Open documentation navigation
Access and responsibilities

Accounts, access and processed data

Required accounts, Shopify permissions and billing, secure credential storage, disconnection, retention and support responsibilities.

Updated: 19 July 2026
On this page

Every connection belongs to a specific Shopify shop. Do not use one carrier or invoicing account for multiple legal entities without explicit authority, separate configuration and accounting review.

Required accounts

Torevo Shipping requires:

  • a Shopify shop with authority to install applications and read required orders,
  • your own compatible Packeta Network sender account,
  • an API password for the server connection,
  • a widget key for pickup-point selection,
  • enabled markets, sender identity and supported services.

Torevo Invoices requires:

  • a Shopify shop with access to orders and company data required by its extensions,
  • your own company in KROS Fakturácia,
  • a licence or trial with API connections,
  • a KROS API token and webhook authorisation key,
  • a numbering sequence, PDF report and accountant-approved configuration.

Shopify, Packeta Network and KROS accounts, contracts and fees are separate. Torevo does not create a third-party account for the merchant or promise a particular plan’s availability.

Shopify access and billing

An authorised shop user installs the app and approves Shopify App Pricing. Always check current price, trial and billing interval on Shopify’s approval screen before confirming. Carrier and KROS charges are billed separately under the merchant’s contract with each provider.

Approve only scopes needed for declared features. A scope change can require new approval. Limit staff access through Shopify roles and remove it when a user leaves.

How data is used

Shipping processes the minimum order and delivery data needed for a shipment, label, tracking and optional fulfilment. Invoices processes data required to build an invoice, register payments, receive callbacks, provide the PDF and audit the operation.

One shop’s data must never be accessible to another shop. Documents and credentials must be tenant-scoped. The current privacy policy and DPA define detailed purposes, legal bases, retention and subprocessors.

Credential storage and rotation

  • Enter credentials only inside the application over a secure connection.
  • Store tokens and passwords as encrypted, write-only values.
  • Never copy them into tickets, analytics, logs or screenshots.
  • Rotate them when an administrator changes or exposure is suspected.
  • After rotation, run a connection test and controlled test operation.
  • Revoke the old token at the provider.

Customer rights and Shopify requests

Send a request to access, correct or erase personal data through the current contact channel in the privacy policy. Shopify privacy webhooks and shop cleanup are processed only for the affected shop.

Statutory invoice or record retention can limit immediate erasure. The operator must explain the legal basis and term; documents held directly in KROS remain under the merchant’s account.

Disconnect and uninstall

Before disconnection:

  1. disable automatic rules,
  2. finish or reconcile pending operations,
  3. export required audit and identifiers,
  4. confirm where shipments and statutory documents remain,
  5. only then revoke the provider token or uninstall the app.

Uninstalling ends the app’s Shopify access and starts shop-scoped cleanup under the retention policy. It does not cancel carrier shipments or delete invoices from the KROS account.

Shop ownership or operator changes

When ownership changes, review Shopify billing, user roles, incident contacts, provider accounts, numbering and legal duties. Do not hand over credentials informally; create new credentials and revoke the old ones.

Contact support

Use the contact form or support channel shown on the Torevo site. Include shop domain, application, safe ID, timestamp and error code. Support should never ask for a complete API password or token. The operator’s company data appears only in legal and contact sections where required.