InvoNorm Privacy Policy

Version 1.2 · Last updated: 31 July 2026 · A German translation is available on request ([email protected]); the English version is authoritative.

Status: the website provisions (technical logs, Cloudflare) are effective now. The app-related provisions take effect for each merchant when that merchant installs InvoNorm; the app has been live on the Shopify App Store since 22 July 2026.

Controller/Processor: Fengjing (Shenzhen) Trading Co., Ltd., Rm 902, Block B, Haijing Court, Haojing Garden, No. 2 Shazui Rd, Futian District, Shenzhen, China · [email protected]

For merchant account data (your company details, login, billing) we act as controller. For personal data contained in your orders (your customers' names, addresses, order details) we act as processor on your behalf under our Data Processing Agreement.

1. What we process and why

DataPurposeLegal basis
Merchant company data (name, address, VAT ID, IBAN, contact)Appears on invoices; account management; billingContract performance (Art. 6(1)(b) GDPR)
Order data incl. customer name, billing/shipping address, email, line items, taxesGenerating legally required invoices; archiving; deliveryContract performance; legal obligation of the merchant (Art. 6(1)(c))
Technical logs (IP, timestamps, app events)Security, abuse prevention, debuggingLegitimate interest (Art. 6(1)(f))
Waitlist email address collected before launch (and store URL/country, if provided)To send a one-time launch announcement, including the early-access benefit we announced; addresses are deleted no later than 90 days after that announcement, or immediately on requestConsent (Art. 6(1)(a))

We do not sell personal data, use it for advertising, or process payment card data (payments are handled by Shopify).

2. Where data is stored

All invoice data and archives are stored exclusively on servers in the European Union. Backups are encrypted (AES-256 at rest, TLS 1.2+ in transit).

3. International access (important notice)

InvoNorm is currently operated by one authorised administrator in China. Production access uses key-based SSH and is limited to security, maintenance and merchant-requested support. We do not operate a support dashboard that routinely exposes customer personal data, and no production personal data is stored in China. Remote administrative access can nevertheless constitute a third-country transfer; it is covered by the EU Standard Contractual Clauses (Module 2) incorporated in our DPA, together with EU data residency, encryption, access restriction and infrastructure access logging.

4. Subprocessors

SubprocessorRoleLocation
Hetzner Online GmbHHosting & storage (Nuremberg, Germany)Germany (EU)
Cloudflare, Inc.DNS, CDN, email routingEU/Global
Shopify International Ltd.Platform, billingEU/Global
Peppol access point partner (when enabled)E-invoice transmissionEU

We will update this list and notify merchants of changes via the app.

5. Retention

Invoice archives are kept on the merchant's documented instruction for the statutory retention period applicable to that merchant — for example 8 years for German invoices, 10 years for French invoices and 7 years for Belgian invoices. A deletion request does not shorten a retention period that still applies; merchants can export the archive from the app and remain responsible for confirming the period required for their circumstances.

Upon app uninstallation, Shopify issues a shop data erasure request (the shop/redact webhook) 48 hours later. We delete the shop's personal data within 30 days of receiving that request, except data we are legally required to retain — principally issued invoice archives, which remain protected for their statutory retention period because tax law obliges their preservation. Technical logs: max. 90 days.

6. No AI or machine-learning training

We do not use merchant data or customer data — including anonymised, aggregated or derived forms of it — to create, develop, train, fine-tune or improve any machine-learning or artificial-intelligence system or model, and we do not make it available to third parties for that purpose. InvoNorm sends your data to no AI service of any kind: the only outbound connections it makes are to Shopify and to the European Commission's VIES service for VAT ID checks. This restates in binding form the obligation in section 9.15 of the Shopify Partner Program Agreement, which permits such use only with Shopify's or the relevant merchant's prior written consent. We have neither sought nor received such consent, and do not intend to.

7. Your rights (and your customers' rights)

Under GDPR: access, rectification, erasure, restriction, portability, objection, and complaint to a supervisory authority. Customer requests should be directed to the merchant (controller); we support merchants in fulfilling them within the statutory timelines (Art. 12(3) GDPR), as required by Art. 28(3)(e).

8. EU representative (Art. 27 GDPR)

As a controller/processor established outside the European Union that offers services to merchants in the Union, we designate a representative in the EU under Art. 27 GDPR where its conditions apply. The representative acts as an additional contact point for supervisory authorities and data subjects on all matters relating to processing. The representative's name and address will be published here and in our DPA as soon as the designation is completed; until then, contact us directly at [email protected].

9. Contact

Privacy inquiries: [email protected] (subject "Privacy"). We respond within 30 days.