Privacy Policy - ERP Integracija | Shopify App by Agilitas
Last updated: August 3, 2026
ERP Integracija is operated by Agilitas Consultatio d.o.o., referred to in this Privacy Policy as “Agilitas”, “we”, “us”, or “our”.
The App provides integration services between Shopify stores and supported enterprise resource planning systems, including PANTHEON and eLine
This Privacy Policy explains how we collect, use, process, disclose, and retain information when a Shopify merchant installs or uses ERP Integracija.
1. Who this Privacy Policy applies to
This Privacy Policy applies to:
-
Shopify merchants who install or use ERP Integracija;
-
authorized employees and users of the merchant;
-
customers whose order information is processed through the App;
-
individuals who contact us for support or other inquiries.
For customer information processed through a merchant’s Shopify store, the merchant generally determines why and how the information is processed and acts as the data controller.
Agilitas generally processes this information on behalf of the merchant as a data processor or service provider, according to the merchant’s instructions and the functionality of ERP Integracija.
2. Information we collect and process
Depending on the App configuration, enabled features, Shopify permissions, and selected ERP integration, we may process the following categories of information.
Merchant and store information
We may process:
-
Shopify store name and domain;
-
store identifier;
-
merchant or account contact information;
-
store currency, country, language, and timezone;
-
Shopify authorization tokens;
-
App configuration and synchronization settings;
-
ERP connection settings and identifiers;
-
information about authorized App users.
Product and inventory information
We may process:
-
product names and descriptions;
-
Shopify product and variant identifiers;
-
variant SKUs;
-
barcodes;
-
prices;
-
inventory quantities;
-
inventory locations;
-
product status;
-
configured inventory adjustments or safety buffers;
-
synchronization history and timestamps.
Order information
To synchronize Shopify orders with the merchant’s ERP system, we may process:
-
Shopify order number and identifier;
-
order date and status;
-
ordered products, variants, quantities, and SKUs;
-
prices, discounts, taxes, shipping costs, and order totals;
-
payment and fulfillment status;
-
cancellation and refund information;
-
billing and shipping information;
-
order notes and other information required by the ERP integration.
ERP Integracija does not process or store complete payment card numbers or card security codes.
Customer information
Where necessary to transfer Shopify orders into the merchant’s ERP system, we may process:
-
customer name;
-
email address;
-
telephone number;
-
billing address;
-
shipping address;
-
Shopify customer identifier;
-
company name;
-
tax or business information supplied with the order;
-
other customer information included in the relevant Shopify order.
The specific customer fields processed depend on the Shopify permissions approved by the merchant and the configuration of the connected ERP system.
Technical and diagnostic information
We may process:
-
synchronization logs;
-
API request and response status;
-
error messages;
-
IP addresses;
-
browser and device information;
-
authentication and security events;
-
dates and times of App access;
-
diagnostic information required to identify and resolve technical issues.
We aim to prevent unnecessary personal information from being stored in technical logs.
3. How we obtain information
We may receive information:
-
directly from Shopify through Shopify APIs and webhooks;
-
from the merchant or the merchant’s authorized users;
-
from the PANTHEON, eLine, or other ERP system connected by the merchant;
-
automatically through the operation of ERP Integracija;
-
when a merchant contacts us for technical support;
-
from service providers used to host, secure, monitor, or maintain the App.
4. How we use information
We process information to:
-
connect a merchant’s Shopify store with the selected ERP system;
-
synchronize product and variant information;
-
match products using variant SKUs or other configured identifiers;
-
synchronize inventory quantities from the ERP system to Shopify;
-
transfer Shopify orders into the ERP system;
-
synchronize Shopify order cancellations with the ERP system;
-
apply inventory safety buffers or adjustments configured by the merchant;
-
perform synchronization at configured intervals;
-
identify and resolve failed synchronization attempts;
-
authenticate users and prevent unauthorized access;
-
provide technical support;
-
monitor App performance and reliability;
-
comply with applicable laws and Shopify platform requirements;
-
prevent fraud, misuse, and security incidents;
-
maintain and improve the App.
We do not sell personal information.
