1. About this policy
EZ Order Printer — PDF Invoice (“the App”, “we”, “us”) is a Shopify application that generates invoices, packing slips, refund documents and draft-order quotes from a merchant’s existing store data, and optionally delivers them by email.
This policy explains what information the App handles, why it handles it, how long it is kept and what choices are available to the people it concerns. It applies to the App itself, to its theme and admin extensions, and to ezorder.io.
It does not apply to Shopify’s own processing of store data, nor to any other app installed on the same store. Those are governed by their own policies.
2. Who controls what: merchant and app roles
Two different relationships run in parallel, and it matters which one you are in.
- Merchant account data. For information about the merchant and their store — contact address, plan, settings — we act as the data controller. We decide why it is held and for how long.
- Store and buyer data. For order, customer and product records belonging to a merchant’s Shopify store, the merchant is the controller and we act as their data processor. We only process that data on the merchant’s instructions, for the purpose of producing and delivering the documents they asked for.
If you are a shopper and want a copy of, or the deletion of, data held about you, contact the store you purchased from. They can raise the request with us, and Shopify’s compliance webhooks (see Shopify compliance webhooks) forward it to us automatically.
3. Information we handle
Merchant and store account data
When the App is installed, Shopify’s OAuth flow gives us the store’s myshopify domain and an access token. From the Shopify Admin API we then read the store profile we need to configure the App sensibly: store name, primary and custom domains, contact email address and phone number, billing country and address, currency, weight unit, timezone, enabled locales and the store’s Shopify plan.
Store data accessed to build documents
The App requests only the Admin API scopes it needs to render a document. Under those scopes it can read orders and their line items, transactions, refunds and returns; draft orders and payment terms; customer names, email addresses, phone numbers and billing/shipping addresses; product and variant details; fulfillment and location data; store locales and markets; and theme files, so the storefront download button can be installed and removed.
Order data is read on demand, not warehoused. When a document is generated the App fetches the current record from Shopify, renders it, and returns the file. We do not maintain a parallel copy of a store’s order book or customer list.
App configuration you create
Templates, layouts, translated strings, numbering and formatting preferences, email automation rules and email templates, and any files you upload for use in documents — logos, signatures, stamps, background images. Uploaded files are stored in our object storage (see Who else is involved).
Email delivery data
If you send documents by email, we store the sender address or sender domain you asked us to verify, together with its verification status from our email provider, and the DNS records you need to publish. We also write a short-lived delivery log entry — store, order identifier, document type and trigger — used solely to stop a retried webhook from sending the same invoice twice. Those entries delete themselves automatically 24 hours after they are written.
Storefront download requests
If a merchant enables the customer-facing download button, a shopper may be asked to enter the email address on the order before a document is released. That address is checked against the order and used to authorise the download; it is a verification step, not a mailing-list signup.
Technical and diagnostic data
Our servers record ordinary request metadata: IP address, user agent, requested path, response status, timestamps and, when something fails, an error trace. This is what lets us find a broken render, block abuse and keep rate limits honest.
4. Cookies and similar technologies
The embedded admin interface authenticates with short-lived Shopify session tokens, not cookies. That is deliberate: it works in browsers that block third-party cookies, and it means no tracking cookie is set on you while you use the App inside the Shopify admin.
Your browser’s own local storage may hold interface preferences — the last table filter you used, for example. That data never leaves your device.
We do not run advertising pixels, cross-site trackers or third-party analytics beacons in the embedded app or in the storefront extension.
5. Why we handle it
| Purpose | What it involves | Legal basis (UK/EU GDPR) |
|---|---|---|
| Providing the App | Rendering documents, applying templates, delivering email, running the storefront button | Performance of a contract |
| Account administration | Plan level, usage counts against plan limits, billing state via Shopify | Performance of a contract |
| Support | Answering your messages and reproducing reported problems | Legitimate interests |
| Security and abuse prevention | Rate limiting, request logs, webhook signature verification | Legitimate interests |
| Service improvement | Aggregate, non-identifying feature and error statistics | Legitimate interests |
| Product announcements | Occasional email about the App to the merchant contact address | Legitimate interests, with opt-out in every message |
| Legal obligations | Responding to lawful requests and to Shopify’s compliance webhooks | Legal obligation |
We do not use store data for automated decision-making that produces legal or similarly significant effects.
6. Artificial intelligence and model training
We do not use merchant data, order data or buyer personal data to train general-purpose AI or machine-learning models, and we do not make such data available to any third party for that purpose.
Where a feature is assisted by a model — for example, drafting suggested wording for a template — the request is scoped to what that feature needs, is not retained for training by us, and is contractually excluded from training by the provider.
7. How long we keep things
| Data | Retention |
|---|---|
| Generated PDF and image documents | Produced on request and streamed to you; transient working copies are cleared automatically |
| Order, customer and product records | Not stored — read from Shopify at render time |
| Email send log (deduplication) | Deletes itself 24 hours after the send |
| Uploaded template assets | Until you delete them in the App, or until you ask us to remove them |
| Templates and app settings | Kept after uninstall so that reinstalling restores your setup; deleted on request |
| Shopify access token and session | Revoked and cleared immediately on uninstall |
| Verified sender addresses and domains | Until you remove them in the App, or until you ask us to remove them |
| Server and error logs | Up to 30 days |
| Billing and tax records | As required by law, typically up to 7 years |
When you uninstall the App, Shopify notifies us immediately. We revoke the access token on receipt, which ends all further access to your store, and we deactivate the account and cancel any subscription. Your templates and settings are deliberately kept beyond that point, because merchants routinely reinstall and expect their configuration to still be there. To have them erased instead, email us and we will delete them.
