Privacy Policy
This policy explains what data the app handles, why, where it is kept, and how to have it deleted. It is written for the merchant who installs the app. The English text is the binding one. A German translation is provided for convenience.
1. What the app does
The app makes a booking batch in the DATEV format from your Shopify orders and refunds, one calendar month at a time, for your tax adviser. It makes the file when you or your tax adviser download it, from the orders as Shopify holds them at that moment. The app adds nothing to your storefront or your checkout and changes nothing in your store. If the app is unavailable, your orders, your checkout and Shopify's own reports keep working.
2. Data we store about your store
When you install the app, Shopify gives us:
- your store's
myshopify.comdomain; - an access token that lets the app read your orders and your products, and nothing else. Of your products, the app reads only the product type (section 3);
- the list of permissions you granted.
While you use the app, we store:
- your booking settings: your tax adviser's adviser number (Beraternummer), your client number (Mandantennummer) and the first day of your financial year. Also the length of your account numbers, your chart of accounts (SKR03 or SKR04) and whether you use the small business rule (Kleinunternehmerregelung). Also your accounts for the collective debtor, for Shopify Payments payouts and for Shopify's fees;
- your account mapping: the revenue account and the tax key (BU-Schlüssel) you chose for each tax treatment and rate. On the Pro plan also the cost centre (KOST1) and the revenue accounts you gave a product type, with the product type as your store names it;
- a record of each month you close: the month, when you closed or reopened it, and the currency. It holds the number of orders, refunds and booking records, and the month's totals. It also holds a fingerprint of those figures that shows whether the month changed after you closed it;
- a receipt for each file that goes out: its name, the format version, the part number, the number of booking records, the totals and the size. It also holds the character set, the plan you were on, the time and a SHA-256 checksum of the file. The file itself is not stored;
- a history of each month: when it was closed, reopened and exported, and when a link for your tax adviser was made, withdrawn or opened. Each entry holds the plan you were on and one line of facts, such as a file name, a checksum, counts or an expiry date. It does not record which member of your staff did it: no staff user number, no name and no email address;
- for each link you make for your tax adviser (section 3): the month, a checksum of its secret, and when it was made and expires. Also whether you withdrew it, when it was last opened and how often. The link itself is not stored;
- the identifiers of the notices Shopify sends us, so each is handled once;
- the email address Shopify holds for your store, so we can send you the notices in section 12. That is the store owner's address, or the store's public contact address when Shopify gives us no owner address. The app reads it when a staff member opens the app, at most once a week, and stores it with the date it was read. We use it for nothing else. It is never shown in the app and never written to a log;
- for each notice we give your store, the record that it was shown to you and, where it applies, that it was emailed, with the times.
None of these records names or describes one of your customers or one of their orders.
Shopify tells the app which language your admin is set to every time a page loads, so the app can show itself in German or English. We do not store it.
If you write to our support address, we store your message, the address you wrote from and any name you give us, so we can answer you and follow up later.
Our servers also keep technical logs of requests for 30 days. For a request to the app it writes one line. It holds the time, the method, the address requested without anything after a question mark, the status and the duration. It also holds a short tag that stands for your store, computed with a key, in place of the store's web address. Where the app's other lines name your store, they hold that tag too. They also hold other fields, such as the month, counts, file sizes, checksums and your plan. The app's logger refuses a field that holds a name, an address, a customer number or a staff user number. Lines that Node or React Router write by themselves are kept as they are written, outside that rule.
We do not store the record that Google's hosting platform makes of each request. That record is the only place the network address of the browser or server making the request would be written. Google processes the network address to deliver each request and keeps its own record of that under its own terms. We do not receive it.
3. Data we read but do not keep
When a file is made, the app reads from Shopify the orders and refunds of that month. Of each order it reads its identifier and its order number (such as #1001), when it was processed and cancelled, and its payment and fulfilment status. It also reads its currency, whether its prices include tax, and its totals, tax lines and shipping charges. Of each line of goods and each shipping charge it reads the amount, the discounts and the tax lines. Of each fulfilment it reads only its status and the day it was made, because a booking must carry the day the goods were supplied. Of each refund it reads what was refunded, the tax on it and the day. On the Pro plan the app may also read the product type of each order line. It does so when you have given a product type its own cost centre or account, and reads nothing else about your products. It also reads your store's time zone and, when a link for your tax adviser is opened, which plan your store is on.
The app asks Shopify for your Shopify Payments payouts too: their dates, status, net amounts, fees and totals, and nothing that names a person. Shopify gives payouts only to an app that holds the permission to read them. The app does not ask for that permission today, so Shopify refuses the request and no payout is read or booked.
The app does not ask Shopify for your customers' names, addresses, email addresses, phone numbers or VAT IDs, and does not read them. It does not read Shopify's customer records, the notes or tags on an order, or the additional details a buyer or your theme adds to an order. A check in the app's code refuses a query that would ask for a customer's details before it can reach your store.
