Privacy Policy
Last updated: 1 August 2026. This policy is published in Italian and English; in case of conflicting interpretation, the Italian version prevails.
1. Data controller
The data controller is Temisfera, developer of the CF Ready app for Shopify. For any question about this policy or to exercise your rights, write to cfready@icloud.com.
No Data Protection Officer has been appointed, as the legal conditions requiring one do not apply.
2. Who this policy is for
This policy describes the processing that concerns the merchant — whoever installs and uses CF Ready in their Shopify store — and visitors to this website.
Your customers’ data is a different matter, and worth stating plainly: CF Ready never receives it. The Codice Fiscale and PEC check runs entirely inside Shopify’s infrastructure, during checkout, and its only output is an error message shown to the customer. The value entered is never sent to our systems, never logged and never stored. For customer data, the merchant remains the data controller and Shopify is the infrastructure provider.
3. Data we process
We process only what is needed to run the app on your store.
- Store identifiers: Shopify domain, technical identifier, store country and admin language.
- Shopify API credentials: session tokens, stored encrypted and used solely to operate on your store.
- App configuration: the rules you chose for Codice Fiscale and PEC, the messages shown to customers, the state of the guided setup and whether validation is active.
- Commercial status: trial start and expiry, payment mode and subscription status, technical references provided by Shopify.
- Technical records: essential events such as installation, uninstallation, validation activation, error codes and receipts of the messages Shopify sends us.
- Support requests: the email address you write from and the content of your message, for as long as needed to answer.
4. Data we do not process
By design, the app neither reads nor stores:
- your customers’ Codice Fiscale values and PEC addresses;
- orders, line items and amounts;
- customer records and addresses;
- products, catalogues and inventory;
- invoices and tax documents.
The permissions the app requests from Shopify are limited to what is needed to manage its own validation and configuration.
5. Purposes and legal bases
- Providing the service you requested by installing the app: performance of a contract (Art. 6(1)(b) GDPR).
- Managing trial, subscription and usage rights, including preventing repeated trials on the same store: performance of a contract and legitimate interest in preventing abuse (Art. 6(1)(b) and 6(1)(f)).
- Ensuring security, continuity and technical diagnosis: legitimate interest (Art. 6(1)(f)).
- Answering support requests: performance of a contract and responding to your request (Art. 6(1)(b)).
- Complying with legal obligations, in particular accounting and administrative ones (Art. 6(1)(c)).
We do not use your data for profiling, advertising or automated decision-making, and we do not sell or share it with third parties for marketing purposes.
6. This website
This website consists of static pages and sets no cookies. It uses Cloudflare Web Analytics to measure aggregated visits and performance, including page views, load times, Core Web Vitals, visited path, referring site, country, device type, browser and operating system. The beacon is loaded from static.cloudflareinsights.com and sends metrics to this website’s /cdn-cgi/rum endpoint. It uses neither cookies nor local storage, creates no fingerprints, records no query strings and does not track visitors across different websites. This processing is necessary to verify the website’s operation and performance on the basis of legitimate interests (Art. 6(1)(f) GDPR).
7. Recipients
Data is accessible to the developer only, and to the infrastructure providers acting as data processors:
- Shopify, which hosts your store, authenticates access to the app, runs the checkout validation and handles app billing;
- Cloudflare, which hosts the application service, the database and this website.
Some of these providers may process data outside the European Economic Area. Where that happens, the transfer relies on the safeguards set out in Chapter V of the GDPR, in particular the standard contractual clauses adopted by the European Commission.
8. Retention
- Sessions and tokens: until expiry or uninstallation, deleted immediately on uninstallation.
- Configuration and guided setup state: up to 90 days after uninstallation.
- Essential technical records: up to 12 months.
- Detailed technical errors and Shopify message receipts: up to 90 days.
- Support requests: 12 months, unless a documented need requires otherwise.
- Trial, acquired pricing conditions and usage rights, kept to the minimum: for as long as needed to prevent abuse, preserve the conditions granted to you and meet administrative obligations.
When Shopify notifies us that a store has been erased, we act without waiting for the periods above.
9. Your rights
You may at any time request access to your data, its rectification or erasure, restriction of processing and portability, and you may object to processing based on legitimate interest. Write to cfready@icloud.com: we will reply within the time limits set by the GDPR.
If you believe the processing infringes the law, you may lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it) or with the supervisory authority of the country where you live.
10. Security
Access tokens are stored encrypted. Communications travel over protected channels, and the messages we receive from Shopify are cryptographically verified before being processed. Access to data is limited to the developer. No measure is infallible: if you find a security issue, the procedure for reporting it is described on the support page.
11. Changes
This policy may change when the app or the applicable law changes. The version published on this page is always the one in force and shows the date it was last updated. Substantial changes are also announced inside the app.