Last updated: August 2026
This Privacy Policy explains how VAT Validator Pro EU (“the App”) collects, uses, shares, and protects personal information when a merchant installs or uses the App on a Shopify store.
The App validates EU and Northern Ireland (XI) VAT numbers for Shopify merchants through the European Commission’s VIES service. It shows verification status on the storefront, writes validation results onto checkout and orders, and — when the merchant turns the setting on — syncs tax-exempt status to the Shopify customer record.
This Policy covers the App and related public pages (including this page). It is not the Terms of Service. Our processing of a merchant’s customer data is also governed by our Data Processing Agreement (see section 3).
We do not sell personal information. We do not use merchant or customer data for advertising, behavioural profiling, or interest-based marketing.
The App is operated by Tom Wilkinson, a sole trader (Einzelunternehmer) established in Austria. Contact details are in section 17.
We are established in the EEA, so no representative under Art. 27 GDPR is required. Art. 37 GDPR does not require us to appoint a Data Protection Officer for this App, and we have not appointed one; data protection enquiries go to the contact in section 17.
Where the App processes Northern Ireland (XI) VAT numbers or otherwise processes the personal data of individuals in the United Kingdom, the UK GDPR may also apply. References to “the GDPR” in this Policy should be read as including the UK GDPR where it applies.
This Policy applies to personal information we process about:
Shopify is responsible for the Shopify platform, billing, and the merchant’s store.
We act in two roles:
Processor. For customer VAT validation and related store records, the merchant (the Shopify store) is the data controller. We process that information on the merchant’s behalf and on their documented instructions, given by installing the App and configuring settings such as auto tax-exempt. Our obligations in this role are set out in our Data Processing Agreement, which forms part of the Terms of Service and satisfies Art. 28(3) GDPR. If you are a store customer, contact that merchant and read their store privacy policy.
Controller. We are the controller where we decide why and how to process information to operate the App: merchant accounts and sessions, app configuration, subscriptions and usage limits, security and rate limiting, and our own records of Shopify data-subject requests.
We collect only what we need to provide the App. We do not collect full street addresses, phone numbers, or payment card details.
A VAT number belonging to a company is not personal data under the GDPR, which protects natural persons (Art. 4(1)). This Policy addresses personal data we do process: for example merchant and staff account details, customer identifiers, and a VAT number that identifies a natural person (such as a sole trader).
You and the merchant provide most of this data directly. We collect it when:
We also receive data indirectly from:
Providing this data is required to use the App, as follows:
We use personal information to provide the App and to keep it secure. We do not use it for unrelated marketing.
We use it to:
Where we act as controller, we rely on the following bases. The Articles cited in this section are from the EU GDPR (Regulation (EU) 2016/679). See Article 6.
| Purpose | Legal basis | Typical information |
|---|---|---|
| Provide the App: install, authenticate, settings, support | Performance of a contract (Art. 6(1)(b)) | Merchant, shop, and configuration data |
| Billing and usage limits | Performance of a contract (Art. 6(1)(b)) | Subscription and quota data |
| Security, rate limiting, and abuse prevention | Legitimate interests (Art. 6(1)(f)) — keeping the App secure and usable | Technical data, including IPs held in memory |
| Respond to Shopify data-subject requests and keep related records | Performance of our contract with the merchant (Art. 6(1)(b)). Where the request concerns customer data, we act as processor and assist the merchant under Art. 28(3)(e); we do not determine a separate basis for that data. | Data-request records and exports |
Where we act as processor, the merchant determines the legal basis for customer VAT data. That is typically the merchant’s legal obligation, or their legitimate interest in applying VAT rules correctly.
We do not rely on consent for the core service. Where consent would apply (it does not today), you could withdraw it at any time without affecting processing already carried out.
