Arure E-Invoicing
Privacy Policy
1. Who we are
This Privacy Policy describes how Arure LLC (“Arure,” “we,” “us”) processes personal data when merchants install and use the Shopify app Arure E-Invoicing (the “App”), which turns Shopify orders and refunds into e-invoices and credit notes under the e-invoicing rules of the Zakat, Tax and Customs Authority of Saudi Arabia (“ZATCA”). It supplements our corporate policy at arure.tech/privacy-policy; where they conflict for App data, this page controls.
For Shopify Protected Customer Data purposes, we process data only for App functionality and for the merchant’s legal and tax compliance.
2. Roles
The merchant is the controller of its customers’ and staff’s data and the taxpayer responsible for its invoices. Arure acts as a processor on the merchant’s instructions, as set out in the Merchant Data Processing Addendum. ZATCA receives invoices because the law requires it and processes them as a public authority under Saudi law. Shopify is a separate controller or processor for platform data under its own terms.
3. Personal data we process
| Data | Examples | Purpose |
|---|---|---|
| Merchant and staff | Shop domain; Shopify access tokens (encrypted at rest); the merchant’s legal name, VAT and commercial registration numbers and national address; staff email on Admin sessions | Install, sign-in, billing, the seller section of every invoice, ZATCA registration |
| Orders and refunds | Order and refund IDs and numbers, items, quantities, prices, discounts, taxes, shipping, payment method type, the Shopify customer ID, and (for business buyers) checkout attributes such as the buyer’s VAT number | Building the invoice or credit note and linking it to the order |
| Business buyers (tax invoices) | Company or contact name, VAT number and billing address, as entered at checkout | The buyer section that ZATCA requires on a standard tax invoice. Simplified (consumer) invoices carry no buyer name or address. |
| E-invoices | The issued XML, its hash, QR code, ZATCA’s response, and a human-readable copy | Reporting or clearance with ZATCA; the merchant’s records; the buyer’s copy |
| Privacy requests | Customer ID and order IDs from Shopify privacy webhooks; data-request exports | Fulfilling customers/data_request, customers/redact and shop/redact |
Order details arrive by Shopify webhook. We keep only the fields an invoice needs, and drop the rest of the webhook on arrival. Once a document is issued, the stored order details are cleared; the document itself and a minimal snapshot needed for later credit notes remain.
4. Disclosure to ZATCA and to buyers
- ZATCA: every document is sent to ZATCA’s Fatoora platform, as Saudi e-invoicing law requires. Simplified invoices are reported within 24 hours; standard tax invoices are cleared by ZATCA before the buyer receives them.
- The buyer’s copy: each document has a web page at an unguessable address, written to the Shopify order so the merchant can include it in order emails. Anyone with the link can view that one document. Pages are marked not to be indexed by search engines.
We do not sell App personal data, use it for advertising, or use it to train unrelated AI models. Disclosure is limited to ZATCA, our hosting provider, Shopify as the platform, and where the law requires it.
5. Retention
- E-invoices are tax records. Saudi VAT law requires the merchant to keep them for at least six years. We keep them while the App is installed, and the merchant can download all of them at any time from the App’s Privacy page.
- Customer erasure: on Shopify’s
customers/redactwe clear stored order details for that customer’s orders. Issued e-invoices are retained, because the law requires the merchant to keep them (GDPR Art. 17(3)(b) and the equivalent provisions of Saudi Arabia’s Personal Data Protection Law). - Customer data requests: exports are kept for 30 days for the merchant to hand over, then cleared.
- Uninstall: on
app/uninstalledwe end all App sessions. About 48 hours later Shopify sendsshop/redactand we delete all of the shop’s App data, including its e-invoices and its ZATCA key and certificates. Merchants must download their documents before uninstalling. - Backups: the database is backed up nightly and each backup is kept for 14 days, so deleted data can remain in backups for up to 14 days.
6. Security
Admin access requires Shopify authentication. Shopify access tokens, the store’s ZATCA private key and its ZATCA credentials are encrypted at rest; the private key never leaves our server. Webhooks are verified with Shopify’s signature. All traffic uses HTTPS. Write to privacy@arure.tech for details of our security measures.
7. Your rights and merchant controls
Customers should contact the merchant first for access, correction or deletion. Merchants can use Shopify’s privacy request tools (which trigger our webhooks and appear on the App’s Privacy page), download all documents, contact us, or uninstall the App.
8. Where data is processed
The App is hosted with DigitalOcean in the United States (New York). Documents are also sent to ZATCA in Saudi Arabia. Where required, transfers rely on appropriate safeguards such as standard contractual clauses.
9. Changes
We may update this policy as the App evolves and will change the “Last updated” date when we do. Continued use of the App after an update means acceptance of the revised policy where the law allows.
10. Contact
Privacy questions about E-Invoicing: privacy@arure.tech. Support: hello@arure.tech.