Upfront Invoice (“the App”, “we”, “us”) is a Shopify application that generates and emails PDF invoices for a merchant’s orders.
When a merchant installs the App, the merchant is the data controller of their customers’ personal data. We act as a data processor, handling that data only to provide the invoicing service, and only on the merchant’s instructions. Our Data Processing Agreement governs this relationship.
For the merchant’s own data — their staff Shopify session, and the business details they enter on their invoice template — we and the merchant each act as controller, because we decide to keep those records in order to run the service and the merchant decides to provide them. Our DPA covers that pairing under Module One of the Standard Contractual Clauses. A merchant or their staff can exercise their own rights over that data by writing to [email protected].
The App is built so that customer personal data is never written to our database and never stored as a file. It is read from Shopify at the moment an invoice is rendered, held in memory for the length of that render, and discarded.
Passes through, never stored:
| Data | Why it is needed | Where it ends up |
|---|---|---|
| Customer name | Required field on a legal VAT invoice | In the PDF sent to the buyer |
| Customer billing & shipping address | Required field on a legal VAT invoice | In the PDF sent to the buyer |
| Customer email | To deliver the invoice to the buyer | The delivery address of that one email |
| Order details (line items, quantities, prices, tax lines, currency, dates) | To build the invoice | In the PDF sent to the buyer |
We deliberately do NOT request the customer phone field — invoices don’t need it, so our data footprint stays smaller (data minimisation).
What we actually store, and all we store:
| Stored record | Contents |
|---|---|
| Shop | Shop domain, install date, invoice number prefix and counter |
| Invoice | Invoice number, sequence, Shopify order ID, issue date, template version |
| Template settings | The merchant’s own logo, seller name/address/VAT ID, colours, footer text |
| Access log | That an order was rendered and when — the order ID, never the data in it |
| Session | The merchant’s Shopify access token and staff account fields |
We do not store the generated PDF. Reissuing an invoice re-renders it from Shopify against the stored template version.
We do not collect: payment card numbers, bank details, passwords, or any special category (“sensitive”) personal data.
Solely to generate and deliver invoices for the merchant, and to provide support for that service. We do not use customers’ personal data for marketing, profiling, automated decision-making, advertising, or training AI models, and we never sell or rent it.
Email we send to the merchant — not to their customers. Separately from invoices, the App emails the store’s own contact address about the store’s own account. Today that is a single message: a notice when a store on the free plan reaches its monthly invoice limit, so the merchant knows invoicing has paused before a buyer notices. That address is read from Shopify at the moment of sending and is not stored. We do not send merchants marketing email.
We use a small set of infrastructure providers. Each is bound by confidentiality and data-protection terms. Because customer data is never stored, most of these providers only ever see it in transit — the database provider never sees it at all.
| Subprocessor | Purpose | Customer data | Processing location |
|---|---|---|---|
| Shopify (Shopify Inc., Canada) | App platform; source of order data | Controller-side platform | Global |
| Fly.io (Fly.io, Inc., USA) | Runs the App; renders the PDF | In memory only, during a render | Frankfurt, Germany (fra) |
| Neon (Neon, LLC — a Databricks company, USA) | Stores invoice numbers and template settings | None | Frankfurt, Germany (AWS eu-central-1) |
| Resend (Resend, Inc., USA) | Delivers the invoice email | Recipient address and the attached PDF, in transit | Ireland (AWS eu-west-1) |
Neon’s own subprocessors are AWS, Microsoft Azure, Grafana Labs and Salesforce (neon.com/subprocessors); none of them receive customer personal data from us, because none of it is stored.
We give 14 days notice before adding or replacing a subprocessor, so you have time to object. We share data with no one else, except where legally required.
For merchants in the EU/UK, invoice rendering and storage happen inside the EU (Frankfurt) and email is sent from Ireland. Your data is not stored in Thailand.
But we are based in Thailand, and that counts as an international transfer even though the data stays in Frankfurt. We run this service from Thailand, so when we log in to support the app or fix a problem, we are reaching that EU data from outside the EU. Under GDPR that is a “restricted transfer” regardless of where the servers sit, and Thailand does not have an EU or UK adequacy decision. We cover it with the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, which are part of our Data Processing Agreement and take effect when you install the app. We have also written a transfer assessment for it, which we will send you on request at no charge.
The providers listed above are incorporated in the USA and Canada, so their support and administrative access can also constitute a transfer; each is engaged under Standard Contractual Clauses or an equivalent lawful mechanism through their own data processing agreements.
customers/data_request, customers/redact, and shop/redact — within the required timeframes. Because we hold no customer personal data, customers/redact has nothing to erase, and we say so rather than pretending otherwise.Encryption in transit (TLS) and at rest, including encrypted backups; least-privilege access with strong passwords and 2FA; an access log for every read of protected customer data; separated test and production environments; and a written incident response policy.
Because we are a processor, buyers should contact the merchant (the store) they purchased from to exercise their rights (access, correction, deletion, objection, portability). We assist merchants promptly with any such request, and act automatically on Shopify’s privacy webhooks.
You can also come to us directly. Where a transfer is covered by the Standard Contractual Clauses in our Data Processing Agreement, Clause 11(a) gives you a right to lodge a complaint with us. Write to [email protected] — we deal with complaints promptly and tell the merchant. This is in addition to your right to complain to your supervisory authority or to go to court.
The App runs embedded in the Shopify admin and uses only strictly necessary session cookies/tokens to keep a merchant signed in. No advertising or tracking cookies.
This website sets no cookies. It stores one item on your device — your light/dark preference — in your browser’s local storage, only after you press the toggle, and never sends it anywhere. Clearing your browser storage removes it.
We’ll update this page and change the “Last updated” date. Material changes will be communicated to merchants before they take effect.
[email protected] — we aim to respond within 2 business days.