Last updated: 1 August 2026
Rechna creates and archives invoices for Shopify merchants. This policy explains what data the app and this site process, why, where — and what that means for your rights. It is written to be read, not to hide behind.
To generate invoices, Rechna reads, through Shopify's APIs, your order data (line items, amounts, taxes, currency) and the associated customer data (name, billing address, email, VAT ID where present). This is personal data about your customers. You are the controller; Rechna processes it only on your behalf under the Data Processing Agreement, and only for one purpose: creating invoices, delivering them (if you enable delivery), and retaining them as the law requires.
For your own account we hold the shop domain, your seller details (company name, address, tax numbers, bank details, logo), your settings, your plan, and your shop's invoice history. We decide the purposes here, so we are the controller for this set.
The legal bases are Art. 6(1)(b) GDPR (performance of contract — providing the app) and Art. 6(1)(c) GDPR (legal obligation: GoBD, §147 AO, §14b UStG — the immutable retention of issued invoices). We do not profile, we do not sell data, and we do not use your data to train machine-learning models. Neither this site nor the app uses tracking cookies, analytics, or advertising services; session cookies exist only to keep you signed in to the embedded app.
All app data is processed and stored in the European Union: AWS region eu-central-1 (Frankfurt) — the application, database, backups, and the invoice archive (Amazon S3 with Object Lock). Every provider is listed on the Sub-processors page.
Rechna is operated from Switzerland, so administering the service means the data is available to us there. Under the GDPR that counts as a transfer to a third country — we would rather say so plainly than claim a Frankfurt address settles the question. Switzerland holds a European Commission adequacy decision, which is the transfer's legal basis; no Standard Contractual Clauses are needed.
If you enable email delivery of invoices to your customers, sending happens through Resend (United States). What is transferred is the recipient's email address and the invoice PDF, under Standard Contractual Clauses. Delivery is off by default and runs only if you switch it on.
Issued invoices are accounting records. They are retained unchangeably for 8 years (§147 AO, §14b UStG; technically: S3 Object Lock in compliance mode — we cannot delete or alter them either). The right to erasure (Art. 17 GDPR) does not extend to these invoices while the statutory retention period runs (Art. 17(3)(b) GDPR). After the period expires, the archived data is deleted.
When you uninstall the app, we delete all remaining shop data — settings, seller details, drafts — in response to Shopify's shop/redact request; only the legally retained invoice archive remains until its period ends. We honour Shopify's customers/redact and customers/data_request topics within the same statutory limits.
Under the GDPR you may request access, rectification, erasure (subject to statutory retention), restriction, portability, and object to processing. For your shop's customer data you are the controller — your customers' requests go to you, and we assist you under the DPA. For your merchant account data, contact hello@anmelda.com.
You also have the right to complain to a supervisory authority (Art. 77 GDPR): in the EU, the authority of your country of residence, place of work, or of the alleged infringement; in Switzerland, the FDPIC.
Encryption in transit (TLS) and at rest; production access restricted to the operator over audited sessions, with no public administrative interface; read-only Shopify scopes (Rechna never modifies your orders); the archive has no delete path.
When this policy changes materially we update the date above and note it in the app.
Questions about this policy or your data: hello@anmelda.com.