Data Retention and Deletion
App: Henhouse Invoices (a Henhouse app)
Provider: Henway LLC, Miami, Florida, USA
Contact: support@henhouseapps.com
Last updated: 23 August 2026
This is the plain-English version of what we keep, for how long, and what happens when you uninstall or a customer asks to be forgotten. It applies alongside our Privacy Policy.
What we store while the app is installed
| Data | Why | Kept |
|---|---|---|
| Shop record (domain, name, owner email, plan, timezone, currency) | Identify your store, bill you, run the app | Life of the install |
| Shopify access token (encrypted) | Call the Shopify API on your behalf | Life of the install; revoked and deleted on uninstall |
| App settings and configuration | Make the app work the way you set it | Life of the install |
| Order and draft-order records (including customer name, email and addresses, line items and totals), read under the read_orders and read_draft_orders scopes | The app's core feature | For the life of the install. We do not copy your orders in bulk: an order is read when you print it, and what we keep is the document you generated. |
| Generated artifacts (for example: PDFs, exports, logs the app produces for you) | So you can re-download them | Generated documents are kept until you delete them or uninstall the app, so you can re-download them. |
| Webhook payloads (raw) | Process events, retry on failure | Up to 7 days, then deleted |
| Server and error logs | Security, debugging | 30 days rolling |
| Analytics events (PostHog, server-side, no customer PII) | Product improvement | 12 months, then aggregated or deleted |
| Support emails | Help you, keep a record | 3 years after the ticket closes |
| Billing records (plan, charge IDs, amounts; no card data) | Accounting and tax law | 7 years |
| Backups (encrypted, US) | Disaster recovery | Rolling; individual records fall out of backups within 7 days of deletion from the live database |
When you uninstall
- Immediately: Shopify sends us
app/uninstalled. We mark your store inactive, stop all processing, and delete the Shopify access token. Billing stops through Shopify. - 48 hours later: Shopify sends
shop/redact. We delete or anonymize all shop data: shop record, settings, and all customer/order/product data we hold for your store, and any generated artifacts. - Within 30 days of the redact webhook deletion is complete in the live database. Backups age out within 7 days after that.
- What we keep after that: billing records required for tax and accounting (7 years), support email history (3 years), and de-identified aggregate analytics that cannot identify you or your customers.
If you reinstall inside the 48-hour window before shop/redact arrives, your settings may still be there. After that, you start fresh.
Want it gone faster? Email support@henhouseapps.com after uninstalling and we will run the deletion by hand within 2 business days and confirm by email.
When a customer asks to be forgotten (customers/redact)
- Shopify sends us the request 10 days after the merchant submits it (or immediately if the customer has no recent orders).
- Within 30 days we delete or anonymize that customer's personal data (name, email, phone, addresses) from our systems, including in any records or artifacts we hold for your store.
- If we are legally required to keep something (for example, an issued invoice for tax purposes), we keep only the minimum required fields and lock them from ordinary use.
- We confirm completion in our logs; email us if you want written confirmation.
When a customer asks for their data (customers/data_request)
Within 30 days we send you (the merchant) a machine-readable file of the personal data we hold for that customer, so you can pass it on. We do not contact your customer directly.
Merchant data requests
You can ask for a full export of what we hold for your store at any time by emailing support@henhouseapps.com. We answer within 30 days, usually much sooner.
Where deletion happens
Primary database and file storage: Railway (US). Analytics: PostHog (US), where we hold no customer PII, so customers/redact needs no action there; on shop/redact we delete the shop's identifying properties from PostHog within 30 days. Sub-processors are listed in our Privacy Policy.
Changes
If we change retention periods, we update the date at the top and notify you inside the app or by email at least 14 days before the change takes effect.