Version 4.1 dated September 16, 2026
We are pleased that you are using our App. The protection of your privacy and the protection of your personal data, so-called personal data, when using our App is an important concern for us.
Personal data according to Art. 4 No. 1 GDPR are all information relating to an identified or identifiable natural person. This includes, for example, information such as your first and last name, your address, your phone number, your email address, but also your IP address.
Data for which no connection to your person can be established, such as through anonymization, are not personal data. The processing (e.g., collection, storage, retrieval, querying, use, transmission, deletion or destruction) according to Art. 4 No. 2 GDPR always requires a legal basis or your consent. Processed personal data must be deleted as soon as the purpose of processing has been achieved and no legally prescribed retention obligations need to be maintained.
Here you will find information about the handling of your personal data when using our App. To provide the functions and services of the App, it is necessary that we collect personal data about you.
We also explain to you the type and scope of the respective data processing, the purpose and the corresponding legal basis and the respective storage period.
This privacy policy applies only to this App. It does not apply to other websites or apps to which we merely refer via a hyperlink. We cannot assume responsibility for the confidential handling of your personal data on third-party websites or apps, as we have no influence on whether these companies comply with data protection regulations. Please inform yourself directly on these websites or apps about the handling of your personal data by these companies.
Responsible for the processing of personal data in connection with the use of the App is: A&C Finance Solutions
When you use this App, we collect technically necessary data via server log files that are automatically transmitted to our server, including:
This processing is technically necessary to be able to display our App to you. We also use the data to ensure the security and stability of our App.
The legal basis for this processing is Art. 6 para. 1 lit. f) GDPR. The processing of the mentioned data is necessary for the provision of an App and thus serves to protect a legitimate interest of our company.
As soon as the mentioned personal data are no longer required for displaying the App, they are deleted. The collection of data for the provision of the App and the storage of data in log files is mandatory for the operation of the App. Consequently, there is no possibility for the user to object to this aspect. Further storage may occur in individual cases if this is legally required.
In the pre-contractual area and when concluding a contract, we collect personal data about you. This includes, for example, first and last name, address, email address, phone number or bank details.
We collect and process this data exclusively for the purpose of contract performance or to fulfill pre-contractual obligations.
The legal basis for this is Art. 6 para. 1 lit. b) GDPR. If there is additionally consent from you, the additional legal basis is Art. 6 para. 1 lit. a) GDPR.
The data will be deleted as soon as they are no longer required for the purpose of their processing.
In addition, there may be legal retention obligations, for example commercial or tax retention obligations under the German Commercial Code (HGB) or the Fiscal Code (AO). If such retention obligations exist, we will block or delete your data at the end of these retention obligations.
We only store those order and customer data that are necessary for the creation of the respective documents (invoice, credit note, etc.).
The data is hosted on servers of Hetzner Online GmbH in Germany.
Users can have all personal data deleted at any time via the compliance interfaces integrated in Shopify.
We only pass on your personal data to third parties if:
We use such service providers in the following areas:
When transmitting to external parties in third countries, i.e., outside the EU or the EEA, we ensure that these parties treat your personal data with the same care as within the EU or the EEA. We only transmit personal data to third countries where the EU Commission has confirmed an adequate level of protection or if we ensure careful handling of personal data through contractual agreements or other appropriate guarantees.
There is the possibility to subscribe to a free regular email newsletter. To be able to send you the newsletter regularly, we need your email address from you.
For newsletter delivery, we use the so-called double opt-in procedure.
This means that we will only send you an email newsletter if you have expressly confirmed to us that you consent to receiving the newsletter. We will then send you a confirmation email asking you to confirm by clicking on a corresponding link that you want to receive newsletters from us in the future.
This serves to ensure that only you yourself can register for the newsletter as the owner of the specified email address. Your confirmation must be made promptly after receiving the confirmation email, otherwise your newsletter registration will be automatically deleted from our database.
