GST Manager for Shopify — Privacy Policy
GST Manager helps Shopify merchants in India comply with Goods and Services Tax (GST) rules — capturing GSTINs, splitting tax into CGST/SGST/IGST, generating GST tax invoices and credit notes, and producing GST return reports. This policy explains what data the App accesses, why, how we store and protect it, and the choices available to merchants and their customers.
1. Who is the data controller
For data the App processes on a merchant’s behalf, the merchant is the data controller and Relyweb is the data processor. Relyweb processes personal data only to provide the App’s functionality to that merchant, under Shopify’s API Terms and the Shopify Protected Customer Data requirements.
2. What data we access
We request only the data needed to make a store GST-compliant.
Merchant / store data
- Store identity: shop domain, store name, legal business name, contact email and phone.
- Business tax identity: merchant GSTIN(s), state code, dispatch location addresses.
- App configuration you enter (invoice numbering, branding, tax settings, email settings).
Protected customer data (accessed via the Shopify Admin API and Customer Account API)
- Customer and order information needed to produce a correct GST invoice: customer name, email, phone, billing and shipping addresses, the customer’s GSTIN (when provided), order line items, amounts, taxes, fulfillments, and refunds.
We do not access payment card numbers, bank details, or passwords. We do not request data unrelated to GST invoicing and reporting.
3. Why we use it (purpose)
- App functionality: generate GST tax invoices, proforma invoices, and credit notes; calculate the CGST/SGST/IGST split based on place of supply; produce GSTR-1 / GSTR-3B return files; and (optionally) email these documents to the customer or merchant.
- Store management: show merchants their GST activity (dashboards, customer/GSTIN lists, report history) and let them re-issue or correct documents.
We process protected customer data strictly to deliver these features and for no other purpose. We do not sell personal data, and we do not use it for advertising or profiling.
4. Where data is stored
- Primary store of record: most domain data (GSTIN, invoice numbers, tax breakdown, party snapshots) is written back to Shopify metafields, so it stays on Shopify’s infrastructure with the resource it describes.
- Operational data: counters, generated report/PDF files, email-delivery records, a customer/GSTIN index, and import job records are stored in the App’s database, hosted in Asia-Pacific (India).
- Secrets: any merchant-supplied credentials (e.g. an email provider API key or SMTP password) are encrypted at rest using AES-256-GCM before storage.
5. Sharing with third parties (sub-processors)
We share data only with service providers that help operate the App, under contract and only as needed:
- Shopify — the platform the App runs on (hosting of metafields, Admin/Customer Account APIs, billing).
- Email delivery provider(s) — when transactional email is enabled, the customer’s email address and the relevant invoice/credit-note PDF are sent to our email service provider solely to deliver that message. Merchants who configure “Send via Own Email” use their own provider instead.
We do not share personal data with any other parties except where required by law.
6. Data retention and deletion
- Data stored in Shopify metafields persists with the store and is governed by the merchant’s own retention choices.
- Operational data in the App’s database is retained for as long as the App is installed.
- We honour Shopify’s mandatory compliance webhooks:
customers/redact— we delete the personal data we hold for the specified customer.shop/redact— 48 hours after a store uninstalls, we delete the store’s data from our database.customers/data_request— we provide the merchant the personal data we hold for a customer so they can fulfil the request.
- A merchant can also uninstall the App at any time, which stops all further processing.
7. Security
We apply industry-standard safeguards: encrypted transport (HTTPS/TLS), encryption of sensitive secrets at rest (AES-256-GCM), HMAC verification of all incoming Shopify webhooks and app-proxy requests, scoped access tokens, and least-privilege API scopes. No method of transmission or storage is 100% secure, but we work to protect data using reasonable technical and organisational measures.
8. Legal bases and rights
We process personal data to perform the service requested by the merchant and to comply with applicable law (including India’s Digital Personal Data Protection Act, 2023, and — where relevant — the EU/UK GDPR). Data subjects may exercise their rights (access, correction, deletion) through the merchant, who is the controller. Merchants and customers can also contact us at [email protected] for assistance, and we will support the controller’s response.
9. Children
The App is a business tool and is not directed to children. We do not knowingly collect personal data from children.
10. Changes to this policy
We may update this policy as the App evolves or as the law requires. Material changes will be reflected by updating the effective date above and, where appropriate, notifying merchants.
11. Contact
Relyweb Technologies Private Limited
Privacy / data requests: [email protected]
Support: [email protected]
501, 5th Floor, Shapath 1, S.G. Highway, Bodakdev, Ahmedabad — 380054, Gujarat, India