The App is operated from Austria (EEA). VIES validation is performed by the European Commission in the EU. The following providers may process personal data outside the EEA/UK, under the transfer mechanisms shown:
| Provider | Role | Location | Transfer mechanism |
|---|---|---|---|
| Shopify | Platform and billing | Initial processing via Shopify International Ltd (Ireland); onward to the Shopify group, including Canada | Binding Corporate Rules for EEA/Switzerland intra-group transfers (effective 8 July 2026). For the UK: SCCs between Shopify entities, and where necessary the EU adequacy decision for Canada for transfers to Shopify Inc. |
| Fly.io | Application hosting | App machines in Amsterdam (ams), EU; Fly.io, Inc. is established in the United States | EU-U.S. Data Privacy Framework, and the UK Extension |
| Neon | Database | United States (Neon Inc.) | 2021 Standard Contractual Clauses (Commission Decision 2021/914) and the UK International Data Transfer Addendum |
| Resend | Email delivery | United States | EU-U.S. Data Privacy Framework, and the UK Extension |
| Upstash | Cache (short-lived) | United States (Upstash Inc.) | 2021 Standard Contractual Clauses (Commission Decision 2021/914) |
For transfers relying on Standard Contractual Clauses, you may request a copy of the relevant clauses using the contact details in section 17. Where a provider is certified under the EU-U.S. Data Privacy Framework, its certification can be verified on the Data Privacy Framework list.
We keep the amount of personal data leaving the EEA to a minimum. Most VAT numbers we handle belong to companies and are not personal data. We run the App in Fly.io’s Amsterdam region as a supplementary measure.
We store App data on Fly.io (application), Neon (database), and Upstash (short-lived cache). Email notifications go through Resend.
We protect this data with:
Breach notification. If a personal-data breach occurs where we are controller, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it (Art. 33(1)), and affected individuals where the breach is likely to result in a high risk to them (Art. 34). Where we are processor, we notify the affected merchant without undue delay after becoming aware (Art. 33(2)), so they can meet their own obligations.
Before uninstalling, export your records. Merchants who rely on VIES checks to support intra-community VAT treatment may be required by their own tax authority to retain evidence of those checks for several years. Because we delete shop data on uninstall, you should download your VAT audit records from the App (Validations → Export CSV) before you uninstall. We are not able to recover data after deletion.
Copies already delivered outside the App database are retained only as needed to complete the relevant request, then deleted.
We do not send marketing emails. We do not share personal information with partners for their marketing. We do not use personal information to build advertising audiences or interest profiles.
Service emails (for example, a notice that a data-request export is ready) are not marketing.
Subject to the conditions in the GDPR (and, where it applies, the UK GDPR):
Where we rectify, erase or restrict your data, we notify each recipient to whom it has been disclosed, unless that proves impossible or would involve disproportionate effort (Art. 19).
We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you (Art. 22). VAT checks are validity look-ups against the EU VIES service. They confirm whether a number is valid; they are not decisions about a person.
We do not sell personal information and do not share it for cross-context behavioural advertising, as those terms are used in the CCPA/CPRA and comparable US state laws. An advertising opt-out therefore does not apply to the App.
Store customers. Contact the merchant whose store collected your data. They are the controller and decide how to respond. We assist merchants in meeting these requests as required by Art. 28(3)(e) GDPR, and Shopify additionally routes access and deletion requests to us.
Merchants and staff. Contact us using the details in section 17. Uninstalling the App deletes shop data as described in section 11.
We respond without undue delay and within one month of receiving a request (Art. 12(3)). Where a request is complex, or where you send several, we may extend by up to two further months; we will tell you within the first month if we do, and why.
Requests are free. Where a request is manifestly unfounded or excessive, in particular because it is repetitive, we may charge a reasonable fee or decline to act, and will explain why (Art. 12(5)).
If we do not act on a request, we will tell you within one month, with our reasons and with information on complaining to a supervisory authority and seeking a judicial remedy (Art. 12(4)).
Where we have reasonable doubts about who is making a request, we may ask for further information to confirm identity (Art. 12(6)). We ask only for what is necessary and do not retain identity documents after verification. You will not be treated differently, and the App will not be degraded, because you exercised a right.
The App is a business tool for Shopify merchants. It is not directed at children and we do not knowingly collect personal information from children. The age of consent for information-society services under Art. 8 GDPR varies by member state (for example, 14 in Austria). If you believe a child has provided personal information through the App, contact us and we will delete it.
We keep this Policy under review and publish updates on this page. The “Last updated” date at the top shows when it last changed. For material changes, we give notice through the App or by email where we have a contact address.
For questions about this Policy, the data we hold, or to exercise your rights:
Tom Wilkinson
Machstrasse 5, 1020 Wien, Austria
vatvalidatorpro@gmail.com