Last updated: September 14, 2026
AppSaaz Automated GST Invoice ("the app", "we", "us"), built by AppSaaz Labs, reads a merchant's Shopify orders, customers, and products to generate GST-compliant tax invoices, credit notes, debit notes, and GSTR-1/GSTR-3B return filing exports — entirely within the app. Unlike accounting-sync apps, we do not send merchant data to any third-party bookkeeping platform.
For each order, refund, or cancellation, we process:
We do not process payment card details.
Customer phone number. The phone number on a Shopify order is used only when the merchant turns on one of two settings: printing the buyer's phone on the document (Design your documents › Buyer), which some buyers ask for on a GST tax invoice, or sending the document to the buyer on WhatsApp. When either is on, the number is stored on the invoice record with the rest of the billing address and printed or sent as the setting says. When both are off — the default — the phone field on the order is discarded and never stored or printed on any document. It is never used for marketing or shared with anyone but the buyer it belongs to.
Invoice data is used solely to generate and store the merchant's own GST records, and to email the invoice to the customer if the merchant enables that. It is never used for marketing, advertising, analytics, or profiling, and it is never sold.
sin) region.Indian GST law (CGST Rules) requires merchants to retain tax invoices, credit notes, and debit notes for several years from the due date of the relevant annual return. Because of this:
customers/redact or shop/redact webhook, since they are the merchant's statutory tax records, not marketing data.shop/redact — Shopify fires this ~48 hours after uninstall.customers/redact request are scrubbed immediately, regardless of normal retention windows.We share data only with the following sub-processors:
This app does not submit e-invoices (IRN/QR) or e-way bills to the GST Network or any GST Suvidha Provider, and holds no credentials for doing so. No invoice data leaves this app for any government or GSP endpoint.
This app receives and handles Shopify's three mandatory privacy webhooks:
customers/data_request — when a customer asks what data we hold about them, we don't auto-export it outside the app; we log any matching invoices (by email) so the merchant can find and share them from their dashboard.customers/redact — when a customer requests erasure, any queued (not-yet-processed) webhook data matching them is scrubbed immediately. Issued invoices, credit notes, and debit notes are not deleted, because CGST Rules require merchants to retain them as statutory tax records for several years, independent of an erasure request made under GDPR or India's DPDP Act.shop/redact — sent ~48 hours after a merchant uninstalls; all operational data (settings, GSTIN/HSN configuration, sessions, queued jobs, billing state) is deleted automatically. Statutory tax records are retained for the same reason.Since this app processes data on behalf of merchants (as a data processor under GDPR, and under India's DPDP Act, not the data controller), a customer's request to access, correct, or delete their personal data should go to the merchant whose store they purchased from, subject to the merchant's own statutory GST record-keeping obligations. The merchant can contact us at support@getsaaz.app for help fulfilling such requests.
We'll update the "Last updated" date above whenever this policy changes. For any change that materially affects how personal data is processed, we'll email connected merchants at their Shopify-registered account email at least 14 days before the change takes effect.
support@getsaaz.app — see also our Terms of Service.