Privacy Policy

Version 3.1 dated February 19, 2026

1. General Information and Principles of Data Processing

We are pleased that you are using our App. The protection of your privacy and the protection of your personal data, so-called personal data, when using our App is an important concern for us.

Personal data according to Art. 4 No. 1 GDPR are all information relating to an identified or identifiable natural person. This includes, for example, information such as your first and last name, your address, your phone number, your email address, but also your IP address.

Data for which no connection to your person can be established, such as through anonymization, are not personal data. The processing (e.g., collection, storage, retrieval, querying, use, transmission, deletion or destruction) according to Art. 4 No. 2 GDPR always requires a legal basis or your consent. Processed personal data must be deleted as soon as the purpose of processing has been achieved and no legally prescribed retention obligations need to be maintained.

Here you will find information about the handling of your personal data when using our App. To provide the functions and services of the App, it is necessary that we collect personal data about you.

We also explain to you the type and scope of the respective data processing, the purpose and the corresponding legal basis and the respective storage period.

This privacy policy applies only to this App. It does not apply to other websites or apps to which we merely refer via a hyperlink. We cannot assume responsibility for the confidential handling of your personal data on third-party websites or apps, as we have no influence on whether these companies comply with data protection regulations. Please inform yourself directly on these websites or apps about the handling of your personal data by these companies.

2. Responsible Party

Responsible for the processing of personal data in connection with the use of the App is: A&C Finance Solutions

3. Provision and Use of the App / Server Log Files

a) Type and Scope of Data Processing

When you use this App, we collect technically necessary data via server log files that are automatically transmitted to our server, including:

  • IP address
  • Date and time of the request
  • Name and URL of the retrieved file
  • Website from which access is made (referrer URL)
  • Access status/HTTP status code
  • Browser type
  • Language and version of the browser software
  • Operating system

b) Purpose and Legal Basis

This processing is technically necessary to be able to display our App to you. We also use the data to ensure the security and stability of our App.

The legal basis for this processing is Art. 6 para. 1 lit. f) GDPR. The processing of the mentioned data is necessary for the provision of an App and thus serves to protect a legitimate interest of our company.

c) Storage Period

As soon as the mentioned personal data are no longer required for displaying the App, they are deleted. The collection of data for the provision of the App and the storage of data in log files is mandatory for the operation of the App. Consequently, there is no possibility for the user to object to this aspect. Further storage may occur in individual cases if this is legally required.

4. Data Collection for Pre-Contractual Measures and Contract Fulfillment

a) Type and Scope of Data Processing

In the pre-contractual area and when concluding a contract, we collect personal data about you. This includes, for example, first and last name, address, email address, phone number or bank details.

b) Purpose and Legal Basis of Data Processing

We collect and process this data exclusively for the purpose of contract performance or to fulfill pre-contractual obligations.

The legal basis for this is Art. 6 para. 1 lit. b) GDPR. If there is additionally consent from you, the additional legal basis is Art. 6 para. 1 lit. a) GDPR.

c) Storage Period

The data will be deleted as soon as they are no longer required for the purpose of their processing.

In addition, there may be legal retention obligations, for example commercial or tax retention obligations under the German Commercial Code (HGB) or the Fiscal Code (AO). If such retention obligations exist, we will block or delete your data at the end of these retention obligations.

5. Storage of Order and Customer Data

We only store those order and customer data that are necessary for the creation of the respective documents (invoice, credit note, etc.).

The data is hosted on servers of Hetzner Online GmbH in Germany.

Users can have all personal data deleted at any time via the compliance interfaces integrated in Shopify.

6. Data Transmission

We only pass on your personal data to third parties if:

  1. you have given your express consent to this according to Art. 6 para. 1 lit. a) GDPR.
  2. this is legally permissible and necessary according to Art. 6 para. 1 lit. b) GDPR for the fulfillment of a contractual relationship with you or the implementation of pre-contractual measures.
  3. there is a legal obligation for the transfer according to Art. 6 para. 1 lit. c) GDPR. We are legally obliged to transmit data to government authorities, e.g., tax authorities, social security institutions, health insurance companies, supervisory authorities and law enforcement agencies.
  4. the transfer is necessary according to Art. 6 para. 1 lit. f) GDPR to protect legitimate business interests, as well as to assert, exercise or defend legal claims and there is no reason to assume that you have an overriding legitimate interest in not transferring your data.
  5. we use external service providers, so-called processors, for processing according to Art. 28 GDPR, who have been obliged to handle your data carefully.