For each booking record, the file holds the amount, debit or credit, the accounts, the tax key, the date and the order number. It also holds a short booking text such as "Bestellung #1001", and on the Pro plan the cost centre. It holds no name, no address, no email address and no VAT ID of your customers. The file is sent to the browser that asked for it and is not written to a database, a file store, a cache or a log. We keep no copy.
The link for your tax adviser. On the Pro plan you can make a link to one closed month and send it to your tax adviser. Your tax adviser can then download that month's file without a Shopify login. The link carries a secret. We show it to you once and store only a checksum of it, and our technical logs never contain it. Whoever opens a working link gets the file. When the link is opened, the app makes the file again from your store and hands it out only when it is identical to the file you downloaded. We record when the link was last opened and how often. We do not record who opened it: no network address, no browser details and no name. A link stops working 30 days after you make it. It stops earlier when the month can no longer be read from Shopify, because the app reads orders of the last 60 days. It also stops when you withdraw it, when you reopen the month and when you uninstall the app. While your store is below the Pro plan, no link works. If a link is opened in that time, or a month's page is viewed in the app, every link of your store stops working for good.
The app asks Shopify for an offline access token only. We do not receive the name or the email address of the staff member who installs the app or opens it. The one address we do read is the one Shopify holds for the store itself, described in section 2.
The app sets no cookies of its own and uses no analytics or advertising trackers.
4. Our role
For the data we hold about your store and your account, we decide why and how it is used, so we are the controller of it. The order identifiers and order numbers the app reads to make your file, and writes into it, can relate to your customers. For those we act on your instructions as your processor under Article 28 of the GDPR. The Data Processing Agreement that governs this is part of our Terms of Service. If your business needs a signed copy of the Data Processing Agreement, write to support@larchline.co and we send one.
When you send a link to your tax adviser, you decide who receives your file. We hand the file to whoever opens the link, on your instruction, and to no one else. Your tax adviser receives it from you. Your tax adviser is not our sub-processor, and we do not give your data to anyone for their own purposes.
5. Why we use this data
- To make the files you ask for: reading the month's orders and refunds and applying your settings and your mapping. We also keep the record of each closed month and each file, so you and your tax adviser can prove which file went out. This is necessary to perform our contract with you (Article 6(1)(b) GDPR).
- To show you the history of each month and to run the link for your tax adviser on the Pro plan. This is part of the same contract (Article 6(1)(b)).
- To tell you about a change to this policy, our terms, our sub-processors or our prices. We also tell you if we shut the service down, if the app passes to another company, or if there is a security problem. We give these notices in the app and by email, as section 12 says. This is part of the same contract (Article 6(1)(b)).
- To help you: answering your support requests and finding the cause of a problem. This is part of the contract. If you are not yet a customer, it is our legitimate interest in answering you (Article 6(1)(f)).
- To keep the app secure and reliable: logs, error tracking and the detection of misuse. Our legitimate interest is a service that works and is not misused (Article 6(1)(f)).
- To meet legal duties, such as answering a public authority (Article 6(1)(c)). Answering a privacy notice from Shopify is part of the contract.
You do not have to give us your booking settings, but without them the app cannot make a file your tax adviser can import. For the order numbers in your file, you decide the purpose and the legal basis, and we act on your instructions (section 4).
We never sell your data and we never use it for advertising.
6. Where the data is kept
The app runs on Google Cloud servers in Belgium (region europe-west1), and its database and technical logs are stored there. Encrypted backups of the database are kept by Google Cloud in the European Union. So the data the app holds is stored in the European Union. Support email is handled on Microsoft 365.
Shopify holds your store's data, including your orders and your customers, under its own privacy policy. When a file is made, Shopify sends the app the order data that file needs, over an encrypted connection.
We are a United States company. The two people who run the app work from the United States. They can reach the database for support and maintenance, and it holds no data about your customers. They build and run the app with Claude, an AI tool made by Anthropic PBC in the United States. A written rule binds that work: the tool never reads your settings, your customers' data or your emails to us. It works only through the operators' own Google sign-in, not an account of its own. Technical messages it works with can still show your store's web address. If you write to us, a person reads your message in the United States.
Resend sends the notice emails described in section 12. It receives the address Shopify holds for your store and the text of the notice. That text holds nothing about your customers. Resend stores the email and the record of its delivery in the United States and keeps them for 30 days.
Google, Microsoft and Resend are on the Data Privacy Framework list for transfers from the European Union to the United States. Resend's data processing terms also state that the standard contractual clauses the European Commission has approved apply to such transfers. Where that framework does not cover a transfer, we rely on the standard contractual clauses the European Commission has approved, which are part of our contracts with them. For the data we handle as your processor, the same clauses are part of our Data Processing Agreement with you.
