Zendat Privacy Policy

Last updated: 29 September 2026

1. Who we are

Zendat is a sole proprietorship established in the Netherlands.

  • Owner: Jason den Hartog, trading as Zendat
  • Chamber of Commerce (KVK) number: 42169110
  • VAT identification number: NL005552054B70
  • Address: De Kriek 30, 3451 KK Vleuten, the Netherlands
  • Email for privacy matters: support@zendat.eu

Zendat has no data protection officer; it is not required to appoint one.

2. What this policy covers

This policy covers the Zendat app for Shopify and the website zendat.eu. It explains what personal data Zendat processes, why, where it goes, how long it is kept, and what rights people have.

The website zendat.eu is a static site. It sets no cookies, uses no analytics and has no forms; contact is by email. It is hosted by Render (section 5), whose servers keep an access log with the visitor's IP address, the page requested, the time and the browser, for a short period (section 4.3), for security and to find faults. Legal basis: Zendat's legitimate interest in a working and secure site (article 6(1)(f) GDPR).

3. Two roles

The app processes personal data of two groups of people, and Zendat's role is different for each.

Merchants. The business that installs the app, and the people who run it. For the data Zendat needs to provide, bill and support the app, Zendat is the controller.

Buyers. Customers of a merchant who place an order and give a VAT number. The app reads their data from the merchant's Shopify shop to build an invoice or credit note on the merchant's behalf. For that data the merchant is the controller and Zendat is its processor, acting on the merchant's instructions, which are: to build a document from an order or refund, have it checked, and send it when the merchant sends it or has switched automatic sending on. Buyers with a question about their data turn to the merchant first; Zendat helps the merchant answer it (section 9).

4. What data, from where, and why

4.1 About the merchant

Data Where it comes from Why Where it is kept
The shop's domain (shop.myshopify.com) and Shopify's identifier for it Shopify, at installation To know which shop a request, an order, a document and a bill belong to; every record is filed under it Zendat's database
The access token Shopify issues the app for the shop, and the scope granted Shopify, at installation To read orders and shop details and to write the VAT number on an order Zendat's database, table of sessions; deleted when the app is uninstalled
The shop's name, billing address, email address, and the name and address of its primary business entity Shopify, read when a document is built and when the settings page is opened To name the supplier on the invoice Not stored by Zendat; read from Shopify each time. Goes into every document sent to the Access Point
The merchant's own VAT number, bank account number (IBAN) and BIC Entered by the merchant in the app Go on every invoice as the supplier's VAT number and the account to pay into Stored by Shopify as metafields on the shop, written and read by the app; not in Zendat's database
Whether automatic sending is on Set by the merchant in the app To know whether paid orders may be invoiced without anyone asking Zendat's database; switched off at uninstall, deleted 48 hours later
The merchant's plan: whether there is a contract, when the trial ends, whether it was cancelled Shopify's Partner API, asked at most every ten minutes To decide whether an invoice may be sent, and to send the merchant to the plan page when there is no plan Zendat's database, deleted 48 hours after uninstall
The account at the Access Point: its identifier and name, the API key, the webhook identifier and its secret, the state of the setup, and the last error Created by Zendat at the Access Point for the merchant To send documents through the merchant's own account Zendat's database; the key and the secret are encrypted (AES-256-GCM) before they are written and are read only where a document is sent or a delivery report is checked. The keys are revoked at uninstall and the row is deleted 48 hours later. From the moment Zendat connects the shop (terms, section 8)
What was billed: one record per invoice sent, with the document identifier and dates The app Zendat's own record of the usage it reported to Shopify, so that no invoice is charged twice Zendat's database; kept after uninstall as a billing record
Support correspondence The merchant, by email To answer questions Zendat's mailbox at Google Workspace (section 5), kept for up to two years after the last message, then deleted

Legal basis, where Zendat is the controller: performance of the agreement with the merchant (article 6(1)(b) GDPR) for everything needed to provide, bill and support the app; Zendat's legitimate interest (article 6(1)(f)) in keeping the app secure and in keeping proof of what it did and billed; legal obligations (article 6(1)(c)) for keeping accounting records.

4.2 About buyers

The app processes buyers' data only to build a document for the merchant.

