Privacy Policy

Last updated: August 24, 2026

This Privacy Policy explains how VAT Radar ("the App"), operated by IT SOFT ARM ("we", "us"), handles data when a merchant installs the App on their Shopify store. VAT Radar is a store-monitoring app that scans a merchant's own orders and catalog for VAT/tax pattern anomalies and reports findings back to that merchant inside the Shopify admin.

What data we access

The App requests the minimum Shopify access scopes needed to function: read_orders and read_products. We do not request write access, and we do not request the read_all_orders scope — order history is limited to Shopify's default 60-day window.

Through these scopes, the App reads:

What we deliberately do not collect

The App is built not to store personally identifiable information about a merchant's customers. We do not store customer names, email addresses, phone numbers, physical addresses, or payment details, and we never request scopes that would grant access to that data beyond what order-level tax facts require. If a future version of the App needs to process such data, this policy will be updated first and merchants will be notified.

How we use data

Order and product data is used exclusively to compute audit findings and a compliance score for the merchant who installed the App, using deterministic, store-local statistical rules. Findings from one merchant's store are never used to inform another merchant's results, and data is never sold or shared with third parties for marketing purposes.

The App includes an optional, on-demand AI explanation layer for findings. AI is never used to decide compliance or generate findings, and when the AI layer is used it only receives aggregated rule statistics — never raw order data or any personal information.

Where data is stored

Data is stored in a database operated by us, scoped per store, and is not accessible to other merchants using the App. Connections to the database are made over encrypted connections; at-rest protections depend on our hosting provider's infrastructure.

How long we keep data

We retain order-level tax and pricing facts for no longer than 12 months, which is enough to compute the trend baselines the App's rules rely on; data older than that is automatically deleted. That deletion logic is running on a recurring schedule as part of our production deployment; until that schedule is fully live, a merchant can request earlier deletion of their store's data at any time by contacting us at the address below. When a merchant uninstalls the App, we stop processing new data for that store.

Mandatory compliance requests

As required for all Shopify apps, we respond to the mandatory compliance webhooks (customers/data_request, customers/redact, shop/redact) that Shopify sends on behalf of merchants and their customers. Because the App does not store customer personal data, data-request and redaction requests for customer records typically have nothing to return or delete; shop-level data deletion requests are honored on our end as described above.

Third parties

We rely on Shopify to operate the App (authentication, billing, and the Admin API). Subscription billing is processed entirely through the Shopify Billing API — we do not collect or store payment card details ourselves.

Contact us

Questions about this policy, or requests relating to your store's data, can be sent to vatradar [at] itsoftarm.com.

See also our Terms of Service.