Larchline

Privacy Policy

App
Rechnung & Lieferschein PDF (the "app"), published under the Larchline brand.
Company
Scena Labs LLC, a limited liability company in Washington State, United States ("we", "us").
Contact
support@larchline.co
Version 1.4, 2026-09-19.
Effective from the day the app is listed on the Shopify App Store.

This policy explains what data the app handles, why, where it is kept, and how to have it deleted. It is written for the merchant who installs the app. The English text is the binding one. A German translation is provided for convenience.

1. What the app does

The app makes invoices (Rechnung), delivery notes (Lieferschein) and credit notes (Gutschrift) as PDF files from your Shopify orders, in German or English. It makes a document when you click, from the order as Shopify holds it at that moment. The app adds nothing to your storefront or your checkout. If the app is unavailable, your orders, your checkout and Shopify's own documents keep working.

2. Data we store about your store

When you install the app, Shopify gives us:

  • your store's myshopify.com domain;
  • an access token that lets the app read your orders, and nothing else;
  • the list of permissions you granted.

While you use the app, we store:

  • your settings: your company name and address, your tax number or VAT ID, and whether you use the small business rule (Kleinunternehmerregelung). Also the bank details line if you enter one, your logo, your numbering and the document language;
  • a register of every document you issue. For each one it holds Shopify's identifier of the order and its order number (such as #1001), the document type, the document number, the date and the currency. It also holds the net, tax and total amounts per tax rate, and a fingerprint of the file that shows whether a reissued document is identical;
  • an activity log: which document was issued or made again, for which order and when, and when the register was exported. It also holds the Shopify user number of the staff member who clicked, not their name or email address. The log also notes when a customer data request named an order we hold records for (section 9);
  • a record of each customer data request that names orders we hold records for. It holds Shopify's identifiers of those orders, when the request arrived and when the file was first downloaded (section 9);
  • the identifiers of the notices Shopify sends us, so each is handled once;
  • the email address Shopify holds for your store, so we can send you the notices in section 12. That is the store owner's address, or the store's public contact address when Shopify gives us no owner address. The app reads it when a staff member opens the app, at most once a week, and stores it with the date it was read. We use it for nothing else. It is never shown in the app and never written to a log;
  • for each notice we give your store, the record that it was shown to you and, where it applies, that it was emailed, with the times.

The first time you open the settings, the app reads your store's name and address from Shopify to fill in the form. We store them only when you save.

Shopify tells the app which language your admin is set to every time a page loads, so the app can show itself in German or English. We do not store it.

If you write to our support address, we store your message, the address you wrote from and any name you give us, so we can answer you and follow up later.

Our servers also keep technical logs of requests for 30 days. For a request to the app it writes one line. It holds the time, the method, the address requested without anything after a question mark, the status and the duration. It also holds a short tag that stands for your store, computed with a key, in place of the store's web address. Where the app's other lines name your store, they hold that tag too. They also hold other fields, such as Shopify's order and refund identifiers, document numbers and counts. The app's logger refuses a field that holds a name, an address, a customer number or a staff user number. Lines that Node or React Router write by themselves are kept as they are written, outside that rule.

Since 13 September 2026 we no longer store the record that Google's hosting platform makes of each request. That record was the only place the network address of the browser or server making the request was written. Records stored before that date are kept for their 30 days and are gone by about 13 October 2026. Google processes the network address to deliver each request and keeps its own record of that under its own terms. We do not receive it.

3. Data we read but do not keep

When you make a document, the app reads from Shopify what the document must show. That is the order's items, prices, discounts, shipping, tax and refunds. It is also your customer's name or company name, and the billing and shipping address. For a business order, it also reads the buyer's VAT ID from the order's additional details. These details go into the PDF, which is sent to your browser. They are not written to a database, a file, a cache or a log.

The app does not ask Shopify for your customers' email addresses or phone numbers and does not read them. It does not read Shopify's customer records either, only the names and addresses on the order.

The app asks Shopify for an offline access token only. We do not receive the name or the email address of the staff member who installs the app or opens it. The one address we do read is the one Shopify holds for the store itself, described in section 2.

The app sets no cookies of its own and uses no analytics or advertising trackers.

