← ELMG Invoice Printer

Privacy Policy

Draft pending legal approval. Last updated July 23, 2026.

ELMG SAS provides ELMG Invoice Printer to Shopify merchants. Contact us at [email protected] about this policy or a privacy request.

Data processed

The app reads paid-order details required to generate an invoice, including customer name, billing and optional shipping address, email address, line items, prices, discounts, taxes, shipping and totals. Order and customer data is processed transiently and is not stored as a local customer database.

Merchant settings and sessions

Shopify sessions are stored in the app's persistent database while the app is installed. Invoice, email, branding and encrypted SMTP settings are stored in Shopify shop metafields. SMTP passwords are encrypted with AES-256-GCM before storage and are decrypted only by the server for delivery.

Email delivery

When a merchant enables automatic delivery, invoice data and the generated PDF are transmitted to the SMTP provider configured by that merchant. ELMG Invoice Printer does not provide the merchant's email account.

Retention and deletion

Operational logs and backups are retained for no longer than 30 days unless a longer period is required by law or necessary to investigate a security incident. Local shop sessions are deleted after uninstall, and Shopify privacy webhooks are used for customer data requests, customer redaction and shop redaction.

Hosting and subprocessors

The application is hosted in [HOSTING_REGION]. Infrastructure services include GitLab for source and container images, Dokploy for container deployment, Cloudflare for DNS and edge TLS, Shopify for platform data and merchant-configured SMTP providers for email delivery. This list must be confirmed before publication.

Security and international transfers

Traffic is protected with HTTPS. Access is restricted to authorized systems and personnel. Details of storage encryption, international transfers and applicable safeguards are [LEGAL_REVIEW_REQUIRED].

Your choices

Merchants and data subjects can contact [email protected] to request access, correction or deletion where applicable. Merchants can disable automatic email delivery by removing their SMTP configuration.