Last updated: 1 August 2026
Bindery is a Shopify app that generates VAT-compliant invoices, credit notes, packing slips, picking lists and return forms for orders in your Shopify store. This policy explains exactly what data the app touches, what it keeps, and for how long.
Bindery is operated by Pond Creek Holdings LLC (Missouri, USA), referred to below as "we" or "us". For questions about this policy or about data we hold, contact support@pondcreekholdings.com.
When you install Bindery you grant it these Shopify API scopes:
| Scope | Why it is needed |
|---|---|
read_orders | To read the order being printed — line items, prices, tax lines, and the billing and shipping addresses that must appear on a legal invoice. |
read_products | To read product titles, variants and SKUs for the document lines. |
read_shop | To read your store's currency, country and basic profile. |
All three are read-only. Bindery cannot modify, create or delete anything in your store. It does not request customer, product-write, or payment scopes.
Order and customer data is fetched from Shopify at the moment you print, passed to your browser, rendered there, and then discarded. It is not written to our database.
These are the only records we keep:
| Record | Contents | Why |
|---|---|---|
| Store connection | Your .myshopify.com domain, an encrypted Shopify access token, its refresh token, expiry times, granted scopes, and install/uninstall timestamps. |
Required to talk to your store's Admin API on your behalf. |
| Your settings | Your legal business name, VAT ID, company registration number, country code, invoice number prefix and padding, payment terms and footer text. | These are printed on every document. They are your business details, not your customers'. |
| Document ledger | For each document issued: document type, sequence number, the formatted number, the Shopify order ID and order name, currency, order total, and the timestamp it was issued. | EU invoice numbering must be sequential and unbroken. We keep this so re-printing an invoice reuses its original number instead of creating a gap an auditor would question. |
We do not store: customer names, email addresses, phone numbers, billing or shipping addresses, line-item detail, or payment information. None of it is written to disk. The document ledger holds only a numeric order total and Shopify's own order identifier.
| Provider | Role | Location |
|---|---|---|
| Shopify Inc. | Source of all order data; handles billing for the app subscription | Canada / global |
| Render Services, Inc. | Application hosting and database storage | United States |
We do not sell data, share it with advertisers, or use it to train machine-learning models. Bindery contains no analytics trackers, no advertising pixels, and no third-party scripts other than Shopify's own App Bridge library, which is required for embedded apps.
Our servers are located in the United States. If your store is in the EEA or UK, the limited data described in section 3 is processed in the US. Because we do not store customer personal data, no customer personal data is transferred or held by us.
app/uninstalled webhook. Bindery can no longer read anything from your store.shop/redact webhook. On receiving it we permanently delete every record associated with your store, including settings and the document ledger.Shopify forwards customer data-access and erasure requests to every installed app. Bindery
implements all three mandatory endpoints. Because we hold no customer personal data, a
customers/data_request returns nothing and a customers/redact has
nothing to erase. Your obligations as data controller are unaffected — this only describes
what we, as a processor, hold.
If you are in the EEA or UK, the GDPR gives you the right to access, correct, export, or erase the data described in section 3, and to object to or restrict its processing. Email support@pondcreekholdings.com and we will respond within 30 days. You also have the right to complain to your national supervisory authority.
Bindery is a business tool sold to merchants. It is not directed at anyone under 16 and we do not knowingly collect data from them.
If we change what we collect or how we use it, we will update this page and change the date at the top. Material changes will be notified inside the app before they take effect.
Bindery is built against Council Directive 2006/112/EC and is designed to produce documents containing the particulars required by Article 226. VAT implementation varies between member states, and responsibility for the accuracy of your invoices remains yours. Bindery is a tool, not a guarantee of compliance, and nothing in the app or this policy is legal or tax advice.