Slip Invoice

Privacy policy

Last updated 21 September 2026.

Who we are

Slip Invoice is built and run by Nhat Minh Nguyen, a sole trader in New South Wales, Australia. Questions about privacy, or any request about your data, go to support@nhatminh.dev, and a postal address is available on request.

Slip Invoice is an app for Shopify stores. It prints invoices, packing slips, quotes and credit notes from a store’s own orders. It does nothing else with order data.

Two different relationships

For a merchant who installs the app, we decide what is stored about their shop, so for that information we are the controller.

For a shop’s customers, we only ever handle personal data on the merchant’s instructions, to print the document the merchant asked for. The merchant is the controller of that data; we are their processor. If you are a customer of a shop and want your data corrected or erased, ask the shop you bought from — they can act on it, and the tools below carry their instruction through to us.

What we store

Permanently, until the app is uninstalled:

  • The shop’s myshopify.com domain.
  • The template settings the merchant chose, and any logo image they uploaded.
  • The access record that lets the app talk to Shopify on the shop’s behalf.

For three months, then deleted automatically:

  • A document log. Each entry holds only the shop’s domain, the type of document, the Shopify record it was made from, and the month. It is what the monthly document allowance is counted from.

What we do not store

We do not keep order contents, customer names, email addresses, postal addresses, phone numbers or amounts. We do not keep the documents themselves. The one thing the document log does hold is Shopify’s own reference number for the order, which someone with access to that shop’s Shopify admin could look up — so we treat it as personal data, and it is deleted when a customer is erased.

A document is built fresh from Shopify each time it is asked for, sent to whoever asked for it, and held in memory for at most five minutes so that a repeated click does not rebuild it. It is never written to disk.

We do not sell data, we do not share it for advertising, and the app contains no analytics or tracking of any kind.

Customer personal data

A document has to name the person it is for, so when a merchant prints one we read that order’s customer name, postal address and — on some document types — email address from Shopify and place it on the page. Where the merchant has switched it on, we also print the order note, which a customer may have typed at checkout. Shopify classifies this as protected customer data and controls who may access it.

None of it is written to our database. The finished document is held in memory for at most five minutes, so that a repeated click does not rebuild it, and then dropped. It is never written to disk.

Our lawful basis is legitimate interest: a merchant cannot send an invoice without naming the buyer. Packing slips deliberately leave off prices, email addresses and tax numbers, because parcels are often opened by someone other than the buyer.

Download links in order emails

A merchant can add a link to their order confirmation email so a customer can download their own invoice. Each link is signed with a secret unique to that shop and is valid for exactly one order and one document type. A link with an invalid signature is refused before anything is fetched from Shopify.

These links carry no expiry date of their own. In practice a link stops working when the order behind it is no longer available to the app, when the merchant changes their signing secret or leaves the paid plan, or when they uninstall. Anyone holding the link can open that one document, so it should be treated as private in the same way the order email itself is.

Who else handles the data

  • Shopify — where the orders live. Everything we print is read from there at the moment it is printed.
  • Fly.io — runs the application. Sydney, Australia.
  • Supabase — hosts the database described above. Sydney, Australia.

There are no others. Our web access log records the path of each request only — never the query string — so signed link tokens and anything typed into a search box are not written down.

Deletion

When a merchant uninstalls, we immediately drop the record that lets us talk to Shopify on their behalf, so the app can no longer read anything from their store. Their settings and logo are deliberately kept for a short while so that reinstalling does not lose their template. Shopify then sends a deletion signal 48 hours after the uninstall, and at that point the settings, the logo, the signing secret and every document-log entry are deleted. Nothing is kept for a rainy day.

When a merchant erases a customer through Shopify, we delete our document-log entries for that customer’s orders. Because we never stored their personal details, there is nothing else of theirs to erase.

Security

Traffic is encrypted in transit and the database is encrypted at rest. Access to the production system is limited to Nhat Minh Nguyen and protected by two-factor authentication. Requests are size-limited and rate-limited. If we ever become aware of a breach affecting a merchant’s data, we will notify the merchant and, where the law requires it, the relevant authority — for Australia, the Office of the Australian Information Commissioner.

Your rights

You can ask what we hold about you, ask for it to be corrected, ask for it to be deleted, or object to how it is handled. Write to support@nhatminh.dev and we will answer within 30 days. We apply the same rights to everyone, wherever you live.

In Australia you can complain to the Office of the Australian Information Commissioner. In the EU or UK you can complain to your local data protection authority.

Changes

If this policy changes, the date at the top changes with it, and anything that materially affects a merchant will be told to them by email before it takes effect.