Privacy Policy

Version 4.1 dated September 16, 2026

1. General Information and Principles of Data Processing

We are pleased that you are using our App. The protection of your privacy and the protection of your personal data, so-called personal data, when using our App is an important concern for us.

Personal data according to Art. 4 No. 1 GDPR are all information relating to an identified or identifiable natural person. This includes, for example, information such as your first and last name, your address, your phone number, your email address, but also your IP address.

Data for which no connection to your person can be established, such as through anonymization, are not personal data. The processing (e.g., collection, storage, retrieval, querying, use, transmission, deletion or destruction) according to Art. 4 No. 2 GDPR always requires a legal basis or your consent. Processed personal data must be deleted as soon as the purpose of processing has been achieved and no legally prescribed retention obligations need to be maintained.

Here you will find information about the handling of your personal data when using our App. To provide the functions and services of the App, it is necessary that we collect personal data about you.

We also explain to you the type and scope of the respective data processing, the purpose and the corresponding legal basis and the respective storage period.

This privacy policy applies only to this App. It does not apply to other websites or apps to which we merely refer via a hyperlink. We cannot assume responsibility for the confidential handling of your personal data on third-party websites or apps, as we have no influence on whether these companies comply with data protection regulations. Please inform yourself directly on these websites or apps about the handling of your personal data by these companies.

2. Responsible Party

Responsible for the processing of personal data in connection with the use of the App is: A&C Finance Solutions

3. Provision and Use of the App / Server Log Files

a) Type and Scope of Data Processing

When you use this App, we collect technically necessary data via server log files that are automatically transmitted to our server, including:

  • IP address
  • Date and time of the request
  • Name and URL of the retrieved file
  • Website from which access is made (referrer URL)
  • Access status/HTTP status code
  • Browser type
  • Language and version of the browser software
  • Operating system

b) Purpose and Legal Basis

This processing is technically necessary to be able to display our App to you. We also use the data to ensure the security and stability of our App.

The legal basis for this processing is Art. 6 para. 1 lit. f) GDPR. The processing of the mentioned data is necessary for the provision of an App and thus serves to protect a legitimate interest of our company.

c) Storage Period

As soon as the mentioned personal data are no longer required for displaying the App, they are deleted. The collection of data for the provision of the App and the storage of data in log files is mandatory for the operation of the App. Consequently, there is no possibility for the user to object to this aspect. Further storage may occur in individual cases if this is legally required.

4. Data Collection for Pre-Contractual Measures and Contract Fulfillment

a) Type and Scope of Data Processing

In the pre-contractual area and when concluding a contract, we collect personal data about you. This includes, for example, first and last name, address, email address, phone number or bank details.

b) Purpose and Legal Basis of Data Processing

We collect and process this data exclusively for the purpose of contract performance or to fulfill pre-contractual obligations.

The legal basis for this is Art. 6 para. 1 lit. b) GDPR. If there is additionally consent from you, the additional legal basis is Art. 6 para. 1 lit. a) GDPR.

c) Storage Period

The data will be deleted as soon as they are no longer required for the purpose of their processing.

In addition, there may be legal retention obligations, for example commercial or tax retention obligations under the German Commercial Code (HGB) or the Fiscal Code (AO). If such retention obligations exist, we will block or delete your data at the end of these retention obligations.

5. Storage of Order and Customer Data

We only store those order and customer data that are necessary for the creation of the respective documents (invoice, credit note, etc.).

The data is hosted on servers of Hetzner Online GmbH in Germany.

Users can have all personal data deleted at any time via the compliance interfaces integrated in Shopify.

