Privacy Policy - GST Invoices for Shopify

Privacy Policy

What this app reads from your Shopify store, what it stores, where, and how to have it deleted.

Last updated: 26 Sept 2026

This page covers the GST Invoices for Shopify Shopify app only. For how NullGlitch handles information on this website - contact forms, quotes, analytics - see our general Privacy Policy.

Read-only access

The app requests read_orders only. It never creates, edits or deletes anything in your store, and its test suite checks that it has no write requests.

Where it is stored

MongoDB Atlas, hosted on AWS in Sydney, behind Vercel functions also running in Sydney. Encrypted at rest and in transit.

Contact route

Requests about your data, or a deletion request: info@nullglitch.co.nz

  1. Who this covers

    This is the privacy policy for the GST Invoices for Shopify app (working name "GST Invoices"), built by NullGlitch - Bakhtiyar Duganov, a sole trader based in Hobsonville, Auckland, New Zealand. It covers the app only: what it reads from Shopify, what it stores, and how that data is deleted. For how this website handles information - contact forms, quotes, analytics - see our general Privacy Policy.

  2. What we read from Shopify, and why
    • When a merchant installs the app, we request the read_orders access scope and nothing else. The app never creates, edits or deletes anything in your store, and our test suite checks that none of its requests to Shopify can write.
    • To print a tax invoice or credit note, we read the order's line items, prices, discounts, shipping and tax lines, and its refunds, directly from Shopify's Admin API, exactly as Shopify recorded them. We never recalculate GST ourselves - every figure we print is a figure Shopify already charged.
    • We also request access to three protected customer data fields on your orders: Name, Email and Address (billing and shipping). We do not request Phone. These three fields are used only to print the buyer's name and address on the invoice or credit note, the same way a paper invoice shows who it was issued to.
  3. What the app stores, and where

    The app keeps its own small database, separate from Shopify, so an invoice stays identical every time it is downloaded. It stores:

    • Your business settings: legal business name, trading name, GST number, address, invoice numbering, an optional logo image and an optional footer note.
    • Every invoice and credit note we have issued, frozen at the moment it was first created (including the buyer's name, email and address, when Shopify provided them), so re-downloading the same document always gives the identical PDF and figures, even if the order later changes at Shopify.
    • Simple counters that assign the next sequential invoice or credit note number.
    • A record of any invoice or credit note we refused to produce - a reason code and the order name, never a copy of the order. Refusing rather than printing a wrong figure is the app's core promise.
    • A log of the compliance requests we receive from Shopify (see item 6 below), and the login session Shopify issues so the app can talk to your store's Admin API.

    Hosting: the app runs on Vercel, with its functions in Sydney. Its database is MongoDB Atlas, hosted on AWS in Sydney (ap-southeast-2). Atlas encrypts this data at rest with AES-256 and requires an encrypted (TLS) connection for every request, on every Atlas cluster - see MongoDB's own documentation on data encryption and network security. At this stage the database runs on Atlas's free tier, which does not include a separate managed backup service - we will move to a backed-up tier as the number of merchants using the app grows.

  4. Who else sees it

    Three parties can see the data described above, and no others:

    • Shopify - the source of the data, and the platform the app runs inside.
    • Vercel - runs the app's server code, in Sydney.
    • MongoDB Atlas - stores the app's database, in Sydney.

    We do not use any third-party analytics, advertising or error-tracking tool inside the app.

  5. No selling, no marketing

    We never sell or rent the data described above. We do not use it for advertising, and we do not add your customers to a mailing list. The only use of a buyer's name, email or address is printing it on the tax invoice or credit note the app was asked to produce.

  6. Keeping data current, and deleting it
    • The app listens for Shopify's mandatory privacy webhooks and verifies each one is genuinely from Shopify (HMAC signature) before acting on it.
    • If a merchant uninstalls the app, we immediately delete the login session Shopify had issued us for that store.
    • Shopify sends a further shop/redact request 48 hours after the uninstall (per Shopify's own developer documentation on privacy law compliance). When it arrives, we delete everything about that store: settings, every stored invoice and credit note, the numbering counters, the refusal log and the compliance log.
    • If a customer asks a merchant to delete their data and Shopify forwards us that request (customers/redact), we remove the buyer's name, email and address from every invoice and credit note we hold for that customer. We keep the document number, date, line items and GST figures on those documents - New Zealand tax law requires a GST-registered business to keep its tax invoices and credit notes for the period that law sets, so removing the financial figures too would leave the merchant unable to meet that legal duty. Speak to a privacy or tax adviser about your own situation if you need this explained further.
    • If a customer asks a merchant what data is held about them and Shopify forwards us that request (customers/data_request), the app does not have a way to send that data out automatically today. It records how many of the stored documents relate to the request so the merchant, or Shopify, can action it.
  7. Your rights

    The Shopify merchant who installed the app decides what their store collects and how their own customers are told about it - the app acts as a processor on the merchant's behalf, not as the party a customer would normally contact directly.

    If you are a New Zealand resident, the Privacy Act 2020 gives you the right to ask what personal information is held about you and to ask for it to be corrected; complaints can be made to the Office of the Privacy Commissioner. If you are a customer of a merchant using this app, please start with that merchant - most of what we hold exists because of their store, not a direct relationship with us.

    Merchants: you can ask us directly for a copy of your own settings or issued documents, or ask us to close your account and delete everything, at any time.

  8. Changes to this policy

    We will update this page if what the app reads, stores or does with data changes, and update the date above.

  9. Contact

    NullGlitch - Bakhtiyar Duganov (sole trader), Hobsonville, Auckland, New Zealand. E-mail: info@nullglitch.co.nz

Last updated: 26 Sept 2026

Back to GST Invoices for Shopify