Privacy Policy
Last updated: 17 September 2026
In short: Klarbuchung reads payouts and orders from your Shopify store to create booking data for your tax accountant. We do not request names, email addresses, phone numbers or street addresses of your customers, and we do not store payout or order data. The app sets no cookies and uses no tracking. Servers and database are located in Germany, and the database is encrypted. This is a translation; the German version prevails.
1. Controller and contact
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
geckIT, Ravel-Lukas Geck
Heidenoldendorfer Straße 126
32758 Detmold, Germany
Email: ravel-lukas@geckit.de
Phone: +49 178 5749602
We have not appointed a data protection officer because the legal requirements for doing so are not met.
2. Overview and roles
Klarbuchung is an app for merchants running a Shopify store (“merchants”). It reconciles Shopify Payments payouts and creates booking data in DATEV or BMD format, optionally including PayPal activity and a bank statement reconciliation.
- As a processor (Art. 28 GDPR) we process data that may relate to the merchant's customers, such as order numbers and amounts. The merchant remains the controller. Details are set out in our data processing agreement (German).
- As a controller we process data required to operate the app, for the contractual relationship with the merchant, for support and for the security of our servers.
Shopify is not our service provider but the platform the merchant uses. Shopify's privacy policy applies to Shopify's processing.
3. Data from the Shopify store
On installation the merchant grants the app read access to the following areas. The app reads this data through Shopify's API on each request and processes it only for the duration of that request. It is not stored in our database, except for the bookings contained in the booking batches you export (section 4).
| Area | Data | Purpose |
|---|---|---|
| Shopify Payments account | Payouts (date, amount, status, bank reference) and their transactions (type, amount, fee, date, order number) | Reconciliation, display, booking batches, PDF reports |
| Orders | Order number, date, amounts, tax rates and tax amounts per line, shipping, refunds, payment method, country code of the shipping or billing address | Revenue bookings in “full” mode and tax classification (domestic, EU, non-EU) |
| Store | Store domain, plan, development store flag | Authentication, feature access |
The app does not request customer names, email addresses, phone numbers or street addresses. Only the country code is read from an address. A booking batch is stored when it is first exported, so that every later download, including through the accountant link, returns exactly the same file. PDF reports are generated on download and sent directly to you; we do not keep copies.
4. Data we store
| Data | Examples | Purpose | Retention |
|---|---|---|---|
| Store access | Store domain, app access token, scopes, expiry | Access to the Shopify API | until uninstall (deleted immediately) |
| Settings | Chart of accounts, DATEV consultant and client number, accounts, booking mode, BMD options, store code, optionally the accountant's email address | Creating booking data; the email address is only used to prefill a message in your own email program | until 7 days after uninstall |
| Booking rules | Transaction type and chosen account | Automatic booking of special cases | same as settings |
| Export log | Month, time, format, number of bookings, checksum, origin (app or accountant access) | Traceability of booking data handed over | same as settings |
| Export files | Booking batches created (DATEV or BMD) with dates, amounts, accounts, booking texts and order numbers, plus checksum, creation time and app version | Re-downloading exactly the same file for you and your accountant | same as settings |
| PayPal transactions | Transaction ID, date, type, status, currency, gross, fee, net, invoice or order number | PayPal reconciliation and booking | same as settings; restricted when a deletion request for the related order is received (see section 13) |
| Bank matches | Payout ID, arrival date, amount, match confidence | Showing whether a payout has arrived | same as settings |
| Accountant links | Label chosen by the merchant, checksum of the link, created, expiry, revoked and last-used time | Accountant access to monthly files | same as settings |
| View per person | ID of the Shopify staff account from the session token (without name or email address) and whether the person chose sample data | Keeping the sample data choice while navigating | same as settings |
| Plan | Plan handle, end of trial and billing period, scheduled change, time of check, for 60 minutes the feature last chosen | Enabling features by plan and opening the requested page after choosing a plan | same as settings |
| Order counts | Number of orders per month, without order numbers | Showing usage within the plan | same as settings |
| Action keys | Random ID of a triggered action (e.g. “create export”), hash of the inputs, status, reference to the result | An action takes effect only once, even on double click or resubmission | 24 hours, then deleted in the next daily run |
| Accountant access protection | Keyed hash of the IP address (IPv6: /64 network only) with a key that changes daily, or the number of an accountant link, plus time | Limiting failed attempts and requests to the accountant access (see section 9) | 24 hours at most |
| Privacy requests | Type of request, Shopify IDs of the request and the customer (no name, email address or phone number), affected PayPal entries, result, times | Proof that privacy requests have been handled | same as settings, at most three years |
| Deletion record | Non-reversible keyed hash of the store domain, times of uninstall and deletion, deleted data categories | Proof of deletion and notice on a later reinstall | three years after deletion |
All entries are assigned to a single store and strictly separated. See section 13 for backups.
