Legal
Privacy Policy
What VATquarter reads from your Shopify store, what it keeps, and how to have it deleted.
Who we are
VATquarter is operated by Tallgrass Apps LLC, a Missouri limited liability company (“we”, “us”). We are the data controller for the app’s own records and a processor of your store’s order data on your behalf. Contact: [email protected].
What the app reads
When you generate a report, VATquarter reads the following from your Shopify store through the Admin API, for the period you chose: order identifiers, dates, financial status, currency, line-item and shipping amounts and tax lines, discount allocations, the destination country and province codes of the shipping address, refund line items and adjustments, fulfillment location country and postcode, and order attributes used to detect business (B2B) orders. It also reads your store’s name, currency, timezone, country and plan.
Orders are “protected customer data” under Shopify’s rules, and VATquarter holds Level 1 access for tax-compliance purposes. It does not request any Level 2 field: it never reads customer names, address lines, postcodes, phone numbers or email addresses.
What the app stores
- Settings: your Member State of identification, dispatch country, period rules and plan.
- Report results: aggregated taxable amounts and VAT per country and rate, and per-order rows containing the Shopify order ID and name, date, country, rate and amounts. These rows exist so that you and your accountant can trace every figure to an order. Where a VAT number was captured on an order, only a masked form (country prefix and last two characters) is stored.
- Exchange rates: public European Central Bank reference rates.
- Session data needed to authenticate your store with Shopify.
Order data is read on demand and reduced to the rows above; the raw order export is not retained after the report is built.
What we do not do
We do not sell data, share it with advertisers, or use it to train models. We do not contact your customers. We do not change anything in your store: the app has read-only access to orders.
Where data is processed
The app and its database run on Railway infrastructure in the United States. Shopify’s order export files are downloaded from Shopify’s servers over an encrypted connection and discarded after processing. If you are subject to the GDPR, the transfer relies on Shopify’s and Railway’s standard contractual clauses; the personal data involved is limited to order identifiers and destination locality, as described above.
Retention and deletion
Report results are kept while the app is installed so you can reopen past periods. When you uninstall, Shopify sends a shop/redact request 48 hours later and we delete all data for your store, including settings, sessions and report results. You can also request deletion at any time by emailing [email protected] from the store’s owner address.
When Shopify sends a customers/redact request, the per-order rows for the orders it lists are removed from stored reports. customers/data_request is acknowledged; the order-level rows we hold are a subset of your own order records.
Security
Access tokens are stored encrypted at rest, all traffic uses TLS, and access to production systems is limited to the operator. Report the security issue you found to [email protected]; we respond within two business days.
Cookies and analytics
The app inside Shopify uses only the session mechanisms Shopify requires for embedded apps. This website sets no tracking cookies.
Your rights
If you are in the EU, UK or another jurisdiction with data-protection rights, you can ask us to access, correct, export or delete the data we hold about your store, and you can complain to your supervisory authority. Email [email protected].
Changes
We will post changes to this policy here and update the effective date. Material changes will be announced inside the app.