LS - PrintFormi — privacy notice

Last updated 2026-08-12.

LS - PrintFormi turns a Shopify order into the paperwork around it: invoices, packing slips, returns forms and similar documents, printed by the merchant or emailed to the shopper. This notice describes what personal data that involves, why, where it is held and for how long.

Who is responsible

Registered nameLorin Soft LLC
Registered addressMarica Gardens 12/20, 4018 Plovdiv, Bulgaria
Company numberVAT ID: BG206285889
Email[email protected]

Only one form of direct contact is published. Two are required.

Our role

For the order and customer data flowing through LS - PrintFormi the merchant is the data controller and Lorin Soft LLC is a data processor, acting on the merchant’s instructions. The processor terms below are accepted by installing the app.

What is processed, and why

DataWhyKept
Order contents, totals, addresses, customer nameRendering the document that was asked forNot stored. Read from Shopify at the moment of rendering and discarded with the request
Invoice numbers against order IDsA reprint must carry the number the customer already holds, and the sequence must have no gapsUntil the shop is erased. Contains no personal data
Shopper email address, in the invoice-email logAnswering the merchant’s question “did it go out”, and not sending the same invoice twiceUntil erased on request or with the shop. Encrypted at rest
Bulk export PDFsA large export is rendered in the background and downloaded afterwardsUntil erased on request or with the shop
Company name and VAT number, per customerPrinting them on business invoicesHeld on the customer record in Shopify, not in our database
Shopify access token, installing user’s name and emailMaking API calls on the shop’s behalfUntil uninstall plus 48 hours. Encrypted at rest
Application logsDiagnosing failures a merchant reports180 days, then deleted automatically

The design goal is that an app which stores almost nothing has almost nothing to answer for. Documents are generated on request rather than kept, which is why most of the table above says so.

Sub-processors

Security

Everything is served over TLS. At rest, the values worth stealing are encrypted individually with AES-256-GCM: Shopify access and refresh tokens, the installing user’s name and email, and invoice-email recipient addresses.

What that does not cover. The encryption key lives on the same host as the database. It therefore protects against a stolen disk, a copied backup or a leaked image — and not against an attacker who has gained root on the running machine. We would rather state that plainly than imply a guarantee the code does not make.

Erasure

Your rights

Shoppers should raise access, correction and erasure requests with the merchant they bought from — they are the controller, and Shopify’s own tools carry those requests to us automatically. Merchants can contact Lorin Soft LLC directly using the details above.

Processor terms (GDPR Article 28)

By installing LS - PrintFormi, the merchant and Lorin Soft LLC agree that:

Changes

Material changes are reflected here with a new date at the top. This notice is versioned with the app’s source, so its history is the repository’s history.