Shopify Apps Privacy Policy

Privacy Policy for Shopify Payment Applications

Last Updated: October 2026 | Applies to: HolestPay – Card Payment & HolestPay – IPS Skeniraj

This Privacy Policy governs the processing of personal and transactional data collected through the Shopify Payment Extension applications “HolestPay – Card Payment” and “HolestPay – IPS Skeniraj” (collectively referred to as the “Apps”), provided by HOLEST E-COMMERCE DOO (PIB: 112300090, MB: 21645150, Registered Office: Dušana Petrovića Šaneta 4/31, 11130 Kaluđerica, Serbia).

HOLEST E-COMMERCE DOO operates as a licensed, PCI DSS compliant Payment Service Provider (PSP). This Privacy Policy specifically addresses data processed during checkout transactions executed via our Shopify Payment Applications and is distinct from the general privacy terms of our primary e-commerce website.


1. Roles & Relationship (PSP Standard)

When a customer places an order on a Shopify merchant’s store, HOLEST E-COMMERCE DOO acts as an independent Payment Service Provider (PSP) responsible for processing secure financial transactions, fraud prevention, and bank-level settlement. The Shopify merchant acts as the merchant of record for the commercial sale.

2. Information We Collect & Process

To securely process payments, enable card tokenization, and fulfill regulatory requirements, our Apps collect and receive transaction data from Shopify during checkout:

  • Customer & Contact Information: Full name, email address, phone number.
  • Billing & Shipping Details: Billing address, shipping address, country.
  • Transaction & Order Data: Order amount, currency, Order ID, Shopify Checkout Session ID, line item summary, IP address.
  • Payment Method Credentials:

    • HolestPay – Card Payment: Cardholder payment data including Primary Account Number (PAN), card expiration date, card brand, and tokenized credentials. Storage of PAN and expiration dates is restricted strictly to payment models that require it (e.g., automated recurring subscriptions, post-authorized billing, or saved customer cards) within an encrypted PCI DSS vault. Standard one-off purchases utilize tokenization. Sensitive authentication data (CVV/CVC) is processed solely during authorization and is NEVER stored.
    • HolestPay – IPS Skeniraj: Transaction payload data generated for NBS IPS QR Code execution or deep-link banking app redirects in accordance with the National Bank of Serbia (NBS) standards.

3. Purpose & Legal Basis of Processing

We process your data strictly for the following purposes:

  • Payment Execution & Subscriptions: Routing transactions securely through acquirer banks, executing pre-authorized/deferred transactions, and processing automated recurring subscription billings.
  • Fraud Prevention & Risk Management: Verifying transaction authenticity, preventing unauthorized payments, and managing chargebacks.
  • Legal & Regulatory Compliance: Fulfilling statutory obligations under applicable banking laws, Anti-Money Laundering (AML) regulations, and fiscal accounting rules.

4. Security, PCI DSS Certification & QSA Auditing

As a certified PSP, HOLEST E-COMMERCE DOO holds full authorization to securely process and store cardholder data (PAN and expiration date) when necessitated by the payment structure (such as subscriptions). Our cardholder data environment undergoes rigorous annual audits conducted by an independent Qualified Security Assessor (QSA) to verify complete adherence to the Payment Card Industry Data Security Standard (PCI DSS). All stored data is protected using strong encryption standards (TLS 1.2+ in transit, and AES-256 / HSM encryption at rest).

5. Data Disclosure & Third Parties

We do not sell, rent, or lease customer data. Transactional data is disclosed exclusively to authorized financial institutions, acquiring banks, processing partners, and legal authorities strictly necessary to complete payment processing, settle funds, or fulfill statutory law enforcement requirements.

6. Shopify Privacy Webhooks & Data Rights

Our Apps fully integrate with Shopify Mandatory Privacy Webhooks (Customer Data Request, Customer Redaction, and Shop Redaction). When a merchant or buyer requests data erasure, we process the request within required statutory timelines, save for data we are legally mandated to retain for fiscal, banking, AML, or PCI DSS compliance audit requirements.

7. Contact Us

For privacy inquiries or data protection requests regarding our Shopify payment applications, please contact us at:

HOLEST E-COMMERCE DOO
Dušana Petrovića Šaneta 4/31, 11130 Kaluđerica, Serbia
PIB: 112300090 | MB: 21645150
Website: ecommerce.holest.com
Email: support@holest.com