to complain to National Supervisory Authority for Personal Data Processing (ANSPDCP) or your local EU supervisory authority
  • The right to know when personal data came from Shopify rather than directly from you

How to exercise your rights

  • Send the request using the support email or legal contact linked from this page
  • Include the affected Shopify shop domain and enough context for Enstellis to verify the request
  • Enstellis aims to respond without undue delay and normally within one month, subject to the GDPR and any lawful extension right

Cookies and similar technologies

The public website is intended to work without marketing or analytics cookies at launch. The embedded Shopify app may still rely on strictly necessary technical tokens for authentication and secure operation.

Automated decision-making

Enstellis does not use personal data for solely automated decisions or profiling that produce legal effects or similarly significant effects on individuals.

Effective date: 2026-06-02

Authority

National Supervisory Authority for Personal Data Processing (ANSPDCP)

Related pages

  • Legal notice
  • Terms
  • Contact support
E
Enstellis

Shipping QA infrastructure. Enstellis SRL. Built for teams that need calm signal after a shipping change, not another oversized rule builder.

SupportTermsPrivacyLegal NoticeInstall Guide

© 2026 Enstellis.