Last updated 16 August 2026
VATparity is operated by [legal name / sole trader name], [country]. Contact: [support email]. We are the data controller for the data described here.
| Data | Why | Where it lives |
|---|---|---|
| Your shop domain and an API access token | To read your store’s tax-relevant configuration and run scan calculations | Encrypted app database |
| Your setup answers (VAT registrations held, how you sell B2B, tax service) | They decide what “correct VAT” means for your store; Shopify’s API cannot read them | Settings |
| Auto-read shop facts (country, currency, tax-inclusive flag, markets, locations) | Scan scoping | Settings |
| Scan evidence — one row per test scenario: inputs, Shopify’s raw calculation response, expected vs actual, verdict | The product is this evidence | Scan records |
| An email address you type in (optional) | Weekly change alerts, paid plan only | Settings |
| Change alerts — what changed between two scans, and whether the email about it was sent | The monitoring feature’s record | Alert records |
No personal data about your customers. Every scan scenario is priced against the
app’s own four synthetic test records — two test customers
(vatparity-…@example.com; stores installed before the August 2026
rename carry the earlier vatproof-parity-…@example.com pair — both
generations are app-created and removable) and two test products, created by the
app, listed on the Setup screen, removable there with one click. The app never
reads your buyers’ names, addresses, or order contents (it holds no orders
permission). Draft-order calculations are used throughout — nothing is
ever ordered or paid for, and no prices, themes, or checkout settings are ever
changed.
Billing is handled entirely by Shopify’s Billing API. We never see a card number or bank detail.
Data is shared with no one, sold to no one, and used to train nothing. Subprocessors: [hosting provider] (the app database) and — only if email alerts are configured — [Resend, or the provider in use], which receives the alert email address and the alert text. That is the complete list.
Uninstalling the app deletes everything we hold about your shop, in one
transaction, when the uninstall notification arrives — and Shopify’s
shop/redact notification re-runs the same purge about 48 hours later
as a guarantee. The app’s test records in your store are removed
best-effort at uninstall (Shopify revokes our access at that moment, so the
reliable path is the one-click “Remove test data” button on Setup, which works
while the app is installed). Exports you downloaded are yours and outside our
reach.
GDPR data-subject requests relayed by Shopify are honoured through the mandatory compliance webhooks; direct requests reach us at [support email].
The embedded app uses only the session tokens Shopify’s App Bridge provides. No analytics, no advertising, no third-party cookies. This website sets no cookies at all.
These are software test results, not tax advice.