Privacy Policy
Last updated: 2026-08-30
Smart Invoices is a Shopify app that generates legally required VAT invoices from paid orders, stores them, and delivers them to the merchant, their accountant and, if enabled, the buyer.
This policy explains what personal data the app processes, why, and how long it is kept. It is written to be read, not to be skimmed past.
Our role
For data about a store's customers, the merchant is the data controller and we act as a data processor on their instructions. The merchant decides which documents are issued and to whom they are sent.
For the merchant's own account data (store domain, company details, recipient email addresses) we act as the controller.
Data we receive
From Shopify, with the merchant's authorisation, for each paid order:
- Order number, date, currency, line items, quantities, prices, taxes, discounts, payment and shipping method
- Buyer's name and address; company name, company registration number and VAT number where the buyer is a business
- Buyer's email address, used only to identify the buyer on the document where the merchant has enabled it
- The order token, used to build the buyer's own invoice download link
We do not request the buyer's phone number. We do not use tracking cookies, advertising identifiers or analytics profiling inside the app.
From the merchant: store domain, access token, company details shown on invoices, and the email addresses the monthly archive is sent to.
Why we process it
To produce invoices, credit notes and related documents that contain the details required by law, and to deliver them to the merchant, their accountant and the buyer.
Data is not sold, not shared with advertising partners, not used for marketing, and not used for automated decision-making or profiling.
Legal basis
- Performance of a contract (GDPR Art. 6(1)(b)) — providing the service the merchant subscribed to
- Compliance with a legal obligation (GDPR Art. 6(1)(c)) — invoicing and VAT rules require these documents to exist and to be retained
Deletion requests
When a buyer asks to be forgotten, Shopify sends us a redaction request and we act on it immediately. What happens is not a full erasure, and it is important to say so plainly:
- Deleted: the raw order data held in our processing queue, the buyer's email address, the delivery address and name, the order note, and any public download links
- Kept: the invoice itself — buyer name and address, company and VAT numbers, amounts and the PDF
The invoice is kept because retaining it is a legal obligation, and the right to erasure does not apply where processing is necessary to comply with one (GDPR Art. 17(3)(b)). Removing those fields would stop the document being a valid invoice.
Your rights
Buyers in the EU/EEA and the UK have the right to access, rectify, restrict, port and object, and the right to erasure subject to the limitation described above. California residents have equivalent rights under the CCPA/CPRA; we do not sell or share personal information.
Because we act as a processor for customer data, please send requests to the store you purchased from. If you contact us directly, we will forward the request to that merchant.
You also have the right to lodge a complaint with your local supervisory authority.
Sub-processors
- Shopify — the source of order data and the platform the app runs on
- Our hosting provider — the server where the database and generated PDF files are stored, located in the European Union
- Our email provider — used to send monthly archives and notifications to the addresses the merchant configured
We do not transfer personal data outside the EU/EEA other than to Shopify, which provides its own transfer safeguards.
Security
Data is encrypted in transit (TLS). The database and the generated files sit on a private server with key-based SSH access only, and access is limited to a single operator.
Each store's data is isolated: every query and every stored file is scoped to the store it belongs to.
Changes to this policy
If we change how data is processed, this page is updated and the date above changes. Material changes are also announced inside the app.
How long we keep invoices
Invoices are accounting documents, and how long they must be kept is set by the law of the merchant's country — not by us. There is no single number: it ranges from five to ten years across the markets we support.
Each merchant sets the period in the app; the values below are the defaults we apply per country. They are a starting point to confirm with an accountant, not legal advice.
Everything that is not an accounting document is kept only as long as it is needed: raw order data in the processing queue is removed once the invoice is created, and all data for a store is deleted within 48 hours of the app being uninstalled and Shopify requesting its removal. We warn the merchant by email before that happens so they can download their archive.
| Country | Default retention |
|---|---|
| Australia (AU) | 5 years |
| Austria (AT) | 7 years |
| Belgium (BE) | 10 years |
| Bulgaria (BG) | 10 years |
| Canada (CA) | 6 years |
| Croatia (HR) | 11 years |
| Cyprus (CY) | 6 years |
| Czechia (CZ) | 10 years |
| Denmark (DK) | 5 years |
| Estonia (EE) | 7 years |
| Finland (FI) | 6 years |
| France (FR) | 10 years |
| Germany (DE) | 10 years |
| Greece (GR) | 5 years |
| Hungary (HU) | 8 years |
| Iceland (IS) | 7 years |
| Ireland (IE) | 6 years |
| Italy (IT) | 10 years |
| Japan (JP) | 7 years |
| Latvia (LV) | 5 years |
| Lithuania (LT) | 10 years |
| Luxembourg (LU) | 10 years |
| Malta (MT) | 9 years |
| Netherlands (NL) | 7 years |
| New Zealand (NZ) | 7 years |
| Norway (NO) | 5 years |
| Poland (PL) | 5 years |
| Portugal (PT) | 10 years |
| Romania (RO) | 10 years |
| Slovakia (SK) | 10 years |
| Slovenia (SI) | 10 years |
| Spain (ES) | 6 years |
| Sweden (SE) | 7 years |
| Switzerland (CH) | 10 years |
| United Kingdom (GB) | 6 years |
| United States (US) | 7 years |
How to contact us
Siuzanos Bagdasarian IDV
Jonažolių g. 3, LT-0434Vilnius, Lietuva
support@druge-apps.com