Privacy Policy
Effective date: August 18, 2026
Who operates the app
Fio QR Payments is operated by Dito Consulting s.r.o. Privacy questions can be sent to support email .
- Legal name:
- Dito Consulting s.r.o.
- Registered office:
- Landererova 8, 811 09 Bratislava, mestská časť Staré Mesto, Slovak Republic
- Company ID:
- 50 144 863
- Tax ID:
- 2120199697
- VAT ID:
- SK2120199697
- Commercial Register:
- Mestský súd Bratislava III, oddiel Sro, vložka č. 108997/B
- Email:
- Email:
- Website:
- https://ditoconsulting.com
Scope and roles
This policy applies to the public Shopify App Store edition of Fio QR Payments. The app helps a merchant show post-purchase manual bank-transfer instructions and reconcile eligible Fio bank transactions against Shopify orders.
For buyer and order data supplied by a merchant through Shopify, the merchant generally determines why that data is processed and Dito Consulting processes it to provide the app. Dito Consulting may act as an independent controller for its own account administration, security, support, and legal-compliance records.
Information processed
- Shop and installation data: Shopify shop domain and identifiers, store settings, country, currency, locale, plan and installation state, granted scopes, and encrypted Shopify access or refresh tokens.
- Protected Shopify order data: Order identifiers, name or number, creation and status dates, amount, currency, country code, financial and cancellation status, manual payment-method labels, relevant order webhook events, and app-owned order metafield values used for payment status.
- Payment-instruction data: Generated payment references and symbols, amount, currency, due and expiry dates, QR payload and image, payment note, receiver reference, public payment-page token, and reconciliation state.
- Fio account and transaction data: Merchant-entered beneficiary and routing details such as IBAN, BIC and local account number, an encrypted Fio API token and token fingerprint, connection and synchronization status, and imported transaction or statement identifiers, dates, amounts, currencies, references, messages, and match results.
- Report and communication data: Merchant-configured report-recipient email addresses, report periods and delivery status, generated statement artifacts, test-recipient email addresses, and information a merchant voluntarily includes in a support request.
- Security, operational, and compliance data: Webhook topic and delivery identifiers, limited delivery headers, affected resource identifiers, processing status and errors, audit events, application logs, and encrypted customer-data-request exports.
The app does not process card details or buyer online-banking credentials and does not operate as a payment gateway. Its normal Shopify API access does not request buyer name, street address, email, or phone fields. The app does process Level 1 protected customer data because Shopify orders, order webhooks, and order metafields relate to individual orders.
The application is designed not to persist raw Shopify webhook bodies or raw Fio API payloads after the required operational fields have been extracted.
How information is used
- Authenticate the merchant's installation and provide the embedded administration interface.
- Create QR Platba or PAY by square instructions after Shopify checkout for a merchant-configured manual payment method.
- Import Fio statement transactions, identify one exact eligible match, and update the corresponding Shopify order.
- Generate and deliver merchant-requested statements and operational reports.
- Diagnose failures, secure the service, prevent duplicate webhook processing, and provide support.
- Respond to Shopify privacy webhooks and applicable access, deletion, or legal requests.
Information is not sold and is not used for advertising or unrelated profiling.
Legal bases for processing
- Performance of a contract or steps taken before entering into a contract when operating the app for a merchant.
- Compliance with legal obligations, especially for accounting, security, and compliance records.
- Legitimate interests in securing the service, providing support, preventing misuse, and protecting legal claims.
- Consent only where required by law. The public website does not use advertising or analytics cookies.
Sources and disclosures
Information comes from the merchant, Shopify APIs and webhooks, the app's Shopify extensions, Fio's API, and the app's own security and operational systems. It is disclosed only as needed to operate the service, comply with law, protect the service, or follow the merchant's instructions.
Relevant recipients and processor categories include Shopify, Fio banka, cloud hosting and database or storage providers, email-delivery providers for requested reports, and monitoring or error-management providers if enabled.
Verified subprocessor names, purposes, processing locations, and links: To provide the service, information may be processed by Shopify, Fio banka, and infrastructure providers needed to operate the app. The public website does not use advertising networks or analytics services. Current purposes, providers, and processing locations are available on request at the contact address.
Primary hosting and data-storage region: The public edition app, database, and queues run in a production environment managed by Dito Consulting. The operator will provide current infrastructure provider and location details on request and update this policy when they change.
Retention
- Active shop configuration, encrypted access tokens, and bank-account configuration are kept while the app remains installed or until the merchant deletes or replaces them.
- Resolved operational order, payment-request, matching, and bank-transaction detail is retained for 70 days. Unresolved records are retained while needed to provide the requested reconciliation workflow.
- Customer privacy exports, webhook delivery records, and audit logs are retained for 30 days.
- Generated report artifacts are retained for 30 days; report-history records are retained for 90 days.
- Daily application logs are retained for 14 days.
- Data can be deleted earlier following a valid Shopify customer-redaction or shop-redaction request, unless retention is legally required.
Backup retention and deletion schedule: Backups are retained only for as long as needed to restore the service and address security or legal obligations. They are securely deleted when no longer needed.
Security
The app uses HTTPS in transit, Shopify session-token and webhook-signature verification, least-privilege API scopes, access controls, encrypted Shopify and Fio tokens at rest, and limited operational logging. No technical system can be guaranteed completely secure; suspected incidents should be reported to support email .
International transfers
Service providers can process information outside the merchant's or buyer's country. The operator must document the actual hosting and subprocessor locations and, where required, the transfer mechanism used for those locations.
Verified transfer countries and safeguards: If a provider processes information outside the European Economic Area, the transfer relies on an adequacy decision, standard contractual clauses, or another GDPR-valid safeguard. The operator can provide the current safeguard details on request.
Privacy rights and requests
Depending on applicable law, individuals may have rights to access, correct, delete, restrict, port, or object to processing of their personal data and to complain to a supervisory authority. Buyers should normally contact the Shopify merchant that received their order. Merchants and other individuals can contact support email . The app also processes Shopify's mandatory customer data-request, customer-redaction, and shop-redaction webhooks.
Supervisory authority A complaint may be lodged with the Office for Personal Data Protection of the Slovak Republic. https://www.dataprotection.gov.sk/sk/kontakt/. No data protection officer has been appointed. The operator handles privacy questions at the contact address.
This page explains which cookies and similar technologies are used by the public Fio QR Payments website. Cookies.
Changes
This policy may be updated when the app, providers, or legal requirements change. A revised effective date will be shown on this page.