Legal
Privacy policy
InvoiceAnvil generates EU-compliant invoices and credit notes for Shopify stores: a PDF with Factur-X or ZUGFeRD XML embedded, plus UBL for PEPPOL. Everything it stores exists to produce those documents.
The app is operated by Eric Mollenthiel, trading as Mollenthiel Studio, 103 avenue Lacassagne, 69003 Lyon, France ("we", "us").
What we collect, and why
An invoice is a legal document, and everything the app stores exists to produce one. When you install the app, we receive and store:
| Data | Why |
|---|---|
Your .myshopify.com domain and an API access token, encrypted at rest |
To authenticate the app with your store |
| Your company details as entered in Settings: legal name, address, country, VAT number, SIREN | The seller block printed on every document |
| For each paid order: the order name and amounts, the line items, the tax breakdown, and the buyer block (customer name, company, billing or shipping address, email address, country, and VAT number when your store collects it) | The content of the invoice itself, snapshotted at issuance so the document can be re-rendered identically for its whole legal life |
| For each refund: the refunded lines and amounts | To issue the corresponding credit note |
We do not collect browsing behaviour, payment card data, passwords, or anything not printed on an invoice. The app is read-only towards your store: it never modifies your products, orders or customers. No advertising, no analytics trackers, and your data is never sold or shared for marketing.
Customer personal data
The buyer block described above is customer personal data under Shopify's Protected Customer Data policy and the GDPR. We process it for one purpose only, issuing the legal invoice your business is required to produce, under Art. 6(1)(c) GDPR (compliance with a legal obligation) and Art. 6(1)(b) (performance of a contract).
VAT number validation (VIES)
On plans with automatic validation, the buyer's VAT number, which is a business identifier, is checked against VIES, the European Commission's official VAT registry, at the moment an invoice is issued. Only the VAT number itself is transmitted: never names, addresses or order contents. A VIES outage never blocks invoicing; the number is then simply marked "not validated".
Retention and erasure
- While the app is installed, issued documents are kept: they are your legal archive, and EU tax law requires invoices to be retained (10 years in France, comparable duties in Belgium and Germany). For the same reason, a customer's right-to-erasure request does not erase issued invoices: GDPR Art. 17(3)(b) exempts data whose processing is necessary to comply with a legal obligation. Each such request is logged with the exact list of retained documents.
- When a customer requests their data (a GDPR access request relayed by Shopify), we log the list of documents holding that customer's data; you can export each of them from the app as PDF, Factur-X XML or UBL to answer the request.
- When you uninstall, Shopify sends the
shop/redactwebhook 48 hours later and everything, settings, tokens and all stored documents, is permanently deleted. Download your invoices before uninstalling: they are your legal archive, and we keep no copy afterwards.
Where your data lives
All data is stored on a server operated by OVH in France (European Union). Connections are encrypted in transit with TLS; API tokens are encrypted at rest.
Sub-processors
| Provider | Purpose | Location |
|---|---|---|
| OVH SAS | Hosting | France (EU) |
| European Commission, VIES | VAT number validation | EU |
Your rights
Under the GDPR you, and your customers, may request access, rectification, erasure (within the legal-retention limits above), restriction or portability of personal data, and lodge a complaint with a supervisory authority (in France, the CNIL). Write to us at the address below for any request.
Contact
Questions about this policy or your data: support@shipanvil.com.
We may update this policy as the app evolves; material changes are announced in the app. The effective date above always reflects the current version.