1. Who we are
E-invoicing for Shopify — the "EU E-Invoicing Connector" (the "App") — is a Shopify application published by:
- Vangelder Solutions BV ("we", "us", "Vangelder Solutions")
- Enterprise number (KBO/BCE): BE 0802.046.676
- Registered address: Pastorijstraat 27, 9100 Nieuwkerken-Waas, Belgium
- Contact for privacy matters: support@vangeldersolutions.be
This policy explains what personal data the App processes, why, on what legal basis, with whom we share it, how long we keep it, and the rights of the individuals concerned.
2. Our role: controller vs. processor
The App connects a merchant's Shopify store to the Peppol e-invoicing network so that B2B invoices can be sent as structured e-invoices, and (optionally) a copy forwarded to the merchant's accountant.
- For the merchant's business data and their customers' invoice data, the merchant is the data controller and we act as a data processor on their behalf, governed by our Data Processing Agreement (DPA).
- For the merchant's own account/administration data (the contact who installs and configures the App, support correspondence), we act as an independent controller, and this policy applies directly.
3. What personal data the App processes
3.1 Merchant and account data (we are controller)
- Shop domain and Shopify store identifiers.
- The name and email of the person configuring the App, and any support correspondence.
- Configuration you enter: company registration details (legal name, enterprise/KBO number, address), invoice numbering, bank account (IBAN/BIC) and payment instructions, accountant contact, and provider credentials.
3.2 Customer / buyer invoice data (merchant is controller, we are processor)
To build a compliant EN 16931 e-invoice, the App reads order, customer and company data from Shopify via the Admin API (scopes read_orders, read_customers, read_companies and the corresponding write scopes for status metafields, plus Protected Customer Data access). For the business customer on a B2B order this can include company name, billing/shipping address, VAT/enterprise number, contact name and (where present) email, and order line items, amounts, taxes and payment details.
This data is processed transiently in memory to generate the UBL/e-invoice and is then transmitted to the Peppol Access Point (and, if enabled, to the accountant copy destination). We do not store the buyer's name, address, email or VAT number in the App database.
3.3 What we actually store in our database
- Session — the Shopify OAuth session/token for the installed store.
- MerchantSettings / ProviderAccount — your configuration and, where you bring your own provider account, your provider credentials encrypted at rest (AES-256-GCM).
- SentInvoice — per document: shop, Shopify order/refund identifiers, our internal document number, the provider's document id, and delivery status/metadata. No buyer personal data is stored here.
- DocumentNumber — the gapless invoice/credit-note number counters.
3.4 Cookies and tracking
The App runs embedded in the Shopify Admin and uses only the strictly necessary cookies/tokens required for authentication and session management. We do not use advertising or analytics tracking cookies. See our Cookie Policy.
4. Purposes and legal bases (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Provide the App and send Peppol e-invoices on the merchant's instruction | Performance of a contract (Art. 6(1)(b)); for buyer data, processing on the controller's documented instructions (Art. 28) |
| Store minimal metadata to prevent duplicate/erroneous sends and show delivery status | Legitimate interest in reliable operation (Art. 6(1)(f)) |
| Forward an invoice copy to the merchant's accountant (if enabled) | Merchant's instruction / legitimate interest of the merchant |
| Retain the legal invoice at the Peppol provider | Legal obligation — Belgian VAT/accounting retention (Art. 6(1)(c)) |
| Provide support and secure the service | Legitimate interest (Art. 6(1)(f)) |
5. Sub-processors and recipients
We use the following sub-processors, depending on the Peppol Access Point provider you choose. The provider(s) shown below are examples; we may add or replace providers over time — an up-to-date list is maintained in the DPA (Annex C).
| Sub-processor | Purpose | Location |
|---|---|---|
| Shopify International Ltd. | Source platform; provides order/customer data | EU / global |
| Peppol Access Point provider(s) — e.g. A-Cube S.r.l. (EU, Italy) or another certified provider you select | Peppol Access Point — transmits and stores the legal e-invoice | EEA (and, where a provider operates outside the EEA, under an appropriate transfer safeguard) |
| Microsoft Azure (Microsoft Ireland Operations Ltd.) | Application hosting, database and transactional email | EU — North Europe (Ireland) |
| The merchant's accountant (if the accountant-copy feature is enabled) | Receives a labelled copy of the invoice (UBL + PDF) | Determined by the merchant |
We do not sell personal data and do not share it with third parties for advertising.
6. International transfers
The App and its database are hosted in the EU (Ireland), and our sub-processors are located in the EEA. Where any processing would involve a transfer outside the EEA, it is covered by an appropriate safeguard (e.g. EU Standard Contractual Clauses).
7. Retention
- Operational data in our database is retained while the App is installed. On uninstall, Shopify sends a
shop/redactrequest (≈48 hours later) and we delete all data for that shop. - The legal e-invoice stored at the Peppol Access Point is retained under Belgian VAT law (currently ~10 years) as a legal obligation, and is therefore not erased on uninstall. That retention is the responsibility of the merchant and the provider.
8. Security
- Provider credentials encrypted at rest with AES-256-GCM, master key held in Azure Key Vault (never in the database), accessed via a managed identity.
- Transport over TLS/HTTPS; the A-Cube delivery webhook is signature-verified.
- Hosted on Microsoft Azure with its physical and network security controls.
- Production access limited to authorised personnel on a need-to-know basis.
9. Data subject rights
Individuals whose personal data is processed have the GDPR rights to access, rectify, erase, restrict, port and object. Because the App stores no buyer personal data and processes buyer data only on the merchant's instructions, requests concerning a buyer's invoice data should be directed to the merchant (the controller). Shopify's mandatory privacy webhooks — customers/data_request, customers/redact, shop/redact — are implemented and acted upon.
For data where we are the controller (Section 3.1), contact support@vangeldersolutions.be. You may also lodge a complaint with the Belgian Data Protection Authority, Rue de la Presse 35, 1000 Brussels.
10. Changes to this policy
We may update this policy to reflect changes to the App or legal requirements. Material changes will be communicated through the App or by email, and the "Last updated" date above will be revised.
11. Contact
Vangelder Solutions BV — support@vangeldersolutions.be — Pastorijstraat 27, 9100 Nieuwkerken-Waas, Belgium