When you subscribe to the newsletter, we collect and store the data you enter in the input form (e.g., last name, first name, email address).
When registering for the newsletter, we also store your IP address registered by the Internet Service Provider (ISP) as well as the date and time of registration to be able to trace any misuse of your email address at a later time. For the confirmation email sent for control purposes (double opt-in in the email), we also store the date and time of the click on the confirmation link and the IP address registered by the Internet Service Provider (ISP).
The data collected by us when registering for the newsletter is used exclusively for advertising purposes via the newsletter.
The processing of your email address for newsletter delivery is based on Art. 6 para. 1 lit. a) GDPR and § 7 para. 2 No. 3 UWG on the consent declaration that you voluntarily give below and can revoke at any time for the future.
In addition, the processing is based on Art. 6 para. 1 lit. f) GDPR due to legitimate interests on our part to document the proof of the required consent.
Your email address will be stored as long as you have subscribed to the newsletter. After unsubscribing from the newsletter, your email address will be deleted, unless you have expressly consented to further use of your data.
We use the web analysis service Google Analytics on our website, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). We do not use Google Analytics inside our Shopify app.
Google Analytics uses cookies and comparable technologies that are stored on your device and enable an analysis of the use of our website. The information generated by these technologies about your use of our website is usually transmitted to Google servers and stored there. This may also involve transmission to Google LLC servers in the USA.
We have activated the IP anonymization function. As a result, your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there.
Google processes this information on our behalf to evaluate the use of our website, to compile reports on activities, and to provide other services related to the use of our website.
The processing is based on your consent in accordance with Art. 6 Para. 1 lit. a GDPR in conjunction with § 25 Para. 1 TDDDG. You give that consent through the "Statistics" category in our cookie banner. Without it, Google Analytics is not loaded.
The recipient of the data is Google Ireland Limited. Transmission to third countries, in particular the USA, cannot be ruled out. Google relies on the standard contractual clauses approved by the EU Commission for this purpose.
The data sent by us to Google and linked to cookies or identifiers will be automatically deleted after a maximum of 14 months.
You can revoke your consent at any time with effect for the future by opening "Cookie settings" in the footer of any page and deselecting the "Statistics" category.
In addition, you can prevent the collection of your data by Google Analytics by installing the following browser plugin: https://tools.google.com/dlpage/gaoptout
Further information on data protection at Google can be found at: https://policies.google.com/privacy
On this website — not inside our Shopify App — we use the Meta Pixel and the Conversions API of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland ("Meta"). Neither is loaded or executed unless you have enabled the "Marketing" category in our cookie banner.
Purpose. We advertise our app on Facebook and Instagram. The Meta Pixel and the Conversions API show us which ad led to a visit to our website and to a click on our Shopify App Store listing. On that basis we build audiences for further advertising (including custom and lookalike audiences) and have Meta optimise the delivery of our ads.
Data processed. Transmitted are the cookie identifiers _fbp and
_fbc, the click identifier fbclid from the ad link, your IP address, your
browser identification (user agent), the address you opened, the time, and the event triggered (page
view, view of the pricing or service pages, click through to the Shopify App Store, opening support).
Not transmitted are names, email addresses or any other contact details: we have
explicitly disabled the Pixel's automatic advanced matching, which reads out form fields.
Server-side transmission. We additionally transmit the same events through the Conversions API from our own server. The reason is purely technical: some events never reach Meta through the browser, because ad blockers or browser settings block the Pixel. No other kinds of data are transmitted than those named above. Both transmissions carry the same event identifier so that an event is not counted twice.
Cookies we set. ei-consent stores the decision you made in the cookie
banner (necessary, lifetime 6 months). _fbp and _fbc are set by Meta
(marketing, lifetime up to 90 days). We set no further cookies for this purpose.
