Privacy Policy

Last updated: August 2026

This Privacy Policy explains how VAT Validator Pro EU (“the App”) collects, uses, shares, and protects personal information when a merchant installs or uses the App on a Shopify store.

1. About this Policy

The App validates EU and Northern Ireland (XI) VAT numbers for Shopify merchants through the European Commission’s VIES service. It shows verification status on the storefront, writes validation results onto checkout and orders, and — when the merchant turns the setting on — syncs tax-exempt status to the Shopify customer record.

This Policy covers the App and related public pages (including this page). It is not the Terms of Service. Our processing of a merchant’s customer data is also governed by our Data Processing Agreement (see section 3).

We do not sell personal information. We do not use merchant or customer data for advertising, behavioural profiling, or interest-based marketing.

2. Who we are and who this Policy applies to

The App is operated by Tom Wilkinson, a sole trader (Einzelunternehmer) established in Austria. Contact details are in section 17.

We are established in the EEA, so no representative under Art. 27 GDPR is required. Art. 37 GDPR does not require us to appoint a Data Protection Officer for this App, and we have not appointed one; data protection enquiries go to the contact in section 17.

Where the App processes Northern Ireland (XI) VAT numbers or otherwise processes the personal data of individuals in the United Kingdom, the UK GDPR may also apply. References to “the GDPR” in this Policy should be read as including the UK GDPR where it applies.

This Policy applies to personal information we process about:

Shopify is responsible for the Shopify platform, billing, and the merchant’s store.

3. Our role: controller and processor

We act in two roles:

Processor. For customer VAT validation and related store records, the merchant (the Shopify store) is the data controller. We process that information on the merchant’s behalf and on their documented instructions, given by installing the App and configuring settings such as auto tax-exempt. Our obligations in this role are set out in our Data Processing Agreement, which forms part of the Terms of Service and satisfies Art. 28(3) GDPR. If you are a store customer, contact that merchant and read their store privacy policy.

Controller. We are the controller where we decide why and how to process information to operate the App: merchant accounts and sessions, app configuration, subscriptions and usage limits, security and rate limiting, and our own records of Shopify data-subject requests.

4. What data we collect

We collect only what we need to provide the App. We do not collect full street addresses, phone numbers, or payment card details.

A VAT number belonging to a company is not personal data under the GDPR, which protects natural persons (Art. 4(1)). This Policy addresses personal data we do process: for example merchant and staff account details, customer identifiers, and a VAT number that identifies a natural person (such as a sole trader).

Merchant and shop data

Customer and order data

Data-subject request data

Technical data

5. How we collect data

You and the merchant provide most of this data directly. We collect it when:

We also receive data indirectly from:

Providing this data is required to use the App, as follows:

6. How we use data

We use personal information to provide the App and to keep it secure. We do not use it for unrelated marketing.

We use it to:

7. Legal bases

Where we act as controller, we rely on the following bases. The Articles cited in this section are from the EU GDPR (Regulation (EU) 2016/679). See Article 6.

PurposeLegal basisTypical information
Provide the App: install, authenticate, settings, supportPerformance of a contract (Art. 6(1)(b))Merchant, shop, and configuration data
Billing and usage limitsPerformance of a contract (Art. 6(1)(b))Subscription and quota data
Security, rate limiting, and abuse preventionLegitimate interests (Art. 6(1)(f)) — keeping the App secure and usableTechnical data, including IPs held in memory
Respond to Shopify data-subject requests and keep related recordsPerformance of our contract with the merchant (Art. 6(1)(b)). Where the request concerns customer data, we act as processor and assist the merchant under Art. 28(3)(e); we do not determine a separate basis for that data.Data-request records and exports

Where we act as processor, the merchant determines the legal basis for customer VAT data. That is typically the merchant’s legal obligation, or their legitimate interest in applying VAT rules correctly.

We do not rely on consent for the core service. Where consent would apply (it does not today), you could withdraw it at any time without affecting processing already carried out.

8. How we share data

We share personal information only as needed to run the App. We do not sell it or share it for advertising.

Recipients:

We also share personal information when the law requires us to, or to establish, exercise, or defend legal claims.

Changes to sub-processors. The providers above act as our sub-processors for data we process as processor. You authorise them on install. We will give at least 14 days’ notice of any intended addition or replacement of a sub-processor, by email or in-App notice, so you can object on reasonable data-protection grounds. If we cannot resolve a reasonable objection, you may terminate by uninstalling the App.

9. International transfers

The App is operated from Austria (EEA). VIES validation is performed by the European Commission in the EU. The following providers may process personal data outside the EEA/UK, under the transfer mechanisms shown:

ProviderRoleLocationTransfer mechanism
ShopifyPlatform and billingInitial processing via Shopify International Ltd (Ireland); onward to the Shopify group, including CanadaBinding Corporate Rules for EEA/Switzerland intra-group transfers (effective 8 July 2026). For the UK: SCCs between Shopify entities, and where necessary the EU adequacy decision for Canada for transfers to Shopify Inc.
Fly.ioApplication hostingApp machines in Amsterdam (ams), EU; Fly.io, Inc. is established in the United StatesEU-U.S. Data Privacy Framework, and the UK Extension
NeonDatabaseUnited States (Neon Inc.)2021 Standard Contractual Clauses (Commission Decision 2021/914) and the UK International Data Transfer Addendum
ResendEmail deliveryUnited StatesEU-U.S. Data Privacy Framework, and the UK Extension
UpstashCache (short-lived)United States (Upstash Inc.)2021 Standard Contractual Clauses (Commission Decision 2021/914)

For transfers relying on Standard Contractual Clauses, you may request a copy of the relevant clauses using the contact details in section 17. Where a provider is certified under the EU-U.S. Data Privacy Framework, its certification can be verified on the Data Privacy Framework list.