6. Data Transmission

We only pass on your personal data to third parties if:

  1. you have given your express consent to this according to Art. 6 para. 1 lit. a) GDPR.
  2. this is legally permissible and necessary according to Art. 6 para. 1 lit. b) GDPR for the fulfillment of a contractual relationship with you or the implementation of pre-contractual measures.
  3. there is a legal obligation for the transfer according to Art. 6 para. 1 lit. c) GDPR. We are legally obliged to transmit data to government authorities, e.g., tax authorities, social security institutions, health insurance companies, supervisory authorities and law enforcement agencies.
  4. the transfer is necessary according to Art. 6 para. 1 lit. f) GDPR to protect legitimate business interests, as well as to assert, exercise or defend legal claims and there is no reason to assume that you have an overriding legitimate interest in not transferring your data.
  5. we use external service providers, so-called processors, for processing according to Art. 28 GDPR, who have been obliged to handle your data carefully.

We use such service providers in the following areas:

  • IT

When transmitting to external parties in third countries, i.e., outside the EU or the EEA, we ensure that these parties treat your personal data with the same care as within the EU or the EEA. We only transmit personal data to third countries where the EU Commission has confirmed an adequate level of protection or if we ensure careful handling of personal data through contractual agreements or other appropriate guarantees.

7. Newsletter

a) Type and Scope of Data Processing

There is the possibility to subscribe to a free regular email newsletter. To be able to send you the newsletter regularly, we need your email address from you.

For newsletter delivery, we use the so-called double opt-in procedure.

This means that we will only send you an email newsletter if you have expressly confirmed to us that you consent to receiving the newsletter. We will then send you a confirmation email asking you to confirm by clicking on a corresponding link that you want to receive newsletters from us in the future.

This serves to ensure that only you yourself can register for the newsletter as the owner of the specified email address. Your confirmation must be made promptly after receiving the confirmation email, otherwise your newsletter registration will be automatically deleted from our database.

When you subscribe to the newsletter, we collect and store the data you enter in the input form (e.g., last name, first name, email address).

When registering for the newsletter, we also store your IP address registered by the Internet Service Provider (ISP) as well as the date and time of registration to be able to trace any misuse of your email address at a later time. For the confirmation email sent for control purposes (double opt-in in the email), we also store the date and time of the click on the confirmation link and the IP address registered by the Internet Service Provider (ISP).

b) Purpose and Legal Basis

The data collected by us when registering for the newsletter is used exclusively for advertising purposes via the newsletter.

The processing of your email address for newsletter delivery is based on Art. 6 para. 1 lit. a) GDPR and § 7 para. 2 No. 3 UWG on the consent declaration that you voluntarily give below and can revoke at any time for the future.

In addition, the processing is based on Art. 6 para. 1 lit. f) GDPR due to legitimate interests on our part to document the proof of the required consent.

c) Storage Period

Your email address will be stored as long as you have subscribed to the newsletter. After unsubscribing from the newsletter, your email address will be deleted, unless you have expressly consented to further use of your data.

8. Web Analysis and Marketing Services

Use of Google Analytics on our website

We use the web analysis service Google Analytics on our website, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). We do not use Google Analytics inside our Shopify app.

Google Analytics uses cookies and comparable technologies that are stored on your device and enable an analysis of the use of our website. The information generated by these technologies about your use of our website is usually transmitted to Google servers and stored there. This may also involve transmission to Google LLC servers in the USA.

We have activated the IP anonymization function. As a result, your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there.

Google processes this information on our behalf to evaluate the use of our website, to compile reports on activities, and to provide other services related to the use of our website.

a) Legal Basis

The processing is based on your consent in accordance with Art. 6 Para. 1 lit. a GDPR in conjunction with § 25 Para. 1 TDDDG. You give that consent through the "Statistics" category in our cookie banner. Without it, Google Analytics is not loaded.

b) Recipients of Data

The recipient of the data is Google Ireland Limited. Transmission to third countries, in particular the USA, cannot be ruled out. Google relies on the standard contractual clauses approved by the EU Commission for this purpose.

c) Storage Period

The data sent by us to Google and linked to cookies or identifiers will be automatically deleted after a maximum of 14 months.

d) Revocation of Consent

You can revoke your consent at any time with effect for the future by opening "Cookie settings" in the footer of any page and deselecting the "Statistics" category.

