Privacy policy
Last updated 10 September 2026
Zeppol ("the app", "we") is operated by BTNG B.V., a company registered in the Netherlands. This policy describes what data we process on this website and inside the Zeppol Shopify app, why, who else touches it, and when it is deleted.
This website
Two things on zeppol.com touch personal data, and nothing else does.
- The early-access form. If you submit your email address, it is stored by Kit (kit.com), our email provider, and tagged so we know which page you signed up from. We use it to tell you when Zeppol is available and to send e-invoicing updates. Every email carries an unsubscribe link, and unsubscribing removes you.
- Analytics. We use Plausible, which is cookieless and stores no personal data and no cross-site identifiers. It counts page views and referrers in aggregate. There is no cookie banner on this site because there are no tracking cookies to consent to.
The site is served by Cloudflare. We do not run advertising pixels, session recording, or third-party trackers of any kind.
The Zeppol Shopify app
This section describes the data the app processes once a merchant installs it on their Shopify store. The app is in development and not yet publicly listed; nothing below happens until you install it.
- Order data: order totals, line items, currency, VAT amounts and order status, read from Shopify to produce the invoice for that order.
- B2B buyer details: company name, VAT number, Peppol participant ID, country and the billing address on the order. An invoice is a legal document that must name its recipient, so this data is the invoice, it cannot be omitted.
- Store configuration you enter: your company name, VAT number, Peppol ID, country and your delivery settings.
- The invoices themselves: the generated EN 16931 document (Peppol BIS Billing 3.0 UBL) and its PDF, the invoice number, amounts and delivery status, retained so you have the audit trail tax law requires.
In short: Zeppol processes what has to appear on a compliant B2B invoice, and nothing beyond it. We do not process payment card details; those never reach us.
What we never do
- We do not sell or rent data to anyone.
- We do not use your data, or your buyers' data, to train machine-learning models.
- We do not share your data with third parties except the processors below.
- We do not read order history beyond what invoicing requires.
Processors
For the website, three providers touch data. For the app, three named sub-processors do, and the data processing agreement sets out exactly what each one receives.
- Cloudflare: serves this website.
- Kit: stores early-access email addresses and sends our emails.
- Plausible: cookieless, aggregate website analytics.
- Hosting & database: the app, its worker and its database run on a server operated by Hetzner Online GmbH (Germany) in the European Union.
- Storage, network edge and email: Cloudflare, Inc. (United States) stores the invoice archive and the database replica in R2 buckets created with EU jurisdiction, which fixes the data at rest to the European Union; it also provides DNS and the tunnel through which traffic reaches the app, and, where configured, the service that sends invoice and alert emails. Transfers to Cloudflare are covered by the EU Standard Contractual Clauses and Cloudflare's certification under the EU-U.S. Data Privacy Framework.
- Peppol access point: when you choose Peppol delivery, the invoice is handed to Recommand (BRBX BV, Belgium), a Peppol Access Point and SMP certified under the Belgian Peppol Authority, for transmission to your buyer. That is inherent to how the Peppol network works.
- VIES: the European Commission's VAT number validation service, queried to check a buyer's VAT number is valid. Required to apply reverse charge correctly.
The data processing agreement is the contract behind this list: roles, the data each sub-processor receives, security measures, audit, and how invoice records are retained and deleted.
GDPR
The app implements Shopify's mandatory privacy webhooks:
- Customer data request: we return the B2B invoice records held for that customer.
- Customer redact: we delete the buyer profile. Issued invoices are retained where tax law requires it; an invoice already sent to a tax authority or a buyer cannot lawfully be erased on request.
- Shop redact: within 48 hours of Shopify's signal (30 days after uninstall), every record belonging to the store is permanently deleted: settings, buyer profiles, invoices and generated documents.
You can request deletion at any time by emailing [email protected]. You also have the right to access, correct, or export your data, and to complain to your national data protection authority.
Data retention
App data is retained while the app is installed, then deleted on Shopify's shop-redact schedule above. Backups expire within 30 days. Early-access email addresses are kept until you unsubscribe. Invoice records may be retained longer where tax law requires it.
Security
- All traffic is encrypted in transit (TLS).
- Access-point API credentials are encrypted at rest.
- Shopify access tokens are stored server-side only and scoped to the minimum permissions the app needs.
- Credentials are never written to logs.
Contact
BTNG B.V. · Netherlands · [email protected]
If we change this policy materially, we'll note it here with a new date.
Zeppol is an independent app and is not affiliated with or endorsed by Shopify.