Upfront Invoice

Privacy Policy

Last updated: 18 August 2026

1. Who we are

Upfront Invoice (“the App”, “we”, “us”) is a Shopify application that generates and emails PDF invoices for a merchant’s orders.

2. Our role: we are a processor, not the owner of your customers’ data

When a merchant installs the App, the merchant is the data controller of their customers’ personal data. We act as a data processor, handling that data only to provide the invoicing service, and only on the merchant’s instructions. Our Data Processing Agreement governs this relationship.

For the merchant’s own data — their staff Shopify session, and the business details they enter on their invoice template — we and the merchant each act as controller, because we decide to keep those records in order to run the service and the merchant decides to provide them. Our DPA covers that pairing under Module One of the Standard Contractual Clauses. A merchant or their staff can exercise their own rights over that data by writing to [email protected].

3. What data we handle — and what we keep

The App is built so that customer personal data is never written to our database and never stored as a file. It is read from Shopify at the moment an invoice is rendered, held in memory for the length of that render, and discarded.

Passes through, never stored:

DataWhy it is neededWhere it ends up
Customer nameRequired field on a legal VAT invoiceIn the PDF sent to the buyer
Customer billing & shipping addressRequired field on a legal VAT invoiceIn the PDF sent to the buyer
Customer emailTo deliver the invoice to the buyerThe delivery address of that one email
Order details (line items, quantities, prices, tax lines, currency, dates)To build the invoiceIn the PDF sent to the buyer

We deliberately do NOT request the customer phone field — invoices don’t need it, so our data footprint stays smaller (data minimisation).

What we actually store, and all we store:

Stored recordContents
ShopShop domain, install date, invoice number prefix and counter
InvoiceInvoice number, sequence, Shopify order ID, issue date, template version
Template settingsThe merchant’s own logo, seller name/address/VAT ID, colours, footer text
Access logThat an order was rendered and when — the order ID, never the data in it
SessionThe merchant’s Shopify access token and staff account fields

We do not store the generated PDF. Reissuing an invoice re-renders it from Shopify against the stored template version.

We do not collect: payment card numbers, bank details, passwords, or any special category (“sensitive”) personal data.

4. Why we process it (purpose limitation)

Solely to generate and deliver invoices for the merchant, and to provide support for that service. We do not use customers’ personal data for marketing, profiling, automated decision-making, advertising, or training AI models, and we never sell or rent it.

Email we send to the merchant — not to their customers. Separately from invoices, the App emails the store’s own contact address about the store’s own account. Today that is a single message: a notice when a store on the free plan reaches its monthly invoice limit, so the merchant knows invoicing has paused before a buyer notices. That address is read from Shopify at the moment of sending and is not stored. We do not send merchants marketing email.

5. Who we share it with (subprocessors)

We use a small set of infrastructure providers. Each is bound by confidentiality and data-protection terms. Because customer data is never stored, most of these providers only ever see it in transit — the database provider never sees it at all.

SubprocessorPurposeCustomer dataProcessing location
Shopify (Shopify Inc., Canada)App platform; source of order dataController-side platformGlobal
Fly.io (Fly.io, Inc., USA)Runs the App; renders the PDFIn memory only, during a renderFrankfurt, Germany (fra)
Neon (Neon, LLC — a Databricks company, USA)Stores invoice numbers and template settingsNoneFrankfurt, Germany (AWS eu-central-1)
Resend (Resend, Inc., USA)Delivers the invoice emailRecipient address and the attached PDF, in transitIreland (AWS eu-west-1)

Neon’s own subprocessors are AWS, Microsoft Azure, Grafana Labs and Salesforce (neon.com/subprocessors); none of them receive customer personal data from us, because none of it is stored.

We give 14 days notice before adding or replacing a subprocessor, so you have time to object. We share data with no one else, except where legally required.

6. International transfers

For merchants in the EU/UK, invoice rendering and storage happen inside the EU (Frankfurt) and email is sent from Ireland. Your data is not stored in Thailand.

But we are based in Thailand, and that counts as an international transfer even though the data stays in Frankfurt. We run this service from Thailand, so when we log in to support the app or fix a problem, we are reaching that EU data from outside the EU. Under GDPR that is a “restricted transfer” regardless of where the servers sit, and Thailand does not have an EU or UK adequacy decision. We cover it with the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, which are part of our Data Processing Agreement and take effect when you install the app. We have also written a transfer assessment for it, which we will send you on request at no charge.

The providers listed above are incorporated in the USA and Canada, so their support and administrative access can also constitute a transfer; each is engaged under Standard Contractual Clauses or an equivalent lawful mechanism through their own data processing agreements.

7. How long we keep it (retention)

8. How we protect it

Encryption in transit (TLS) and at rest, including encrypted backups; least-privilege access with strong passwords and 2FA; an access log for every read of protected customer data; separated test and production environments; and a written incident response policy.

9. Data subject rights

Because we are a processor, buyers should contact the merchant (the store) they purchased from to exercise their rights (access, correction, deletion, objection, portability). We assist merchants promptly with any such request, and act automatically on Shopify’s privacy webhooks.

You can also come to us directly. Where a transfer is covered by the Standard Contractual Clauses in our Data Processing Agreement, Clause 11(a) gives you a right to lodge a complaint with us. Write to [email protected] — we deal with complaints promptly and tell the merchant. This is in addition to your right to complain to your supervisory authority or to go to court.

10. Cookies

The App runs embedded in the Shopify admin and uses only strictly necessary session cookies/tokens to keep a merchant signed in. No advertising or tracking cookies.

This website sets no cookies. It stores one item on your device — your light/dark preference — in your browser’s local storage, only after you press the toggle, and never sends it anywhere. Clearing your browser storage removes it.

11. Changes

We’ll update this page and change the “Last updated” date. Material changes will be communicated to merchants before they take effect.

12. Contact

[email protected] — we aim to respond within 2 business days.