Privacy policy
Effective date: 28 August 2026
StatementClerk (statementclerk.com) is an app for Shopify stores that emails account statements to a store's business customers on a schedule. It is operated by MB Croppick, company code 308104331, registered office Krivių g. 5, LT-01204 Vilnius, Lithuania ("StatementClerk", "we", "us"). Questions and requests: privacy@statementclerk.com.
The short version
- We read your store's companies, orders, payments and refunds from Shopify — read-only — and keep a ledger of the money facts (order references, amounts, dates) needed to compute statements.
- We store the statements we build for you (the figures and the PDF) so you can review, re-send and keep a history.
- We do not store your customers' email addresses, names, addresses or phone numbers. The billing contact's email is read from Shopify at the moment a statement is sent, used for that send, and not kept.
- No artificial-intelligence processing of any kind; statements are arithmetic over Shopify's own records.
- Everything runs on Cloudflare's platform; the database and file storage are in Cloudflare's Eastern Europe region.
- We never sell data, never use it for marketing, and show no ads.
- Uninstall the app and everything is deleted, automatically, on Shopify's standard schedule.
Who this policy covers
- Merchants — the store that installs StatementClerk. For your account data, we are the data controller.
- Recipients — the people at your business customers who receive the statements (a bookkeeper, an accounts-payable contact). For recipient data, you (the merchant) are the controller and StatementClerk is your processor: we handle it only to send the statements you configured, on your instructions as expressed through the app. The data processing agreement sets out that relationship in full and forms part of the terms.
Why we may process it (legal basis)
For your merchant account data, the basis is the performance of our contract with you (GDPR Article 6(1)(b)). For usage metrics, security logs and abuse prevention, it is our legitimate interest in running a reliable, secure service (Article 6(1)(f)). For plan and billing records, it is our legal obligation under accounting law (Article 6(1)(c)). Recipient data we process on your instructions as your processor, so the legal basis for it is yours to establish, not ours.
What we collect, why, where, and for how long
| What | Why | Where it is stored | How long |
|---|---|---|---|
| Merchant account — store domain, store name, store contact email, currency, timezone, app settings (schedule, branding, templates, your own CC/BCC addresses), plan and billing status, encrypted Shopify API tokens | To run the app for your store and bill through Shopify | Cloudflare D1 database (Eastern Europe region) | While the app is installed; deleted after uninstall (see "Uninstalling") |
| Companies — the names, Shopify identifiers and external references of your B2B companies, how many locations they have, and the per-company settings you choose | To know who receives a statement and on what schedule | Cloudflare D1 | While installed; deleted on uninstall |
| Ledger — for each company order: order reference, issue and due dates, amounts, what is outstanding, payment and refund events with dates and amounts, and whether a payment was recorded manually. No line items, no products, no customer data | To compute opening balances, activity, open items and days past due | Cloudflare D1 | While installed; deleted on uninstall |
| Statements — the computed statement (figures and lines) and the PDF we emailed | So you can review, re-send and keep a history; so the next statement can carry the balance forward | Statement data in Cloudflare D1; PDFs in Cloudflare R2 file storage (Eastern Europe region) | While installed; deleted on uninstall |
| Delivery log — per statement: when it was sent, the outcome (sent, bounced, refused), and how many recipients it went to. Never the addresses | To show you what went out and surface bounces | Cloudflare D1 | While installed; deleted on uninstall |
| Audit log — operational events, including a record each time the app reads a billing contact's email from Shopify to send a statement (company and count, not the address) | Support, and the access log required for Shopify's protected customer data | Cloudflare D1 | While installed; deleted on uninstall |
| Usage metrics — counts of statements built, sent, held and bounced, keyed to your store | Service quality and plan limits | Cloudflare Analytics Engine | About three months (Cloudflare's retention), then expires |
| Feedback — messages you send through the in-app or site feedback form, with an optional email address | To read and answer your feedback | Cloudflare D1 | Until handled; deleted on uninstall |
We do not collect payment card details (Shopify handles all billing) and we place no advertising or cross-site tracking cookies. The embedded app uses Shopify session tokens for sign-in; the website uses no analytics that identify you. The public feedback form is protected by Cloudflare Turnstile, a privacy-preserving check that blocks automated spam.
