Privacy Policy

Last updated: 29 June 2026

This Privacy Policy explains how Boekhoudbrug (“we”, “us”, “the app”) handles personal data when a merchant installs and uses the app on their Shopify store. Boekhoudbrug automatically books a merchant’s paid Shopify orders into their own accounting platform and, optionally, issues PEPPOL e-invoices.

For the personal data of a merchant’s customers, the merchant is the data controller and Boekhoudbrug acts as a data processor on the merchant’s behalf, governed by our Data Processing Agreement.

Who we are

Boekhoudbrug is a product of Bright Fern Labs, a sole proprietorship (eenmanszaak) of Mike den Boer, registered in the Netherlands.
Chamber of Commerce (KVK): 42099020
VAT (BTW): NL224101183B01
Registered address: Galgendijk 105, 4484 NH Kortgene
Contact / data protection enquiries: joandenboe@gmail.com

What personal data we process

We practise data minimisation: we request only the order fields needed to book the order. We do not access customer telephone numbers, and we do not sell data or use it for marketing, profiling or automated decision-making.

Accounting (all installs)

DataSourcePurpose
Customer nameShopify paid orderCreate/match the contact in the accounting platform
Customer emailShopify paid orderFind-or-create key for the contact
Customer / billing addressShopify paid orderInvoice and contact address; VAT determination

E-invoicing (PEPPOL) — only if the merchant enables it

A compliant PEPPOL invoice must state the buyer on the document, so when a merchant turns on the e-invoice sink we additionally process the buyer name, VAT number, address and email in order to build the legally required UBL invoice and deliver it (via the PEPPOL network, or by email as a PDF fallback).

Legal basis

We process this data to perform the service the merchant has instructed us to provide (Article 6(1)(b)/(f) GDPR) and to enable the merchant to comply with their own legal accounting and tax obligations (Article 6(1)(c) GDPR). The merchant determines the purposes and means; we act on their documented instructions.

Who we share data with (sub-processors)

We use the following sub-processors to deliver the service. Each is bound by a data processing agreement and processes data only as needed.

Sub-processorPurposeLocation
SupabaseManaged PostgreSQL database (application data)EU (Frankfurt)
VercelApplication hostingUSA (SCCs)
ResendTransactional & failure-alert email; PDF e-invoice fallbackUSA (SCCs)
RecommandPEPPOL access point (e-invoicing only)EU
EC / OpenPeppol validatorsUBL conformance checking (e-invoicing only)EU

In addition, we forward order data to the merchant’s own accounting platform (Moneybird, Acumulus or e-Boekhouden), at the merchant’s direction. That platform is the merchant’s own tool and account; its handling of the data is governed by the merchant’s agreement with that provider.

International transfers

Application data is stored in the EU. Where a sub-processor is located outside the EEA (e.g. hosting/email providers in the USA), transfers are covered by appropriate safeguards such as the EU Standard Contractual Clauses.

How long we keep data

We keep data only as long as needed for the service. Customer name, email and address are forwarded to the merchant’s accounting platform and are not retained in raw form beyond what the booking requires; we keep order/invoice references and amounts as accounting records.

An issued PEPPOL e-invoice is a fiscal record and is retained for the statutory period (issue date + 7 years). On a valid deletion request the personal data within it is scrubbed and the record is purged once the retention period ends.

Security

All traffic is encrypted in transit (TLS). The database and its backups are encrypted at rest. Access is restricted by Row Level Security and application-only database credentials; secrets are held in environment variables and never committed to source control. Every read of customer personal data by the sync pipeline is logged for auditability.

Your rights & data deletion

Data subjects (a merchant’s customers) can exercise their GDPR rights — access, rectification, erasure, restriction, objection and portability — by contacting the merchant (the controller). We support these requests through Shopify’s mandatory privacy webhooks:

Changes to this policy

We may update this policy from time to time. Material changes will be reflected here with an updated “Last updated” date.

Contact

Questions or privacy requests: joandenboe@gmail.com. If you believe we have not handled your data lawfully, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).