We keep the amount of personal data leaving the EEA to a minimum. Most VAT numbers we handle belong to companies and are not personal data. We run the App in Fly.io’s Amsterdam region as a supplementary measure.

10. How we store data

We store App data on Fly.io (application), Neon (database), and Upstash (short-lived cache). Email notifications go through Resend.

We protect this data with:

Breach notification. If a personal-data breach occurs where we are controller, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it (Art. 33(1)), and affected individuals where the breach is likely to result in a high risk to them (Art. 34). Where we are processor, we notify the affected merchant without undue delay after becoming aware (Art. 33(2)), so they can meet their own obligations.

11. How long we keep data

Before uninstalling, export your records. Merchants who rely on VIES checks to support intra-community VAT treatment may be required by their own tax authority to retain evidence of those checks for several years. Because we delete shop data on uninstall, you should download your VAT audit records from the App (Validations → Export CSV) before you uninstall. We are not able to recover data after deletion.

Copies already delivered outside the App database are retained only as needed to complete the relevant request, then deleted.

12. Marketing

We do not send marketing emails. We do not share personal information with partners for their marketing. We do not use personal information to build advertising audiences or interest profiles.

Service emails (for example, a notice that a data-request export is ready) are not marketing.

13. Cookies and similar technologies

A cookie is a small text file a site stores on your device. We do not use advertising cookies, analytics pixels, or tracking beacons. We do not log how customers browse a merchant’s store beyond the VAT validation request itself.

You can block cookies in your browser. Blocking Shopify session cookies stops the embedded App from staying signed in.

14. Your data protection rights

Subject to the conditions in the GDPR (and, where it applies, the UK GDPR):

Where we rectify, erase or restrict your data, we notify each recipient to whom it has been disclosed, unless that proves impossible or would involve disproportionate effort (Art. 19).

Automated decision-making

We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you (Art. 22). VAT checks are validity look-ups against the EU VIES service. They confirm whether a number is valid; they are not decisions about a person.

US state privacy laws

We do not sell personal information and do not share it for cross-context behavioural advertising, as those terms are used in the CCPA/CPRA and comparable US state laws. An advertising opt-out therefore does not apply to the App.

How to exercise these rights

Store customers. Contact the merchant whose store collected your data. They are the controller and decide how to respond. We assist merchants in meeting these requests as required by Art. 28(3)(e) GDPR, and Shopify additionally routes access and deletion requests to us.

Merchants and staff. Contact us using the details in section 17. Uninstalling the App deletes shop data as described in section 11.

How we respond

We respond without undue delay and within one month of receiving a request (Art. 12(3)). Where a request is complex, or where you send several, we may extend by up to two further months; we will tell you within the first month if we do, and why.

Requests are free. Where a request is manifestly unfounded or excessive, in particular because it is repetitive, we may charge a reasonable fee or decline to act, and will explain why (Art. 12(5)).

If we do not act on a request, we will tell you within one month, with our reasons and with information on complaining to a supervisory authority and seeking a judicial remedy (Art. 12(4)).

Where we have reasonable doubts about who is making a request, we may ask for further information to confirm identity (Art. 12(6)). We ask only for what is necessary and do not retain identity documents after verification. You will not be treated differently, and the App will not be degraded, because you exercised a right.

15. Children’s data

The App is a business tool for Shopify merchants. It is not directed at children and we do not knowingly collect personal information from children. The age of consent for information-society services under Art. 8 GDPR varies by member state (for example, 14 in Austria). If you believe a child has provided personal information through the App, contact us and we will delete it.

16. Changes to this Policy

We keep this Policy under review and publish updates on this page. The “Last updated” date at the top shows when it last changed. For material changes, we give notice through the App or by email where we have a contact address.

17. How to contact us

For questions about this Policy, the data we hold, or to exercise your rights:

Tom Wilkinson
Machstrasse 5, 1020 Wien, Austria
vatvalidatorpro@gmail.com

18. How to contact the supervisory authority

You may lodge a complaint with a supervisory authority, in particular in the EU or UK member state of your habitual residence, place of work, or the place of the alleged infringement (Art. 77). Our lead supervisory authority is:

Österreichische Datenschutzbehörde
Barichgasse 40–42, 1030 Vienna, Austria
dsb@dsb.gv.at · dsb.gv.at

In the United Kingdom, you may instead contact the Information Commissioner’s Office.

You also have the right to an effective judicial remedy (Arts. 78–79) and to compensation for damage suffered (Art. 82 GDPR; §29 DSG, brought before the competent Landesgericht).