We do not use customer information for independent advertising or marketing purposes.
We do not use Shopify customer information to build customer profiles unrelated to providing ERP Integracija services.
5. Legal bases for processing
Where the General Data Protection Regulation, or GDPR, applies, we rely on one or more of the following legal bases.
Performance of a contract
We process merchant account, store, configuration, and support information where necessary to provide ERP Integracija and perform our agreement with the merchant.
Legitimate interests
We may process limited technical, diagnostic, security, and usage information for legitimate interests such as:
-
maintaining the App;
-
protecting the App and connected systems;
-
preventing misuse;
-
resolving technical issues;
-
improving service reliability.
Compliance with legal obligations
We may process or retain information where necessary to comply with applicable legal, regulatory, accounting, or security obligations.
Processing on behalf of the merchant
Customer and order information is generally processed on behalf of the Shopify merchant and according to the merchant’s instructions.
The merchant is responsible for establishing the appropriate legal basis for collecting customer information and transferring it through Shopify, ERP Integracija, and the selected ERP system.
6. How ERP Integracija works
ERP Integracija acts as a technical connection between Shopify and the ERP system configured by the merchant.
Depending on the enabled functionality:
-
inventory information may be retrieved from the ERP system and sent to Shopify;
-
product, variant, and SKU information may be exchanged between Shopify and the ERP system;
-
Shopify orders may be transmitted to the ERP system;
-
Shopify order cancellations may be transmitted to the ERP system;
-
synchronization results and errors may be recorded in technical logs;
-
configured inventory adjustments may be applied before quantities are sent to Shopify;
-
synchronization may run automatically at configured time intervals.
The merchant controls which ERP system is connected and which synchronization features are enabled.
7. Information sharing
We disclose information only where necessary to operate ERP Integracija.
Shopify
The App exchanges information with Shopify through Shopify APIs, webhooks, and related platform services.
The merchant’s ERP provider
Information may be transferred to the ERP system selected by the merchant, including PANTHEON, eLine, or another supported ERP platform.
The relevant ERP provider may process information under its own contractual terms and privacy policy.
The merchant is responsible for ensuring that it is authorized to connect the selected ERP system and transfer information to it.
Infrastructure and service providers
We may use trusted service providers for:
-
cloud and database hosting;
-
error and performance monitoring;
-
security monitoring;
-
email delivery;
-
backups;
-
technical support;
-
infrastructure maintenance.
These providers may process information only where necessary to provide their services and are required to protect it appropriately.
Legal disclosures
We may disclose information where reasonably necessary to:
-
comply with applicable law or a valid legal request;
-
respond to a court order or regulatory authority;
-
protect our rights, users, systems, or property;
-
investigate fraud, abuse, or security incidents;
-
enforce our agreements.
Business transfers
If Agilitas Consultatio d.o.o. is involved in a merger, acquisition, restructuring, or sale of assets, relevant information may be transferred as part of that transaction, subject to appropriate confidentiality and data-protection safeguards.
8. International data transfers
Information may be processed in countries other than the country in which the merchant or customer is located.
Where personal information is transferred outside the European Economic Area or another jurisdiction with data-transfer restrictions, we use appropriate safeguards where required, such as:
-
European Commission adequacy decisions;
-
Standard Contractual Clauses;
-
contractual data-protection obligations;
-
other legally recognized transfer mechanisms.
The locations in which information is processed depend on the infrastructure and service providers used to operate ERP Integracija.
9. Data retention
We retain information only for as long as reasonably necessary to:
-
provide ERP Integracija;
-
perform synchronization services;
-
maintain security and diagnostic records;
-
resolve technical issues;
-
comply with legal obligations;
-
establish, exercise, or defend legal claims.
Merchant configuration and operational data may be retained while ERP Integracija remains installed and active.
After the App is uninstalled, merchant and customer information will be deleted or anonymized within the period defined by our operational and legal requirements, unless:
-
the merchant requests earlier deletion;
-
a longer period is required by law;
-
the information is required to investigate a security incident;
-
limited information must be retained for legal claims;
-
information remains temporarily in secured backups.
