Privacy policy
Two platforms, two very different data stories. Arrears runs on servers Dortus operates. The Confluence apps run inside your own Atlassian site. Both are described below.
1. Who we are
Dortus ("we", "us") is an independent software vendor. We publish Arrears for Shopify, and AskSpace and Mermaid Live Preview for Atlassian Confluence.
Contact for privacy questions and data requests: dortus.support@gmail.com
2. Our role
For business data inside our apps, you are the controller and Dortus is the processor. You decide which companies, contacts, questions, or pages exist. We process that data only to deliver the features you switched on.
For your own contact with us (support email, billing questions), Dortus is the controller of that correspondence.
Short version. Arrears stores merchant and B2B contact data on Dortus-operated infrastructure in the EU, because a collections desk needs a database. The Confluence apps store nothing on Dortus servers at all.
3. Arrears for Shopify
3.1 What the app does
Arrears is an embedded Shopify app for business-to-business collections. It reads your companies, company locations, contacts, orders, and payment terms through the Shopify Admin API, and turns them into aging views, statements, reminders, payment allocations, and credit holds.
3.2 Where it runs
Unlike our Confluence apps, Arrears needs a server. We host it on Fly.io in the Amsterdam region (EU), with the application database on a persistent volume attached to that machine. Access to the production environment is limited to Dortus.
3.3 What data Arrears processes and stores
- Your shop domain and the Shopify access token issued during install
- Company names, company locations, and payment terms as configured in Shopify
- Company contact names and email addresses, used to address statements and reminders
- Order references, amounts, currencies, due dates, and payment schedule status
- Reminder records: recipient address, subject, message body, send time, and result
- Payment records you enter, including allocation across open invoices
- Credit limits, hold and release events, and the staff action behind them
- App settings, such as sender name, dunning policy, and automation switches
Arrears does not ask for or store payment card details. Subscription charges are handled by Shopify billing.
3.4 Protected customer data
Business contact data (company contact names and email addresses) is used only to produce and send the statements and reminders you request, and to show you who was contacted. We do not use it for our own marketing, we do not sell it, and we do not share it with anyone outside the subprocessors listed in section 5.
3.5 Email sending
Statement and reminder emails are delivered through Resend. That means the recipient address, subject, and message body pass through Resend in order to be delivered, along with normal delivery metadata.
3.6 Shopify data requests and deletion
Arrears implements Shopify's mandatory compliance webhooks:
- customers/data_request: we respond to the merchant with the data we hold for the requested person.
- customers/redact: we delete or anonymise the stored personal data for that person.
- shop/redact: we delete the shop's stored data after Shopify's redaction window.
Uninstalling the app also revokes our access: the stored session for your shop is removed when we receive the app/uninstalled webhook.
4. AskSpace and Mermaid Live Preview for Confluence
4.1 Where the data lives
Both apps are built on Atlassian Forge and run entirely inside Atlassian's cloud. Their data is kept in Forge app storage in your Atlassian site. We do not operate an application server for these apps, and app content is not sent to Dortus.
AskSpace is built for Atlassian's "Runs on Atlassian" programme: there is no required data egress to Dortus for normal use of the app.
4.2 What AskSpace processes
- Question and answer text people enter
- Votes and best-answer marks
- Space settings, for example who may ask and who may answer
- Atlassian account identifiers, needed to show authors and enforce permissions
- Display names and avatar URLs provided by Atlassian APIs, so authors can be shown
- In-app notification records, for example that someone answered your question
4.3 What Mermaid Live Preview processes
- The diagram source you type in the macro
- Earlier versions of that source, kept so you can step back after a bad edit
Rendering happens in the browser and in the Forge environment. Diagram content is not sent to Dortus and is not sent to any third party for rendering.
4.4 Billing
Marketplace billing is handled by Atlassian. We never see card details.
5. Subprocessors
- Shopify Inc.: platform, app hosting surface, and billing for Arrears.
- Fly.io: application hosting and database storage for Arrears, EU (Amsterdam) region.
- Resend: delivery of statement and reminder email from Arrears.
- Atlassian Pty Ltd: platform, Forge runtime, storage, and billing for AskSpace and Mermaid Live Preview.
We do not use advertising networks, session recording, or third-party analytics inside our apps.
6. This website
This site is a static set of pages. We do not set tracking cookies and we run no analytics script. Fonts are loaded from Google Fonts, which means your browser requests font files from Google servers and Google receives your IP address as part of that request.
The product walkthrough on the Arrears page is a YouTube embed served from youtube.com. It loads only when you open that page, and playing it means YouTube receives your IP address and player data under Google's own terms.
7. Why we process data
Only to provide the features you enable: showing aging, producing statements, sending the reminders you approve, allocating payments, applying credit holds, storing and displaying questions and answers, and rendering diagrams. Our legal basis is the performance of our agreement with you, and our legitimate interest in keeping the service running securely.
8. Retention
- Arrears: data is kept while the app is installed. It is deleted on shop redaction, and on request. Reminder history is kept so you can prove what was sent, until the shop data is deleted.
- Confluence apps: content stays in Forge storage for your site. Uninstall and deletion follow Atlassian's platform rules for app storage.
- Support email: kept only as long as needed to help you and to keep a record of the issue.
9. Security
Traffic to Arrears is served over HTTPS only. Platform credentials and API keys are held as environment secrets, not in source code. Access to production is limited to Dortus. We are a small vendor and we do not claim certifications we do not have: if you need a security review or a data processing agreement, email us and we will answer concretely.
10. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete personal data.
- For data inside Confluence or Forge, start with your Atlassian site administrator.
- For data inside Arrears, start with the merchant that installed the app, or contact us directly.
You can always email dortus.support@gmail.com and we will answer within one business day.
11. International transfers
Arrears is hosted in the EU. Some subprocessors listed in section 5 are established outside the EU and may process limited data there under their own transfer mechanisms.
12. Children
Our apps are intended for workplace use, not for children.
13. Changes
We may update this policy. The "last updated" date at the top of the page changes when we do, and material changes will be noted in the app release notes.
14. Contact
Dortus
dortus.support@gmail.com
Home · Support ·
Terms of service