Privacy Policy
Last updated: July 2026
1. Introduction
VAT Validator Pro EU (“we”, “our”, or “the App”) is committed to protecting the privacy of merchants and their customers. This Privacy Policy describes what data we collect, how we use it, and your rights.
The App is operated by Tom Wilkinson, a sole trader based in Austria (“we”). For personal data processed through the App, the merchant (the Shopify store) is the data controller and we act as a data processor on the merchant’s behalf, except where we determine the purposes of processing (e.g. billing and service operation), in which case we are the controller.
2. Data We Collect
- Merchant data: Shopify shop domain; session tokens and related Session staff fields (Shopify user ID, name, email, account-owner and collaborator flags, locale, email-verified status, OAuth scope, and expiry); app configuration settings (badge text, badge colour, enabled status, merchant VAT number (“merchantVatNumber”), and auto tax-exempt (“autoTaxExempt”)); and subscription/quota rows (plan, status, monthly limit, validation counts, and period reset times).
- Customer data: EU VAT numbers submitted through the storefront widget, the associated company name, the validation result, and related Shopify customer and order identifiers. We read ship-to and bill-to country codes (not full street address) for intra-community VAT checks. We also store a one-way hash of the customer email on some order VAT records so guest-checkout redaction and export can find matching rows without retaining the raw email. On Shopify we write
_vat_* cart attributes, $app checkout metafields, and order note_attributes snapshots so validation results travel with the checkout and order. We use this to show verification status, record VIES results, and (when the merchant enables auto tax-exempt) sync tax-exempt status to the Shopify customer. - Data-subject request data: When Shopify sends a customer data request or redaction request on a customer’s behalf, the notification includes the customer’s Shopify ID and email address. We temporarily store the email and a generated export snapshot so we can fulfil the request. Those fields are cleared when the export is delivered (operator email succeeds) or when the merchant downloads the export in the App. Remaining request metadata (shop, customer ID, timestamps, status) is deleted on uninstall, shop redact, or customer redact.
- Usage data: Aggregate validation counts per shop for billing purposes. We do not use customer data for advertising or behavioural profiling.
- Technical / operational data: short-lived Redis cache entries for recent VIES results (valid ~5 minutes, invalid ~1 minute) and circuit-breaker state; request IP addresses used only for in-memory rate limiting of the storefront validation proxy (not persisted to the database); and VAT audit log rows (validation outcomes, order reconciliation events) retained while the app is installed and deleted on uninstall / customer or shop redact.
- International transfers: the App is operated from Austria (EEA). Application hosting (Fly.io), database (Neon), Redis cache (Upstash), email delivery (Resend), and Shopify may process data in the United States or other regions outside the EEA/UK. Where such transfers occur, we rely on each provider’s Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms and their published data processing terms as our sub-processors.
3. How We Use Data
- To validate EU and Northern Ireland (XI) VAT numbers via the EU VIES service.
- To display verification badges on the merchant’s storefront.
- Tax-exempt sync: when auto tax-exempt is enabled, write tax-exempt status to the Shopify customer after a successful intra-community VIES validation, and record the result.
- Order tagging and note writes (
_vat_* attributes, checkout metafields, and order notes). - Periodic 90-day revalidation of stored VAT numbers.
- Order reconciliation to backfill or correct VAT records on orders.
- To manage subscriptions and enforce usage limits.
- To comply with GDPR data subject requests.
4. Sub-Processors and Third-Party Services
We rely on the following sub-processors to operate the App. We do not sell personal data or share it for advertising.
- EU VIES (European Commission) — receives submitted VAT numbers for validation.
- Shopify — hosts the merchant store, provides the customer and order data the App processes, and handles all billing.
- Fly.io — application hosting; processes data in transit and at rest on our behalf.
- Neon — managed PostgreSQL database that stores the App’s data at rest.
- Upstash — managed Redis used for short-lived VIES response caching and circuit-breaker state. Cache keys may include VAT numbers (personal data) for a few minutes until TTL expiry.
- Resend — sends emails to the App operator (developer). Operational alerts may contain only the shop domain and internal request identifiers. When Shopify sends a customer data access request and we hold data for that customer, Resend also delivers the CSV export attachment, which can include VAT numbers, trader/company names, order identifiers, and audit events. That means customer personal data is transmitted to and processed by Resend (and lands in the operator mailbox) for fulfilment. Plain status alerts without an attachment do not include that export.
5. Data Retention
Merchant configuration and customer VAT records are retained while the app is installed. Redis VAT cache entries expire within minutes (see above). Data-request email addresses and export snapshots are cleared when the export is emailed successfully or downloaded by the merchant. Upon uninstallation, shop data is deleted immediately via APP_UNINSTALLED; any residual data is purged within 48 hours via Shopify’s SHOP_REDACT webhook. Customer-specific deletion follows CUSTOMERS_REDACT. Email copies already delivered to the operator mailbox are outside the App database and should be handled under the operator’s own retention practices once fulfilment is complete.
6. GDPR Rights
Customers may request access to, correction of, or deletion of their data. Deletion requests (CUSTOMERS_REDACT, SHOP_REDACT) are processed automatically. When Shopify sends a customer data access request, the App records the request, generates an export snapshot immediately, and emails that export to the operator so fulfilment does not depend on someone opening the admin App. The same export is available on the Data requests page for the merchant to download and forward to the customer. This means customer personal data from the export is processed by the App operator (as part of providing the processing service) and by Resend as email infrastructure. Reminders escalate if delivery fails. We aim to prepare and deliver the export within 30 days of Shopify notifying us of the request. The merchant, as data controller, remains responsible for responding to the customer and for meeting any statutory deadlines that apply to them.
7. Security
All data is transmitted over HTTPS. Database access is restricted to authenticated application processes. We do not store payment information — billing is handled entirely by Shopify.
8. Contact
For privacy-related questions, contact:
Tom Wilkinson
Machstrasse 5, 1020 Wien, Austria
Austria
vatvalidatorpro@gmail.com