Privacy Policy

Linkbase AB | Last Updated: 2026-01-21

1. Introduction

This Privacy Policy describes how Linkbase AB ("Linkbase", "we", "us", or "our") collects, uses, and shares information when you use our Shopify application and related services (the "Service"). The Service provides integration between Shopify and Fortnox accounting software.

By installing or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with this Privacy Policy, please do not use the Service.

2. Data Controller

Linkbase AB is the data controller for personal data processed through the Service. Our contact information:

3. Information We Collect

3.1 Information from Shopify

When you install and use our Service, we access the following data from your Shopify store through Shopify's APIs:

  • Order information (order details, amounts, dates, status)
  • Customer information (names, addresses, email addresses for invoicing purposes)
  • Product information (product names, SKUs, prices, VAT rates)
  • Payment and refund information
  • Store settings and configuration

3.2 Information from Fortnox

When you connect your Fortnox account, we access:

  • Account settings and chart of accounts
  • Customer records
  • Invoice and voucher data
  • Article/product information

3.3 Information You Provide Directly

  • Account registration information (name, email, company details)
  • Billing information for subscription payments
  • Configuration settings for the integration
  • Support communications

3.4 Automatically Collected Information

  • Usage data and interaction logs
  • IP addresses and device information
  • Browser type and version
  • Error logs and performance data

4. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Synchronize data between Shopify and Fortnox
  • Create accounting entries, invoices, and vouchers in Fortnox
  • Process payments and manage subscriptions
  • Provide customer support
  • Send service-related communications
  • Detect, prevent, and address technical issues
  • Comply with legal obligations

5. Legal Basis for Processing (GDPR)

We process personal data based on the following legal grounds under the General Data Protection Regulation (GDPR):

  • Contract Performance: Processing necessary to provide the Service you have subscribed to (Article 6(1)(b))
  • Legitimate Interests: Processing necessary for our legitimate business interests, such as improving our Service and ensuring security (Article 6(1)(f))
  • Legal Obligation: Processing necessary to comply with applicable laws, such as tax and accounting regulations (Article 6(1)(c))
  • Consent: Where applicable, processing based on your explicit consent (Article 6(1)(a))

6. Information Sharing and Disclosure

We share your information with:

  • Fortnox AB: To enable the integration functionality
  • Shopify Inc.: As required by the Shopify platform
  • Service Providers: Third-party providers who assist in operating our Service (e.g., hosting, payment processing)
  • Legal Requirements: When required by law, court order, or governmental authority

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

7. Data Retention

We retain your personal data for as long as necessary to provide the Service and fulfill the purposes described in this Privacy Policy. When you uninstall the app or terminate your account, we will delete or anonymize your data within 30 days, unless we are required to retain it for legal or regulatory purposes (such as tax or accounting requirements, which may require retention for up to 7 years in Sweden).

8. International Data Transfers

Your data is primarily processed within the European Union (EU) and European Economic Area (EEA). If data is transferred outside the EU/EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission, or transfers to countries with an adequacy decision.

9. Your Rights

Under GDPR and other applicable privacy laws, you have the following rights:

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Request correction of inaccurate or incomplete data
  • Erasure: Request deletion of your personal data ("right to be forgotten")
  • Restriction: Request restriction of processing
  • Portability: Request your data in a portable format
  • Objection: Object to processing based on legitimate interests
  • Withdraw Consent: Withdraw consent at any time where processing is based on consent

To exercise these rights, contact us at privacy@linkbase.se. We will respond within 30 days.

10. Data Security

We implement industry-standard technical and organizational security measures to protect your data, including encryption in transit (TLS/SSL) and at rest, access controls, and regular security assessments. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

11. GDPR Compliance and Data Subject Requests

We respond to mandatory GDPR compliance webhooks from Shopify, including customer data requests, customer data erasure requests, and shop data erasure requests. When we receive such requests, we will process them within the required timeframe (30 days) and delete all associated personal data from our systems.

12. Third-Party Services

Our Service integrates with Shopify and Fortnox. Your use of these third-party services is subject to their respective privacy policies. We encourage you to review the privacy policies of Shopify and Fortnox.

13. Children's Privacy

Our Service is not directed to children under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new Privacy Policy on our website and, where appropriate, by email. Your continued use of the Service after such changes constitutes acceptance of the updated Privacy Policy.

15. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

Linkbase AB

Email: privacy@linkbase.se

Website: https://linkbase.se

You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) or your local supervisory authority.

Linkbase

Last updated 2026-01-21