Zendat Privacy Policy
Last updated: 29 September 2026
1. Who we are
Zendat is a sole proprietorship established in the Netherlands.
- Owner: Jason den Hartog, trading as Zendat
- Chamber of Commerce (KVK) number: 42169110
- VAT identification number: NL005552054B70
- Address: De Kriek 30, 3451 KK Vleuten, the Netherlands
- Email for privacy matters: support@zendat.eu
Zendat has no data protection officer; it is not required to appoint one.
2. What this policy covers
This policy covers the Zendat app for Shopify and the website zendat.eu. It explains what personal data Zendat processes, why, where it goes, how long it is kept, and what rights people have.
The website zendat.eu is a static site. It sets no cookies, uses no analytics and has no forms; contact is by email. It is hosted by Render (section 5), whose servers keep an access log with the visitor's IP address, the page requested, the time and the browser, for a short period (section 4.3), for security and to find faults. Legal basis: Zendat's legitimate interest in a working and secure site (article 6(1)(f) GDPR).
3. Two roles
The app processes personal data of two groups of people, and Zendat's role is different for each.
Merchants. The business that installs the app, and the people who run it. For the data Zendat needs to provide, bill and support the app, Zendat is the controller.
Buyers. Customers of a merchant who place an order and give a VAT number. The app reads their data from the merchant's Shopify shop to build an invoice or credit note on the merchant's behalf. For that data the merchant is the controller and Zendat is its processor, acting on the merchant's instructions, which are: to build a document from an order or refund, have it checked, and send it when the merchant sends it or has switched automatic sending on. Buyers with a question about their data turn to the merchant first; Zendat helps the merchant answer it (section 9).
4. What data, from where, and why
4.1 About the merchant
| Data | Where it comes from | Why | Where it is kept |
|---|---|---|---|
The shop's domain (shop.myshopify.com) and Shopify's identifier for it |
Shopify, at installation | To know which shop a request, an order, a document and a bill belong to; every record is filed under it | Zendat's database |
| The access token Shopify issues the app for the shop, and the scope granted | Shopify, at installation | To read orders and shop details and to write the VAT number on an order | Zendat's database, table of sessions; deleted when the app is uninstalled |
| The shop's name, billing address, email address, and the name and address of its primary business entity | Shopify, read when a document is built and when the settings page is opened | To name the supplier on the invoice | Not stored by Zendat; read from Shopify each time. Goes into every document sent to the Access Point |
| The merchant's own VAT number, bank account number (IBAN) and BIC | Entered by the merchant in the app | Go on every invoice as the supplier's VAT number and the account to pay into | Stored by Shopify as metafields on the shop, written and read by the app; not in Zendat's database |
| Whether automatic sending is on | Set by the merchant in the app | To know whether paid orders may be invoiced without anyone asking | Zendat's database; switched off at uninstall, deleted 48 hours later |
| The merchant's plan: whether there is a contract, when the trial ends, whether it was cancelled | Shopify's Partner API, asked at most every ten minutes | To decide whether an invoice may be sent, and to send the merchant to the plan page when there is no plan | Zendat's database, deleted 48 hours after uninstall |
| The account at the Access Point: its identifier and name, the API key, the webhook identifier and its secret, the state of the setup, and the last error | Created by Zendat at the Access Point for the merchant | To send documents through the merchant's own account | Zendat's database; the key and the secret are encrypted (AES-256-GCM) before they are written and are read only where a document is sent or a delivery report is checked. The keys are revoked at uninstall and the row is deleted 48 hours later. From the moment Zendat connects the shop (terms, section 8) |
| What was billed: one record per invoice sent, with the document identifier and dates | The app | Zendat's own record of the usage it reported to Shopify, so that no invoice is charged twice | Zendat's database; kept after uninstall as a billing record |
| Support correspondence | The merchant, by email | To answer questions | Zendat's mailbox at Google Workspace (section 5), kept for up to two years after the last message, then deleted |
Legal basis, where Zendat is the controller: performance of the agreement with the merchant (article 6(1)(b) GDPR) for everything needed to provide, bill and support the app; Zendat's legitimate interest (article 6(1)(f)) in keeping the app secure and in keeping proof of what it did and billed; legal obligations (article 6(1)(c)) for keeping accounting records.
