Effective date: 27 July 2026
Last updated: 27 July 2026
PDF Builder Invoices (“the App”) is a Shopify app that generates invoices, packing slips, refund receipts and similar order documents as PDF files. This policy explains what the App collects, why, how long it is kept, and how to have it deleted.
The App is operated by Yee Add-ons (“we”, “us”). Contact: [email protected] · https://add-ons.org
1. Who the data belongs to
The App is installed by a merchant (a Shopify store owner). Documents the App produces describe that store’s customers (buyers). The merchant is the data controller for their store’s data; we act as a data processor on their behalf, under the Shopify API Licence and Terms of Use.
2. What we access from Shopify
When a merchant installs the App they grant these access scopes, each of which we use for a specific documented purpose:
| Scope | Why the App needs it |
|---|---|
read_orders |
Read the order a document is generated for: line items, quantities, prices, discounts, taxes, shipping and totals. |
read_products |
Product titles, SKUs and variant details printed on line items. |
read_customers |
Billing and shipping address, name and email printed on the document, and the buyer’s language for translated documents. |
read_companies, read_payment_terms |
B2B documents: company name, company location and payment terms (Ultra plan). |
read_locations, read_merchant_managed_fulfillment_orders, read_assigned_fulfillment_orders, read_third_party_fulfillment_orders |
Determine which store location fulfilled an order, so the correct branch details appear on the document (Ultra plan). |
The App does not request read_all_orders, does not process payments, does not modify orders, products or themes, and does not read data belonging to other apps.
3. What we store on our servers
Order and customer data is read from Shopify at the moment a document is rendered and is not copied into our database. The PDF is streamed to the merchant (or attached to an email) and is not retained on our servers.
We store only the following, keyed by the merchant’s shop domain:
| Data | Purpose |
|---|---|
| Shopify session and access token | Authenticate API calls on the merchant’s behalf. |
| Store profile entered by the merchant: business name, address, email, phone, tax/VAT ID, logo URL, footer text | Printed on the merchant’s documents. |
| Document templates, layouts, fonts, watermark and translation settings | The merchant’s designs. |
| Per-location details entered by the merchant (tax ID, email, logo, footer) | Branch details on documents. |
| Invoice numbering settings, and one record per issued document number containing the Shopify order id, document type and the issued number | Sequential, gap-free, permanently stable document numbers. |
| Usage log: one record per document actually produced, containing the Shopify order id, document type, action (print / download / email) and a timestamp | The in-app Reports screen, and enforcing monthly plan limits. Previews are never recorded. |
| A record of which orders an automatic email has already been sent for (Shopify order id + timestamp) | Prevent duplicate emails when Shopify retries a webhook. |
| The merchant’s own SMTP server settings, including the password | Send documents from the merchant’s own email account. The password is encrypted at rest (AES-256-GCM). |
| Cached billing plan and monthly order count | Enforce plan limits. |
We do not store buyer names, addresses, emails or order contents. Where a Shopify order id is stored (numbering, usage log, email de-duplication), it is an identifier only and cannot be resolved to a person without the merchant’s own Shopify store.
4. Emails the App sends
If the merchant enables automatic emails, the App sends order documents to the buyer’s email address using the merchant’s own SMTP server, configured by the merchant. We do not operate a shared mail service and the message does not pass through any mail infrastructure of ours. The buyer’s email address is read from the order at send time and is not stored afterwards.
5. Retention
- Session tokens, settings, templates, numbering records and usage logs: kept while the App is installed.
- On uninstall: Shopify sends an
app/uninstalledwebhook and we delete the store’s session immediately. - On a shop redaction request (
shop/redact, sent by Shopify 48 hours after uninstall): we delete all data for that shop — settings, templates, location profiles, issued document numbers, usage log, email de-duplication records and sessions. - Generated PDFs: never stored.
- Backups containing residual data are rotated out within 3 days.
6. Mandatory Shopify privacy webhooks
We implement all three:
customers/data_request— we hold no personal customer data, so there is nothing to return. The merchant should answer such requests from Shopify’s own data.customers/redact— no customer personal data is stored, so no deletion is required.shop/redact— every record for that shop is deleted, as described above.
7. Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Shopify Inc. | Source of order data; hosts the embedded app surface | Canada / global |
| Vultr | Application hosting | US |
| vultr | PostgreSQL database | US |
The merchant’s own SMTP provider receives outgoing mail but is chosen and controlled by the merchant, not by us.
We do not sell, rent or share data with advertisers, and we do not use merchant or buyer data to train machine-learning models.
8. International transfers
Data is processed in US. Where data is transferred out of the EEA or UK, we rely on the European Commission’s Standard Contractual Clauses.
9. Security
- All traffic is served over HTTPS/TLS.
- SMTP passwords are encrypted at rest with AES-256-GCM.
- Customer-facing document links are authorised with a per-shop secret token compared in constant time; an invalid token returns 404. A merchant can rotate this token at any time from the App, which immediately invalidates previously issued links.
- Access to production systems is limited to personnel who need it.
10. Your rights
Depending on where you live, you may have the right to access, correct, export, restrict or delete your personal data, and to object to processing (GDPR, UK GDPR, CCPA/CPRA and similar laws).
- Merchants: uninstall the App to trigger deletion, or email us to request access or erasure directly.
- Buyers: contact the store you purchased from. They are the controller of their customer data; we will assist them with any request.
We respond within 30 days. Under the CCPA/CPRA we do not sell or share personal information, and we do not discriminate against anyone who exercises their rights.
11. Cookies
The App is embedded in the Shopify admin and authenticates with Shopify session tokens. It does not set advertising or analytics cookies and does not track merchants across sites.
12. Children
The App is a business tool and is not directed at children under 16.
13. Changes
We will update this page and its “Last updated” date when this policy changes. Material changes will be communicated to installed merchants.
14. Contact
[email protected]
Yee Add-ons, 76 thai phien, da nang, viet nam