Legal
Privacy Policy
Last updated: May 28, 2026 · MyTimologio (formerly AFM_Filler)
Welcome to MyTimologio, where privacy and efficiency in online transactions are our top priorities. MyTimologio is a Shopify app that validates Greek VAT numbers (Α.Φ.Μ.) through the official AADE/GSIS service, auto-fills invoice details, and stores them on the order so you can issue invoices correctly. This Privacy Policy explains what information we collect, the permissions we request from your store, how we use that information, and how we keep it secure. If you have any questions, please contact us at any time.
Information We Collect
To provide the service, MyTimologio processes the following data:
- VAT numbers (Α.Φ.Μ.) entered by the customer or the merchant in order to perform the validation.
- Business details returned by AADE/GSIS for a valid VAT number — such as company name, activity, address and tax office (Δ.Ο.Υ.) — which are used to fill the invoice fields.
- Order and draft order data needed to attach the invoice details to the correct order.
- Customer profile data when invoice details are saved to a customer, so they can be auto-filled on future orders.
- Store and session data provided through Shopify OAuth (such as your shop domain and access token) required for the app to function.
- Log and usage data such as IP address, browser type, timestamps and referring/exit pages, used for security, troubleshooting and app administration.
Permissions We Request
So that MyTimologio is fully covered and works end-to-end across the storefront, the cart, the checkout and the Shopify Admin, the app requests the following access scopes during installation. We only use each permission for the purpose described below.
Read and write orders so the validated invoice details (VAT number, company name, address, Δ.Ο.Υ.) can be saved onto the order and stay accessible for invoicing, ERP or export.
Read and write draft orders so invoice details can be added to manual, phone and B2B orders created from the Shopify Admin.
Read and write customer profiles so invoice details can be stored on the customer and auto-filled on the customer's next order, without asking for the VAT number again.
Serve the VAT validation form and AADE/GSIS lookup securely through a Shopify App Proxy on your own domain, so the request stays within your storefront.
MyTimologio also registers an orders/create webhook so invoice details submitted at checkout are reliably attached to the new order, and uses direct API access from within the embedded admin to read and write the data above on your behalf.
How We Use the Information
The information is used solely to provide and improve the service: validating VAT numbers through AADE/GSIS, auto-filling and saving invoice details to orders, draft orders and customers, generating commercial documents for internal preview, and enabling export to CSV/PDF. We do not sell your data or the data of your customers, and we do not use it for advertising.
Data Sharing
To validate a VAT number, the 9-digit Α.Φ.Μ. is sent to the official AADE/GSIS service, which returns the corresponding business details. Apart from this validation and the data we write back into your own Shopify store, we do not share personal information with third parties, except where required to operate the service (e.g. our hosting provider) or to comply with the law.
Data Security
Access is controlled through Shopify OAuth, and we implement a variety of technical and organizational measures to keep your information safe when it is entered, submitted, stored or accessed. Communication with Shopify and AADE/GSIS takes place over encrypted connections.
Data Retention & Deletion
We keep data only for as long as needed to provide the service. MyTimologio supports Shopify's mandatory privacy (GDPR) webhooks and responds to them automatically:
- customers/data_request — when a customer asks what data is held, we provide the relevant information to the store owner.
- customers/redact — when a customer requests deletion, their data is removed from our records.
- shop/redact — 48 hours after a store uninstalls the app, the store's data is deleted from our records.
You can also uninstall the app at any time, after which we stop processing your data and delete it in line with the above.
Invoices Disclaimer
The commercial documents produced inside the app are intended for preview and internal use. They are not official tax invoices. To issue legal tax documents, please use your accounting software or your accountant.
Cookies and Log Files
Like many web applications, MyTimologio may use cookies and log files to keep you signed in, improve your experience, and gather general usage statistics for trend analysis and app administration.
Children's Privacy
MyTimologio is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 13 years of age. If you believe a child has provided us with personal information, please contact us so we can remove it.
Third-Party Links
Our app or website may contain links to third-party sites that we do not operate. We are not responsible for the content or privacy practices of those sites, and we encourage you to review their privacy policies.
Changes to This Policy
We may update this Privacy Policy from time to time, for example when we add new features or request additional permissions. Material changes will be reflected by updating the "Last updated" date above.
Consent
By installing or using MyTimologio, you consent to this Privacy Policy and agree to its terms.
Contact
If you have any questions about this Privacy Policy or your data, email us at [email protected].