Recipients — how the billing contact is handled
Shopify holds each company's billing contact. When a statement is sent, StatementClerk reads that contact's email address from Shopify, hands the message to Cloudflare Email Sending for delivery, and records only that a send happened and to how many addresses. The address itself is not written to our database or files. The email is your communication to your customer, not ours: it shows your store's name as the sender (the sending address is ours, mail.statementclerk.com, so that delivery and bounces work), carries your store's email address as the reply address, and mentions StatementClerk only in a one-line "Sent with StatementClerk" note. Cloudflare keeps delivery events — including the recipient address — in its email analytics for about 31 days, so that bounces can be reported back to you; after that they expire.
Extra recipients you add yourself in the app (a company's second contact, your own bookkeeper) are settings you control and can remove at any time.
Where your data lives
StatementClerk runs entirely on Cloudflare's platform. The database (Cloudflare D1) and file storage (Cloudflare R2) that hold the data above are located in Cloudflare's Eastern Europe region. Requests are processed by Cloudflare's global edge network in transit, as with any Cloudflare-hosted service. Statement emails and before-due reminders are sent through Cloudflare Email Sending from mail.statementclerk.com, in your store's name, with replies going to your store's email address.
Who we share data with (subprocessors)
| Subprocessor | What they process | Why |
|---|---|---|
| Cloudflare (hosting, storage, email, PDF rendering) | All data in the table above, encrypted in transit; the statement HTML during PDF rendering; recipient addresses during delivery | Runs the entire service |
| Shopify | Your store identity and subscription/billing events | The platform the app runs on |
| Google (Gmail) | The content of email you send to support@ or privacy@statementclerk.com — those addresses forward to a Gmail mailbox — and our replies | Reading and answering your email |
That is the whole list. There is no AI provider. We do not sell personal data, share it with data brokers or advertisers, or use recipient data for any marketing.
Changes to this list. Before a new subprocessor starts processing your data we update this table and notify you in the app or by email at least 14 days in advance. If you object, you may uninstall before it takes effect, and your data is deleted as described below.
How long we keep data (summary)
- While installed: everything above stays so that balances carry forward correctly and your statement history remains reviewable.
- Customer redaction: on a customer data-erasure request relayed by Shopify, we remove the reference to that contact; there is no stored email, name or address to erase.
- Uninstalling: uninstalling revokes our access token immediately. Shopify sends the shop-deletion signal about 48 hours later, and on it we delete everything — every PDF and every database record for the store.
Your rights
Merchants can see and change their data in the app (settings, companies, statements) or write to privacy@statementclerk.com to access, correct, export, or delete anything, or to object to or restrict processing. If you are in the EU/EEA or UK, you also have the right to complain to a supervisory authority. Ours is the State Data Protection Inspectorate of Lithuania (Valstybinė duomenų apsaugos inspekcija, L. Sapiegos g. 17, LT-10312 Vilnius, vdai.lrv.lt); you may equally complain to the authority in your own EU/EEA or UK country.
Recipients should direct requests to the merchant they receive statements from — the merchant is the controller. StatementClerk supports the merchant's obligations automatically through Shopify's mandatory privacy webhooks:
customers/data_request— logged and surfaced so the merchant can respond; we assist on request.customers/redact— the reference to the contact is removed.shop/redact— the store's complete data is erased after uninstall.
Security
- Shopify access tokens are stored encrypted (AES-GCM) and never leave the server side.
- All traffic is TLS; webhooks are verified with Shopify's HMAC signatures before anything is processed.
- The app requests read-only permissions. It never creates, edits or collects payments, orders or invoices.
- The app holds Shopify's protected customer data approval for the billing contact's email and name. Today it reads only the email address — at the moment a statement or reminder is sent, to address it — and never stores it; the name is not read at all.
- Every account behind the service (Cloudflare, GitHub, Shopify Partners, the domain registrar) is protected by two-factor authentication, and access is limited to the operator.
- PDFs are stored under per-store keys and served only through authenticated, signed links.
International transfers
Primary storage is in Cloudflare's Eastern Europe region. Cloudflare processing is covered by Cloudflare's data-processing addendum, which incorporates the EU standard contractual clauses. Email you send us is read in Gmail; Google LLC participates in the EU–U.S. Data Privacy Framework, which covers any processing of that correspondence in the United States.
Children
StatementClerk is a business tool for merchants and is not directed at children.
Changes to this policy
If this policy changes materially, we will note it here with a new effective date and flag it in the app.
Contact
privacy@statementclerk.com — or support@statementclerk.com for anything else.