4. Our role

For the data we hold about your store and your account, we decide why and how it is used, so we are the controller of it. For the personal data we handle to make your documents, we act on your instructions as your processor under Article 28 of the GDPR. That covers your customers' names, addresses and VAT IDs, and the user numbers of your staff. It also covers the order identifiers in the register, in the activity log and in the records of customer data requests, and the order numbers in the register. The Data Processing Agreement that governs this is part of our Terms of Service. If your business needs a signed copy of the Data Processing Agreement, write to support@larchline.co and we send one.

5. Why we use this data

  • To make the documents you ask for: reading the order, applying your settings and your numbering, and keeping the register so that no number is used twice. This is necessary to perform our contract with you (Article 6(1)(b) GDPR).
  • To show you what was issued, when, and by which staff account. This is part of the same contract (Article 6(1)(b)).
  • To tell you about a change to this policy, our terms, our sub-processors or our prices. We also tell you if we shut the service down, if the app passes to another company, or if there is a security problem. We give these notices in the app and by email, as section 12 says. This is part of the same contract (Article 6(1)(b)).
  • To help you: answering your support requests and finding the cause of a problem. This is part of the contract. If you are not yet a customer, it is our legitimate interest in answering you (Article 6(1)(f)).
  • To keep the app secure and reliable: logs, error tracking and the detection of misuse. Our legitimate interest is a service that works and is not misused (Article 6(1)(f)).
  • To meet legal duties, such as answering a public authority (Article 6(1)(c)). Answering a privacy notice from Shopify is part of the contract.

You do not have to give us your settings, but without them the app cannot make a correct document. For your customers' data on the documents, you decide the purpose and the legal basis, and we act on your instructions (section 4).

We never sell your data and we never use it for advertising.

6. Where the data is kept

The app runs on Google Cloud servers in Belgium (region europe-west1), and its database and technical logs are stored there. Encrypted backups of the database are kept by Google Cloud in the European Union. So the data the app holds is stored in the European Union. Support email is handled on Microsoft 365.

Shopify holds your store's data, including your orders and your customers, under its own privacy policy. When you make a document, Shopify sends the app what that document needs, over an encrypted connection.

We are a United States company. The two people who run the app work from the United States. They can reach the database for support and maintenance, and your customers' names and addresses are not in it. They build and run the app with Claude, an AI tool made by Anthropic PBC in the United States. A written rule binds that work: the tool never reads your settings, your customers' data or your emails to us. It works only through the operators' own Google sign-in, not an account of its own. Technical messages it works with can still show your store's web address. If you write to us, a person reads your message in the United States.

Resend sends the notice emails described in section 12. It receives the address Shopify holds for your store and the text of the notice. That text holds nothing about your customers. Resend stores the email and the record of its delivery in the United States and keeps them for 30 days.

Google, Microsoft and Resend are on the Data Privacy Framework list for transfers from the European Union to the United States. Resend's data processing terms also state that the standard contractual clauses the European Commission has approved apply to such transfers. Where that framework does not cover a transfer, we rely on the standard contractual clauses the European Commission has approved, which are part of our contracts with them. For the data we handle as your processor, the same clauses are part of our Data Processing Agreement with you.

Companies that process data for us:

CompanyPurpose
Google LLC (Google Cloud)Hosting, database, backups and technical logs, Belgium and the European Union
Microsoft Corporation (Microsoft 365)Support email
Resend (Plus Five Five, Inc.)Sending the notices in section 12, United States

Shopify is not on this list. It is the platform your store runs on, you have your own agreement with it, and the app receives order data from it when you make a document.

