Privacy Policy
App: Henhouse Invoices (a Henhouse app)
Developer: Henway LLC, Miami, Florida, USA ("Henhouse", "we", "us")
Contact: support@henhouseapps.com
Effective date: 23 August 2026
Last updated: 23 August 2026
This policy explains what data Henhouse Invoices collects when a Shopify merchant installs it, why we collect it, how long we keep it, and how to get it deleted. We wrote it in plain English on purpose. If anything is unclear, email us.
1. Who we are and our role
Henhouse Invoices is an embedded Shopify app built and operated by Henway LLC.
- For merchant account data (your store name, contact email, plan, app settings), Henway LLC is the data controller.
- For your customers' and orders' data that flows through the app so it can do its job, you (the merchant) are the controller and Henway LLC is a data processor acting on your instructions. Our Terms of Service and this policy together form our data processing terms with you.
2. What we collect
From your Shopify store (via the Shopify Admin API, only within the scopes you approve at install):
- Shop details: store domain, store name, owner email, currency, timezone, plan.
- Order and draft-order records (including customer name, email and addresses, line items and totals), read under the read_orders and read_draft_orders scopes (for example: orders, customers, products, fulfillments). We request only the scopes Henhouse Invoices needs to function. The exact scopes are listed on the app's Shopify listing and on the install screen.
- Customer and order data (name, email, address, order lines, totals) only to the extent the app's feature requires it, and only for as long as needed (see Data Retention).
From you directly:
- App settings and configuration you enter.
- Support emails you send us.
Automatically:
- Server logs (IP address, timestamps, request paths, error traces) for security and debugging.
- Product analytics via PostHog, run server-side. We send event names, the shop domain, and app-level context (plan, feature used, timing). We do not send your customers' names, emails, addresses, or order contents to PostHog.
- Cookies: only what Shopify's embedded-app framework needs to keep you signed in inside Shopify Admin. No advertising cookies.
3. Why we collect it (legal bases)
| Purpose | Data | Legal basis (GDPR/UK GDPR) |
|---|---|---|
| Run the app's features | Shop, order, customer, product data | Performance of a contract |
| Billing through Shopify | Shop, plan | Performance of a contract |
| Security, fraud, and abuse prevention | Server logs | Legitimate interest |
| Improve the product | Aggregated usage analytics | Legitimate interest |
| Support you | Support emails, shop details | Performance of a contract |
| Comply with the law | Whatever the law requires | Legal obligation |
We do not sell personal data. We do not use your customers' data for advertising, profiling, or training models.
4. Where data lives and who sees it
- Hosting: Railway (United States). Databases and backups are in the US.
- Sub-processors: Shopify (platform and billing), Railway (hosting), PostHog (analytics, US region), and Resend (email delivery, US; Henhouse Waitlist only). We keep an up-to-date list at https://henhouseapps.com/subprocessors and will notify you by email at least 14 days before adding one that handles personal data.
- International transfers: If you or your customers are in the EU/UK/Switzerland, data is transferred to the US under Standard Contractual Clauses (and the UK Addendum) with our sub-processors.
- Access: Only Henway LLC personnel who need access to run or support the app can see it, under confidentiality obligations. We never post, share, or resell it.
5. Security
Data in transit is encrypted (TLS). Data at rest is encrypted by our hosting provider. Access tokens for your store are stored encrypted and scoped to the minimum permissions. We log access and review it. No system is perfect; if we ever learn of a breach affecting your data, we will notify you without undue delay and, where required, within 72 hours.
6. Shopify's mandatory privacy webhooks
We honor Shopify's compliance webhooks automatically:
- customers/data_request: we send you (the merchant) the personal data we hold on that customer within 30 days so you can pass it to them.
- customers/redact: we delete or anonymize that customer's personal data from our systems within 30 days, unless we must keep it for legal reasons (for example, tax records on an issued invoice), in which case we keep only what the law requires.
- shop/redact: 48 hours after you uninstall, Shopify tells us to delete your shop's data. We complete deletion within 30 days. See our Data Retention policy for the full timeline.
7. Your rights (and your customers' rights)
Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal data, and to object to processing based on legitimate interest. To exercise these rights, email support@henhouseapps.com. We answer within 30 days.
If a request comes from your customer, we will point them to you as the controller and help you fulfil it. You can also handle it directly through Shopify, which triggers the webhooks above.
- EU/UK/Swiss residents: you may lodge a complaint with your local data protection authority.
- California residents (CCPA/CPRA): we do not sell or share personal information, and we act as a "service provider" for merchant data. You have the right to know, delete, correct, and not be discriminated against for exercising these rights.
- Other US states and Canada (PIPEDA): similar rights apply and the same email address works.
8. Children
Henhouse Invoices is a business tool for merchants and is not directed at anyone under 16. We do not knowingly collect data from children.
9. Changes
If we make a material change, we will update the date at the top and notify you inside the app or by email at least 14 days before it takes effect. Continued use after that date means you accept the change.
10. Contact
Henway LLC
1355 NW 91st St
Miami, Florida, USA
support@henhouseapps.com