The archive and how long it keeps things

The archive is one of the two things Zeppol owns outright, the invoice number being the other. An Access Point is a supplier you could change tomorrow; the record of what you invoiced and when is not.

What is kept for each invoice

  • The EN 16931 UBL document exactly as it was sent.
  • The PDF, which is the same invoice in a form a person can read.
  • The invoice number, and the reason for any gap in the sequence.
  • The channel it left by, and the AS4 receipt id if it went over Peppol.
  • Timestamps for every state it passed through.
  • The VAT breakdown, and both parties' legal details as they stood at the time.

The last point matters more than it looks. An invoice records who the parties were on the day it was issued. Changing your company address two years later does not rewrite an invoice you sent before you moved.

Zeppol's invoice archive, each row with its number, channel and state

Eight years, and why not ten

German law has two retention periods and they are routinely confused with each other.

PeriodCoversBasis
8 years Invoices, sent and received §14b(1) UStG, as amended, in force since 1 January 2025
10 years The books: ledgers, inventories, annual accounts and the records underpinning them §147(3) AO

Invoice retention was ten years until the end of 2024 and was shortened to eight. Zeppol stores invoices rather than books, so the number it implements is eight, counted from the issue date.

That is a floor Zeppol sets, not a ceiling on you. If your accountant treats an invoice as a book-keeping voucher under §147 AO, keep it ten.

Nothing is deleted on a timer

When the eight years are up, the record becomes eligible for deletion. It is not deleted. §147(3) AO expressly preserves the suspension of expiry while a matter is open, and an app that silently destroyed a statutory record on a schedule would be a worse failure than one that kept it too long.

What happens when a buyer asks to be erased

Shopify requires every app to answer a customer redaction request. German tax law requires the merchant to keep the invoice. Both are true at once, and Zeppol's position is written down rather than improvised.

An erasure request does not reach the invoice. Article 17(3)(b) GDPR disapplies the right to erasure where processing is necessary to comply with a legal obligation, and §14b(1) UStG is exactly such an obligation. It binds you, the merchant, as controller. Zeppol holds the record on your behalf as processor, so it is not Zeppol's to erase, and erasing it would put you in breach.

Everything else does go. The reusable buyer profile, the link back into Shopify, the workflow state: all of it exists for the software's convenience, has no statutory basis, and is removed.

Getting your records out

Both the UBL and the PDF are downloadable per invoice, and the list can be exported. Nothing is held hostage: the documents are standard files in a standard format, and a DATEV-shaped export for handing the year to your tax office is in progress. There is a guide on Shopify und DATEV.

If you need something the export does not cover, write to [email protected]. The data processing agreement on the DPA page sets out the rest.

Something missing here?

Write to me. Anything asked more than once ends up on this page.