Privacy Policy
Last updated: August 3, 2026
This is the current Privacy Policy for the IFG Registro dei Corrispettivi Shopify app, in force for the app as it operates today.
Data controller
The data controller is Francesco Guiducci, owner of IFG eCommerce, reachable at info@ifgecommerce.com. IFG Registro dei Corrispettivi is the Shopify app the controller develops and operates to automate, for Italian merchants under the ordinary VAT regime, the keeping of the mandatory Italian daily sales register (“Registro dei Corrispettivi”, Art. 24 of Italian Presidential Decree 633/1972) and its reconciliation against issued invoices.
Data we process
To compute the register and the reconciliation, the app receives from your Shopify store, via webhooks and the Admin API (scope read_orders):
- Order data: total amount, tax breakdown by VAT rate, destination country, refund status.
- Invoicing indicators: checkout note attributes and Shopify’s native Italian tax field (VAT number / national tax code / SDI code), used exclusively to exclude already-invoiced orders from the register, avoiding double VAT counting (Italian Revenue Agency FAQ no. 45, 21 Dec 2018).
If you choose to fill them in, we also process data you enter yourself in Settings or during initial setup: your store’s legal name, VAT number and address (used to head the exports), your accountant’s email address (for the automatic report, if you enable it), and, on the Unlimited plan, your own SMTP server credentials if you prefer to send those reports from your own address instead of ours.
What we do not collect
We do not collect, process or store the name, email, phone number or address of your store’s end customers. By law, the sales register is a daily total aggregated by VAT rate — not a customer list. The app does not request Shopify’s read_customers scope.
Purpose and legal basis
- Compliance with a legal obligation (Art. 6(1)(c) GDPR): computing and keeping the sales register required by Art. 24 of Presidential Decree 633/1972.
- Performance of a contract (Art. 6(1)(b) GDPR): providing the features of the app you installed, including export and any automatic report you configured.
- Legitimate interest (Art. 6(1)(f) GDPR): keeping the app running and secure (technical logs, diagnostics), always limited to what is strictly necessary.
We do not use this data for marketing, profiling, advertising, or any purpose other than those listed here.
Where data is stored
Data is stored on Google Cloud Firestore, europe-west1 region (European Union), protected by encryption both in transit (HTTPS/TLS) and at rest (Google Cloud’s native encryption). Access is limited to the app’s own code via service credentials — there is no dashboard for direct access to raw data.
Recipients and data transfers
We do not sell, rent or share the data this app processes with third parties, except as strictly necessary to make it work:
- Google Cloud / Firestore (europe-west1 region, EU) — hosting and storage infrastructure, acting as a processor on our behalf.
- Resend Inc. (United States) — used to email the report to your accountant, when automatic sending is enabled and you have not configured your own SMTP server. The transfer to the United States is covered by the European Commission’s Standard Contractual Clauses.
- Your own SMTP server, if you configure one (Unlimited plan): in that case the report is sent through your own mail provider, not ours.
- Shopify Inc. — the platform the app runs on, which processes your store’s data under its own terms.
No AI or LLM provider is involved in this product. Unlike other IFG eCommerce apps, no order or business data is ever sent to a third-party language model.
How long we keep data
- Sales register: kept for as long as the app stays installed on your store, in our capacity as processor on your behalf, for the duration of the Italian statutory bookkeeping retention period (Art. 2220 of the Italian Civil Code, 10 years).
- On uninstall: your Shopify sessions and your SMTP server credentials are deleted immediately. All remaining data — including your legal name, your accountant’s email and the sales register itself — is permanently deleted 48 hours after uninstall, when Shopify notifies us of the erasure request (
shop/redact). From that point on, keeping your own accounting records is, as required by law, your direct responsibility again: if you uninstall the app, export the register from the Export page first.
Your rights
Under Articles 15–22 GDPR, you have the right to:
- Access the personal data we process about you.
- Request correction of inaccurate or incomplete data.
- Request deletion of data not subject to a legal retention duty.
- Object to processing or request its restriction.
- Request data portability in a structured format.
- Lodge a complaint with a data protection supervisory authority (in Italy, the Garante per la protezione dei dati personali).
To exercise any of these rights, write to info@ifgecommerce.com.
Data security
Shopify webhooks are verified via HMAC signature before being processed. Communication with the app always happens over HTTPS/TLS. Data on Google Cloud is encrypted at rest using the platform’s native encryption.
Changes to this notice
We may update this notice when the way we process data changes. The date at the top of the page shows the latest update; material changes are also announced inside the app.
Contact
For any question about this notice: info@ifgecommerce.com.