In addition, you can prevent the collection of your data by Google Analytics by installing the following browser plugin: https://tools.google.com/dlpage/gaoptout

Further information on data protection at Google can be found at: https://policies.google.com/privacy

Use of the Meta Pixel and the Conversions API (Facebook/Instagram)

On this website — not inside our Shopify App — we use the Meta Pixel and the Conversions API of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland ("Meta"). Neither is loaded or executed unless you have enabled the "Marketing" category in our cookie banner.

Purpose. We advertise our app on Facebook and Instagram. The Meta Pixel and the Conversions API show us which ad led to a visit to our website and to a click on our Shopify App Store listing. On that basis we build audiences for further advertising (including custom and lookalike audiences) and have Meta optimise the delivery of our ads.

Data processed. Transmitted are the cookie identifiers _fbp and _fbc, the click identifier fbclid from the ad link, your IP address, your browser identification (user agent), the address you opened, the time, and the event triggered (page view, view of the pricing or service pages, click through to the Shopify App Store, opening support). Not transmitted are names, email addresses or any other contact details: we have explicitly disabled the Pixel's automatic advanced matching, which reads out form fields.

Server-side transmission. We additionally transmit the same events through the Conversions API from our own server. The reason is purely technical: some events never reach Meta through the browser, because ad blockers or browser settings block the Pixel. No other kinds of data are transmitted than those named above. Both transmissions carry the same event identifier so that an event is not counted twice.

Cookies we set. ei-consent stores the decision you made in the cookie banner (necessary, lifetime 6 months). _fbp and _fbc are set by Meta (marketing, lifetime up to 90 days). We set no further cookies for this purpose.

a) Legal basis

Storing and reading the identifiers on your device, and the processing that follows, take place solely on the basis of your consent under Art. 6 (1) (a) GDPR in conjunction with § 25 (1) TDDDG. You give that consent through the "Marketing" category in our cookie banner. Without it, the Pixel is not loaded and no event is transmitted to Meta.

By selecting the "Marketing" category you also expressly consent to the transfer of your data to the USA (Art. 49 (1) (a) GDPR).

b) Joint controllership with Meta

For the collection of the data named above and its transmission to Meta, we and Meta are joint controllers within the meaning of Art. 26 GDPR. We have entered into Meta's Controller Addendum with Meta (https://www.facebook.com/legal/controller_addendum). It sets out which obligations are met by whom: in particular, Meta assumes responsibility for honouring your data subject rights with regard to the data stored at Meta. For any further processing after the transmission — in particular the combination with your Meta account — Meta is solely responsible.

c) Recipients and transfer to third countries

The recipient is Meta Platforms Ireland Limited. A transfer to Meta Platforms, Inc. in the USA takes place. Meta is certified under the EU-US Data Privacy Framework, for which the European Commission established an adequate level of protection by decision of 10 July 2023; standard contractual clauses apply in addition. It nevertheless cannot be ruled out that US authorities access the data, and that you do not have the same legal remedies against this as you would in the EU.

d) Storage period

The cookies we set expire after the periods named above. How long the event data stored at Meta is kept is determined by Meta; details can be found in Meta's privacy policy. The events triggered by your visit to this website we do not store ourselves: our server forwards them immediately and does not retain them.

e) Withdrawal of consent

You can withdraw your consent at any time with effect for the future by opening "Cookie settings" in the footer of any page and deselecting the "Marketing" category. The withdrawal takes effect immediately: the Pixel is removed, the identifiers _fbp and _fbc are deleted, and no further event is transmitted.

Independently of this, you can object to the use of your data for advertising in your Meta account settings: https://www.facebook.com/adpreferences.

Further information on data protection at Meta can be found at: https://www.facebook.com/privacy/policy

f) Reports from the Shopify App Store

When you click the link on this website to our Shopify App Store listing, you leave our website. What happens there is reported by Shopify — not by us — to the same Meta advertising account: that our listing was viewed, that the "Install" button was clicked, and that an install was completed. For the completed install, Shopify also transmits the name and the address of the installing shop. Shopify offers this to every app provider; all we do is enter our Pixel ID in the distribution settings of our app listing.

