Henhouse

Data Retention and Deletion

App: Henhouse Invoices (a Henhouse app)

Provider: Henway LLC, Miami, Florida, USA

Contact: support@henhouseapps.com

Last updated: 23 August 2026

This is the plain-English version of what we keep, for how long, and what happens when you uninstall or a customer asks to be forgotten. It applies alongside our Privacy Policy.

What we store while the app is installed

DataWhyKept
Shop record (domain, name, owner email, plan, timezone, currency)Identify your store, bill you, run the appLife of the install
Shopify access token (encrypted)Call the Shopify API on your behalfLife of the install; revoked and deleted on uninstall
App settings and configurationMake the app work the way you set itLife of the install
Order and draft-order records (including customer name, email and addresses, line items and totals), read under the read_orders and read_draft_orders scopesThe app's core featureFor the life of the install. We do not copy your orders in bulk: an order is read when you print it, and what we keep is the document you generated.
Generated artifacts (for example: PDFs, exports, logs the app produces for you)So you can re-download themGenerated documents are kept until you delete them or uninstall the app, so you can re-download them.
Webhook payloads (raw)Process events, retry on failureUp to 7 days, then deleted
Server and error logsSecurity, debugging30 days rolling
Analytics events (PostHog, server-side, no customer PII)Product improvement12 months, then aggregated or deleted
Support emailsHelp you, keep a record3 years after the ticket closes
Billing records (plan, charge IDs, amounts; no card data)Accounting and tax law7 years
Backups (encrypted, US)Disaster recoveryRolling; individual records fall out of backups within 7 days of deletion from the live database

When you uninstall

  1. Immediately: Shopify sends us app/uninstalled. We mark your store inactive, stop all processing, and delete the Shopify access token. Billing stops through Shopify.
  2. 48 hours later: Shopify sends shop/redact. We delete or anonymize all shop data: shop record, settings, and all customer/order/product data we hold for your store, and any generated artifacts.
  3. Within 30 days of the redact webhook deletion is complete in the live database. Backups age out within 7 days after that.
  4. What we keep after that: billing records required for tax and accounting (7 years), support email history (3 years), and de-identified aggregate analytics that cannot identify you or your customers.

If you reinstall inside the 48-hour window before shop/redact arrives, your settings may still be there. After that, you start fresh.

Want it gone faster? Email support@henhouseapps.com after uninstalling and we will run the deletion by hand within 2 business days and confirm by email.

When a customer asks to be forgotten (customers/redact)

When a customer asks for their data (customers/data_request)

Within 30 days we send you (the merchant) a machine-readable file of the personal data we hold for that customer, so you can pass it on. We do not contact your customer directly.

Merchant data requests

You can ask for a full export of what we hold for your store at any time by emailing support@henhouseapps.com. We answer within 30 days, usually much sooner.

Where deletion happens

Primary database and file storage: Railway (US). Analytics: PostHog (US), where we hold no customer PII, so customers/redact needs no action there; on shop/redact we delete the shop's identifying properties from PostHog within 30 days. Sub-processors are listed in our Privacy Policy.

Changes

If we change retention periods, we update the date at the top and notify you inside the app or by email at least 14 days before the change takes effect.