Privacy Policy

Invocourier — e‑invoicing for Shopify. Last updated 27 August 2026. · Back to invocourier.com

The short version

Invocourier turns a merchant's Shopify orders into legally compliant electronic invoices and delivers them. To do that we handle the buyer details that belong on an invoice — name, billing address, email, VAT number — on the merchant's behalf and under the merchant's instructions.

We never sell personal data, never use it for advertising, and never use it for anything other than producing, delivering and archiving the merchant's invoices. We keep the list of companies that help us run the service below, and we keep it current.

1. Who we are

CompanyLIQUID ECOMM S.R.L. (trading as Invocourier)
Registered officeStr. Dealu Nou 13A, Sat Sărata, Comuna Sărata, Bacău county, 607361, Romania
Tax ID (CUI)48989226
Trade RegistryJ2023001636041 (EUID ROONRC.J2023001636041)
Contact[email protected]
Supervisory authorityANSPDCP, Romania (dataprotection.ro)

We have not appointed a Data Protection Officer; we are not required to. Privacy questions go to the contact address above and are handled by the company's administrator.

2. Two different roles

Which rules apply depends on whose data it is. Invocourier wears two hats:

We are a processor for buyer data

The personal data that appears on invoices — the merchant's customers — belongs to the merchant. The merchant decides what to invoice and why; we act only on their instructions, through the app's settings. In GDPR terms the merchant is the controller and we are the processor. If you bought something from a shop and have a question about your data, contact that shop first; they are the right party to answer, and we will support them.

The obligations that bind us as a processor are set out in our Data Processing Agreement, which is entered into automatically with every merchant who installs the app.

We are a controller for our own business data

For the data we hold about merchants themselves — the account, the settings, billing — and for people who leave an email address on this website, we are the controller and this policy is our own notice to you.

3. What we process, and why

a. Buyer data on invoices (processor)

When an order qualifies for an invoice, Shopify sends us the order and we render the invoice document. That document contains: buyer name, billing address, email address, VAT or company registration number where the buyer provided one, the ordered items, and the amounts. We store the finished document (its XML, and the PDF where one was produced) plus the buyer name and VAT number as index fields so the merchant can find it.

We also store the result of VAT-number checks against the EU VIES service (the number, whether it was valid, the registered trader name, and when it was checked), because that is the evidence for the VAT treatment applied to the invoice.

Purpose and basis: producing and transmitting invoices that the merchant is legally required to issue. The merchant's basis is their legal obligation (GDPR art. 6(1)(c)); ours is our contract with the merchant (art. 6(1)(b)) and their documented instructions. We request the minimum an invoice needs — we do not ask Shopify for the buyer's phone number.

b. Merchant account data (controller)

The shop's .myshopify.com domain, the merchant's own company details entered in Settings (legal name, address, VAT number, company registration number, contact email and phone, bank IBAN where they add one for payment instructions), their invoicing preferences, the authentication session with Shopify, and the count of documents issued each month for billing.

Purpose and basis: providing and billing the service — our contract with the merchant (art. 6(1)(b)).

c. Email signups on this website (controller)

If you use the readiness checker and leave your email, we store the email address and the answers you selected (your country, whether you sell B2B, how you invoice today). We use it to send you the compliance checklist you asked for and to tell you when the connector launches for your country.

Basis: your consent (art. 6(1)(a)). You can withdraw it at any time by replying to any message or writing to [email protected], and we delete the address.

d. Technical logs

Our web server records requests in the ordinary way: IP address, time, the page requested, and the browser's user-agent string. This is what lets us diagnose faults and spot abuse. Basis: our legitimate interest in operating a secure service (art. 6(1)(f)).

4. Who else is involved

These companies process personal data on our behalf so that the service can run. Each is bound by a contract limiting them to our instructions.

WhoWhat they doWhere
Hetzner Online GmbHHosts the application and its database — all invoice data lives hereHelsinki, Finland (EU)
Cloudflare, Inc.DNS, TLS and the network edge in front of our serversGlobal edge; US company
Recommand BVPeppol access point — transmits invoices to Belgian recipients over the Peppol networkBelgium (EU)

Shopify is not in this list: Shopify is the merchant's own platform and the source the order data comes from, not a party we pass data to.

We keep this list current. Before any new sub-processor starts handling personal data — for example an email delivery provider for countries where invoices travel by email, or a French Plateforme Agréée when we support the French mandate — we update this page and notify merchants, so they can object.

5. Where data is processed

Invoice data is stored and processed inside the European Union, on servers in Helsinki, Finland. Documents sent over the Peppol network reach the recipient's access point, which is determined by the recipient's own registration.

Cloudflare, which operates the network edge in front of our servers, is a US company with a global network; traffic to this site may be routed through infrastructure outside the EU. Where that involves a transfer, it relies on the European Commission's Standard Contractual Clauses.

6. How long we keep it

Invoices, while the merchant uses Invocourier. Invoices are accounting records: the law obliges the merchant to keep them for years, not months (ten years in France and Germany, seven in Belgium, and so on). While the app is installed we keep the merchant's archive intact for exactly that reason.

An erasure request from a buyer does not delete an invoice. GDPR art. 17(3)(b) keeps records that exist to satisfy a legal obligation out of reach of erasure, and an issued invoice is such a record. When a request arrives, we tell the merchant which documents hold the buyer's data and confirm that we hold nothing else about them. Anything about that buyer that is not in an invoice, we do not keep in the first place.

Uninstalling deletes everything. When a merchant removes the app, Shopify notifies us 48 hours later and we delete all data for that shop, the archived invoices included. Our reason for holding them was that we act for the merchant; when the relationship ends, so does the basis, and the merchant's own statutory duty to keep the records travels with them. Merchants should download their documents from the Invoices page before uninstalling.

Everything else: merchant account data and settings are deleted with the shop, as above. Website signup emails are kept until you unsubscribe. Server logs are rotated and deleted after no more than 14 days.

7. Your rights

Under the GDPR you can ask for access to your personal data, correction of it, erasure, restriction of processing, portability, and you can object to processing based on legitimate interests. Where processing rests on consent, you can withdraw it at any time without affecting what was done beforehand.

If you are a shopper whose details appear on an invoice: please contact the shop you bought from. They decide what happens to that data; we act on their instructions and will help them respond.

If you are a merchant, or you signed up on this website: write to [email protected]. We answer within 30 days.

If you think we have handled your data badly, you are entitled to complain to your local data protection authority, or to ours: ANSPDCP in Romania.

8. Cookies

This website sets no cookies. There is no analytics, no tracking pixel and no advertising script on these pages — which is why you are not being asked to accept anything.

The application itself, inside the Shopify admin, sets only the session cookies needed to keep a merchant signed in. Those are strictly necessary and are not used to track anyone.

9. Security

Data is encrypted in transit (TLS everywhere) and at rest. Access to production systems is limited to the company's administrator, over key-based authentication only, and is logged. Backups are encrypted. We keep a written incident response procedure: if personal data is ever breached, we notify affected merchants without undue delay and the supervisory authority within 72 hours where the GDPR requires it.

10. Changes to this policy

When we change something material — a new sub-processor, a new category of data, a different retention period — we update the date at the top of this page and notify merchants before the change takes effect. Older versions are available on request.