Privacy policy · LG Boleta y Factura Chile
Last updated: 9 October 2026
This policy explains which personal data the LG Boleta y Factura Chile app for Shopify (the “app”) processes, why, and for how long. The app issues the electronic receipts (boletas), invoices and credit notes for the store's orders with Chile's tax service (SII), through the e-invoicing provider the merchant connects (for example, OpenFactura), and sends them to customers.
1. Controller and processor
Controller: the merchant (the Shopify store that installs the app), who decides to process its own customers' data and sets the purpose.
Processor: the app developer, which processes the data on the merchant's behalf and only to provide the service:
LÍNEA GRÁFICA ESPECIALISTAS EN COMERCIO ELECTRÓNICO S.L. (Línea Gráfica)
VAT ID: B91794685
C/ Astronomía 1, Torre 1, Planta 10, Módulos 8-11, 41015 Sevilla (España)
Phone: 954 312 200
Email: contacto@lineagrafica.es
App support: soporte@lineagrafica.es
Data protection officer: dpo@lbo-abogados.com
Registry details: Registro Mercantil de Sevilla, folio 208, tomo 5072, sección General, hoja SE-82.558, inscripción 1ª
2. Data the app processes
Customers' details for invoicing
- If they request an invoice: the company's RUT (tax ID), legal name, line of business (giro), address and comuna.
- Email address, to send the document.
- Order number, products, amounts and taxes of the purchase.
Customers give their details on the order thank-you page, in their account or in the store's invoicing portal. If they don't, a receipt (boleta) is issued to an unidentified final consumer. To fill in the invoice, the app may ask the provider for a RUT's public SII details.
Store data
- The merchant's tax details, shown as the issuer of the documents.
- The API key of the merchant's account with its e-invoicing provider. It is stored encrypted (AES-256-GCM) with a key only the server holds; it is never shown and is only used to issue that store's documents.
Shopify permissions
read_ordersandwrite_orders: read orders, cancellations and refunds to issue invoices and credit notes, and note the issued document on the order.read_customersandwrite_customers: read and save the customer's tax details so they aren't asked for on every purchase.read_products: read the products listed on the document.- Customer account permissions: customers view and download their documents from their account.
The app does not use tracking or advertising cookies and does not profile customers.
3. Purpose and legal basis
Data is processed to issue, send and keep the merchant's documents. This is needed for the merchant to meet its tax obligations (the SII's electronic tax documents) and to perform the customer's purchase, under Chile's Privacy Law 19,628 (as amended by Law 21,719) and, as regards the developer, the EU General Data Protection Regulation (art. 6.1.b and c).
4. Storage and security
- Data is stored on servers located in the European Union.
- An issued document is never modified: if it is wrong, it is voided with a credit note and a new one is issued.
- All traffic is encrypted with TLS/HTTPS. Each document's download link carries its own random code.
5. Recipients
- Chile's tax service, the SII, which receives each document (legal obligation).
- The merchant's e-invoicing provider (for example, Haulmer's OpenFactura), which signs the documents with the merchant's folios, sends them to the SII and generates the PDF. The merchant has its own contract with it.
- Shopify, the platform the store runs on.
- The email provider the app uses to send the documents.
Personal data is not sold or shared with third parties, nor used to train AI models.
6. Retention
Receipts are part of the merchant's accounting records and are kept for 6 years. During that period they cannot be deleted, not even at the customer's request or if the store uninstalls the app. After it, they are deleted automatically.
The store's settings and provider API key are deleted when Shopify reports the store's removal (48 hours after uninstalling the app).
7. Your rights
Anyone may exercise their rights of access, rectification, updating and erasure (Law 19,628), as well as restriction and portability. As the merchant is the controller, the main route is to contact the store where the order was placed. The app implements Shopify's compliance webhooks:
customers/data_request: the customer's documents are located so the merchant can provide them. Customers also see them in their account.customers/redact: documents are not deleted while they must be kept; the request is recorded and the customer's email is removed from each document once its period ends.shop/redact: the store's settings and provider API key are deleted; documents are deleted when their retention period ends.
You can also write to soporte@lineagrafica.es or to the data protection officer at dpo@lbo-abogados.com. In Chile, the Personal Data Protection Agency is the supervisory authority under Law 21,719.
8. International transfers
The app is hosted in the European Union, with the safeguards of the General Data Protection Regulation, and documents are sent to the merchant's e-invoicing provider and to the SII in Chile, which is essential to issue them. Shopify may process data in other countries under its own contractual safeguards.
9. Changes to this policy
If the processing changes, this page will be updated along with the date at the top. Previous versions are available on request at the support address.