Privacy Policy
Last updated September 7, 2026
This Privacy Policy explains how TaxEqual (“TaxEqual,” “we,” “us”) collects, uses, and protects information through the TaxEqual app for Shopify (the “Service”). TaxEqual is installed by merchants (“you,” the “merchant”) who run stores on the Shopify platform. This policy covers what we collect from your store and from you as the merchant, and how we handle data belonging to your own customers that passes through the Service incidentally.
In short: TaxEqual is a business tool. We deliberately hold as little of your customers' personal data as possible — we need to know where an order shipped to calculate tax, not who placed it. We do not sell data, run advertising, or share it with anyone except the service providers named below.
1. Information we collect
1.1 From your Shopify store
When you install TaxEqual, Shopify grants us read-only access to exactly three things:
your orders, your products, and your store's
locations. Nothing else. We do not request the
read_customers scope, so we never receive your customers' account or
marketing profile data from Shopify's Customer API — and we do not request access to
payouts, analytics reports, returns, order edits or shipping settings, because
calculating sales tax does not need them.
Order data reaches us two ways, and they carry different amounts of personal data:
- Historical import (backfill). We request only what jurisdiction resolution needs — the shipping city, region, and country. Customer identity is deliberately excluded from this request.
- Real-time order and refund events (webhooks). Shopify sends us the full order payload as it does to any app watching orders, which can include your customer's name, email, phone number, IP address, and complete shipping/billing address. We discard all of that before storing anything: the name, email, phone, IP address, checkout tokens and street address are removed the moment the payload arrives, and only the city, region, postal code and country are kept, because those are what determine which tax applies. What we do keep is encrypted at rest (see §3) and is not shared onward.
1.2 Information you provide directly
| What | Why we ask for it |
|---|---|
| Business legal name, federal tax ID (EIN/FEIN) | Required by states to process a sales-tax registration |
| Owner and business contact name, email, phone | Registration paperwork and account communication |
| Business address | Registration paperwork |
| Registration documents you upload | Supporting proof for state registration, at your request |
| Notification preferences | Where and how often to send filing and nexus alerts |
| Support messages | Responding to questions you send us |
All of this is optional to provide, though some features (state registration assistance) cannot work without it.
1.3 Information collected automatically
We keep operational logs of API calls made to Shopify on your behalf and of background job activity, so we can diagnose sync problems. These logs can incidentally contain order addresses passed through in a request or response body; they are not used for any purpose beyond troubleshooting and are not shared with anyone.
2. How we use information
We use the data described above only to operate the Service, specifically to:
- Calculate sales tax on each order line and reconcile it against what your sales channel actually collected;
- Track where you have crossed an economic nexus threshold and may owe a filing obligation;
- Build the filing-ready reports and exports you generate from the app;
- Prepare and support state sales-tax registration, where you request it;
- Send you notifications about upcoming deadlines, nexus changes, and sync status;
- Respond to support requests; and
- Maintain the security and integrity of the Service.
We do not use your data to train third-party AI models, build advertising profiles, or for any purpose unrelated to operating the Service.
3. How information is protected
- Encryption at rest. Your business tax ID, owner and contact details, uploaded documents' metadata, order shipping city/ZIP, and the raw order payloads described in §1.1 are encrypted at the database level. Only the fields genuinely needed for reporting (shipping state and country) are kept in plain, searchable form.
- Tenant isolation. Every record is scoped to your store account. Access checks are enforced on every request; a request for another merchant's data is treated as not found, not merely refused.
- Read-only access. Every Shopify API scope TaxEqual requests is read-only — the Service cannot modify your products, orders, or store settings.
- Access within our team is limited to what is needed to operate and support the Service.
4. Data retention and deletion
We retain your data for as long as the app remains installed, so the Service can keep producing accurate reports across filing periods. When you uninstall TaxEqual, Shopify notifies us and we erase your store's data, along with your account-level records (business profile, registration documents, filing history, and notification settings) once your last connected store is removed.
As required by Shopify's Partner Program, we also honor two requests concerning your customers' data, triggered automatically by Shopify on your behalf:
- A customer's data request.When Shopify forwards one, we compile everything we hold for the orders named in the request and send it to you, the store owner, so your reply to the customer is complete. Shopify does not relay our answer, and we have no relationship with your customer — you do.
- A customer's erasure request. We remove that customer's name, contact details, IP address, and address identity fields from our stored order payloads. We retain the shipping state, region, and ZIP on that order — not as identity, but because removing them would silently change a tax figure you have already reported to a state.
5. Who we share information with
We do not sell personal information. We share it only as needed to run the Service:
| Party | What they receive |
|---|---|
| Shopify | API requests to read the store data described above, and to process app billing |
| Our transactional email provider | Notification emails containing state names, sale totals, and due dates — never your customers' personal data |
| State agencies (only if you request registration assistance) | The business information and documents needed to register your business, submitted at your direction |
We use no advertising, analytics, or tracking services, and no data broker.
We may also disclose information if required by law, or to protect the rights, property, or safety of TaxEqual, our merchants, or others.
6. Your rights and choices
As the merchant, you can review, correct, or delete your business profile and registration documents from within the app at any time, and you can withdraw consent for a specific state registration by disabling that state. Uninstalling the app triggers deletion as described in §4.
If you are a customer of a merchant using TaxEqual and have a question about your own data, please contact that merchant directly — they control your relationship and your order data. Where a data-subject request reaches us through Shopify on a merchant's behalf, we respond as described in §4.
Depending on where you or your business are located, you may have additional rights under laws such as the GDPR or applicable US state privacy laws (for example, the right to access, correct, or delete your information, or to object to certain processing). To exercise any of these rights, contact us using the details in §9.
7. International data transfers
TaxEqual is built for US sales-tax compliance and operates primarily for merchants selling into the United States. Data may be processed in the United States. Where we transfer personal data internationally, we rely on appropriate safeguards required by applicable law.
8. Changes to this policy
We may update this policy as the Service changes. We will update the date at the top of this page, and where a change is material we will provide additional notice (such as an in-app notification) before it takes effect.
9. Contact us
Questions about this policy or a data request can be sent to hello@taxequal.com.