Storing and reading the identifiers on your device, and the processing that follows, take place solely on the basis of your consent under Art. 6 (1) (a) GDPR in conjunction with § 25 (1) TDDDG. You give that consent through the "Marketing" category in our cookie banner. Without it, the Pixel is not loaded and no event is transmitted to Meta.
By selecting the "Marketing" category you also expressly consent to the transfer of your data to the USA (Art. 49 (1) (a) GDPR).
For the collection of the data named above and its transmission to Meta, we and Meta are joint controllers within the meaning of Art. 26 GDPR. We have entered into Meta's Controller Addendum with Meta (https://www.facebook.com/legal/controller_addendum). It sets out which obligations are met by whom: in particular, Meta assumes responsibility for honouring your data subject rights with regard to the data stored at Meta. For any further processing after the transmission — in particular the combination with your Meta account — Meta is solely responsible.
The recipient is Meta Platforms Ireland Limited. A transfer to Meta Platforms, Inc. in the USA takes place. Meta is certified under the EU-US Data Privacy Framework, for which the European Commission established an adequate level of protection by decision of 10 July 2023; standard contractual clauses apply in addition. It nevertheless cannot be ruled out that US authorities access the data, and that you do not have the same legal remedies against this as you would in the EU.
The cookies we set expire after the periods named above. How long the event data stored at Meta is kept is determined by Meta; details can be found in Meta's privacy policy. The events triggered by your visit to this website we do not store ourselves: our server forwards them immediately and does not retain them.
You can withdraw your consent at any time with effect for the future by opening "Cookie settings" in the
footer of any page and deselecting the "Marketing" category. The withdrawal takes effect immediately: the
Pixel is removed, the identifiers _fbp and _fbc are deleted, and no further
event is transmitted.
Independently of this, you can object to the use of your data for advertising in your Meta account settings: https://www.facebook.com/adpreferences.
Further information on data protection at Meta can be found at: https://www.facebook.com/privacy/policy
When you click the link on this website to our Shopify App Store listing, you leave our website. What happens there is reported by Shopify — not by us — to the same Meta advertising account: that our listing was viewed, that the "Install" button was clicked, and that an install was completed. For the completed install, Shopify also transmits the name and the address of the installing shop. Shopify offers this to every app provider; all we do is enter our Pixel ID in the distribution settings of our app listing.
Controllership and legal basis. This processing takes place on
apps.shopify.com, that is, on a Shopify website. Whether identifiers are stored and read
there is governed by the Shopify App Store's own privacy and cookie settings, not by the choice you
make in our cookie banner. For the processing of the data transmitted to the advertising account in
this way, we and Meta are joint controllers within the meaning of Art. 26 GDPR (see b).
What we do NOT do. We transmit no information from your use of our app to Meta: neither the start of a trial, nor the conclusion or renewal of a paid subscription, no invoices, no revenue and none of your customers' data. Nor do we store any ad identifiers in our system for this purpose.
On this website we use Pipedrive Web Visitors. The service is technically provided by Leadfeeder Oy (Dealfront Group), Keilaranta 16, 02150 Espoo, Finland; the identified companies are transferred into our CRM system Pipedrive (Pipedrive OÜ, Mustamäe tee 3a, 10615 Tallinn, Estonia). The script is loaded only if you have enabled the "Company identification" category in our cookie banner.
Purpose and how it works. Our app is aimed at merchants and agencies. The service matches your IP address against a database of commercial IP ranges in order to determine which company visited our website, and files that company together with the pages viewed as a sales contact. The aim is to approach companies, not to identify individual people. A match is only possible where your internet connection is registered to a company; private connections are usually resolved to the access provider only.
Data processed. Your IP address, the pages you opened, the time and duration of
the visit, the referring page, and browser and device information. The cookie _lfa is
set, which recognises your visit across sessions. Because an IP address is personal data, we treat
this as processing of personal data — even though the result is a company name.
