Privacy policy
Last updated September 30, 2026
Mint Invoices is a Shopify app made by Mint Labs ("we", "us"). It creates PDF invoices, packing slips and credit notes for a merchant's Shopify orders. This policy explains what the app handles about merchants and about the merchant's customers, why, and when it's deleted. For customer data we act as a service provider (processor) to the merchant, who is the controller.
The short version
- A document is made from the order in Shopify at the moment it's printed, downloaded or emailed. The customer details on it (name, email address, billing and shipping address) are read from Shopify for that moment only and are never stored or logged.
- We keep a register of the numbers the app has issued: invoice or credit note number, the Shopify order (and refund) ID, the order number such as #1042, the date, currency and totals. No names, email addresses, phone numbers or addresses.
- We never sell or share data, use it for advertising, or combine it across stores. The app sets no cookies on your storefront and adds no scripts to it.
Information about merchants
| Information | Why |
|---|---|
| Store domain and a Shopify access token | To read the orders documents are made for, and receive order notifications the merchant switched on. |
| Store name, contact email, time zone, currency and address from Shopify | As defaults for the seller details on documents, for dates in the store's time zone, and as the reply-to address of invoice emails. |
| Business details the merchant enters (legal name, address, tax ID, registration, email, phone, website), logo, and document settings | Printed on the merchant's documents. |
| Plan and subscription status | Read from Shopify to decide which features apply. Payments are handled entirely by Shopify. |
| The status of the last email sent and of the order notifications | To tell the merchant in the app if something isn't working. |
Information about the merchant's customers
| Information | How it's used | Kept |
|---|---|---|
| Name, billing and shipping address, email address; the order's items, prices, discounts, shipping, taxes, payments and refunds | Read from Shopify to make the PDF the merchant (or the signed-in customer, for their own order) asked for. Phone numbers are not read. | Not stored |
| Document register: invoice/credit note number, Shopify order ID and refund ID, order number, issue date, currency, total and tax amount, whether and when it was emailed | So each order keeps its number, numbering never repeats or skips, and the merchant can find and re-download documents. | While the app is installed (see Retention) |
| Invoice emails (Pro, if the merchant switches them on): the order's email address | Read from Shopify at the moment of sending, used once to send the customer the PDF of their own document through Cloudflare Email Service. | Not stored or logged |
| Customer download (Pro): the customer ID in Shopify's signed session token | To confirm the order belongs to the signed-in customer before offering its invoice. | Not stored |
| Order notifications from Shopify (orders paid, refunds created), limited to IDs, order number and a test flag | To number, email or credit the order as the merchant chose. The notification ID is kept for 7 days so a repeated notification isn't processed twice. | 7 days (notification ID only) |
Customer privacy requests
- Access requests (Shopify's
customers/data_request): the app home shows the request and the merchant downloads what we hold for the listed orders (the register entries above) to send to the customer. - Erasure requests (
customers/redact): we hold no names, email addresses or addresses to erase. The register entries for the listed orders contain only numbers, dates and amounts; they are the merchant's accounting record and are kept so invoice numbering stays complete, as tax law usually requires. Any stored email error message for those orders is deleted. - Store deletion (
shop/redact, sent 48 hours after a merchant uninstalls): we permanently delete everything we hold for the store, including the register. Merchants should export the register (Documents → Export CSV) before uninstalling.
Where data is processed and how it's protected
The app runs on Cloudflare (hosting, database and email sending) and connects to Shopify's APIs. Data is encrypted in transit (TLS) and at rest. Document links are signed and expire after 10 minutes. Access is limited to Mint Labs staff who need it to provide support. We use no other sub-processors, analytics or trackers. See our security policy.
Retention
PDFs and customer details are not stored at all. Notification IDs are deleted after 7 days. Access tokens are deleted as soon as the app is uninstalled; settings, the logo and the document register are deleted when Shopify sends the store deletion request 48 hours later.
Your rights
Depending on where you are, you may have the right to access, correct or delete information about you. Merchants can contact us directly; customers should contact the store they ordered from, or email us and we'll pass the request on. We respond within 30 days.
Changes
If we change this policy we'll update the date above and, for significant changes, notify merchants in the app.
Contact
Mint Labs — support@stickermint.com