InvoiceKit Privacy Policy
**Effective date:** September 21, 2026
InvoiceKit is a Shopify application operated by Atamgo Media Advertising LTD
(“Atamgo”, “we”, “us”, or “our”). This Privacy Policy explains how InvoiceKit
collects, uses, stores, and shares information when Shopify merchants install or use
the app.
For personal information contained in a merchant’s Shopify store, the merchant is
generally the data controller and InvoiceKit acts as a service provider or processor
on the merchant’s behalf. Merchants remain responsible for their own privacy notices
and obligations to their customers.
## Information InvoiceKit processes
Depending on the features selected by a merchant, InvoiceKit processes:
– **Shop and merchant information:** shop domain, store name, locale, currency,
timezone, installation status, approved Shopify scopes, subscription/entitlement
information, and merchant-provided company and contact details.
– **Document settings:** company identity, logo URL, address, phone/email, tax and
registration identifiers, invoice numbering, template preferences, and optional
payment instructions entered by the merchant.
– **Customer and order information:** customer name, email, phone, billing and shipping
address when available, order identifiers, dates and status, line items, quantities,
prices, discounts, taxes, totals, currency, fulfillment, tracking, and refund data.
– **Draft order information:** only when the merchant separately grants Shopify’s
optional `read_draft_orders` permission. InvoiceKit uses this information on a
read-only basis to display a draft and prepare a pro forma document.
– **Documents and email information:** invoice and document records, generated PDF
files, expiring public-document links, email templates and settings, sender,
recipient and merchant-configured Reply-To information, message subject, related
order/document reference, and delivery, bounce, or complaint status returned by the
email delivery provider.
– **Technical and security information:** timestamps, authentication and webhook
verification records, and limited request information such as IP address and
user-agent information contained in server traffic and security logs.
InvoiceKit does not require customer payment-card numbers and does not process Shopify
checkout card details. Shopify handles app subscription billing.
## How information is collected
InvoiceKit receives information:
– through Shopify APIs and authenticated Shopify webhooks;
– directly from merchants when they configure company, document, email, or Reply-To
settings;
– when an authorized merchant user generates, downloads, prints, or emails a
document; and
– from the transactional email provider when it reports message delivery status.
InvoiceKit does not collect information directly from shoppers through storefront
cookies, advertising pixels, or behavioral tracking. Cookies or analytics used on the
Atamgo public website are separate from InvoiceKit’s processing of Shopify merchant
and customer data and are controlled through that website’s cookie settings.
## How information is used
InvoiceKit uses information only to:
– authenticate and authorize merchant and staff access;
– keep each Shopify store’s information separated;
– retrieve supported order, customer, fulfillment, refund, and optionally authorized
draft-order information;
– generate, render, number, display, download, and print documents;
– send documents requested by an authorized merchant user and direct replies to the
monitored Reply-To mailbox configured by the merchant;
– show message delivery status and prevent duplicate or unsafe sends;
– verify plan entitlements through Shopify;
– provide support, troubleshoot problems, and protect and operate the service; and
– respond to Shopify privacy/compliance webhooks and applicable data-rights requests.
InvoiceKit does not sell merchant or customer personal information and does not use it
for targeted advertising or data brokerage.
## Shopify permissions and data minimization
InvoiceKit uses the Shopify permissions needed to provide its document functions.
The required scopes are `read_orders` and `read_customers`. Access to Draft Orders uses
the separate optional `read_draft_orders` scope. InvoiceKit does not require write
access to orders or draft orders for these features.
Optional merchant settings can be left blank. InvoiceKit limits processing to the
information needed for the functions selected by the merchant.
## Sharing and service providers
InvoiceKit shares information only as needed with:
– **Shopify**, for app authentication, APIs, webhooks, protected customer data access,
and app subscription billing;
– **Resend and its delivery infrastructure**, when a merchant sends a document by
email and for authenticated delivery-status callbacks;
– **hosting and infrastructure providers**, to run the application, database, file
storage, networking, backups, and security controls; and
– legal or regulatory authorities when disclosure is required by applicable law.
Service providers receive only the information needed to perform their services.
InvoiceKit does not sell personal information to these providers.
## Retention and deletion
InvoiceKit retains active merchant settings, document records, and related operational
information while the app is installed and for as long as needed to provide and
support the service, comply with legal obligations, resolve disputes, or protect the
service.
– Privacy data-request export files expire after 30 days.
– Ordinary public-document links expire after 30 days and can be revoked sooner.
– Customer-redaction requests remove or redact matching stored customer and order
personal fields, revoke affected public links, and remove affected cached PDFs.
– Shop-redaction requests remove archived shop data and associated privacy-export
records in accordance with Shopify’s mandatory privacy workflow.
– Operational rollback backups are normally retained for up to 30 days. The newest
verified recovery copies can be retained longer until newer valid copies replace
them. A specific legal or security hold can extend retention where required.
– Documents already delivered to an external recipient cannot be recalled from that
recipient’s mailbox.
## Security
InvoiceKit uses administrative, technical, and organizational safeguards appropriate
to the service, including HTTPS/TLS, authenticated Shopify sessions and webhooks,
authenticated email-provider callbacks, access controls, tenant separation,
restricted server-side storage, expiring and revocable document links, and controls
against duplicate or replayed email operations.
No system or method of electronic transmission or storage can be guaranteed to be
completely secure.
## Privacy rights and requests
Shopify sends InvoiceKit the mandatory `customers/data_request`,
`customers/redact`, and `shop/redact` compliance webhooks. InvoiceKit verifies these
requests before processing them.
Customers should normally direct access, correction, deletion, restriction, or other
privacy requests to the Shopify merchant with which they have a relationship. The
merchant can then use Shopify’s privacy process or contact us for assistance.
Merchants and other authorized parties can contact us at contact@ecomgrowth.ma.
## International processing
InvoiceKit and its service providers may process information in countries where
Atamgo and those providers operate. Where applicable law requires it, appropriate
contractual or other transfer safeguards are used.
## Children’s privacy
InvoiceKit is a business application for Shopify merchants and is not directed to
children. It is not intended to independently collect personal information directly
from children.
## Changes to this policy
We may update this policy when InvoiceKit’s features, providers, or legal obligations
change. The current effective date will be displayed at the top of this page.
## Contact us
Atamgo Media Advertising LTD
7 Coronation Road, Dephna House
London NW10 7PQ, United Kingdom
Email: contact@ecomgrowth.ma