Privacy Policy
Application: SuperGST • Provider: Starmatic Technologies Pvt. Ltd.
Effective Date: September 16, 2026 • Last Updated: September 16, 2026
1. Privacy Overview & Commitment
Starmatic Technologies Pvt. Ltd. (“Starmatic”, “We”, “Us”, or “Our”) is committed to protecting the privacy and security of your store and customer data. This Privacy Policy details how the SuperGST Shopify application (“App”) collects, processes, stores, and protects information when installed on your Shopify store (“Merchant”, “You”).
2. Information We Collect
To provide automated Indian GST invoicing and statutory GSTR filing summaries, SuperGST collects the minimum required information authorized via Shopify OAuth and webhooks:
A. Merchant Business Profile
- Store name, shop domain (
.myshopify.com), owner email address, and phone number. - Business credentials entered during onboarding or settings: Legal Business Name, GSTIN, PAN, FSSAI License Number, IEC Code, CIN, and registered business address.
- Brand customization assets: Uploaded store logos, custom font preferences, brand colors, and authorized digital signature images.
B. Order & Transaction Data
- Order IDs, order numbers, order dates, financial statuses (Paid, Pending, Refunded), and fulfillment statuses.
- Itemized product details: Product titles, SKU codes, quantities, base taxable values, GST rates (0%, 5%, 12%, 18%, 28%), HSN/SAC codes, and discounts.
- Computed tax breakdowns: CGST, SGST, IGST, cess, and rounded grand totals.
C. Customer & Shipping Details
- Customer name, billing address, and shipping address (including state, province code, and PIN code) required to compute inter-state vs. intra-state GST liabilities.
- Customer email address and phone number for invoice delivery and order matching.
- Buyer GSTIN and legal business name collected via our storefront B2B Cart Capture Widget for B2B tax invoice generation.
D. Financial & Payment Information
All app subscription charges are processed securely via Shopify Subscription Billing API.
3. Purpose of Data Processing
We process the collected data solely for the following legitimate business and legal purposes:
Accurate Tax Invoicing
Computing correct CGST, SGST, and IGST splits based on place of supply (PoS) rules and generating legally compliant PDF Tax Invoices, Credit Notes, and Packing Slips.
Statutory GSTR Return Preparation
Compiling GSTR-1 (B2B, B2C Large, B2C Small, CDNR, CDNUR) and GSTR-3B monthly and quarterly summaries in Excel and CSV formats.
B2B Input Tax Credit (ITC) Compliance
Verifying and embedding customer GSTINs to ensure buyers can legally claim Input Tax Credit under Indian GST law.
Order Metafield Synchronization
Attaching PDF download links directly to Shopify order metafields under the super_gst namespace for merchant and buyer access.
Customer Support
Diagnosing app issues and assisting merchants through our dedicated support desk.
4. Data Security, Storage & Architecture
We maintain enterprise-grade security controls to safeguard all merchant and customer records:
All Shopify OAuth access tokens and sensitive session credentials are encrypted in PostgreSQL using industry-standard AES-256-GCM encryption.
All database rows strictly enforce foreign-key tenant scoping (tenantId), guaranteeing complete isolation between stores and preventing cross-tenant data access.
PDF invoices, credit notes, brand logos, and signature assets are stored in Cloudflare R2 (S3-compatible, SOC 2 compliant) cloud storage using private access controls and HTTPS encryption in transit and at rest.
Heavy PDF rendering and report compilation tasks are handled by background worker queues (Inngest) to protect merchant store performance and prevent latency spikes.
5. Third-Party Service Providers & Subprocessors
We work only with vetted, enterprise-grade subprocessors necessary to deliver the application:
Core e-commerce platform, OAuth authentication, and billing API.
Encrypted PDF invoice file storage and CDN distribution.
Cloud server infrastructure, process execution, and database hosting.
Transactional email delivery for setup confirmations and administrative alerts.
Data Privacy Guarantee: We do not sell, rent, monetize, or share merchant or customer data with advertisers or data brokers.
6. Mandatory Shopify GDPR Webhook Compliance
SuperGST strictly complies with Shopify's mandatory data protection webhooks to protect merchant and customer rights:
CUSTOMERS_DATA_REQUESTWhen a merchant or customer requests an export of their data via Shopify, our system provides all stored personal data associated with that customer.
CUSTOMERS_REDACTWhen Shopify requests customer data deletion, all customer PII (names, phone numbers, addresses) is permanently redacted from our records.
SHOP_REDACT48 hours after an app uninstallation, upon receiving Shopify's official shop redaction webhook, all database records for that store (invoices, orders, product mappings, and tenant sessions) are permanently wiped.
APP_UNINSTALLEDImmediately upon uninstallation, our system invalidates API tokens and ceases all background data synchronization.
7. Data Retention Policy
We retain tax invoices and transaction records for as long as your Shopify store maintains an active SuperGST installation. This ensures historical tax documents remain available for statutory scrutiny under Indian tax laws.
If you uninstall the app or request data deletion, your data is completely purged in accordance with our GDPR SHOP_REDACT workflow.
8. Merchant and Customer Rights
You and your customers have the right to:
9. Contact Us & Compliance Team
For any privacy inquiries, data deletion requests, or questions regarding this policy, please reach out to our data compliance team:
Starmatic Technologies Pvt. Ltd.
Office No. 435 A Building, Gera's Imperium Gateway,
Nashik Phata, Pune, Maharashtra 411034