Privacy Policy
Last updated: July 13, 2026
1. Who we are
TaxPad ("the App", "we", "us") is a Shopify app that applies the correct VAT for postal-code-dependent tax zones (such as the Greek islands, the Canary Islands, the Azores/Madeira or the Åland Islands) through an automatic discount at checkout, a checkout banner and a storefront widget. It is operated by GC Global Digital Services LLC, a Delaware limited liability company (600 N Broad Street, Suite 5, Middletown, DE 19709, United States). For any privacy matter, contact us at support@dro.wtf.
2. Scope and roles
The App is installed by Shopify merchants. For any personal data of a merchant's customers, the merchant is the data controller and we act as a data processor / service provider, processing data only on the merchant's instructions to provide the App. For the merchant's own account data (store domain, contact email, subscription plan), we act as an independent controller for the purpose of operating and billing the App.
3. Data we process
- Store data: store domain, store name, contact email, currency and subscription plan.
- Tax-zone configuration: the zones, postal-code ranges and VAT rules the merchant creates in the App. This is configuration data, not personal data.
- Order aggregates: from the orders/create webhook we store the order ID, order name, country code, the name of the matched tax zone, order totals and the discount amount applied. We do not store customer names, emails, addresses or postal codes — the shipping postal code is evaluated in memory only to determine the matching zone and is immediately discarded.
- Technical data: Shopify API access tokens required to operate, and minimal operational logs.
At checkout,the buyer's shipping postal code is read by Shopify's discount function and checkout extension, which run entirely inside Shopify's infrastructure. That postal code never leaves Shopify and is never sent to TaxPad servers.
The storefront widget stores the postal code a visitor types locally in their own browser (localStorage and/or a cart attribute), so the estimate persists while browsing. It is never transmitted to or stored on TaxPad servers.
We do not process payment card data. Payments and app billing are handled entirely by Shopify (Shopify Billing API).
4. Purposes and legal bases (GDPR)
- Providing the App (zone matching, automatic VAT discount, checkout banner, storefront widget, statistics) — performance of a contract (Art. 6(1)(b) GDPR) and the merchant's instructions as controller.
- Billing and account management — performance of a contract (Art. 6(1)(b)).
- Security, abuse prevention and troubleshooting — legitimate interest (Art. 6(1)(f)).
- Compliance with legal obligations (Art. 6(1)(c)).
5. Sharing and subprocessors
We do not sell or share personal information for advertising, and we do not use it for profiling or training purposes. Data is shared only with the infrastructure providers strictly needed to run the App:
- Shopify (platform; source of store and order data; runs the discount function and checkout extension).
- Vercel Inc. (application hosting, USA/EU edge network).
- Neon Inc.(managed PostgreSQL database, EU region, where the App's data is stored).
6. International transfers
Where data is transferred outside the EEA/UK (e.g. to the USA), we rely on appropriate safeguards: the EU Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework.
7. Retention and deletion
- Data is retained only while the App is installed and the service is provided.
- When a merchant uninstalls the App, Shopify sends us a mandatory redaction request (shop/redact) about 48 hours later and all of that store's data is permanently deleted from our database within 30 days.
- customers/data_request: because the App does not store any customer personal data, there is no customer personal data to return. We confirm this to the merchant.
- customers/redact: as no customer personal data is stored, there is nothing to delete; the request is acknowledged automatically.
8. Security
All traffic is encrypted in transit (TLS). Data at rest is encrypted by our hosting providers. Every App request from the Shopify admin is verified with signed session tokens, and webhooks are verified with HMAC signatures. Access to production systems is limited to the operator.
9. Your rights (EEA/UK)
Subject to the GDPR, you may exercise the rights of access, rectification, erasure, restriction, portability and objection. If you are a customer of a store using the App, please direct your request to that store (the controller); note that TaxPad holds no personal data about store customers. You may also lodge a complaint with your local supervisory authority.
10. US privacy rights (CCPA/CPRA and state laws)
We act as a service provider for merchant data. We do not sell personal information, do not share it for cross-context behavioral advertising, and do not use sensitive personal information beyond providing the service. US residents may have rights to know, delete and correct their personal information and will not be discriminated against for exercising them. Requests can be made through the merchant whose store you interacted with, or via support@dro.wtf.
11. Cookies and local storage
The App does not use advertising or analytics cookies. The storefront widget uses only essential browser storage on the visitor's device (localStorage and/or a cart attribute) to remember the postal code they typed; this data stays in the browser. The App runs inside the Shopify admin and checkout, whose cookies are governed by Shopify's own privacy policy.
12. Children
The App is a business tool and is not directed to individuals under 16.
13. Changes
We may update this policy; the date above reflects the latest version. Material changes will be communicated through the App or the listing.
14. Contact
GC Global Digital Services LLC · 600 N Broad Street, Suite 5, Middletown, DE 19709, United States · support@dro.wtf