Simple Invoice — Privacy Policy

Last updated: 2 September 2026

Simple Invoice ("the app") generates PDF invoices for Shopify orders on behalf of the merchants who install it. This policy explains what personal data the app processes and why.

What we process, and why

For each order in a merchant's store, the app stores the data needed to produce an invoice, and nothing else:

The app requests only the read_orders Shopify scope. It does not request access to the merchant's customer list (read_customers), does not collect phone numbers, payment details, or browsing data, and does not use tracking or analytics on personal data.

What we do not do

Subprocessors

We use two subprocessors. No others receive personal data.

Subprocessor Purpose Data received Location
Fly.io Application hosting and database storage All data listed above Frankfurt, Germany (fra)
Resend Invoice email delivery — only when the merchant turns on auto-email Recipient email address and the invoice PDF United States

If a merchant leaves auto-email off, no personal data reaches Resend at all. We will give notice before adding or replacing a subprocessor.

Storage and security

Retention and deletion

Customer data requests

When Shopify sends a customer data request (customers/data_request), the merchant — not us — is the data controller and owns the response. We record the request and show it to the merchant in the app, where they can download a JSON export of every invoice we hold for that customer and pass it on. GDPR allows 30 days.

The export is assembled at download time from current records rather than stored as a snapshot, so a redaction that arrives in the meantime is reflected in whatever is handed over. We never keep a second copy of customer data.

Contact

Questions or data requests: contact the developer via the app's support email listed on the Shopify App Store listing.