BillNest Global ("the App", "we", "our", "us"), published by AppNest Studio, is a Shopify app that issues invoices and credit notes for a merchant's paid orders. This policy explains what data the App accesses, why, how long we keep it, and who it is shared with.
Contact / Data Protection: support@appnest.studio
1. Who the data belongs to
The App acts as a data processor on behalf of the installing merchant (the data controller). We process the merchant's store data solely to produce the documents the merchant is required to issue.
2. What we access and why
| Scope | Why |
|---|---|
read_orders |
The order, its line items and tax lines are what an invoice is made of. Limited to the last 60 days; read_all_orders is not requested. |
read_customers |
The buyer's name, address and tax ID are required on the document itself. |
The App requests no write scopes. It changes nothing in your store.
3. What we store
| Data | Stored? | Notes |
|---|---|---|
| Document snapshot and cached PDF | Yes | The invoice or credit note as issued. A later edit to the order does not change it. |
| Buyer tax ID, per customer | Yes | So a repeat buyer's VAT or GST number is reused. |
| Seller configuration | Yes | Your legal name, addresses, tax registrations and numbering. This is merchant configuration, not customer data. |
| Payment details | No | Never accessed. |
Buyer personal data is never sold, never used for analytics about buyers, and never shared outside the sub-processors listed below.
4. Retention and deletion
- Issued documents are fiscal records and are kept while the App is installed.
- Pending rows that never became a document are deleted automatically.
- On
customers/redact, identifying fields (name, email, address lines, tax ID, order note) are removed from the stored snapshot. - On
customers/data_request, we email you the list of document numbers holding that customer's data so you can respond. - On app uninstall and on
shop/redact, all data for that store is deleted.
5. Sub-processors
Buyer personal data reaches these services and no others.
| Service | What reaches it | Why |
|---|---|---|
| Railway (hosting, Postgres) | Stored data listed in section 3 | Runs the App |
| Cloudflare R2 | Document PDFs, CSV and ZIP exports, your logo | Document storage |
| Resend | Buyer name and email, and the invoice PDF | Delivering the document, when you enable emailing |
| EU Commission VIES | The buyer's VAT number only, with no name or address | Validating an EU VAT ID so reverse charge can be applied |
| Slack | Alert text, which can name document numbers | Operational alerts, only to a webhook you supply |
| Sentry | Error reports with credentials and personal data scrubbed before send | Diagnosing failures |
6. International transfers
AppNest Studio operates from India, and the providers listed above may process data in regions outside your own. Where a transfer leaves the UK or the European Economic Area, we rely on the Standard Contractual Clauses incorporated into those providers' data-processing terms. Write to support@appnest.studio if you need detail on a specific provider.
7. Security
HTTPS everywhere. The database is encrypted at rest, and document storage uses server-side encryption. Staff access is limited to the developer, for support, when a merchant asks about a specific document.
8. Your rights
You are the controller for your store's data. Contact us at support@appnest.studio to ask what we hold, to correct it, or to have it deleted. We will respond within 30 days.
9. Changes
We may update this policy as the App changes. The date above reflects the current version, and material changes are announced in the App.