Upfront Invoice (“the App”, “we”, “us”) is a Shopify application that generates and emails PDF invoices, credit notes, and packing slips for a merchant’s orders.
When a merchant installs the App, the merchant is the data controller of their customers’ personal data. We act as a data processor, handling that data only to provide the invoicing service, and only on the merchant’s instructions. Our Data Processing Agreement governs this relationship.
The App is built so that customer personal data is never written to our database and never stored as a file. It is read from Shopify at the moment an invoice is rendered, held in memory for the length of that render, and discarded.
Passes through, never stored:
| Data | Why it is needed | Where it ends up |
|---|---|---|
| Customer name | Required field on a legal VAT invoice | In the PDF sent to the buyer |
| Customer billing & shipping address | Required field on a legal VAT invoice | In the PDF sent to the buyer |
| Customer email | To deliver the invoice to the buyer | The delivery address of that one email |
| Order details (line items, quantities, prices, tax lines, currency, dates) | To build the invoice | In the PDF sent to the buyer |
We deliberately do NOT request the customer phone field — invoices don’t need it, so our data footprint stays smaller (data minimisation).
What we actually store, and all we store:
| Stored record | Contents |
|---|---|
| Shop | Shop domain, install date, invoice number prefix and counter |
| Invoice | Invoice number, sequence, Shopify order ID, issue date, template version |
| Template settings | The merchant’s own logo, seller name/address/VAT ID, colours, footer text |
| Access log | That an order was rendered and when — the order ID, never the data in it |
| Session | The merchant’s Shopify access token and staff account fields |
We do not store the generated PDF. Reissuing an invoice re-renders it from Shopify against the stored template version.
We do not collect: payment card numbers, bank details, passwords, or any special category (“sensitive”) personal data.
Solely to generate and deliver invoices, credit notes, and packing slips for the merchant, and to provide support for that service. We do not use customers’ personal data for marketing, profiling, automated decision-making, advertising, or training AI models, and we never sell or rent it.
We use a small set of infrastructure providers. Each is bound by confidentiality and data-protection terms. Because customer data is never stored, most of these providers only ever see it in transit — the database provider never sees it at all.
| Subprocessor | Purpose | Customer data | Processing location |
|---|---|---|---|
| Shopify (Shopify Inc., Canada) | App platform; source of order data | Controller-side platform | Global |
| Fly.io (Fly.io, Inc., USA) | Runs the App; renders the PDF | In memory only, during a render | Frankfurt, Germany (fra) |
| Neon (Neon, LLC — a Databricks company, USA) | Stores invoice numbers and template settings | None | Frankfurt, Germany (AWS eu-central-1) |
| Resend (Resend, Inc., USA) | Delivers the invoice email | Recipient address and the attached PDF, in transit | Ireland (AWS eu-west-1) |
Neon’s own subprocessors are AWS, Microsoft Azure, Grafana Labs and Salesforce (neon.com/subprocessors); none of them receive customer personal data from us, because none of it is stored.
We publish changes to this list before adding a new subprocessor. We share data with no one else, except where legally required.
For merchants in the EU/UK, invoice rendering and storage happen inside the EU (Frankfurt) and email is sent from Ireland. The providers above are incorporated in the USA and Canada, so their support and administrative access can constitute a transfer; each is engaged under Standard Contractual Clauses or an equivalent lawful mechanism through their own data processing agreements.
customers/data_request, customers/redact, and shop/redact — within the required timeframes. Because we hold no customer personal data, customers/redact has nothing to erase, and we say so rather than pretending otherwise.Encryption in transit (TLS) and at rest, including encrypted backups; least-privilege access with strong passwords and 2FA; an access log for every read of protected customer data; separated test and production environments; and a written incident response policy.
Because we are a processor, buyers should contact the merchant (the store) they purchased from to exercise their rights (access, correction, deletion, objection, portability). We assist merchants promptly with any such request, and act automatically on Shopify’s privacy webhooks.
The App runs embedded in the Shopify admin and uses only strictly necessary session cookies/tokens to keep a merchant signed in. No advertising or tracking cookies. This website sets no cookies at all.
We’ll update this page and change the “Last updated” date. Material changes will be communicated to merchants before they take effect.
support@upfrontinvoice.com — we aim to respond within 2 business days.