Privacy & data use

Last updated 16 August 2026

Who we are

VATparity is operated by [legal name / sole trader name], [country]. Contact: [support email]. We are the data controller for the data described here.

What the app stores, and why

DataWhyWhere it lives
Your shop domain and an API access token To read your store’s tax-relevant configuration and run scan calculations Encrypted app database
Your setup answers (VAT registrations held, how you sell B2B, tax service) They decide what “correct VAT” means for your store; Shopify’s API cannot read them Settings
Auto-read shop facts (country, currency, tax-inclusive flag, markets, locations) Scan scoping Settings
Scan evidence — one row per test scenario: inputs, Shopify’s raw calculation response, expected vs actual, verdict The product is this evidence Scan records
An email address you type in (optional) Weekly change alerts, paid plan only Settings
Change alerts — what changed between two scans, and whether the email about it was sent The monitoring feature’s record Alert records

What the app does not store

No personal data about your customers. Every scan scenario is priced against the app’s own four synthetic test records — two test customers (vatparity-…@example.com; stores installed before the August 2026 rename carry the earlier vatproof-parity-…@example.com pair — both generations are app-created and removable) and two test products, created by the app, listed on the Setup screen, removable there with one click. The app never reads your buyers’ names, addresses, or order contents (it holds no orders permission). Draft-order calculations are used throughout — nothing is ever ordered or paid for, and no prices, themes, or checkout settings are ever changed.

Payment data

Billing is handled entirely by Shopify’s Billing API. We never see a card number or bank detail.

Sharing

Data is shared with no one, sold to no one, and used to train nothing. Subprocessors: [hosting provider] (the app database) and — only if email alerts are configured — [Resend, or the provider in use], which receives the alert email address and the alert text. That is the complete list.

Retention and deletion

Uninstalling the app deletes everything we hold about your shop, in one transaction, when the uninstall notification arrives — and Shopify’s shop/redact notification re-runs the same purge about 48 hours later as a guarantee. The app’s test records in your store are removed best-effort at uninstall (Shopify revokes our access at that moment, so the reliable path is the one-click “Remove test data” button on Setup, which works while the app is installed). Exports you downloaded are yours and outside our reach.

Your rights

GDPR data-subject requests relayed by Shopify are honoured through the mandatory compliance webhooks; direct requests reach us at [support email].

Cookies

The embedded app uses only the session tokens Shopify’s App Bridge provides. No analytics, no advertising, no third-party cookies. This website sets no cookies at all.

These are software test results, not tax advice.