This Privacy Policy explains how Attesta ("the App"), operated by Obarito ("we", "us"), handles data when you install and use the App on your Shopify store. Attesta writes invoices, so unlike our other apps it does process personal data about your buyers. This policy sets out exactly which data, why, and how long we keep it.
Two relationships run in parallel, and which one applies decides who answers a question about the data.
If one of your buyers contacts us directly about their data, we will point them to you, because the decision about their data is yours to make.
The processor relationship is set out in full in our Data Processing Agreement, which takes effect when you install the App.
A German invoice has to name the person it is addressed to, so an invoicing app cannot avoid buyer personal data the way a catalog app can. To produce the document, Attesta processes the buyer's name and any company name, the invoice address, the email address the invoice is sent to, the EU VAT ID where a business buyer provides one, and the contents and amounts of the order. These are the fields EN 16931 and §14 UStG require the invoice to carry.
Attesta never receives card numbers, bank credentials or any other payment instrument. Payment is handled by Shopify and its payment providers, and the App only learns that an order was paid and for how much.
Access to buyer data is granted by Shopify under its Protected Customer Data terms, and we use it only for the purposes set out below.
We do not sell data, we do not share it for advertising, and we do not use the contents of your invoices to train machine-learning models.
Attesta requests three read scopes and no write scope: read_orders, which drives invoicing; read_customers, which backs VAT-ID capture from a business buyer's account; and read_products, which fills in the line-item detail. The App does not modify your catalog, your orders or your customers.
It subscribes to order webhooks so that a paid order, a refund or an edit reaches the invoicing pipeline. It also registers the three privacy webhooks Shopify requires:
We pass data to others only where running the App requires it:
A current list of our sub-processors, with the entity and the country each operates in, is available on request from support@obarito.com.
An issued invoice is not ordinary app data. German law requires it to be kept, complete and unaltered, for ten years (GoBD, §14b UStG). GDPR Art. 17(3)(b) is explicit that the right to erasure does not apply where processing is necessary to meet a legal retention obligation. That produces three different outcomes, and it is worth knowing which is which.
shop/redact we erase what we hold for your shop as your processor: your seller profile, the invoice ledger, the archived PDFs, the VIES evidence and your logo. Your ten-year duty does not end with the uninstall, it stays with you as the controller, so export your GoBD ZIP before you leave.Operational logs are kept only as long as they are useful for running and debugging the service.
Where we are the controller, you have the rights the GDPR gives you: access, rectification, erasure, restriction of processing, portability and objection, and you may complain to your supervisory authority. Write to support@obarito.com and we will answer within the statutory period.
Where you are the controller and we process buyer data for you, you can exercise the same rights on your buyers' behalf through the App: the ledger and the exports give you everything we hold, subject to the retention limit above.
Data moves over HTTPS and is stored on access-controlled infrastructure. Archived invoices are kept outside the public web root and are served only to the shop that owns them, through links that are scoped and time-limited. Each document's hash is chained to the one before it, so a change to an archived invoice is detectable rather than silent.
Buyer personal data is encrypted at rest with AES-256, not only in transit. That covers the buyer name, VAT ID and email we store against an invoice, the EN 16931 XML and the stored invoice view (both of which carry the full billing address), the order payload behind a failed invoice attempt, the trader details VIES returns, and your Shopify access token. The archived PDFs are encrypted on disk as well, so a copy of the archive without the key is not readable.
There is no admin panel and no support login, so there is no screen through which we can browse your invoices. Every request is authenticated by a Shopify session token and every database query is scoped to the shop making it, so one merchant's data is not reachable from another's session. Reads of buyer data through the App, meaning invoice views, downloads and the two bulk exports, are written to a separate access log that records who read what and when, never the data itself. That log is kept for one year.
No system is perfectly secure, and we do not claim otherwise, but we take reasonable measures to protect what we hold.
We may update this policy. Material changes will be reflected in the "Last updated" date above, and where the change affects how buyer data is processed we will tell you before it takes effect.
Privacy questions, and anything else about using the App, go to support@obarito.com. Day to day usage is covered in the guide, and our Terms of Service cover the rest of the relationship.