Legal basis. Your consent under Art. 6 (1) (a) GDPR in conjunction with § 25 (1) TDDDG, given through the "Company identification" category in the cookie banner. Without that consent the script is not loaded and no IP address is transmitted to the service.
Recipients and storage period. The recipients are Leadfeeder Oy and Pipedrive OÜ.
Processing takes place within the European Union; a transfer to the USA is not envisaged for this
service. The _lfa cookie has a lifetime of up to two years. Company data stored in
the CRM is deleted once the sales contact is no longer pursued.
Withdrawal. You can withdraw your consent at any time with effect for the future
via "Cookie settings" in the footer of any page. The _lfa cookie is deleted and no
further data is transmitted.
Further information can be found in the providers' privacy notices: https://www.leadfeeder.com/privacy/ and https://www.pipedrive.com/en/privacy
We use technical and organizational security measures to protect the data managed by us against accidental or intentional manipulation, loss, destruction or against access by unauthorized persons. Our security measures are continuously improved in accordance with technological development.
Access to your data is only possible for a limited group of people and is carried out exclusively within the framework of activities necessary for the fulfillment of contractual services.
You have the following rights:
To exercise your rights, you can contact the responsible party mentioned above at any time.
After uninstallation or cancellation of the app, we grant you a grace period of 3 months during which you can access your data through our support team. During this period, you can:
Access is exclusively through our support (support@easy-invoices.de). You must prove that you are or were the owner or authorized person of the Shopify shop.
Legal basis: Art. 6 Para. 1 lit. b) GDPR (contract fulfillment) and Art. 6 Para. 1 lit. f) GDPR (legitimate interest in proper contract processing)
After the 3-month grace period expires, all your personal data will be automatically and irrevocably deleted. This includes:
Important: Technical recovery of data after deletion is not possible. Please export and secure all important data in time within the 3-month period.
Legal basis: Art. 17 GDPR (Right to erasure)
Important note: As the invoice issuer (shop owner) you must retain your invoices as accounting vouchers for eight years (§ 147 Abs. 1 Nr. 4 in conjunction with Abs. 3 AO, § 14b Abs. 1 UStG; shortened from ten to eight years on 1 January 2025). Books, inventories and annual accounts still carry ten years (§ 147 Abs. 1 Nr. 1 AO). Details on our data retention page.
Easy Invoices is a software service provider and creates invoices on your behalf. The legal retention obligation lies with you as the entrepreneur, not with us as the software provider.
Recommendation: Export all invoices regularly (monthly or annually) and store them securely. Use the app's export function or contact our support.
To access your data after cancellation, proof is required that you are or were the shop owner. Access is exclusively through our support.
Verification process:
These security measures serve to protect your data from unauthorized access.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format (Art. 20 GDPR). The export includes:
You can perform the export at any time through the app functions or request it through our support after cancellation.
Detailed information about data retention after app uninstallation can be found on our data retention page.
In the course of using Easy Invoices, A&C Finance Solutions GbR acts as a processor within the meaning of Art. 28 GDPR. The Shopify merchants using Easy Invoices are the controllers for the processing of their end customers' personal data.
A Data Processing Agreement (DPA) is concluded electronically during the app's onboarding process. The DPA can be downloaded as a PDF document at any time via the app settings.
Categories of data processed:
Processing purposes:
Sub-processors used:
These providers process the data listed above on our behalf. The general authorisation under § 8 of the Data Processing Agreement covers only them, and only a change to this list triggers the prior notice and the merchant's right to object agreed there.
Recipients outside the processing relationship:
The following services receive no invoice or end-customer data belonging to our merchants. They are used solely on this website and in our own sales process. For that we are ourselves the controller within the meaning of Art. 4 (7) GDPR, not a processor; they are therefore not sub-processors within the meaning of Art. 28 (2) GDPR:
We reserve the right to update this statement as needed at any time. The current version of the privacy policy can be viewed in the App. Please inform yourself regularly about the applicable data protection regulations.