7. How long we keep it

  • Your settings, the register, the activity log and the access token: for as long as the app is installed.
  • When you uninstall the app: the access token and the email address Shopify holds for your store are deleted at once. Everything else we hold about the store is deleted when Shopify sends us the removal notice, 48 hours after you uninstall. The one exception is the record in the next point. Write to us if you want it deleted sooner.
  • The record that a Shopify notice was handled (your store's web address, the kind of notice and its date): at the earliest 23 days after it arrives. In any case within 30 days of its arrival. The last one is deleted within 30 days after you uninstall.
  • The record of a customer data request (section 2): you can download its file for 55 days after the request arrives. The record is deleted within 60 days after the request arrives. It is deleted earlier when you uninstall the app, or when Shopify asks us to delete that customer's data.
  • The record that a notice from us (section 12) was shown to your store and emailed to it: while the app is installed. It is deleted with the rest of the store's data when Shopify sends us the removal notice. We keep it so you can see that you were told.
  • The notice emails at Resend, with the records of their delivery: 30 days.
  • Deleted data can remain in the encrypted database backups for up to 8 days, until those backups are replaced.
  • Technical logs: 30 days.
  • Support emails: up to 24 months, so we can follow up on earlier requests.
  • The documents themselves: we keep no copy. The PDFs you download are yours, and you keep them for as long as the law of your country requires.

8. Your rights

If you are in the European Union, the European Economic Area, the United Kingdom or Switzerland, you can ask us at any time to:

  • see the data we hold about your store;
  • correct it;
  • delete it;
  • limit how we use it while a question about it is open;
  • receive it in a portable format.

Your right to object. You can object at any time to a use based on our legitimate interest (section 5). We then stop, unless we have compelling reasons that override yours.

The app makes no decisions about people by automated means.

Write to support@larchline.co. We answer within one month. If a request is complex, we may take two more months, and we tell you why within the first month. You can also complain to a data protection authority, in particular where you live or work or where you think the problem happened. In Germany that is the data protection authority of your federal state. In Austria it is the Datenschutzbehörde. In Switzerland it is the Federal Data Protection and Information Commissioner (FDPIC).

If you are a customer of a shop that uses the app, the shop decides how the data on its documents is used. Write to the shop first. You can also write to us at support@larchline.co. We pass your request to the shop and help it answer you.

9. Requests that come through Shopify

Shopify sends apps three kinds of privacy notices. This is how the app answers them:

  • Customer data request: we find what we hold for the orders named in the request. That is the document numbers, dates and amounts, and when documents were made and by which staff user number. If we hold any, we record that the request came in and the app shows you a notice. From it you download these records as a machine-readable file (JSON), so you can answer your customer. The file covers the orders we held records for when the request arrived. It holds every entry the register and the activity log keep for those orders, and nothing about other orders. It is made when you download it; we keep no copy. If we hold nothing for those orders, the app shows no notice.
  • Customer data deletion: for the orders named in the request, we delete the activity log entries. We also delete the record of any customer data request that names one of those orders. We keep each document's number, date and amounts in the register, because your numbering must stay complete. We remove the link to the order, which is its identifier and its order number. We can then no longer tell which order a document belonged to.
  • Store data deletion: we delete everything we hold about the store: settings, logo, register, activity log, records of customer data requests and access token. One record that the deletion happened stays: your store's web address, the kind of notice and its date, so the same notice is not processed twice. We delete it at the earliest 23 days after it arrives, and in any case within 30 days after you uninstall.

10. Security

The app's own keys and the database password are kept in a secrets manager, never in code. Each store's access token is kept in the app's database, which is encrypted. Data travels encrypted, and the database and its backups are encrypted at rest. Your customers' names and addresses are never stored, so no copy of our database contains them. Only the app and the two people who run it can reach the database. The people sign in through Google, with two-factor authentication. The AI tool they work with is barred by the written rule in section 6 from opening it. If a security problem affects personal data we handle, we tell you without undue delay, and at the latest within 48 hours of becoming aware of it.

11. Children

The app is a tool for merchants and is not directed at children.

12. Changes to this policy

When we change this policy, we post the new version with its date. For a change that affects your rights, we tell you before it takes effect. Before we use data for a new purpose, we tell you first.

How we tell you. Where this policy says we tell you something, you get the same notice in two places. The app shows it on every page until you mark it read. It stops showing 30 days after the change takes effect, or 60 days after we post it when it names no date. We also send it by email to the address Shopify holds for your store, when Shopify gives us one (section 2). The sender is noreply@larchline.co, and you can reply to support@larchline.co. These emails are about the app and this policy only. We never use them for advertising.

13. Contact

Scena Labs LLC 522 W Riverside Ave, Ste N Spokane, WA 99201 United States support@larchline.co