Fortegia

Privacy Policy

This Policy explains what data Fortegia processes, why it is processed, and how the public Shopify app accesses store data.

1.0 Effective from 28 July 2026 Last updated: 28 July 2026

1. Controller and contact details

Fortegia sp. z o.o. is the controller of data processed for Fortegia's own purposes. Our registered office is at Gotarda 9, 02-683 Warsaw, Poland. We are entered in the register of entrepreneurs of the National Court Register under KRS 0001131555, tax identification number NIP 5214089069, and statistical number REGON 529888480.

For privacy questions or rights requests, email kontakt@fortegia.com or use our contact form.

2. Our data protection roles

2.1. Fortegia as controller. We act as controller for merchant contact details, Fortegia account users, sales and support enquiries, billing, security, and the establishment or defence of claims.

2.2. Fortegia as processor. When we process a store catalog or storefront visitor chat content on a merchant's documented instructions, the merchant remains the controller and Fortegia acts as processor within the scope agreed for the relevant service. If the parties have entered into a separate data processing agreement, its terms also apply.

2.3. Storefront visitor requests. A person who uses chat in a merchant's store should contact that merchant first. Fortegia assists the merchant with a valid request concerning data processed in that merchant's workspace.

3. Data we process and why

The data involved depends on how Fortegia is used:

  • Account and contact data: name, company details, business email address, telephone number, role, and correspondence. We use it to create and service an account, communicate, provide support, and enter into or perform an agreed service.
  • Billing and legal data: company and invoicing details, billing history, and service documentation. We use it for billing, accounting, and legal compliance.
  • Technical and security data: account, workspace, store, and session identifiers, IP address, timestamps, authorization events, and activity, error, and webhook logs. We use it to operate and diagnose the service, prevent abuse, and maintain an event record.
  • Storefront feature activity: views and interactions with the chat bubble and recommendation frames, recommendation impressions and clicks, pseudonymous session or visitor identifiers, page context, basic browser and device information, and timestamps. We use this data to display features, measure how they operate, diagnose issues, and improve relevance. Location is not required for core operation. It may be processed only when an enabled feature uses it and, where required by law or device settings, after consent or browser permission.
  • Catalog data: store, product, and variant information described in more detail in section 4. We use it to import and reconcile the catalog, provide product search, answer chat messages, and populate recommendation frames.
  • Storefront chat data: messages entered in chat, conversation history required for context, and related session technical data. A message may contain personal data if a visitor voluntarily enters it. This data comes from chat, not from Shopify customer records.

Please do not enter special category data, payment information, or other information that is not needed to find a product in chat.

4. The public Fortegia app for Shopify

4.1. Permission scope. The app's catalog access uses read_products and is read-only. The app does not modify products or variants, does not read or modify orders or customer records, does not handle payments or fulfillment, and does not manage inventory. The app does write its own app-data metafields associated with the installation. They contain configuration needed to operate the app, not product, order, customer, or inventory data.

4.2. Store and installation data. We process the store ID and domain, store name, primary currency, installation state, workspace connection, storefront element configuration, app-owned app-data metafields, and the OAuth credential required to operate the integration.

4.3. Catalog data. Depending on the store catalog, this may include IDs, titles, handles, descriptions, product type and category, collections, vendor, tags, status, URL, images, and variant fields including ID, title, SKU, barcode, price, compare-at price, selected options, inventory quantity, availability for sale, and whether inventory tracking is enabled, as returned with product records. We do not use these fields to manage inventory or write them back to Shopify.

4.4. Updates. Product creation, update, and deletion webhooks signal that catalog reconciliation is required. We process technical webhook identifiers and delivery status to verify authenticity, prevent duplicate processing, and diagnose errors. Periodic reconciliation helps identify a missed change.

4.5. Storefront features. After connecting the store, the merchant can manually enable the Chat bubble app embed and add Recommendation frame blocks in a compatible Shopify Online Store theme. Catalog data then supports product search, chat answers, and recommendation selection.

4.6. Shopify customer data. The app does not retrieve customer or order records from the Shopify Admin API. We handle customers/data_request and customers/redact webhooks as required by Shopify. If the integration has no data originating from Shopify customer records, we acknowledge the request without creating such data. Data voluntarily entered in storefront chat is handled separately under section 3.

