Privacy policy
Last updated October 4, 2026
This policy explains what data the InvoiceHop Shopify app ("InvoiceHop", "we") handles when a merchant installs it, and how that data is used. InvoiceHop is operated by MerchMend. Questions: [email protected].
Our role
For the personal data of a store's customers, the merchant is the data controller and InvoiceHop is a data processor acting on the merchant's instructions. For the merchant's own account and contact details, InvoiceHop is the controller.
Data we collect
From the merchant's store
- Store name, domain, contact email and the access token Shopify issues to the app.
- Company details the merchant enters: legal name, address, VAT number, SIREN/SIRET, logo, bank details and legal wording printed on invoices.
- Order data needed to build invoices: order number, dates, line items, prices, discounts, taxes, shipping, refunds and payment status.
About the store's customers
- Name, email address, billing and shipping address, and phone number when it appears on the order.
- Business details: company name, VAT number, company ID (such as SIREN), purchase order number and Peppol ID, entered by the buyer on the cart, taken from Shopify B2B, or added by the merchant.
We don't collect payment card data. We don't use cookies or analytics on this website.
How we use it
- To create, number, store and display invoices and credit notes, as PDF and as e-invoice XML (Factur-X, Peppol UBL).
- To check buyer VAT numbers, when the merchant turns this on.
- To email documents to customers and let them download their invoices, when the merchant turns this on.
- To back up documents to the merchant's Google Drive, when the merchant connects it.
- To provide support and keep the service secure.
We never sell data, and we don't use it for advertising or to train AI models.
Who we share it with
| Recipient | Why | When |
|---|---|---|
| OVHcloud | Host the servers that run the app and its database | Always |
| European Commission (VIES) | Check a buyer's EU VAT number | If VAT checks are on |
| Resend | Send invoice emails to customers | If invoice emails are on |
| Google (Drive) | Save copies of documents in the merchant's Drive | If the merchant connects Drive |
| The merchant's e-invoicing provider | Deliver e-invoices to buyers | If the merchant connects a provider |
We may also disclose data when the law requires it.
How long we keep it
Issued invoices and credit notes are accounting records. Merchants must keep them for years (ten in France), so we keep them while the app is installed, even when a customer asks for their data to be erased. The merchant stays responsible for that retention. When a merchant uninstalls InvoiceHop, Shopify asks us to delete the store's data 48 hours later, and we then delete all invoices, settings and access tokens for that store. Merchants should export their documents before uninstalling.
Security
Data travels over HTTPS. Provider credentials and Google tokens are stored encrypted. Access to production systems is limited to the people who run the service.
Your rights
Customers of a store should contact that store first, since the merchant controls their data. Shopify forwards customer data and erasure requests to us, and we act on them as described above. Merchants can ask us for access, correction or deletion of their data at [email protected]. In the EU you can also complain to your data protection authority.
International transfers
Some of the services above may process data outside the European Economic Area. Where they do, we rely on safeguards such as the EU Standard Contractual Clauses.
Changes
We'll update this page when our practices change and show the date of the last update at the top.