Data Where it comes from Why Where it is kept
The buyer's VAT number, and whether VIES confirmed it Entered by the buyer in the app's block on the thank-you page or order status page, or by the merchant in the app To identify the buyer as a business, to address the document to the right Peppol participant, and to put the number on the invoice as the law requires Stored by Shopify as metafields on the order (vat_number, vat_number_status), written by the app. Not in Zendat's database, except where it appears in a reason or error text (see below)
The buyer's name, company, billing address and email address Shopify, read from the order when a document is built Named on the invoice or credit note as the customer Not stored by Zendat; read from Shopify each time. Goes into every document sent to the Access Point. The app never reads the phone number
The order: number, date, currency, lines (products, quantities, prices, taxes), shipping, discounts, payment terms, amount outstanding, purchase order number; and for refunds, what was refunded Shopify, read when a document is built The content of the invoice or credit note Not stored by Zendat; read from Shopify each time. Goes into the document
Shopify's identifier and number of the order, and of the refund Shopify's webhooks and the app To keep one document per order and one credit note per refund, and to show the merchant what became of each Zendat's database, per document and per queued order; kept after uninstall in a minimal form (section 6)
Free text about an order: the Access Point's answer when a document was refused (which can quote the document, buyer details included), and the reason the app gives the merchant for what it did (which can name the buyer's VAT number) The Access Point, and the app To tell the merchant why an order was not invoiced Zendat's database; erased on a customer erasure request and 48 hours after uninstall
Delivery reports about a document: the Access Point's event identifier, the document identifier, the kind of event and when it arrived The Access Point To record whether a document was delivered Zendat's database; deleted 48 hours after uninstall. Contains no name or address
The identifiers Shopify sends in a privacy request: the customer's identifier and the orders' identifiers Shopify's privacy webhooks To do what the request asks and to prove it was done in time Zendat's database; kept as the record of the request. The email address and phone number Shopify includes in such a request are not written down

Legal basis: Zendat processes buyers' data on the merchant's instructions (article 28 GDPR). The merchant's own basis for invoicing its buyers is its contract with them and its legal obligation to issue invoices.

4.3 Technical data and logs

The app writes log lines when it works: which shop, which order number, which document, what happened and when. A log line can repeat the reason the app gave the merchant, which can contain a buyer's VAT number, and the Access Point's error text. Logs are kept by the hosting provider (section 5) for at most thirty days (Render keeps them for 7, 14 or 30 days, depending on the plan) and are read only to find and fix faults. No analytics, tracking or advertising cookies are used in the app.

5. Where the data goes

Zendat uses the following processors and other recipients. Each receives only what its part of the service needs.

Recipient Role Where What it receives
Shopify (Shopify International Limited, Ireland, and its affiliates) The platform the app runs in; independent controller under its own terms and privacy policy EU and elsewhere, under Shopify's own safeguards Everything in the merchant's shop is Shopify's to begin with. The app writes the buyer's VAT number and its status onto the order, and the merchant's VAT number and bank account onto the shop; reports the number of invoices sent for billing (the shop's identifier and a count, no buyer data); and reads the shop's plan
e-invoice.be (Belgium) Access Point: the certified Peppol access point that checks and delivers documents. Sub-processor Belgium, EU Every document the app creates: the merchant's details, the buyer's name, company, address, email address and VAT number, the order lines and amounts; the PDF of the document it makes; delivery reports back to the app. Documents stay at the Access Point for as long as the merchant's account exists there.
Render (Render Services, Inc., 525 Brannan St, San Francisco, CA 94131, United States) Hosting of the app and its PostgreSQL database, in Render's Frankfurt region. Sub-processor Germany, EU, for the servers and the database; the company is in the United States. Render's Data Processing Addendum applies to every customer and incorporates the EU Standard Contractual Clauses and the UK addendum, and Render is certified under the EU-US Data Privacy Framework; its sub-processors are listed at render.com/trust Everything in section 4 that is kept in Zendat's database, and the logs
Google Workspace (Google, under its Workspace terms and data processing addendum) Zendat's mailbox, including support@zendat.eu. Processor EU and elsewhere, under Google's data processing addendum and the EU-US Data Privacy Framework Every email to or from Zendat: the sender's address and name, and what was written.
VIES, the VAT information exchange system of the European Commission Public register used to check a VAT number EU Only the country code and the VAT number being checked. VIES answers whether the number exists and the registered name; the app stores only whether the number was confirmed
The buyer's own access point and the buyer Recipients of the document over the Peppol network Wherever the buyer's access point is The delivered document. Once delivered it is outside Zendat's control; the buyer's access point has its own rules

Zendat does not sell personal data and does not use it for advertising. Zendat shares data with others only where the law requires it.

