Parchio

Security and data protection practices

Last updated: August 28, 2026

Purpose and minimization

We process only the Shopify order and customer data needed to create an invoice selected by a merchant or to send that invoice to a recipient chosen by the merchant. We do not sell personal data, use it for advertising, or make automated decisions about customers.

Access and audit records

Access to the app requires Shopify authentication. Access to infrastructure and service-provider accounts is restricted to authorized staff. The app records protected-data actions such as invoice exports, deliveries, and customer-email lookups without placing customer names, addresses, emails, phone numbers, or invoice contents in the audit record.

Storage, encryption, and retention

The app uses encrypted connections to Shopify and its service providers. Generated invoice files are not retained after the requested export or delivery finishes. Activity and security audit records are removed through the app’s 180-day retention-cleanup process, and shop records are deleted when Shopify sends an uninstall or shop-redaction request.

Data-loss prevention

We reduce data-loss risk through least-privilege access, protected secrets, encrypted service providers, limited retention, deletion webhooks, and a policy not to write customer data to application logs. We do not use merchant production customer data for application development or testing.

Security incidents

If we suspect unauthorized access, loss, or disclosure of personal data, we investigate promptly, contain the issue, preserve relevant evidence, rotate or revoke affected credentials, remediate the cause, and notify affected merchants, Shopify, and authorities when required by applicable law or contractual obligations.

Contact

For a security or privacy concern, contact us through the Parchio Support form.


Privacy Policy·Terms of Service