← Rechna

Privacy Policy

Last updated: 1 August 2026

Rechna creates and archives invoices for Shopify merchants. This policy explains what data the app and this site process, why, where — and what that means for your rights. It is written to be read, not to hide behind.

Controller

Santo Gigliotti, trading as Rechna
Via Vergiò 27
6932 Lugano
Switzerland
E-Mail: hello@anmelda.com

Roles: who is responsible for what

a) Your shop's order and customer data — you are the controller

To generate invoices, Rechna reads, through Shopify's APIs, your order data (line items, amounts, taxes, currency) and the associated customer data (name, billing address, email, VAT ID where present). This is personal data about your customers. You are the controller; Rechna processes it only on your behalf under the Data Processing Agreement, and only for one purpose: creating invoices, delivering them (if you enable delivery), and retaining them as the law requires.

b) Your merchant account — we are the controller

For your own account we hold the shop domain, your seller details (company name, address, tax numbers, bank details, logo), your settings, your plan, and your shop's invoice history. We decide the purposes here, so we are the controller for this set.

Legal bases and purposes

The legal bases are Art. 6(1)(b) GDPR (performance of contract — providing the app) and Art. 6(1)(c) GDPR (legal obligation: GoBD, §147 AO, §14b UStG — the immutable retention of issued invoices). We do not profile, we do not sell data, and we do not use your data to train machine-learning models. Neither this site nor the app uses tracking cookies, analytics, or advertising services; session cookies exist only to keep you signed in to the embedded app.

Where data is hosted

All app data is processed and stored in the European Union: AWS region eu-central-1 (Frankfurt) — the application, database, backups, and the invoice archive (Amazon S3 with Object Lock). Every provider is listed on the Sub-processors page.

Rechna is operated from Switzerland, so administering the service means the data is available to us there. Under the GDPR that counts as a transfer to a third country — we would rather say so plainly than claim a Frankfurt address settles the question. Switzerland holds a European Commission adequacy decision, which is the transfer's legal basis; no Standard Contractual Clauses are needed.

If you enable email delivery of invoices to your customers, sending happens through Resend (United States). What is transferred is the recipient's email address and the invoice PDF, under Standard Contractual Clauses. Delivery is off by default and runs only if you switch it on.

Retention — and the limit of the right to erasure

Issued invoices are accounting records. They are retained unchangeably for 8 years (§147 AO, §14b UStG; technically: S3 Object Lock in compliance mode — we cannot delete or alter them either). The right to erasure (Art. 17 GDPR) does not extend to these invoices while the statutory retention period runs (Art. 17(3)(b) GDPR). After the period expires, the archived data is deleted.

When you uninstall the app, we delete all remaining shop data — settings, seller details, drafts — in response to Shopify's shop/redact request; only the legally retained invoice archive remains until its period ends. We honour Shopify's customers/redact and customers/data_request topics within the same statutory limits.

Your rights

Under the GDPR you may request access, rectification, erasure (subject to statutory retention), restriction, portability, and object to processing. For your shop's customer data you are the controller — your customers' requests go to you, and we assist you under the DPA. For your merchant account data, contact hello@anmelda.com.

You also have the right to complain to a supervisory authority (Art. 77 GDPR): in the EU, the authority of your country of residence, place of work, or of the alleged infringement; in Switzerland, the FDPIC.

Security

Encryption in transit (TLS) and at rest; production access restricted to the operator over audited sessions, with no public administrative interface; read-only Shopify scopes (Rechna never modifies your orders); the archive has no delete path.

Changes

When this policy changes materially we update the date above and note it in the app.

Contact

Questions about this policy or your data: hello@anmelda.com.