6. How long data is kept

  • While the app is installed, the records in section 4 are kept for as long as they are needed to show the merchant what became of each order and to keep one document per order. Zendat does not delete them on a schedule.
  • When a merchant asks Shopify to erase a customer (Shopify's customers/redact request, which Shopify sends when a merchant erases a customer or the customer asks to be forgotten), the app erases within the request every free text about that customer's orders, and with it every VAT number it wrote down itself; a queued order for that customer is stopped. What stays per order is the minimal record: shop, order identifier and number, document identifier, state and dates. The VAT number the app wrote on the order in Shopify stays with the order and is subject to Shopify's own erasure of the order. Documents already sent stay at the Access Point and with the buyer.
  • When the merchant uninstalls the app, the app deletes Shopify's access token at once, cancels queued orders and switches automatic sending off. Forty-eight hours later Shopify sends the shop/redact request, and the app then deletes the shop's settings, plan, queued orders, delivery reports, account at the Access Point and any session that is left, and erases the free text of every document record. What stays: the minimal record per document (shop, order identifier and number, document identifier, state and dates), which stops a reinstall from sending a second document for an order that already has one; the records of privacy requests, as proof they were handled in time; and Zendat's billing records (shop, document identifier, dates and state), kept for seven years, the Dutch fiscal retention period (article 52 of the General Tax Act, Algemene wet inzake rijksbelastingen), as accounting records.
  • When a merchant asks for a customer's data (Shopify's customers/data_request), Zendat writes the request down and answers it to the merchant within thirty days, by email, with what the app holds about the orders named.
  • Logs: at most thirty days (section 4.3).
  • Support email: up to two years after the last message.

7. Security

  • Zendat's servers and database run in the EU. Connections between the buyer's browser, Shopify, the app, the Access Point and VIES are encrypted (TLS).
  • Requests from the app's block on the thank-you page carry Shopify's session token, and the app checks that the order the buyer names is theirs before it writes a VAT number on it.
  • Every request from Shopify and from the Access Point to the app is checked against its signature before it is acted on.
  • The keys and secrets of a merchant's account at the Access Point are encrypted at rest with AES-256-GCM, with a key that lives only on the server, and are decrypted only at the moment a document is sent or a delivery report is verified. They never appear in a log, an error or a page.
  • Every database query the app makes is scoped to one shop; an automated test refuses any page that reaches for a table directly.
  • Access to the servers, the database and the logs is limited to the owner of Zendat, with two-factor authentication on the accounts at Render, GitHub, Shopify Partners and Google.
  • Zendat reports a personal data breach to the affected merchants without undue delay after becoming aware of it, and to the supervisory authority where the law requires it.

8. Shopify's privacy requests

Shopify sends every app three kinds of privacy request, which the app answers automatically:

  • customers/data_request: written down, answered by hand within thirty days (section 6).
  • customers/redact: done within the request (section 6).
  • shop/redact: done within the request, forty-eight hours after the app was uninstalled (section 6).

A request whose signature does not check out is refused. A request that names one shop in its header and another in its signed body is ignored without anything being written or erased.

9. Your rights

Buyers. The merchant whose shop you bought from is the controller of your data in the shop and on your invoice. To access, correct, erase or object to that data, contact the merchant; Zendat helps the merchant answer, and does what Shopify's privacy requests ask (section 8). A document already sent over the Peppol network cannot be recalled by Zendat; correcting it is the merchant's to do, with a credit note.

Merchants. You can see and change your own settings in the app at any time. For access to, correction or erasure of the data Zendat holds about you and your shop, or to object to its processing, email support@zendat.eu. Uninstalling the app erases your data as described in section 6.

Everyone has the right to lodge a complaint with a supervisory authority. Zendat's authority is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), autoriteitpersoonsgegevens.nl; buyers and merchants in Belgium can turn to the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit), dataprotectionauthority.be.

10. Changes to this policy

Zendat may change this policy. The date at the top says when it last changed. A change that affects what data is processed or where it goes is announced in the app or by email to the shop's contact address before it applies.

11. Contact

support@zendat.eu, or by post to the address in section 1.