zrsPOSLegal
HomePricingApps

zrsPOS — Privacy Policy

Version 1.0 (draft for legal review) · 15 September 2026 · Contact: support@zrspos.com

This policy explains what personal data the zrsPOS app processes, why, and how, for two audiences: merchants who install zrsPOS on their Shopify store, and their customers, whose data appears on fiscal documents zrsPOS issues.

What zrsPOS does

zrsPOS connects a merchant's Shopify POS to the merchant's own SAGE invoicing system so that every sale, refund and exchange at the till produces a legally valid Portuguese fiscal document, and prints it. Optionally it issues Global Blue tax-free forms for eligible travellers.

Who is responsible

For customers' personal data, the merchant is the data controller: it decides to issue invoices and is legally obliged to keep them. zrsPOS is the merchant's processor, acting on its instructions under a Data Processing Agreement.

For merchants' own account data (the person who installs and configures the app), zrsPOS is the controller.

Data we process, and why

About the merchant's customers (received from Shopify when a sale, refund or return happens, or captured at the till):

Data Why
Name, tax number (NIF), billing address Required content of a Portuguese invoice (legal obligation)
Email, phone Delivering the document; finding it again at the POS
Order lines, amounts, payment method, store location, refunds Issuing and correcting the document
Passport details, nationality, residence, date of birth (only with the Tax Free feature, from a passport the traveller presents) Issuing a Global Blue tax-free form at the traveller's request

About the merchant (the person using the app): the Shopify store domain, the staff member's Shopify session, the configuration entered (SAGE endpoint and key, printers, Global Blue login, document layouts, contact email). Credentials are encrypted with a key unique to the store.

We do not process payment card data. We do not use personal data for marketing, profiling or automated decisions, and we never sell it.

Where it goes

Hosting is in the European Union (Railway, Netherlands; Supabase, Ireland).

How long we keep it

Fiscal documents are kept for the period Portuguese tax law requires the merchant to keep them (currently 10 years). Email and phone are not part of the document and are removed on request. Everything else — event payloads, rendered receipts, configuration, credentials — is deleted within 48 hours of the merchant uninstalling the app.

Your rights

Customers should contact the merchant that issued their document; we help the merchant respond. Through Shopify's data request and redaction mechanisms we provide the data we hold for an order, and we erase the email and phone on request. We cannot erase the name, tax number or address on an issued fiscal document, because the law requires the merchant to keep the document intact; we tell the merchant so, so they can explain this to the customer.

Merchants can see and change everything they've configured inside the app, and uninstalling it triggers the deletion above.

Security

Every record is bound to the store it belongs to, and automated tests prevent any store's data from being reachable by another. Credentials are encrypted per store. All connections use TLS; storage and backups are encrypted. Access by zrsPOS staff is limited, logged, and protected by two-factor authentication. Our full Data Loss Prevention Strategy and Security Incident Response Policy are available to merchants on request.

If a security incident affects a merchant's data, we notify that merchant within 24 hours of confirming it.

Changes and contact

We'll post changes to this policy here and notify merchants of material changes through the app. Questions: support@zrspos.com.