Companies that process data for us:
| Company | Purpose |
|---|---|
| Google LLC (Google Cloud) | Hosting, database, backups and technical logs, Belgium and the European Union |
| Microsoft Corporation (Microsoft 365) | Support email |
| Resend (Plus Five Five, Inc.) | Sending the notices in section 12, United States |
Shopify is not on this list. It is the platform your store runs on, you have your own agreement with it, and the app receives order data from it when a file is made. Your tax adviser is not on this list either (section 4).
7. How long we keep it
- Your booking settings, your mapping, the records of your closed months, the receipts of your files and the history: for as long as the app is installed. The same goes for the access token. When you reopen a month, the receipts of that month's files are deleted; the history keeps each file's name and checksum.
- The records of the links for your tax adviser: for as long as the app is installed. A link stops working earlier, as section 3 says.
- When you uninstall the app: the access token, the email address Shopify holds for your store and every link for your tax adviser are deleted at once. Everything else we hold about the store is deleted when Shopify sends us the removal notice, 48 hours after you uninstall. The one exception is the record in the next point. Write to us if you want it deleted sooner.
- The record that a Shopify notice was handled (your store's web address, the kind of notice and its date): at the earliest 23 days after it arrives. In any case within 30 days of its arrival. The last one is deleted within 30 days after you uninstall.
- The record that a notice from us (section 12) was shown to your store and emailed to it: while the app is installed. It is deleted with the rest of the store's data when Shopify sends us the removal notice. We keep it so you can see that you were told.
- The notice emails at Resend, with the records of their delivery: 30 days.
- Deleted data can remain in the encrypted database backups for up to 8 days, until those backups are replaced.
- Technical logs: 30 days.
- Support emails: up to 24 months, so we can follow up on earlier requests.
- The files themselves: we keep no copy. The files you and your tax adviser download are yours, and you keep them for as long as the law of your country requires.
8. Your rights
If you are in the European Union, the European Economic Area, the United Kingdom or Switzerland, you can ask us at any time to:
- see the data we hold about your store;
- correct it;
- delete it;
- limit how we use it while a question about it is open;
- receive it in a portable format.
Your right to object. You can object at any time to a use based on our legitimate interest (section 5). We then stop, unless we have compelling reasons that override yours.
The app makes no decisions about people by automated means.
Write to support@larchline.co. We answer within one month. If a request is complex, we may take two more months, and we tell you why within the first month. You can also complain to a data protection authority, in particular where you live or work or where you think the problem happened. In Germany that is the data protection authority of your federal state. In Austria it is the Datenschutzbehörde. In Switzerland it is the Federal Data Protection and Information Commissioner (FDPIC).
If you are a customer of a shop that uses the app, the shop decides how its order data is used. Write to the shop first. You can also write to us at support@larchline.co. We pass your request to the shop and help it answer you.
9. Requests that come through Shopify
Shopify sends apps three kinds of privacy notices. This is how the app answers them:
- Customer data request: the app stores nothing about any of your customers and nothing about any single order, so it has nothing to report. We keep only the record that the notice was handled (section 7).
- Customer data deletion: for the same reason there is nothing to delete. The files you have already downloaded are yours and are not in our hands.
- Store data deletion: we delete everything we hold about the store. That is the booking settings, the mapping, the cost centres and accounts per product type, the records of closed months, the receipts of files and the history. It is also the links for your tax adviser, our notices and the records of them, the email address Shopify holds for your store and the access token. One record that the deletion happened stays: your store's web address, the kind of notice and its date, so the same notice is not processed twice. We delete it at the earliest 23 days after it arrives, and in any case within 30 days after you uninstall.
10. Security
The app's own keys and the database password are kept in a secrets manager, never in code. Each store's access token is kept in the app's database, which is encrypted. Data travels encrypted, and the database and its backups are encrypted at rest. The database holds no data about your customers, so no copy of it does either. The secret of a link for your tax adviser is never stored, only its checksum. Only the app and the two people who run it can reach the database. The people sign in through Google, with two-factor authentication. The AI tool they work with is barred by the written rule in section 6 from opening it. If a security problem affects personal data we handle, we tell you without undue delay, and at the latest within 48 hours of becoming aware of it.
11. Children
The app is a tool for merchants and is not directed at children.
12. Changes to this policy
When we change this policy, we post the new version with its date. For a change that affects your rights, we tell you before it takes effect. Before we use data for a new purpose, we tell you first.
How we tell you. Where this policy says we tell you something, you get the same notice in two places. The app shows it on every page until you mark it read. It stops showing 30 days after the change takes effect, or 60 days after we post it when it names no date. We also send it by email to the address Shopify holds for your store, when Shopify gives us one (section 2). The sender is noreply@larchline.co, and you can reply to support@larchline.co. These emails are about the app and this policy only. We never use them for advertising.
13. Contact
Scena Labs LLC 522 W Riverside Ave, Ste N Spokane, WA 99201 United States support@larchline.co