We use such service providers in the following areas:

  • IT

When transmitting to external parties in third countries, i.e., outside the EU or the EEA, we ensure that these parties treat your personal data with the same care as within the EU or the EEA. We only transmit personal data to third countries where the EU Commission has confirmed an adequate level of protection or if we ensure careful handling of personal data through contractual agreements or other appropriate guarantees.

7. Newsletter

a) Type and Scope of Data Processing

There is the possibility to subscribe to a free regular email newsletter. To be able to send you the newsletter regularly, we need your email address from you.

For newsletter delivery, we use the so-called double opt-in procedure.

This means that we will only send you an email newsletter if you have expressly confirmed to us that you consent to receiving the newsletter. We will then send you a confirmation email asking you to confirm by clicking on a corresponding link that you want to receive newsletters from us in the future.

This serves to ensure that only you yourself can register for the newsletter as the owner of the specified email address. Your confirmation must be made promptly after receiving the confirmation email, otherwise your newsletter registration will be automatically deleted from our database.

When you subscribe to the newsletter, we collect and store the data you enter in the input form (e.g., last name, first name, email address).

When registering for the newsletter, we also store your IP address registered by the Internet Service Provider (ISP) as well as the date and time of registration to be able to trace any misuse of your email address at a later time. For the confirmation email sent for control purposes (double opt-in in the email), we also store the date and time of the click on the confirmation link and the IP address registered by the Internet Service Provider (ISP).

b) Purpose and Legal Basis

The data collected by us when registering for the newsletter is used exclusively for advertising purposes via the newsletter.

The processing of your email address for newsletter delivery is based on Art. 6 para. 1 lit. a) GDPR and § 7 para. 2 No. 3 UWG on the consent declaration that you voluntarily give below and can revoke at any time for the future.

In addition, the processing is based on Art. 6 para. 1 lit. f) GDPR due to legitimate interests on our part to document the proof of the required consent.

c) Storage Period

Your email address will be stored as long as you have subscribed to the newsletter. After unsubscribing from the newsletter, your email address will be deleted, unless you have expressly consented to further use of your data.

8. Web Analysis Services

Use of Google Analytics on our website and in our Shopify App

We use the web analysis service Google Analytics on our website and within our Shopify App, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google").

Google Analytics uses cookies and comparable technologies that are stored on your device and enable an analysis of the use of our website or our app. The information generated by these technologies about your use of our offers is usually transmitted to Google servers and stored there. This may also involve transmission to Google LLC servers in the USA.

We have activated the IP anonymization function. As a result, your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there.

Google processes this information on our behalf to evaluate the use of our website and our Shopify App, to compile reports on activities, and to provide other services related to the use of our offers.

a) Legal Basis

The processing is based on your consent in accordance with Art. 6 Para. 1 lit. a GDPR in conjunction with § 25 Para. 1 TTDSG.

  • On our website, you give your consent via our cookie or consent tool.
  • In our Shopify App, consent is given by your approval during the installation of the app.

b) Recipients of Data

The recipient of the data is Google Ireland Limited. Transmission to third countries, in particular the USA, cannot be ruled out. Google relies on the standard contractual clauses approved by the EU Commission for this purpose.

c) Storage Period

The data sent by us to Google and linked to cookies or identifiers will be automatically deleted after a maximum of 14 months.

d) Revocation of Consent

You can revoke your consent at any time with effect for the future:

  • on the website via our cookie settings,
  • within the Shopify App by uninstalling the app or via the privacy settings provided there (if available).

In addition, you can prevent the collection of your data by Google Analytics by installing the following browser plugin: https://tools.google.com/dlpage/gaoptout

Further information on data protection at Google can be found at: https://policies.google.com/privacy

9. Data Security and Security Measures

We use technical and organizational security measures to protect the data managed by us against accidental or intentional manipulation, loss, destruction or against access by unauthorized persons. Our security measures are continuously improved in accordance with technological development.

