Legal

Privacy Policy

What VATquarter reads from your Shopify store, what it keeps, and how to have it deleted.

Effective 1 October 2026 · Tallgrass Apps LLC

Who we are

VATquarter is operated by Tallgrass Apps LLC, a Missouri limited liability company (“we”, “us”). We are the data controller for the app’s own records and a processor of your store’s order data on your behalf. Contact: [email protected].

What the app reads

When you generate a report, VATquarter reads the following from your Shopify store through the Admin API, for the period you chose: order identifiers, dates, financial status, currency, line-item and shipping amounts and tax lines, discount allocations, the destination country and province codes of the shipping address, refund line items and adjustments, fulfillment location country and postcode, and order attributes used to detect business (B2B) orders. It also reads your store’s name, currency, timezone, country and plan.

Orders are “protected customer data” under Shopify’s rules, and VATquarter holds Level 1 access for tax-compliance purposes. It does not request any Level 2 field: it never reads customer names, address lines, postcodes, phone numbers or email addresses.

What the app stores

Order data is read on demand and reduced to the rows above; the raw order export is not retained after the report is built.

What we do not do

We do not sell data, share it with advertisers, or use it to train models. We do not contact your customers. We do not change anything in your store: the app has read-only access to orders.

Where data is processed

The app and its database run on Railway infrastructure in the United States. Shopify’s order export files are downloaded from Shopify’s servers over an encrypted connection and discarded after processing. If you are subject to the GDPR, the transfer relies on Shopify’s and Railway’s standard contractual clauses; the personal data involved is limited to order identifiers and destination locality, as described above.

Retention and deletion

Report results are kept while the app is installed so you can reopen past periods. When you uninstall, Shopify sends a shop/redact request 48 hours later and we delete all data for your store, including settings, sessions and report results. You can also request deletion at any time by emailing [email protected] from the store’s owner address.

When Shopify sends a customers/redact request, the per-order rows for the orders it lists are removed from stored reports. customers/data_request is acknowledged; the order-level rows we hold are a subset of your own order records.

Security

Access tokens are stored encrypted at rest, all traffic uses TLS, and access to production systems is limited to the operator. Report the security issue you found to [email protected]; we respond within two business days.

Cookies and analytics

The app inside Shopify uses only the session mechanisms Shopify requires for embedded apps. This website sets no tracking cookies.

Your rights

If you are in the EU, UK or another jurisdiction with data-protection rights, you can ask us to access, correct, export or delete the data we hold about your store, and you can complain to your supervisory authority. Email [email protected].

Changes

We will post changes to this policy here and update the effective date. Material changes will be announced inside the app.