Privacy Policy

Last updated: 17 September 2026

In short: Klarbuchung reads payouts and orders from your Shopify store to create booking data for your tax accountant. We do not request names, email addresses, phone numbers or street addresses of your customers, and we do not store payout or order data. The app sets no cookies and uses no tracking. Servers and database are located in Germany, and the database is encrypted. This is a translation; the German version prevails.

1. Controller and contact

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

geckIT, Ravel-Lukas Geck
Heidenoldendorfer Straße 126
32758 Detmold, Germany
Email: ravel-lukas@geckit.de
Phone: +49 178 5749602

We have not appointed a data protection officer because the legal requirements for doing so are not met.

2. Overview and roles

Klarbuchung is an app for merchants running a Shopify store (“merchants”). It reconciles Shopify Payments payouts and creates booking data in DATEV or BMD format, optionally including PayPal activity and a bank statement reconciliation.

  • As a processor (Art. 28 GDPR) we process data that may relate to the merchant's customers, such as order numbers and amounts. The merchant remains the controller. Details are set out in our data processing agreement (German).
  • As a controller we process data required to operate the app, for the contractual relationship with the merchant, for support and for the security of our servers.

Shopify is not our service provider but the platform the merchant uses. Shopify's privacy policy applies to Shopify's processing.

3. Data from the Shopify store

On installation the merchant grants the app read access to the following areas. The app reads this data through Shopify's API on each request and processes it only for the duration of that request. It is not stored in our database, except for the bookings contained in the booking batches you export (section 4).

AreaDataPurpose
Shopify Payments accountPayouts (date, amount, status, bank reference) and their transactions (type, amount, fee, date, order number)Reconciliation, display, booking batches, PDF reports
OrdersOrder number, date, amounts, tax rates and tax amounts per line, shipping, refunds, payment method, country code of the shipping or billing addressRevenue bookings in “full” mode and tax classification (domestic, EU, non-EU)
StoreStore domain, plan, development store flagAuthentication, feature access

The app does not request customer names, email addresses, phone numbers or street addresses. Only the country code is read from an address. A booking batch is stored when it is first exported, so that every later download, including through the accountant link, returns exactly the same file. PDF reports are generated on download and sent directly to you; we do not keep copies.

4. Data we store

DataExamplesPurposeRetention
Store accessStore domain, app access token, scopes, expiryAccess to the Shopify APIuntil uninstall (deleted immediately)
SettingsChart of accounts, DATEV consultant and client number, accounts, booking mode, BMD options, store code, optionally the accountant's email addressCreating booking data; the email address is only used to prefill a message in your own email programuntil 7 days after uninstall
Booking rulesTransaction type and chosen accountAutomatic booking of special casessame as settings
Export logMonth, time, format, number of bookings, checksum, origin (app or accountant access)Traceability of booking data handed oversame as settings
Export filesBooking batches created (DATEV or BMD) with dates, amounts, accounts, booking texts and order numbers, plus checksum, creation time and app versionRe-downloading exactly the same file for you and your accountantsame as settings
PayPal transactionsTransaction ID, date, type, status, currency, gross, fee, net, invoice or order numberPayPal reconciliation and bookingsame as settings; restricted when a deletion request for the related order is received (see section 13)
Bank matchesPayout ID, arrival date, amount, match confidenceShowing whether a payout has arrivedsame as settings
Accountant linksLabel chosen by the merchant, checksum of the link, created, expiry, revoked and last-used timeAccountant access to monthly filessame as settings
View per personID of the Shopify staff account from the session token (without name or email address) and whether the person chose sample dataKeeping the sample data choice while navigatingsame as settings
PlanPlan handle, end of trial and billing period, scheduled change, time of check, for 60 minutes the feature last chosenEnabling features by plan and opening the requested page after choosing a plansame as settings
Order countsNumber of orders per month, without order numbersShowing usage within the plansame as settings
Action keysRandom ID of a triggered action (e.g. “create export”), hash of the inputs, status, reference to the resultAn action takes effect only once, even on double click or resubmission24 hours, then deleted in the next daily run
Accountant access protectionKeyed hash of the IP address (IPv6: /64 network only) with a key that changes daily, or the number of an accountant link, plus timeLimiting failed attempts and requests to the accountant access (see section 9)24 hours at most
Privacy requestsType of request, Shopify IDs of the request and the customer (no name, email address or phone number), affected PayPal entries, result, timesProof that privacy requests have been handledsame as settings, at most three years
Deletion recordNon-reversible keyed hash of the store domain, times of uninstall and deletion, deleted data categoriesProof of deletion and notice on a later reinstallthree years after deletion

All entries are assigned to a single store and strictly separated. See section 13 for backups.

