

PDF documents use the Inter typeface by The Inter Project Authors (https://github.com/rsms/inter), licensed under the SIL Open Font License 1.1. A Latin, Cyrillic and Greek subset is bundled in assets/fonts/ together with the licence (OFL.txt); tools/build-font.php rebuilds it.
The plugin works without any external service until you switch one on. What follows is every service it can contact, what it sends and when.
Used when you enable Econt: to load its localities and offices, to ask for a delivery price at the checkout, to create, cancel and track a waybill and to download the label. Requests go to https://ee.econt.com/services (or https://demo.econt.com/ee/services with the demo account) with the credentials you enter.
Sent when you use those features: your sender details, the recipient’s name, phone and e-mail, the chosen office or address, the parcel’s weight, count and description, the cash-on-delivery amount and the order number. Nothing is sent for orders delivered by another method.
Service by “Econt Express” OOD: https://www.econt.com/ — terms: https://www.econt.com/za-nas/obshti-uslovia — privacy: https://www.econt.com/politika-za-poveritelnost
Used when you enable Speedy, for the same purposes and with the same kind of data as above. Requests go to https://api.speedy.bg/v1 with the credentials you enter.
Service by “Speedy” AD: https://www.speedy.bg/ — terms: https://www.speedy.bg/bg/terms-and-conditions — privacy: https://www.speedy.bg/bg/gdpr
Used when you enable Pigeon Express, for the same purposes and with the same kind of data as above. Requests go to the API address of the account you enter (its sandbox or its production address).
Service by “Pigeon Express”: https://pigeonexpress.com/ — terms: https://pigeonexpress.com/terms — privacy: https://pigeonexpress.com/privacy
Used when a buyer asks for a company invoice and VAT checking is on (it can be switched off in the settings, and then only the format is checked). The VAT number and its country code are sent to https://ec.europa.eu/taxation_customs/vies/rest-api/check-vat-number, which answers whether the number is registered and, when the country publishes them, the company name and address.
Service by the European Commission: https://ec.europa.eu/taxation_customs/vies/ — legal notice: https://ec.europa.eu/info/legal-notice_en — privacy: https://commission.europa.eu/privacy-policy-websites-managed-european-commission_en
Used when “Invoices for orders in another currency” is on: the euro reference rates are downloaded from https://www.ecb.europa.eu/stats/eurofxref/eurofxref-hist-90d.xml (and the full file when an older rate is needed) to convert an order into euro. No data about your shop, your orders or your buyers is sent.
Service by the European Central Bank: https://www.ecb.europa.eu/stats/policy_and_exchange_rates/euro_reference_exchange_rates/html/index.en.html — disclaimer and copyright: https://www.ecb.europa.eu/services/disclaimer/html/index.en.html — data protection: https://www.ecb.europa.eu/services/data-protection/html/index.en.html
Off by default. It works only after you switch the add-on on and enter your own API key. Before a cash-on-delivery order the buyer’s phone number is sent to https://nepostop.com/api/v1 to ask how many of that phone’s parcels were not collected. If you also switch on reporting, the phone number and the waybill number of your cash-on-delivery shipments are sent after they are created, so their outcome adds to the shared history. Tell your buyers about this check in your privacy policy.
Service by НепоСтоп: https://nepostop.com/ — terms: https://nepostop.com/terms — privacy: https://nepostop.com/gdpr
Off by default. It works only after you switch the “BulCommerce Guard” add-on on. Before a cash-on-delivery order the buyer’s phone number is sent to https://wpsupporting.com/api/wp to ask how many of that phone’s parcels were not collected; the phone is hashed on the server. If auto-reporting is on, the phone, the waybill number and the outcome (delivered / returned) of your cash-on-delivery shipments are sent after they are final, so the shared history stays useful, together with your licence key and your site’s domain to identify the shop. The order screen can also report a customer or erase them from the network on request. Tell your buyers about this check in your privacy policy.
Service by wpsupporting (the makers of BulCommerce): https://wpsupporting.com/
Three more couriers, used in the same way and with the same kind of data as the couriers above, each only after you switch it on and enter your account: euShipments (https://eushipments.com/ — https://api1.inout.bg/api/v1, tests https://test-api.inout.bg/api/v1), BOX NOW (https://boxnow.bg/ — the public locker list at https://locationapi-production.boxnow.bg (tests https://locationapi-stage.boxnow.bg) and the Partner API at https://api-production.boxnow.bg, tests https://api-stage.boxnow.bg) and Sameday (https://sameday.bg/ — https://api.sameday.bg, tests https://sameday-api-bg.demo.zitec.com).
This package contains no licence check and no update server of its own.
Off by default. When you choose to show a courier’s offices on a map, the buyer’s browser loads the map images from https://tile.openstreetmap.org when the map is shown, which sends the buyer’s IP address and browser details to OpenStreetMap. Nothing about the order or the buyer is sent.
Service by the OpenStreetMap Foundation: https://www.openstreetmap.org/ — tile usage policy: https://operations.osmfoundation.org/policies/tiles/ — privacy: https://osmfoundation.org/wiki/Privacy_Policy
Off by default. When it is on, the plugin talks to the ErpNet.FP service at the address you enter, which is normally a computer in your own shop (for example http://localhost:8001). The sale’s items, amounts and payment type are sent so the device can print the receipt. This is your own local network, not a service of ours. ErpNet.FP is free software: https://github.com/erpnet/ErpNet.FP
The plugin makes no other external requests, and it collects no telemetry and no usage data.