Privacy Policy

Last updated: 18 June 2026

This Privacy Notice for Berdibekov Solutions ("we," "us," or "our") describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you:

  • Use Fatura. Fatura is a Shopify app that automatically generates UAE VAT-compliant tax invoices for every paid order. The app creates PDF invoices, sends them to buyers by email, and provides quarterly VAT reports to help merchants meet UAE Federal Tax Authority (FTA) requirements.
  • Engage with us in other related ways, including any marketing or events

Questions or concerns? If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at berdibekovadilet@gmail.com.

Table of contents

  1. What information do we collect?
  2. How do we process your information?
  3. What legal bases do we rely on to process your personal information?
  4. When and with whom do we share your personal information?
  5. Is your information transferred internationally?
  6. How long do we keep your information?
  7. How do we keep your information safe?
  8. Do we collect information from minors?
  9. What are your privacy rights?
  10. Controls for do-not-track features
  11. Do United States residents have specific privacy rights?
  12. Do we make updates to this notice?
  13. How can you contact us about this notice?
  14. How can you review, update, or delete the data we collect from you?

1. What information do we collect?

Personal information you disclose to us

We collect personal information that you voluntarily provide to us when you install and configure our Services, and that is automatically provided by Shopify when orders are processed in your store.

The personal information we collect may include:

  • Merchant information: Shopify store domain, Tax Registration Number (TRN), company name and address, contact email
  • Buyer information (from Shopify orders): buyer name, email address, billing address
  • Order data: order items, amounts, tax information, order numbers

Sensitive Information. We do not process sensitive information beyond what is required for UAE VAT invoice generation.

Payment Data. We do not store payment card data. All payment processing is handled by Shopify. You may find their privacy notice here: https://www.shopify.com/legal/privacy.

2. How do we process your information?

We process your information to:

  • Generate UAE VAT-compliant PDF tax invoices for each paid order
  • Send invoice emails to buyers on behalf of the merchant
  • Store invoices for the legally required 5-year retention period under UAE VAT law
  • Generate quarterly VAT summary reports for merchants
  • Provide and improve our Services
  • Comply with UAE Federal Tax Authority (FTA) regulations

3. What legal bases do we rely on to process your information?

We only process your personal information when we believe it is necessary and we have a valid legal reason to do so under applicable law.

Performance of a Contract: We process your information to provide the invoicing services you have subscribed to.

Legal Obligation: UAE VAT law requires tax invoices to be generated and retained for 5 years. We process data to help merchants comply with these legal requirements.

If you are located in the EU or UK: We may rely on Consent, Performance of a Contract, Legitimate Interests, or Legal Obligation.

4. When and with whom do we share your personal information?

We may share your data with the following third-party service providers:

  • Email delivery: Resend (resend.com) — used to send invoice emails to buyers
  • File storage: Supabase (supabase.com) — used to store generated PDF invoices
  • Application hosting: Railway (railway.app) — used to host our application and database
  • E-commerce platform: Shopify (shopify.com) — the platform through which our app operates

We do not sell your personal information to third parties.

5. Is your information transferred internationally?

Our servers are located in Europe (EU region). Invoice PDF files are stored in Supabase (EU West region). If you are accessing our Services from outside the EU, please be aware that your information may be transferred to and processed in EU facilities.

We have implemented appropriate safeguards to protect your data during international transfers.

6. How long do we keep your information?

We retain invoice data for a minimum of 5 years as required by UAE Federal Tax Authority regulations. Merchant account data is retained for as long as the app is installed. When you uninstall the app, we will delete your access credentials within 30 days, but invoice records will be retained for the legally required period.

7. How do we keep your information safe?

We have implemented appropriate technical and organizational security measures including:

  • Encrypted data transmission (HTTPS/TLS)
  • Encrypted data storage
  • Access controls limiting data access to authorized personnel only
  • Regular security reviews

However, no electronic transmission over the Internet can be guaranteed to be 100% secure. You should only access the Services within a secure environment.

8. Do we collect information from minors?

We do not knowingly collect, solicit data from, or market to children under 18 years of age. Our Services are intended for business use only. By using the Services, you represent that you are at least 18 years of age.

9. What are your privacy rights?

Depending on your location, you may have rights including:

  • The right to access your personal information
  • The right to correct inaccurate data
  • The right to request deletion of your data (subject to legal retention requirements)
  • The right to withdraw consent
  • The right to data portability

To exercise your rights, contact us at berdibekovadilet@gmail.com.

10. Controls for do-not-track features

We do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online.

11. Do United States residents have specific privacy rights?

If you are a resident of California, Colorado, Connecticut, or other US states with privacy laws, you may have the right to request access to, correct, or delete the personal information we maintain about you.

To exercise these rights, email us at berdibekovadilet@gmail.com.

12. Do we make updates to this notice?

Yes, we will update this notice as necessary to stay compliant with relevant laws. The updated version will be indicated by an updated "Last updated" date at the top of this Privacy Notice.

13. How can you contact us about this notice?

If you have questions or comments about this notice, you may contact us at:

Berdibekov Solutions
Bishkek, Kyrgyzstan
Email: berdibekovadilet@gmail.com

14. How can you review, update, or delete the data we collect from you?

Based on the applicable laws of your country or state of residence, you may have the right to request access to the personal information we collect from you, correct inaccuracies, or delete your personal information. Note that invoice data may be retained for the legally required 5-year period under UAE VAT law. To make a request, email us at berdibekovadilet@gmail.com.