Controllership and legal basis. This processing takes place on apps.shopify.com, that is, on a Shopify website. Whether identifiers are stored and read there is governed by the Shopify App Store's own privacy and cookie settings, not by the choice you make in our cookie banner. For the processing of the data transmitted to the advertising account in this way, we and Meta are joint controllers within the meaning of Art. 26 GDPR (see b).

What we do NOT do. We transmit no information from your use of our app to Meta: neither the start of a trial, nor the conclusion or renewal of a paid subscription, no invoices, no revenue and none of your customers' data. Nor do we store any ad identifiers in our system for this purpose.

Use of Pipedrive Web Visitors (company identification)

On this website we use Pipedrive Web Visitors. The service is technically provided by Leadfeeder Oy (Dealfront Group), Keilaranta 16, 02150 Espoo, Finland; the identified companies are transferred into our CRM system Pipedrive (Pipedrive OÜ, Mustamäe tee 3a, 10615 Tallinn, Estonia). The script is loaded only if you have enabled the "Company identification" category in our cookie banner.

Purpose and how it works. Our app is aimed at merchants and agencies. The service matches your IP address against a database of commercial IP ranges in order to determine which company visited our website, and files that company together with the pages viewed as a sales contact. The aim is to approach companies, not to identify individual people. A match is only possible where your internet connection is registered to a company; private connections are usually resolved to the access provider only.

Data processed. Your IP address, the pages you opened, the time and duration of the visit, the referring page, and browser and device information. The cookie _lfa is set, which recognises your visit across sessions. Because an IP address is personal data, we treat this as processing of personal data — even though the result is a company name.

Legal basis. Your consent under Art. 6 (1) (a) GDPR in conjunction with § 25 (1) TDDDG, given through the "Company identification" category in the cookie banner. Without that consent the script is not loaded and no IP address is transmitted to the service.

Recipients and storage period. The recipients are Leadfeeder Oy and Pipedrive OÜ. Processing takes place within the European Union; a transfer to the USA is not envisaged for this service. The _lfa cookie has a lifetime of up to two years. Company data stored in the CRM is deleted once the sales contact is no longer pursued.

Withdrawal. You can withdraw your consent at any time with effect for the future via "Cookie settings" in the footer of any page. The _lfa cookie is deleted and no further data is transmitted.

Further information can be found in the providers' privacy notices: https://www.leadfeeder.com/privacy/ and https://www.pipedrive.com/en/privacy

9. Data Security and Security Measures

We use technical and organizational security measures to protect the data managed by us against accidental or intentional manipulation, loss, destruction or against access by unauthorized persons. Our security measures are continuously improved in accordance with technological development.

Access to your data is only possible for a limited group of people and is carried out exclusively within the framework of activities necessary for the fulfillment of contractual services.

10. Rights of Data Subjects

You have the following rights:

  • Right to information about your data stored with us
  • Right to correction of incorrect personal data
  • Right to deletion of your data stored with us, provided that no legal retention obligations oppose this
  • Right to restriction of processing of your personal data
  • Right to data portability
  • Right to object to the processing of your personal data

To exercise your rights, you can contact the responsible party mentioned above at any time.

11. Storage and Provision of Customer Data After Contract Termination

a) Grace Period for Data Access (3 Months)

After uninstallation or cancellation of the app, we grant you a grace period of 3 months during which you can access your data through our support team. During this period, you can:

  • Download all invoices as a ZIP export
  • Access all historical invoice data
  • Create exports for your accountant or your own archiving

Access is exclusively through our support (support@easy-invoices.de). You must prove that you are or were the owner or authorized person of the Shopify shop.