4.2 About buyers
The app processes buyers' data only to build a document for the merchant.
| Data | Where it comes from | Why | Where it is kept |
|---|---|---|---|
| The buyer's VAT number, and whether VIES confirmed it | Entered by the buyer in the app's block on the thank-you page or order status page, or by the merchant in the app | To identify the buyer as a business, to address the document to the right Peppol participant, and to put the number on the invoice as the law requires | Stored by Shopify as metafields on the order (vat_number, vat_number_status), written by the app. Not in Zendat's database, except where it appears in a reason or error text (see below) |
| The buyer's name, company, billing address and email address | Shopify, read from the order when a document is built | Named on the invoice or credit note as the customer | Not stored by Zendat; read from Shopify each time. Goes into every document sent to the Access Point. The app never reads the phone number |
| The order: number, date, currency, lines (products, quantities, prices, taxes), shipping, discounts, payment terms, amount outstanding, purchase order number; and for refunds, what was refunded | Shopify, read when a document is built | The content of the invoice or credit note | Not stored by Zendat; read from Shopify each time. Goes into the document |
| Shopify's identifier and number of the order, and of the refund | Shopify's webhooks and the app | To keep one document per order and one credit note per refund, and to show the merchant what became of each | Zendat's database, per document and per queued order; kept after uninstall in a minimal form (section 6) |
| Free text about an order: the Access Point's answer when a document was refused (which can quote the document, buyer details included), and the reason the app gives the merchant for what it did (which can name the buyer's VAT number) | The Access Point, and the app | To tell the merchant why an order was not invoiced | Zendat's database; erased on a customer erasure request and 48 hours after uninstall |
| Delivery reports about a document: the Access Point's event identifier, the document identifier, the kind of event and when it arrived | The Access Point | To record whether a document was delivered | Zendat's database; deleted 48 hours after uninstall. Contains no name or address |
| The identifiers Shopify sends in a privacy request: the customer's identifier and the orders' identifiers | Shopify's privacy webhooks | To do what the request asks and to prove it was done in time | Zendat's database; kept as the record of the request. The email address and phone number Shopify includes in such a request are not written down |
Legal basis: Zendat processes buyers' data on the merchant's instructions (article 28 GDPR). The merchant's own basis for invoicing its buyers is its contract with them and its legal obligation to issue invoices.
4.3 Technical data and logs
The app writes log lines when it works: which shop, which order number, which document, what happened and when. A log line can repeat the reason the app gave the merchant, which can contain a buyer's VAT number, and the Access Point's error text. Logs are kept by the hosting provider (section 5) for at most thirty days (Render keeps them for 7, 14 or 30 days, depending on the plan) and are read only to find and fix faults. No analytics, tracking or advertising cookies are used in the app.
5. Where the data goes
Zendat uses the following processors and other recipients. Each receives only what its part of the service needs.
| Recipient | Role | Where | What it receives |
|---|---|---|---|
| Shopify (Shopify International Limited, Ireland, and its affiliates) | The platform the app runs in; independent controller under its own terms and privacy policy | EU and elsewhere, under Shopify's own safeguards | Everything in the merchant's shop is Shopify's to begin with. The app writes the buyer's VAT number and its status onto the order, and the merchant's VAT number and bank account onto the shop; reports the number of invoices sent for billing (the shop's identifier and a count, no buyer data); and reads the shop's plan |
| e-invoice.be (Belgium) | Access Point: the certified Peppol access point that checks and delivers documents. Sub-processor | Belgium, EU | Every document the app creates: the merchant's details, the buyer's name, company, address, email address and VAT number, the order lines and amounts; the PDF of the document it makes; delivery reports back to the app. Documents stay at the Access Point for as long as the merchant's account exists there. |
| Render (Render Services, Inc., 525 Brannan St, San Francisco, CA 94131, United States) | Hosting of the app and its PostgreSQL database, in Render's Frankfurt region. Sub-processor | Germany, EU, for the servers and the database; the company is in the United States. Render's Data Processing Addendum applies to every customer and incorporates the EU Standard Contractual Clauses and the UK addendum, and Render is certified under the EU-US Data Privacy Framework; its sub-processors are listed at render.com/trust | Everything in section 4 that is kept in Zendat's database, and the logs |
| Google Workspace (Google, under its Workspace terms and data processing addendum) | Zendat's mailbox, including support@zendat.eu. Processor | EU and elsewhere, under Google's data processing addendum and the EU-US Data Privacy Framework | Every email to or from Zendat: the sender's address and name, and what was written. |
| VIES, the VAT information exchange system of the European Commission | Public register used to check a VAT number | EU | Only the country code and the VAT number being checked. VIES answers whether the number exists and the registered name; the app stores only whether the number was confirmed |
| The buyer's own access point and the buyer | Recipients of the document over the Peppol network | Wherever the buyer's access point is | The delivered document. Once delivered it is outside Zendat's control; the buyer's access point has its own rules |
Zendat does not sell personal data and does not use it for advertising. Zendat shares data with others only where the law requires it.