Technical and security logs may be retained for a limited period necessary for troubleshooting, security, and compliance purposes.
Information already transferred to the merchant’s ERP system is controlled by the merchant and the relevant ERP provider. Uninstalling ERP Integracija does not automatically delete information previously transferred to PANTHEON, eLine, or another ERP system.
10. Security
We apply reasonable administrative, technical, and organizational measures designed to protect information against:
-
unauthorized access;
-
loss;
-
alteration;
-
disclosure;
-
misuse;
-
accidental or unlawful destruction.
These measures may include:
-
encrypted network communication;
-
access controls;
-
authentication controls;
-
restricted access to production systems;
-
secure credential management;
-
logging and monitoring;
-
software maintenance and security updates;
-
backups and recovery procedures.
No system can guarantee absolute security. Merchants are responsible for protecting their Shopify and ERP credentials and limiting access to authorized personnel.
11. Shopify privacy requests
ERP Integracija processes Shopify privacy and compliance requests in accordance with applicable law and Shopify platform requirements.
These requests may include:
-
requests for information about customer data processed by the App;
-
requests to delete or redact customer data;
-
requests to delete or redact shop data after the App is uninstalled.
Where information has already been transferred to the merchant’s ERP system, the merchant may also need to process the request directly within PANTHEON, eLine, or the other connected ERP system.
12. Individual privacy rights
Depending on applicable law, individuals may have the right to:
-
request access to their personal information;
-
request correction of inaccurate information;
-
request deletion of their information;
-
request restriction of processing;
-
object to certain processing;
-
request data portability;
-
withdraw consent where processing is based on consent;
-
lodge a complaint with a competent data-protection authority.
These rights are subject to applicable legal limitations.
Customers of a Shopify merchant should generally submit privacy requests directly to the merchant from whom they purchased products.
We will assist merchants with valid privacy requests relating to information processed through ERP Integracija.
13. Children’s information
ERP Integracija is intended for use by businesses and Shopify merchants.
We do not knowingly collect personal information directly from children for the purpose of creating App accounts.
The App may process customer order information provided by a merchant, but we do not use such information to determine a customer’s age or market directly to children.
14. Automated processing
ERP Integracija performs automated synchronization based on settings configured by the merchant.
For example, the App may automatically:
-
update Shopify inventory quantities;
-
apply a configured inventory safety buffer;
-
create order records in the connected ERP system;
-
transmit Shopify order cancellations;
-
retry failed synchronization operations.
ERP Integracija does not independently make decisions that produce legal or similarly significant effects concerning customers.
15. Cookies and similar technologies
ERP Integracija may use essential cookies or similar technologies where required to:
-
authenticate merchant users;
-
maintain secure sessions;
-
protect the App;
-
remember necessary App settings.
We do not use customer order information for cross-site behavioral advertising.
16. Merchant responsibilities
The merchant is responsible for:
-
providing customers with an appropriate store privacy notice;
-
ensuring a lawful basis for collecting and processing customer information;
-
configuring ERP Integracija only for authorized business purposes;
-
ensuring that the selected ERP system is lawfully used;
-
managing access to Shopify, ERP Integracija, and the ERP system;
-
responding to customer privacy requests;
-
maintaining appropriate retention and deletion procedures in the ERP system;
-
ensuring synchronized information is accurate, relevant, and necessary.
17. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect:
-
changes to ERP Integracija;
-
new integration functionality;
-
changes to Shopify requirements;
-
changes to service providers;
-
legal or regulatory developments;
-
security or operational changes.
The updated version will be published with a revised “Last updated” date.
Where required by law, we will provide additional notice of material changes.
18. Contact us
For questions about this Privacy Policy, ERP Integracija, or our processing of personal information, contact:
Agilitas Consultatio d.o.o.
Spinčićeva 2b
21000 Split
Croatia
OIB: 26219128187
Email: info@agilitas.ba
Individuals may also lodge a complaint with the competent data-protection authority:
Croatian Personal Data Protection Agency — AZOP
Agencija za zaštitu osobnih podataka Republike Hrvatske