Security and data protection practices
Last updated: August 28, 2026
Purpose and minimization
We process only the Shopify order and customer data needed to create an invoice selected by a merchant or to send that invoice to a recipient chosen by the merchant. We do not sell personal data, use it for advertising, or make automated decisions about customers.
Access and audit records
Access to the app requires Shopify authentication. Access to infrastructure and service-provider accounts is restricted to authorized staff. The app records protected-data actions such as invoice exports, deliveries, and customer-email lookups without placing customer names, addresses, emails, phone numbers, or invoice contents in the audit record.
Storage, encryption, and retention
The app uses encrypted connections to Shopify and its service providers. Generated invoice files are not retained after the requested export or delivery finishes. Activity and security audit records are removed through the app’s 180-day retention-cleanup process, and shop records are deleted when Shopify sends an uninstall or shop-redaction request.
Data-loss prevention
We reduce data-loss risk through least-privilege access, protected secrets, encrypted service providers, limited retention, deletion webhooks, and a policy not to write customer data to application logs. We do not use merchant production customer data for application development or testing.
Security incidents
If we suspect unauthorized access, loss, or disclosure of personal data, we investigate promptly, contain the issue, preserve relevant evidence, rotate or revoke affected credentials, remediate the cause, and notify affected merchants, Shopify, and authorities when required by applicable law or contractual obligations.
Contact
For a security or privacy concern, contact us through the Parchio Support form.
Privacy Policy·Terms of Service