6. How long data is kept
- While the app is installed, the records in section 4 are kept for as long as they are needed to show the merchant what became of each order and to keep one document per order. Zendat does not delete them on a schedule.
- When a merchant asks Shopify to erase a customer (Shopify's
customers/redactrequest, which Shopify sends when a merchant erases a customer or the customer asks to be forgotten), the app erases within the request every free text about that customer's orders, and with it every VAT number it wrote down itself; a queued order for that customer is stopped. What stays per order is the minimal record: shop, order identifier and number, document identifier, state and dates. The VAT number the app wrote on the order in Shopify stays with the order and is subject to Shopify's own erasure of the order. Documents already sent stay at the Access Point and with the buyer. - When the merchant uninstalls the app, the app deletes Shopify's access
token at once, cancels queued orders and switches automatic sending off.
Forty-eight hours later Shopify sends the
shop/redactrequest, and the app then deletes the shop's settings, plan, queued orders, delivery reports, account at the Access Point and any session that is left, and erases the free text of every document record. What stays: the minimal record per document (shop, order identifier and number, document identifier, state and dates), which stops a reinstall from sending a second document for an order that already has one; the records of privacy requests, as proof they were handled in time; and Zendat's billing records (shop, document identifier, dates and state), kept for seven years, the Dutch fiscal retention period (article 52 of the General Tax Act, Algemene wet inzake rijksbelastingen), as accounting records. - When a merchant asks for a customer's data (Shopify's
customers/data_request), Zendat writes the request down and answers it to the merchant within thirty days, by email, with what the app holds about the orders named. - Logs: at most thirty days (section 4.3).
- Support email: up to two years after the last message.
7. Security
- Zendat's servers and database run in the EU. Connections between the buyer's browser, Shopify, the app, the Access Point and VIES are encrypted (TLS).
- Requests from the app's block on the thank-you page carry Shopify's session token, and the app checks that the order the buyer names is theirs before it writes a VAT number on it.
- Every request from Shopify and from the Access Point to the app is checked against its signature before it is acted on.
- The keys and secrets of a merchant's account at the Access Point are encrypted at rest with AES-256-GCM, with a key that lives only on the server, and are decrypted only at the moment a document is sent or a delivery report is verified. They never appear in a log, an error or a page.
- Every database query the app makes is scoped to one shop; an automated test refuses any page that reaches for a table directly.
- Access to the servers, the database and the logs is limited to the owner of Zendat, with two-factor authentication on the accounts at Render, GitHub, Shopify Partners and Google.
- Zendat reports a personal data breach to the affected merchants without undue delay after becoming aware of it, and to the supervisory authority where the law requires it.
8. Shopify's privacy requests
Shopify sends every app three kinds of privacy request, which the app answers automatically:
customers/data_request: written down, answered by hand within thirty days (section 6).customers/redact: done within the request (section 6).shop/redact: done within the request, forty-eight hours after the app was uninstalled (section 6).
A request whose signature does not check out is refused. A request that names one shop in its header and another in its signed body is ignored without anything being written or erased.
9. Your rights
Buyers. The merchant whose shop you bought from is the controller of your data in the shop and on your invoice. To access, correct, erase or object to that data, contact the merchant; Zendat helps the merchant answer, and does what Shopify's privacy requests ask (section 8). A document already sent over the Peppol network cannot be recalled by Zendat; correcting it is the merchant's to do, with a credit note.
Merchants. You can see and change your own settings in the app at any time. For access to, correction or erasure of the data Zendat holds about you and your shop, or to object to its processing, email support@zendat.eu. Uninstalling the app erases your data as described in section 6.
Everyone has the right to lodge a complaint with a supervisory authority. Zendat's authority is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), autoriteitpersoonsgegevens.nl; buyers and merchants in Belgium can turn to the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit), dataprotectionauthority.be.
10. Changes to this policy
Zendat may change this policy. The date at the top says when it last changed. A change that affects what data is processed or where it goes is announced in the app or by email to the shop's contact address before it applies.
11. Contact
support@zendat.eu, or by post to the address in section 1.