5. Legal bases

When Fortegia acts as controller, the legal basis depends on the context:

  • Article 6(1)(b) GDPR where processing is necessary to agree or perform a service or a contract, if one has been entered into, or to take steps requested by a person before agreement;
  • Article 6(1)(c) GDPR where processing is required by law, including tax, accounting, and data protection duties;
  • Article 6(1)(f) GDPR for our legitimate interests in securing and diagnosing the service, preventing abuse, establishing or defending claims, and improving the service while respecting user rights;
  • Article 6(1)(a) GDPR when we ask for voluntary consent, for example for specified marketing communications or optional analytics technologies.

When Fortegia acts as processor, the merchant acting as controller determines the purpose and legal basis.

6. Recipients and international transfers

Data may be available to authorized Fortegia personnel and providers actually used to supply the relevant service, for example hosting and database, monitoring and security, email communication, technical support, and artificial intelligence providers used for chat and recommendations. The specific provider list, roles, and processing locations depend on the deployment. For current information relevant to a specific deployment, email kontakt@fortegia.com.

This Policy does not assume that every deployment transfers data outside the European Economic Area. If a transfer occurs, its legal basis and safeguards depend on the recipient, country, and applicable law. Depending on the circumstances, an adequacy decision, Standard Contractual Clauses, or another legally recognized mechanism may apply. Information about the mechanism relevant to a specific deployment is available through the contact address. We do not sell personal data.

We may disclose data to public authorities only when applicable law or a valid legal demand requires it.

7. Retention and deletion

We do not apply one retention period to all data and deployments. The period depends on purpose, service configuration, merchant instructions, and legal duties:

  • Account, contact, and configuration data may be retained while a service or enquiry is active and afterwards to the extent needed for legal duties or the establishment, exercise, or defence of claims.
  • The Shopify catalog copy and workspace connection are needed while the integration is active and supports search, chat, recommendations, or catalog reconciliation.
  • Conversation content and metadata, and storefront feature activity data, may be retained for the period resulting from merchant configuration and instructions and the needs of conversation history, diagnostics, performance measurement, and security.
  • Technical and security logs may be retained for a period justified by diagnostics, service protection, event accountability, and incident handling.
  • Accounting and legal records are retained if and for as long as applicable law requires.

App uninstall. When we receive a valid app/uninstalled webhook, we remove Shopify credential material, stop automatic imports, and remove storefront origins managed by the app.

Store data deletion. When we receive and verify a shop/redact webhook, we remove credential material, the external store connection, and storefront access, and trigger deletion of the catalog assigned to the correct tenant workspace. A minimal secret-free technical record may remain until successful catalog deletion is confirmed.

If data is present in a backup, removal from that backup may occur only when it is rotated or overwritten in the current technical cycle. A backup is not used to continue ordinary operation of a disconnected integration. Exact periods for a specific environment or agreed service must be confirmed with Fortegia because this Policy does not establish a fixed backup, log, or conversation schedule.

8. Security, rights, and automated decisions

We apply technical and organizational measures appropriate to risk, including access restrictions, tenant separation, transmission protection, security event logging, and webhook signature verification. No storage or transmission method removes all risk.

Depending on the circumstances, a person may have rights of access, correction, deletion, restriction, portability, objection, and withdrawal of consent without affecting earlier lawful processing. The scope of a right depends on Fortegia's role, the legal basis, and applicable exceptions. Send a request to kontakt@fortegia.com. You may also lodge a complaint with the Polish President of the Personal Data Protection Office or another competent supervisory authority.

Chat and recommendations may automatically match products to a query using message content and catalog data. This does not produce legal or similarly significant effects for the visitor. The user makes the final product choice.

9. Cookies and local technologies

The Fortegia website and store-embedded elements may use cookies, local storage, or similar technologies needed to maintain a session, secure the service, remember settings, and operate chat. Optional analytics or marketing technologies are used only when configured and, where required by law, after consent.

The merchant is responsible for informing its storefront visitors about technologies used on its site and configuring any consent mechanism required by applicable law. Users can manage cookies in their browser settings, although blocking essential technologies may limit the service.

10. Changes to this Policy

We may update this Privacy Policy when laws, service features, the Shopify app scope, or our processing changes. The effective and last updated dates appear at the start of the document. We will use an appropriate channel to inform a Customer of a material change affecting an active Service.

A privacy or deletion question?

Tell us which store, workspace, or account the request concerns. Do not send passwords or access tokens.

Contact us

Legal documents

Privacy Policy

How data is processed, including data used by the Shopify app.

Version 1.0
Aktualny dokument
Terms of Service

Terms governing use of the Fortegia website and platform.

Version 1.0
Przejdź do dokumentu