Legal basis: Art. 6 Para. 1 lit. b) GDPR (contract fulfillment) and Art. 6 Para. 1 lit. f) GDPR (legitimate interest in proper contract processing)

b) Automatic Deletion After 3 Months

After the 3-month grace period expires, all your personal data will be automatically and irrevocably deleted. This includes:

  • All invoice PDFs
  • All invoice metadata (numbers, amounts, dates)
  • Configuration data (templates, SMTP settings)
  • All other customer-related data

Important: Technical recovery of data after deletion is not possible. Please export and secure all important data in time within the 3-month period.

Legal basis: Art. 17 GDPR (Right to erasure)

c) Your Legal Retention Obligation

Important note: As the invoice issuer (shop owner) you must retain your invoices as accounting vouchers for eight years (§ 147 Abs. 1 Nr. 4 in conjunction with Abs. 3 AO, § 14b Abs. 1 UStG; shortened from ten to eight years on 1 January 2025). Books, inventories and annual accounts still carry ten years (§ 147 Abs. 1 Nr. 1 AO). Details on our data retention page.

Easy Invoices is a software service provider and creates invoices on your behalf. The legal retention obligation lies with you as the entrepreneur, not with us as the software provider.

Recommendation: Export all invoices regularly (monthly or annually) and store them securely. Use the app's export function or contact our support.

d) Identity Verification for Data Access

To access your data after cancellation, proof is required that you are or were the shop owner. Access is exclusively through our support.

Verification process:

  • Contact from the email address registered with Shopify
  • Provide your Shopify shop domain
  • If necessary: Proof through screenshot from Shopify admin or other documents
  • Processing time: 24-48 hours on business days

These security measures serve to protect your data from unauthorized access.

e) Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format (Art. 20 GDPR). The export includes:

  • All invoice PDFs
  • Metadata in JSON format
  • Configuration data

You can perform the export at any time through the app functions or request it through our support after cancellation.

f) Further Information

Detailed information about data retention after app uninstallation can be found on our data retention page.

12. Data Processing Pursuant to Art. 28 GDPR

In the course of using Easy Invoices, A&C Finance Solutions GbR acts as a processor within the meaning of Art. 28 GDPR. The Shopify merchants using Easy Invoices are the controllers for the processing of their end customers' personal data.

A Data Processing Agreement (DPA) is concluded electronically during the app's onboarding process. The DPA can be downloaded as a PDF document at any time via the app settings.

Categories of data processed:

  • Identification data (first and last name, company name)
  • Contact data (email address, phone number, postal address)
  • Order data (order numbers, line items, payment method)
  • Financial data (invoice amounts, currency)
  • Tax data (VAT ID, tax ID)

Processing purposes:

  • Automatic creation of invoices, cancellation invoices and credit notes
  • Generation of PDF documents
  • Sending invoice documents by email
  • Export and archiving of invoice data

Sub-processors used:

These providers process the data listed above on our behalf. The general authorisation under § 8 of the Data Processing Agreement covers only them, and only a change to this list triggers the prior notice and the merchant's right to object agreed there.

  • Hetzner Online GmbH (Germany/EU) — Server hosting, databases
  • Shopify Inc. (Canada/EU) — E-commerce platform
  • Sentry / Functional Software, Inc. (USA, EU hosting) — Error monitoring

Recipients outside the processing relationship:

The following services receive no invoice or end-customer data belonging to our merchants. They are used solely on this website and in our own sales process. For that we are ourselves the controller within the meaning of Art. 4 (7) GDPR, not a processor; they are therefore not sub-processors within the meaning of Art. 28 (2) GDPR:

  • Google LLC / Google Analytics (USA) — Landing page usage analysis (only with consent)
  • Meta Platforms Ireland Limited (Ireland/USA) — Landing page audience measurement and advertising (only with consent)
  • Leadfeeder Oy / Dealfront (Finland) — landing page company identification (only with consent)
  • Pipedrive OÜ (Estonia) — CRM for sales contacts

13. Changes to the Privacy Policy

We reserve the right to update this statement as needed at any time. The current version of the privacy policy can be viewed in the App. Please inform yourself regularly about the applicable data protection regulations.