Docket privacy policy
Docket — PDF Invoices, Packing Slips & Order Printer ("Docket") is operated by Piya Traders. This policy explains how Docket processes data when a Shopify merchant installs or uses the app.
Data Docket processes
- Shop identity, locale, currency, locations, plan, and app settings.
- Order and draft-order details needed for documents: order numbers, products, quantities, prices, taxes, discounts, fulfillment and payment status, notes, tags, and Shopify custom fields selected by the merchant.
- Customer name, email, and billing or shipping address when needed to create or deliver a requested document. Docket does not request buyer phone fields.
- Business-customer company details, tax registration, payment terms, and order currency used on merchant-configured documents.
- Saved copies of generated documents, invoice-number records, email delivery status, export progress, security and activity logs, and error details.
Docket receives this data from Shopify and from settings entered by the merchant. Docket does not sell personal data, use it for advertising, or use it for decisions with legal or similarly significant effects.
Purposes
Docket uses the minimum data required to create invoices and other merchant-selected documents, send them, provide customer-account and POS downloads, run merchant-configured automatic delivery, prevent duplicate emails or invoice numbers, provide support, keep the service secure, and complete privacy requests.
Service providers and location
Docket uses Shopify for commerce data and sign-in, Railway for EU-hosted web and background processing, Supabase for an EU-hosted database and private file storage, Resend for service emails, and Sentry when configured for error monitoring. These providers process data only to operate Docket under their applicable contractual and security terms.
Retention
- Private generated files and customer data-request reports are deleted within 30 days; most signed download URLs expire in 7 days and privacy-report URLs in 14 days.
- Bulk-export order identity is removed after 90 days.
- Email recipient identity and related provider details are anonymized after 2 years.
- Saved copies of generated financial documents are kept for no more than 7 years so merchants can reproduce issued documents. After a document copy is removed, numbering records retain only a protected replacement for the original order identifier.
- Protected-data access logs are deleted after 1 year and operational activity logs after 2 years.
- After uninstall, Docket stops pending work immediately and schedules remaining store data for deletion within 30 days. A deletion request from Shopify removes stored files and database records promptly, normally well before that deadline.
Security
Data is encrypted while it is sent and while it is stored by the managed database and storage providers. Production and test data are separated. Private files use links that expire. Docket verifies requests from Shopify, prevents duplicate background work, records access without storing full Shopify identifiers in the log, and protects its internal support area with strong password security. The support area does not display document contents or customer contact details.
Privacy rights
Customers should submit access or deletion requests to the Shopify merchant they purchased from. Shopify sends the required request to Docket. Docket tracks it securely and completes the applicable data export or deletion within 30 days. Merchants may contact Docket for assistance.
Contact
Privacy and support questions: omdeeppiyanp@gmail.com.