Access to your data is only possible for a limited group of people and is carried out exclusively within the framework of activities necessary for the fulfillment of contractual services.

10. Rights of Data Subjects

You have the following rights:

  • Right to information about your data stored with us
  • Right to correction of incorrect personal data
  • Right to deletion of your data stored with us, provided that no legal retention obligations oppose this
  • Right to restriction of processing of your personal data
  • Right to data portability
  • Right to object to the processing of your personal data

To exercise your rights, you can contact the responsible party mentioned above at any time.

11. Storage and Provision of Customer Data After Contract Termination

a) Grace Period for Data Access (3 Months)

After uninstallation or cancellation of the app, we grant you a grace period of 3 months during which you can access your data through our support team. During this period, you can:

  • Download all invoices as a ZIP export
  • Access all historical invoice data
  • Create exports for your accountant or your own archiving

Access is exclusively through our support (support@easy-invoices.app). You must prove that you are or were the owner or authorized person of the Shopify shop.

Legal basis: Art. 6 Para. 1 lit. b) GDPR (contract fulfillment) and Art. 6 Para. 1 lit. f) GDPR (legitimate interest in proper contract processing)

b) Automatic Deletion After 3 Months

After the 3-month grace period expires, all your personal data will be automatically and irrevocably deleted. This includes:

  • All invoice PDFs
  • All invoice metadata (numbers, amounts, dates)
  • Configuration data (templates, SMTP settings)
  • All other customer-related data

Important: Technical recovery of data after deletion is not possible. Please export and secure all important data in time within the 3-month period.

Legal basis: Art. 17 GDPR (Right to erasure)

c) Your Legal Retention Obligation

Important note: As the invoice issuer (shop owner), you have the legal obligation to retain your business documents including invoices for 10 years (§ 147 Para. 1 No. 1 AO).

Easy Invoices is a software service provider and creates invoices on your behalf. The legal retention obligation lies with you as the entrepreneur, not with us as the software provider.

Recommendation: Export all invoices regularly (monthly or annually) and store them securely. Use the app's export function or contact our support.

d) Identity Verification for Data Access

To access your data after cancellation, proof is required that you are or were the shop owner. Access is exclusively through our support.

Verification process:

  • Contact from the email address registered with Shopify
  • Provide your Shopify shop domain
  • If necessary: Proof through screenshot from Shopify admin or other documents
  • Processing time: 24-48 hours on business days

These security measures serve to protect your data from unauthorized access.

e) Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format (Art. 20 GDPR). The export includes:

  • All invoice PDFs
  • Metadata in JSON format
  • Configuration data

You can perform the export at any time through the app functions or request it through our support after cancellation.

f) Further Information

Detailed information about data retention after app uninstallation can be found on our data retention page.

12. Data Processing Pursuant to Art. 28 GDPR

In the course of using Easy Invoices, A&C Finance Solutions GbR acts as a processor within the meaning of Art. 28 GDPR. The Shopify merchants using Easy Invoices are the controllers for the processing of their end customers' personal data.

A Data Processing Agreement (DPA) is concluded electronically during the app's onboarding process. The DPA can be downloaded as a PDF document at any time via the app settings.

Categories of data processed:

  • Identification data (first and last name, company name)
  • Contact data (email address, phone number, postal address)
  • Order data (order numbers, line items, payment method)
  • Financial data (invoice amounts, currency)
  • Tax data (VAT ID, tax ID)

Processing purposes:

  • Automatic creation of invoices, cancellation invoices and credit notes
  • Generation of PDF documents
  • Sending invoice documents by email
  • Export and archiving of invoice data

Sub-processors used:

  • Hetzner Online GmbH (Germany/EU) — Server hosting, databases
  • Shopify Inc. (Canada/EU) — E-commerce platform
  • Sentry / Functional Software, Inc. (USA, EU hosting) — Error monitoring
  • Google LLC / Google Analytics (USA) — Landing page usage analysis

13. Changes to the Privacy Policy

We reserve the right to update this statement as needed at any time. The current version of the privacy policy can be viewed in the App. Please inform yourself regularly about the applicable data protection regulations.