Effective date: July 1, 2026
InvoicePilot ("the app") generates EU-compliant invoices and credit notes (PDF with embedded Factur-X/ZUGFeRD XML, UBL/PEPPOL) for merchants who use Shopify. This policy describes what information the app collects, why, and how it is handled. The app is operated by Eric Mollenthiel, 103 Avenue Lacassagne, 69003 Lyon, France ("we", "us").
An invoice is a legal document, and everything the app stores exists to produce one. When you install the app, we receive and store:
| Data | Why |
|---|---|
| Your .myshopify.com domain and an API access token (encrypted at rest) | To authenticate the app with your store |
| Your company details as you enter them in Settings (legal name, address, country, VAT number, SIREN) | The seller block printed on every document |
| For each paid order: the order name and amounts, the line items, the tax breakdown, and the buyer block — customer name, company, billing (or shipping) address, email address, country, and VAT number when your store collects it | The content of the invoice itself, snapshotted at issuance so the document can be re-rendered identically for its whole legal life |
| For each refund: the refunded lines and amounts | To issue the corresponding credit note |
We do not collect browsing behaviour, payment card data, passwords, or anything not printed on an invoice. The app is read-only towards your store: it never modifies your products, orders or customers. No advertising, no analytics trackers, and your data is never sold or shared for marketing.
The buyer block described above is customer personal data under Shopify's Protected Customer Data policy and the GDPR. We process it for one purpose only — issuing the legal invoice your business is required to produce — under Art. 6(1)(c) GDPR (compliance with a legal obligation) and Art. 6(1)(b) (performance of a contract).
On plans with automatic validation, the buyer's VAT number (a business identifier) is checked against VIES, the European Commission's official VAT registry, at the moment an invoice is issued. Only the VAT number itself is transmitted — never names, addresses or order contents. A VIES outage never blocks invoicing; the number is then simply marked "not validated".
shop/redact webhook 48 hours later and everything —
settings, tokens, and all stored documents — is permanently deleted.
Download your invoices before uninstalling: they are
your legal archive, and we keep no copy afterwards.All data is stored on a server operated by OVH in France (European Union). Connections are encrypted in transit (TLS); API tokens are encrypted at rest.
| Provider | Purpose | Location |
|---|---|---|
| OVH SAS | Hosting | France (EU) |
| European Commission — VIES | VAT number validation | EU |
Under the GDPR you (and your customers) may request access, rectification, erasure (within the legal-retention limits above), restriction or portability of personal data, and lodge a complaint with a supervisory authority (in France: the CNIL). Write to us at the address below for any request.
Questions about this policy or your data: support@shipanvil.com
We may update this policy as the app evolves; material changes are announced in the app. The effective date above always reflects the current version.