InvoiceFlow โ Privacy Policy
Last updated: 8 July 2026
Who we are
InvoiceFlow is a Shopify app that automatically generates legally compliant tax invoices (including Factur-X / ZUGFeRD e-invoices) for orders in your store. Contact: andrix.ork@gmail.com.
What personal data we process, and why
For each order in your store we process: order line items, totals and tax amounts, and the customer's name, billing address and email. This data is required solely to render the fields that tax law mandates on invoices (EU VAT invoicing rules; e.g. ยง14 UStG in Germany, Art. 226 of Council Directive 2006/112/EC). The legal basis is the merchant's legal obligation to issue compliant invoices. We do not use this data for marketing, profiling or automated decision-making, we do not sell it, and we do not share it with third parties other than our hosting subprocessors.
Where data is stored
Data is stored in a PostgreSQL database hosted on Railway (EU-West region), encrypted in transit (TLS) and at rest. Access is limited to the app itself and the operator of InvoiceFlow.
Retention and deletion
Generated invoices are retained while the app is installed, so the merchant can re-download them. When a merchant uninstalls InvoiceFlow, all shop data โ invoices, settings and access tokens โ is permanently deleted within 48 hours, triggered by Shopify's shop/redact webhook. Customer data erasure requests (customers/redact) are honoured except where invoice records must be retained under statutory bookkeeping obligations applicable to the merchant; in that case the merchant remains the data controller for the retained records.
Your rights
Merchants and their customers can request access to, correction of, or deletion of personal data by contacting andrix.ork@gmail.com. Data access requests forwarded by Shopify (customers/data_request) are answered within 30 days.