Privacy Policy
This policy explains what data the App collects from a Shopify store that installs it, why it collects it, who it is shared with, and how long it is kept. The App generates GST-compliant tax invoices and credit notes for Indian merchants; every category of data below is collected for that purpose and no other.
1. Who we are
The App is published by Shivani Bhadauria, a sole proprietor trading as Esby, based in India. For the data described in this policy we act as a data processor on behalf of the merchant who installs the App; the merchant remains the controller of their own customers’ data.
Contact: support@esby.app
2. What the App collects
2.1 Store and merchant data
- Your
.myshopify.comstore domain and installation status. - Your GST registration details, which you enter yourself: GSTIN, legal business name, registered address, and the derived state code.
- Optional invoice branding you provide: logo image, accent colour, invoice notes or terms, contact phone, contact email, and website.
- Tax configuration: whether storefront prices include GST, per-product HSN codes and GST rates, and your invoice number series.
- Your subscription plan.
2.2 Shopify authentication data
Shopify issues the App an access token so it can read the orders needed to build invoices. Alongside it we store the session record Shopify provides, which may include the store user’s ID, first and last name, email address, locale, and whether they are the account owner.
2.3 Order and customer data
When an order is paid, or a refund is created, Shopify sends the App a webhook. From it we store:
- The order identifier and order number, the refund identifier for credit notes.
- The buyer’s name, email address, and GSTIN where supplied, plus the place of supply.
- Line items, taxable value, the CGST / SGST / IGST / cess breakdown, and the invoice total.
- The raw webhook payload for the order, sent to us by Shopify. We keep it so invoice generation can be retried if it fails, and so an invoice can be recalculated if you later correct the buyer’s GSTIN or reassign it to a different GST registration. It can contain the customer’s phone number and billing or shipping address. It is retained for as long as the invoice it belongs to, and is deleted with everything else 48 hours after you uninstall the App. It is also scrubbed immediately on a customer erasure request, regardless of that period.
2.4 Generated documents
The App stores the invoice and credit note PDFs it renders. These contain the merchant and buyer details listed above, as tax law requires.
3. What we do not do
- We do not sell or rent any data.
- We do not use your data or your customers’ data for advertising.
- We do not use it to train machine-learning models, and we do not share it with data brokers.
- We do not run third-party analytics, advertising, or tracking scripts inside the App.
4. How the data is used
- To calculate GST and generate numbered invoices and credit notes.
- To email the invoice or credit note, with its PDF attached, to the buyer’s email address from the order.
- To produce the reports and exports you request, such as GSTR-1 spreadsheets, Tally XML, and bulk PDF downloads.
- To show you the status of invoice generation and to retry failed jobs.
5. Service providers
The App relies on a small number of processors. Each receives only what it needs to perform its function, and none is permitted to use the data for its own purposes.
| Provider | Purpose | Data involved |
|---|---|---|
| Shopify | Source of order data; hosts the embedded app | Orders, refunds, products, session |
| Render | Application hosting | All data in transit through the App |
| Neon | PostgreSQL database | All stored data described above |
| Resend | Sending invoice email | Buyer name, buyer email, invoice PDF |
These providers operate servers outside India, including in the United States, so data covered by this policy may be transferred and processed outside India.
6. How long we keep it
A tax invoice is a statutory record. Section 36 of the CGST Act, 2017 requires the records underlying it to be retained for approximately six years. The App is built around that obligation:
- Customer erasure request. On Shopify’s
customers/redactrequest we anonymise the buyer’s name and delete the buyer’s email from the affected invoices and credit notes, and we scrub the stored raw order payload, which removes the phone number and address. The tax figures, invoice number, GSTIN and place of supply are preserved, because deleting them would destroy a record we are legally required to keep. - Uninstall. Shopify sends a
shop/redactrequest 48 hours after the App is uninstalled. At that point we permanently delete everything belonging to the store — settings, GST profiles, invoices, credit notes, stored PDFs, processing jobs, and sessions. - Raw webhook payloads are working data, not records, and are scrubbed on a redaction request regardless of the invoice retention period.
7. Data requests and your rights
If you are a shopper, the merchant you bought from is the controller of your data. Send your access or deletion request to that merchant; Shopify forwards it to us automatically and the App responds as described in section 6.
If you are a merchant, you can export your invoice data at any time from inside the App, and uninstalling triggers the deletion described above. For anything else, including access, correction, or deletion requests, write to support@esby.app. We aim to respond within 30 days.
8. Security
- All traffic to the App is served over HTTPS.
- Every incoming Shopify webhook is HMAC-verified before it is accepted.
- Credentials and API keys are held in server-side environment variables, never in the codebase or the browser.
- The database is not publicly reachable and requires TLS.
No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your data we will notify affected merchants without undue delay.
9. Children
The App is a business tool sold to merchants. It is not directed at children and we do not knowingly collect data from them.
10. Changes to this policy
We may update this policy as the App changes. The effective date at the top reflects the current version, and material changes will be communicated to installed merchants.
11. Contact
Shivani Bhadauria, sole proprietor trading as Esby — India
support@esby.app