Billsora Privacy Policy
Last updated: 10 September 2026
This Privacy Policy describes how Billsora ("we", "us", or "our") collects,
uses, and protects information across both parts of the Billsora product: the
Billsora Shopify app (the "Shopify App"), an embedded app that generates branded
PDF invoices and receipts from a merchant's Shopify orders and emails them to the
merchant's customers, and the Billsora mobile app (the "Mobile App"), which lets a
store's registered owner log in and view that store's orders, receipts, and invoices on
their phone.
1. Information We Collect
When a merchant installs the App, Shopify grants us access to specific data through
Shopify's APIs. We access and process this data only to provide the App's invoicing
functionality:
- Order data: Order number, line items, quantities, prices, taxes,
discounts, shipping, currency, and financial/fulfillment status. Retrieved via the
Shopify Admin GraphQL API and Shopify order webhooks
(
orders/create, orders/updated).
- Customer personal data (protected customer data): Customer name,
email address, and billing/shipping address associated with an order. This is
included on the generated invoice and used to email it to the customer.
- Store information: The store's
myshopify.com domain
and basic store details, used to associate data with the correct merchant.
- Generated documents: The invoice/receipt PDFs the App produces
from the order data.
We access only the minimum customer data required to generate and
deliver invoices. We do not collect location, contacts, photos, or
advertising identifiers, and the App contains no advertising.
When a store owner uses the Mobile App, we additionally collect:
- Owner login information: The store domain and owner email address
entered at login, used solely to verify that the person logging in is the
registered owner of that store, and a one-time login code sent to that email.
The Mobile App does not use passwords.
- Push notification token: If the owner allows notifications, we
store a device push token (provided by Expo, our push notification service) so we
can alert them when an order is created or its status changes. This token
identifies the device for notification delivery only — it is not used for
advertising, profiling, or tracking, and is removed from our systems when the owner
logs out of the Mobile App.
2. How We Use Information
- To generate branded PDF invoices and receipts from the merchant's Shopify orders.
- To email generated invoices to the merchant's customers on the merchant's behalf.
- To display the merchant's orders and generated invoices within the embedded app.
- To verify that the person logging into the Mobile App is the store's registered
owner, and to send them a one-time login code.
- To send the store owner a push notification when an order is created or its status
changes, if they've enabled notifications in the Mobile App.
- To operate, maintain, and secure the App and its backend services.
We use protected customer data solely for the invoicing purpose
above. We do not sell personal information, use it for advertising or
profiling, or share it for third-party marketing.
3. How Information Is Stored and Shared
- Order, customer, and invoice data is processed and stored via our backend and our
data provider, Supabase, with encryption in transit (HTTPS/TLS) and encryption at
rest.
- All communication with Shopify's APIs, and all webhook traffic, occurs over
encrypted (HTTPS/TLS) connections, and Shopify webhooks are verified using HMAC
signatures.
- We share data with service providers only as strictly needed to operate the App
(for example, Supabase for data storage, an email delivery provider for sending
invoices, and Expo for delivering push notifications to the Mobile App). These
providers process data on our behalf and are not permitted to use it for their own
purposes.
4. Data Retention and Deletion
We retain order, customer, and invoice data only as long as needed to provide the
invoicing service to the merchant. We honor Shopify's mandatory data-protection
webhooks:
- customers/redact: When a customer requests deletion, we delete
that customer's personal data and associated invoices for the store.
- shop/redact: When a store uninstalls the App, we delete that
store's data.
- customers/data_request: We provide the stored personal data for a
customer on request.
5. Merchant and Customer Rights
Merchants and their customers may request access to, correction of, or deletion of
personal data by contacting us at the address below, or (for customers) through the
store's standard data-request process, which triggers the webhooks described above.
6. Children's Privacy
The App is a business tool for merchants and is not directed to children under 13. We
do not knowingly collect personal information from children.
7. Security
We use industry-standard measures — including encryption in transit and at rest, HMAC
verification of webhooks, and least-privilege access to data — to protect information. No
method of transmission or storage is completely secure, but we work to protect the data
entrusted to us.
8. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this
page with an updated "Last updated" date.
9. Contact Us
If you have questions about this Privacy Policy or your data, contact us at:
billsora.dev@gmail.com.