8. Who else is involved
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
We rely on a small set of vetted service providers, each bound by a data processing agreement and each given only the data its function requires:
| Provider | Function | Region |
|---|---|---|
| Shopify Inc. | Platform, authentication, billing, store data source | Global |
| Amazon Web Services | Application hosting, object storage for uploaded assets, transactional email delivery | United States |
| Managed database and cache hosting | Settings, templates and job queues | United States |
| Slack Technologies | Internal operational alerting (no buyer personal data) | United States |
We may also disclose information where the law requires it, to establish or defend legal claims, or to protect the rights and safety of our users. If our business is merged, acquired or otherwise transferred, information may pass to the successor entity under this same policy; you will be told before that happens.
Payments. Subscriptions are handled by the Shopify Billing API and charged to your Shopify invoice. We never receive, process or store your card details.
9. International transfers
Our infrastructure is operated in the United States. If you are in the United Kingdom, the European Economic Area or another region with transfer restrictions, your data will be transferred outside that region.
Those transfers are covered by the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, together with technical measures — encryption in transit and at rest, and access limited to named personnel — appropriate to the data involved.
10. How we protect it
- All traffic to and from the App is encrypted with TLS; plain HTTP is redirected.
- Admin requests are authenticated with short-lived, signed Shopify session tokens, verified on every request. Shopify webhooks are rejected unless their HMAC signature validates.
- Stored data is encrypted at rest, and access tokens are held separately from application settings.
- Access to production systems is restricted to the engineers who need it, on the principle of least privilege, and is logged.
- Rate limiting and abuse controls protect the public download endpoints.
- Dependencies are monitored for known vulnerabilities and patched on a regular cadence.
No system is perfectly secure. If we become aware of a breach affecting personal data we will notify affected merchants and the relevant supervisory authority without undue delay, and within 72 hours where the law requires it.
11. Shopify compliance webhooks
Shopify requires every app to answer three mandatory privacy webhooks. The App implements all three, and verifies the signature on each before acting:
customers/data_request— a shopper has asked a merchant for the data an app holds about them. We report back what is held for that store so the merchant can pass it on.customers/redact— a shopper has asked for erasure. Because the App reads order and customer records from Shopify at the moment a document is rendered and does not keep a copy, there is normally no buyer record on our side to erase; anything found is removed.shop/redact— sent 48 hours after a store is closed or the App is uninstalled. We clear the store’s session and revoke its access token, ending all access. Remaining app settings follow the retention schedule above.
12. Your rights
United Kingdom and European Economic Area
You may request access to your personal data; correction of inaccurate data; erasure; restriction of processing; portability in a machine-readable format; and you may object to processing based on legitimate interests. Where processing rests on consent, you may withdraw it at any time without affecting what was done beforehand. You also have the right to complain to your local supervisory authority.
California
You may request to know the categories and specific pieces of personal information collected, the sources, and the purposes; request deletion; request correction; and opt out of sale or sharing — although, as stated above, we do neither. We will not discriminate against you for exercising any of these rights.
Other regions
If your local law grants equivalent rights — for example under Brazil’s LGPD, Canada’s PIPEDA, or Australia’s Privacy Act — we will honour them on the same terms.
To exercise any right, email support@ezorder.io from the address associated with your store. We respond within 30 days and may need to verify your identity first. Shoppers should contact the merchant they bought from, whose request reaches us through the webhooks described in Shopify compliance webhooks.
13. If you are a merchant using the App
Because you are the controller of your store’s data, a few responsibilities stay with you:
- Make sure your own privacy notice tells your customers that invoices and related documents are generated and, if you enable it, emailed by a third-party service.
- Only put information in a template that you are entitled to include in a document sent to that customer.
- Verify a sender address or domain you are entitled to send from, and keep its DNS records current.
- Forward any shopper privacy request to us promptly if Shopify’s webhook has not already done so.
14. Children’s privacy
The App is a business tool for merchants and is not directed at children. We do not knowingly collect personal information from anyone under 16. If we learn that we hold such information without an appropriate basis, we will delete it. If you believe a child’s data has reached us, write to support@ezorder.io and we will act on it.
15. Third-party links
Documents and interfaces produced by the App may contain links you or a merchant configured — a storefront, a support page, a social profile. Following such a link takes you to a site we do not operate and whose privacy practices are its own. Read its policy before providing information there.
16. Changes to this policy
We update this policy when the App changes or the law does. The date at the top always reflects the current version.
Minor clarifications take effect when published. For changes that materially affect how personal data is handled, we will notify merchants by email or through the App at least 14 days before they take effect, so there is time to review them or to uninstall.
17. Contact us
Questions about this policy, or about the data we hold, go to support@ezorder.io. We aim to reply within two business days.
If you are in the EEA or the UK and are not satisfied with our response, you may lodge a complaint with your national data protection authority.