5. Uploaded files
PayPal activity export
PayPal's CSV file also contains names and email addresses of counterparties. The app does not import these columns; only the fields listed in section 4 are stored. The file itself is not kept.
Bank statement (CAMT.053 or CSV)
A bank statement contains entries, payment references and names and account numbers of counterparties. The app reads the file only to match payouts to incoming payments and discards it afterwards. We only store which payout arrived on which day with which amount.
6. Accountant access
Merchants can give their tax accountant a personal link. It shows the monthly overview and lets the accountant download booking data and summary sheets without a Shopify account. Order details and customer data are not visible there.
We store the link only as a checksum and cannot restore it. We record the time of last use, and every download appears in the merchant's export log. Links expire after twelve months and can be revoked at any time.
7. Billing through Shopify
Paid plans are purchased and paid for through Shopify. We do not receive payment details. The app only asks Shopify which plan is active in order to enable features.
8. Contact and support
If you email us, we process your details to answer your request. We delete requests once they are resolved unless statutory retention obligations apply.
9. Server logs
When our pages are accessed, including accountant access and this page, our web server processes technically necessary data: truncated IP address, time, requested address (without access keys and without parameters), status code and browser identifier.
- IP addresses are truncated before being written (IPv4 to the first three octets, IPv6 to the first 32 bits).
- Accountant links and authentication parameters are removed before logging.
- Logs are deleted after 7 days at the latest.
To protect the accountant access against guessing links, the app counts requests and failed attempts. Instead of the IP address it stores only a keyed hash with a key that changes daily (IPv6: /64 network only). These entries are deleted after 24 hours at most.
11. Recipients and hosting
| Recipient | Task | Location |
|---|---|---|
| netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, Germany | Servers, data storage and connectivity (processor) | Data centre in Germany |
We do not transfer data to countries outside the EU/EEA and we do not sell data. We only disclose data if you initiate it (for example downloads by your accountant) or if we are legally required to.
12. Security
- Encrypted transport only (TLS 1.2 and 1.3).
- Database and backups are stored on an encrypted volume (LUKS2, AES-256).
- The database is not reachable from the internet.
- Server access by cryptographic key only, firewall and automatic security updates.
- Accountant links are stored as checksums only.
13. Retention and deletion
- Uninstall: store access data is deleted immediately and accountant links are blocked. All other data of the store is deleted 7 days after uninstall; if the app is reinstalled before then, the data is kept. After deletion we keep only a deletion record for three years: a keyed hash of the store address that cannot be reversed, the date and the deleted data categories.
- Customer deletion requests submitted through Shopify are honoured. We do not store customer data. Imported PayPal entries for the affected orders are bookkeeping records the merchant must retain: we restrict them, use them only in the booking batch, no longer display their order number and delete them together with the other store data. Booking batches already stored remain unchanged as bookkeeping records and are likewise deleted together with the other store data. Each request is logged without names, email addresses or phone numbers.
- Backups: the database is backed up daily and before each new version. Daily backups are overwritten after seven days, pre-release backups are deleted after 14 days. Deleted data may therefore remain in a backup for up to 14 days.
- Server logs: after 7 days at the latest. Accountant access protection entries after 24 hours at most, action keys on the day after their 24-hour validity ends.
14. Legal bases
| Processing | Legal basis |
|---|---|
| Providing the app and its features to the merchant | Art. 6(1)(b) GDPR (contract) |
| Processing data of the merchant's customers | Processing on behalf under Art. 28 GDPR; the merchant as controller ensures the legal basis |
| Server logs, accountant access protection, security, backups | Art. 6(1)(f) GDPR (legitimate interest in secure and stable operation) |
| Privacy requests and deletion record | Art. 6(1)(c) GDPR (accountability under Art. 5(2) GDPR), additionally Art. 6(1)(f) GDPR |
| Answering requests | Art. 6(1)(b) GDPR, otherwise Art. 6(1)(f) GDPR |
| Retention of business records | Art. 6(1)(c) GDPR together with commercial and tax law obligations |
15. Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interest (Art. 21). Contact ravel-lukas@geckit.de. If you are a customer of a store, please contact the merchant first; we support them in handling your request.
You may also lodge a complaint with a supervisory authority (Art. 77 GDPR). Our competent authority is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.
16. Further information and changes
There is no automated decision-making, including profiling. Providing the data is necessary to use the app. We update this policy when the app or the law changes and inform merchants about material changes in the app.