Privacy Policy
Draft pending legal approval. Last updated July 23, 2026.
ELMG SAS provides ELMG Invoice Printer to Shopify merchants. Contact us at [email protected] about this policy or a privacy request.
Data processed
The app reads paid-order details required to generate an invoice, including customer name, billing and optional shipping address, email address, line items, prices, discounts, taxes, shipping and totals. Order and customer data is processed transiently and is not stored as a local customer database.
Merchant settings and sessions
Shopify sessions are stored in the app's persistent database while the app is installed. Invoice, email, branding and encrypted SMTP settings are stored in Shopify shop metafields. SMTP passwords are encrypted with AES-256-GCM before storage and are decrypted only by the server for delivery.
Email delivery
When a merchant enables automatic delivery, invoice data and the generated PDF are transmitted to the SMTP provider configured by that merchant. ELMG Invoice Printer does not provide the merchant's email account.
Retention and deletion
Operational logs and backups are retained for no longer than 30 days unless a longer period is required by law or necessary to investigate a security incident. Local shop sessions are deleted after uninstall, and Shopify privacy webhooks are used for customer data requests, customer redaction and shop redaction.
Hosting and subprocessors
The application is hosted in [HOSTING_REGION]. Infrastructure services include GitLab for source and container images, Dokploy for container deployment, Cloudflare for DNS and edge TLS, Shopify for platform data and merchant-configured SMTP providers for email delivery. This list must be confirmed before publication.
Security and international transfers
Traffic is protected with HTTPS. Access is restricted to authorized systems and personnel. Details of storage encryption, international transfers and applicable safeguards are [LEGAL_REVIEW_REQUIRED].
Your choices
Merchants and data subjects can contact [email protected] to request access, correction or deletion where applicable. Merchants can disable automatic email delivery by removing their SMTP configuration.