Privacy Policy
AppSaaz Automated GST Invoice, by AppSaaz Labs · Last updated July 28, 2026
AppSaaz Automated GST Invoice ("the app", "we", "us") reads a merchant's
Shopify orders, customers, and products to generate GST-compliant tax
invoices, credit notes, debit notes, and GSTR-1/GSTR-3B return filing
exports — entirely within the app. We do not send merchant data to any
third-party bookkeeping or accounting platform.
Data we process
For each order, refund, or cancellation, we process:
- Customer name, email, and shipping/billing address — used to populate the invoice/credit note and to determine place of supply (CGST+SGST vs. IGST).
- Customer GSTIN, when provided at checkout — used to mark the invoice as B2B.
- Order line items, prices, quantities, discounts, and shipping — used to compute GST and build the invoice.
- Product HSN/SAC codes and GST rates, as configured by the merchant.
- Merchant shop settings — Shopify domain, legal business name, business address, GSTIN, state code, and app configuration — used to configure tax settings and format invoice headers.
We do not process payment card details, and we do not process customer phone numbers — the phone field on an order is discarded and never stored or printed on any document.
How the data is used
Invoice data is used solely to generate and store the merchant's own GST
records, and to email the invoice to the customer if the merchant enables
that. It is never used for marketing, advertising, analytics, or profiling,
and it is never sold.
Error diagnostics
When something in the app fails, we record the fault so it can be fixed
without waiting for the merchant to report it. These records contain the
error message, the code location, the Shopify shop domain, and the page the
merchant was on.
Customer names, addresses, email addresses, and phone numbers are
removed automatically before a fault record is stored or sent, along
with anything else in the surrounding data that could identify an individual.
Diagnosing a fault does not require them. Fault records are used only to fix
the app, are never used for analytics, marketing, or profiling, and are never
shared or sold.
How the data is stored and secured
- Webhook payloads awaiting processing are encrypted at rest (AES-256-GCM) and cleared immediately after successful processing.
- All communication with Shopify happens over HTTPS.
- Data is hosted and processed on cloud infrastructure provided by Fly.io, in their Singapore ("sin") region.
- Generated invoices, credit notes, and debit notes are not deleted on a customer data-erasure request — see "Data retention" below for why.
Data retention
Indian GST law (CGST Rules) requires merchants to retain tax invoices,
credit notes, and debit notes for several years from the due date of the
relevant annual return. Because of this:
- Invoice, credit note, and debit note records are retained even after a Shopify customer or shop data-erasure request, since they are the merchant's statutory tax records, not marketing data.
- Queued webhook payloads are deleted automatically immediately after they're processed successfully.
- All other shop data (settings, GSTIN/HSN configuration, queued background jobs, session, billing state) is purged automatically within 48 hours of a merchant uninstalling the app.
Third parties
We share data only with the following sub-processors:
- Resend (privacy policy) — only if the merchant enables automatic invoice emailing, to deliver the PDF to the customer's email address.
- Shopify (privacy policy) — as the platform this app is built on.
- Fly.io (privacy policy) — our cloud hosting provider; all app data is stored on their infrastructure.
This app does not submit e-invoices (IRN/QR) or e-way bills to the GST
Network or any GST Suvidha Provider, and holds no credentials for doing so.
No invoice data leaves this app for any government or GSP endpoint.
Data subject rights & Shopify privacy requests
This app receives and handles Shopify's three mandatory privacy webhooks:
- Customer data request — when a customer asks what data we hold about them, we don't auto-export it outside the app; we log any matching invoices so the merchant can find and share them from their dashboard (Invoices → search by customer email).
- Customer redact — when a customer requests erasure, any queued (not-yet-processed) webhook data matching them is scrubbed immediately. Issued invoices, credit notes, and debit notes are not deleted, because Indian GST law (CGST Rules) requires merchants to retain them as statutory tax records for several years, independent of an erasure request made under GDPR or India's DPDP Act.
- Shop redact — sent roughly 48 hours after a merchant uninstalls the app; all operational data (settings, GSTIN/HSN configuration, sessions, queued jobs, billing state) is deleted automatically. Statutory tax records are retained for the same legal reason as above.
Since this app processes data on behalf of merchants (as a data
processor under GDPR, and under India's DPDP Act, not the data controller),
a customer's request to access, correct, or delete their personal data
should go to the merchant whose store they purchased from, subject to the
merchant's own statutory GST record-keeping obligations. The merchant can
contact us using the details below for help fulfilling such requests.
Changes to this policy
We'll update the "Last updated" date above whenever this policy changes.
For any change that materially affects how personal data is processed,
we'll email connected merchants at their Shopify-registered account email
at least 14 days before the change takes effect.