Privacy policy
Last updated: 2026-08-03
KSeF for Shopify issues invoices from store orders and submits them to Poland's National e-Invoice System. This policy describes what data is processed along the way, and why.
Who controls the data
The merchant — the Shopify store owner — is the controller of buyers' personal data. Leon Rhein acts as a processor, only to the extent needed to issue and submit an invoice.
Contact: alpineappsolutionsdev@gmail.com, Algierstrasse 4, 8048 Zürich, Switzerland.
What we process
Order data: order number, line items, prices, VAT rates, currency, payment date and status.
Buyer data: NIP tax number, company or personal name, billing address, email address.
Merchant data: NIP, name, address, contact details, and the KSeF access token.
We do not process payment data — card numbers and bank details never reach the app.
Legal basis and purpose
Data is processed to meet a legal obligation binding on the merchant (GDPR art. 6(1)(c)): the obligation under the Polish VAT Act to issue structured invoices and submit them to KSeF.
Who we share it with
Invoice data is transmitted to the National e-Invoice System operated by the Polish Ministry of Finance. This transfer is required by law.
Beyond that, data is not shared with third parties and is never used for marketing. We do not sell data.
The app is operated from Switzerland, which holds a European Commission adequacy decision. Data is stored on servers within the European Union.
How long we keep it
Invoices and their official confirmations of receipt (UPO) are retained for five years from the end of the tax year in which the invoice was issued, as Polish tax record-keeping rules require.
For that reason a buyer erasure request (the customers/redact webhook) does not delete an issued invoice — the retention obligation takes precedence. All shop data is deleted on uninstall together with a shop/redact request.
Security
The merchant's KSeF token is encrypted with AES-256-GCM before it is stored, and is never displayed in the app.
All communication with Shopify and KSeF uses HTTPS. Documents sent to KSeF are additionally encrypted under a session key, as that system requires.
Data subject rights
Buyers have the right to access, rectify and restrict processing of their data, and to lodge a complaint with the Polish data protection authority. Requests should be directed to the merchant as controller.