5. Uploaded files

PayPal activity export

PayPal's CSV file also contains names and email addresses of counterparties. The app does not import these columns; only the fields listed in section 4 are stored. The file itself is not kept.

Bank statement (CAMT.053 or CSV)

A bank statement contains entries, payment references and names and account numbers of counterparties. The app reads the file only to match payouts to incoming payments and discards it afterwards. We only store which payout arrived on which day with which amount.

6. Accountant access

Merchants can give their tax accountant a personal link. It shows the monthly overview and lets the accountant download booking data and summary sheets without a Shopify account. Order details and customer data are not visible there.

We store the link only as a checksum and cannot restore it. We record the time of last use, and every download appears in the merchant's export log. Links expire after twelve months and can be revoked at any time.

7. Billing through Shopify

Paid plans are purchased and paid for through Shopify. We do not receive payment details. The app only asks Shopify which plan is active in order to enable features.

8. Contact and support

If you email us, we process your details to answer your request. We delete requests once they are resolved unless statutory retention obligations apply.

9. Server logs

When our pages are accessed, including accountant access and this page, our web server processes technically necessary data: truncated IP address, time, requested address (without access keys and without parameters), status code and browser identifier.

  • IP addresses are truncated before being written (IPv4 to the first three octets, IPv6 to the first 32 bits).
  • Accountant links and authentication parameters are removed before logging.
  • Logs are deleted after 7 days at the latest.

To protect the accountant access against guessing links, the app counts requests and failed attempts. Instead of the IP address it stores only a keyed hash with a key that changes daily (IPv6: /64 network only). These entries are deleted after 24 hours at most.

10. Cookies, tracking, third-party content

The app and our public pages set no cookies and use no analytics, advertising or tracking tools. Public pages such as this one and the accountant access load no third-party content (no external fonts, scripts or maps).

The app itself runs inside the Shopify admin, where Shopify loads its own interface components and fonts. That processing is Shopify's responsibility.

11. Recipients and hosting

RecipientTaskLocation
netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, GermanyServers, data storage and connectivity (processor)Data centre in Germany

We do not transfer data to countries outside the EU/EEA and we do not sell data. We only disclose data if you initiate it (for example downloads by your accountant) or if we are legally required to.

12. Security

  • Encrypted transport only (TLS 1.2 and 1.3).
  • Database and backups are stored on an encrypted volume (LUKS2, AES-256).
  • The database is not reachable from the internet.
  • Server access by cryptographic key only, firewall and automatic security updates.
  • Accountant links are stored as checksums only.

13. Retention and deletion

  • Uninstall: store access data is deleted immediately and accountant links are blocked. All other data of the store is deleted 7 days after uninstall; if the app is reinstalled before then, the data is kept. After deletion we keep only a deletion record for three years: a keyed hash of the store address that cannot be reversed, the date and the deleted data categories.
  • Customer deletion requests submitted through Shopify are honoured. We do not store customer data. Imported PayPal entries for the affected orders are bookkeeping records the merchant must retain: we restrict them, use them only in the booking batch, no longer display their order number and delete them together with the other store data. Booking batches already stored remain unchanged as bookkeeping records and are likewise deleted together with the other store data. Each request is logged without names, email addresses or phone numbers.
  • Backups: the database is backed up daily and before each new version. Daily backups are overwritten after seven days, pre-release backups are deleted after 14 days. Deleted data may therefore remain in a backup for up to 14 days.
  • Server logs: after 7 days at the latest. Accountant access protection entries after 24 hours at most, action keys on the day after their 24-hour validity ends.

15. Your rights

You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interest (Art. 21). Contact ravel-lukas@geckit.de. If you are a customer of a store, please contact the merchant first; we support them in handling your request.

You may also lodge a complaint with a supervisory authority (Art. 77 GDPR). Our competent authority is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.

16. Further information and changes

There is no automated decision-making, including profiling. Providing the data is necessary to use the app. We update this policy when the app or the law changes and inform merchants about material changes in the app.