Starmatic Technologies Official Logo
Starmatic
Shopify App Privacy Policy

Privacy Policy

Application: SuperGST • Provider: Starmatic Technologies Pvt. Ltd.

Effective Date: September 16, 2026 • Last Updated: September 16, 2026

1. Privacy Overview & Commitment

Starmatic Technologies Pvt. Ltd. (“Starmatic”, “We”, “Us”, or “Our”) is committed to protecting the privacy and security of your store and customer data. This Privacy Policy details how the SuperGST Shopify application (“App”) collects, processes, stores, and protects information when installed on your Shopify store (“Merchant”, “You”).

Shopify App Store Partner RequirementsIndian Information Technology Act (2000)General Data Protection Regulation (GDPR)

2. Information We Collect

To provide automated Indian GST invoicing and statutory GSTR filing summaries, SuperGST collects the minimum required information authorized via Shopify OAuth and webhooks:

A. Merchant Business Profile

  • Store name, shop domain (.myshopify.com), owner email address, and phone number.
  • Business credentials entered during onboarding or settings: Legal Business Name, GSTIN, PAN, FSSAI License Number, IEC Code, CIN, and registered business address.
  • Brand customization assets: Uploaded store logos, custom font preferences, brand colors, and authorized digital signature images.

B. Order & Transaction Data

  • Order IDs, order numbers, order dates, financial statuses (Paid, Pending, Refunded), and fulfillment statuses.
  • Itemized product details: Product titles, SKU codes, quantities, base taxable values, GST rates (0%, 5%, 12%, 18%, 28%), HSN/SAC codes, and discounts.
  • Computed tax breakdowns: CGST, SGST, IGST, cess, and rounded grand totals.

C. Customer & Shipping Details

  • Customer name, billing address, and shipping address (including state, province code, and PIN code) required to compute inter-state vs. intra-state GST liabilities.
  • Customer email address and phone number for invoice delivery and order matching.
  • Buyer GSTIN and legal business name collected via our storefront B2B Cart Capture Widget for B2B tax invoice generation.

D. Financial & Payment Information

Zero Financial Credentials Collected:We do NOT collect, access, or store credit card numbers, debit card details, CVVs, or banking credentials. All billing and payment transactions are handled directly through Shopify or your configured payment gateway.

All app subscription charges are processed securely via Shopify Subscription Billing API.

3. Purpose of Data Processing

We process the collected data solely for the following legitimate business and legal purposes:

1

Accurate Tax Invoicing

Computing correct CGST, SGST, and IGST splits based on place of supply (PoS) rules and generating legally compliant PDF Tax Invoices, Credit Notes, and Packing Slips.

2

Statutory GSTR Return Preparation

Compiling GSTR-1 (B2B, B2C Large, B2C Small, CDNR, CDNUR) and GSTR-3B monthly and quarterly summaries in Excel and CSV formats.

3

B2B Input Tax Credit (ITC) Compliance

Verifying and embedding customer GSTINs to ensure buyers can legally claim Input Tax Credit under Indian GST law.

4

Order Metafield Synchronization

Attaching PDF download links directly to Shopify order metafields under the super_gst namespace for merchant and buyer access.

5

Customer Support

Diagnosing app issues and assisting merchants through our dedicated support desk.

4. Data Security, Storage & Architecture

We maintain enterprise-grade security controls to safeguard all merchant and customer records:

Token Encryption

All Shopify OAuth access tokens and sensitive session credentials are encrypted in PostgreSQL using industry-standard AES-256-GCM encryption.

Database Tenant Isolation

All database rows strictly enforce foreign-key tenant scoping (tenantId), guaranteeing complete isolation between stores and preventing cross-tenant data access.

Encrypted Document Storage

PDF invoices, credit notes, brand logos, and signature assets are stored in Cloudflare R2 (S3-compatible, SOC 2 compliant) cloud storage using private access controls and HTTPS encryption in transit and at rest.

Asynchronous Execution

Heavy PDF rendering and report compilation tasks are handled by background worker queues (Inngest) to protect merchant store performance and prevent latency spikes.

5. Third-Party Service Providers & Subprocessors

We work only with vetted, enterprise-grade subprocessors necessary to deliver the application:

Shopify Inc.

Core e-commerce platform, OAuth authentication, and billing API.

Cloudflare (R2)

Encrypted PDF invoice file storage and CDN distribution.

Railway

Cloud server infrastructure, process execution, and database hosting.

Resend

Transactional email delivery for setup confirmations and administrative alerts.

Data Privacy Guarantee: We do not sell, rent, monetize, or share merchant or customer data with advertisers or data brokers.

6. Mandatory Shopify GDPR Webhook Compliance

SuperGST strictly complies with Shopify's mandatory data protection webhooks to protect merchant and customer rights:

CUSTOMERS_DATA_REQUEST

When a merchant or customer requests an export of their data via Shopify, our system provides all stored personal data associated with that customer.

CUSTOMERS_REDACT

When Shopify requests customer data deletion, all customer PII (names, phone numbers, addresses) is permanently redacted from our records.

SHOP_REDACT

48 hours after an app uninstallation, upon receiving Shopify's official shop redaction webhook, all database records for that store (invoices, orders, product mappings, and tenant sessions) are permanently wiped.

APP_UNINSTALLED

Immediately upon uninstallation, our system invalidates API tokens and ceases all background data synchronization.

7. Data Retention Policy

We retain tax invoices and transaction records for as long as your Shopify store maintains an active SuperGST installation. This ensures historical tax documents remain available for statutory scrutiny under Indian tax laws.

If you uninstall the app or request data deletion, your data is completely purged in accordance with our GDPR SHOP_REDACT workflow.

8. Merchant and Customer Rights

You and your customers have the right to:

Access the personal data we hold about you.
Request rectification of inaccurate or incomplete details.
Request erasure of your data subject to regulatory GST record-keeping requirements.
Withdraw consent by uninstalling the application at any time.

9. Contact Us & Compliance Team

For any privacy inquiries, data deletion requests, or questions regarding this policy, please reach out to our data compliance team:

Entity:Starmatic Technologies Pvt. Ltd.
Product:SuperGST Shopify App
Official Website:https://www.starmatic.org
Office Address:

Starmatic Technologies Pvt. Ltd.

Office No. 435 A Building, Gera's Imperium Gateway,

Nashik Phata, Pune, Maharashtra 411034