Seaside StudioContact
← Shopify apps

Easy EU VAT Exemption — Shopify app

Privacy Policy

Last updated 2026-09-24

Overview

Easy EU VAT Exemption ("the App") is a Shopify app developed by Seaside Studio Ltd. ("we", "us", "our"). The App lets merchants validate EU VAT numbers entered by their B2B customers and apply VAT exemption to eligible customers and orders. This policy explains what information we collect when a merchant installs the App, how we use it, and how to contact us.

If you are a customer of a store that uses the App, the merchant operating that store is the data controller of your personal information, and we act as a data processor on their behalf.

Information we collect

From merchants

When the App is installed, Shopify shares the following with us under the access scopes the merchant approves at install time:

  • Store information — store name, domain, country, contact email, and plan.
  • Customers (read_customers, write_customers) — used to read a customer's tags and VAT details and to set their tax-exempt status.
  • Orders (read_orders, write_orders) — used to apply VAT exemption to eligible orders.
  • Products (read_products) — used for product-level exemption settings.
  • App configuration — the country tax settings and exemption rules the merchant sets in the App.

We do not collect payment information. Billing is handled by Shopify.

From the merchant's customers

When a customer enters a VAT number in the store (on the account page, in the cart, or at checkout), we process on the merchant's behalf:

  • The customer's Shopify customer ID and email address.
  • The VAT number they entered.
  • The registered company name and address returned by the EU VIES validation service for that VAT number.
  • The validation result and when it expires.

How we use the information

  • To validate VAT numbers and apply or remove VAT exemption, as described on the App's listing.
  • To show merchants which customers have been validated.
  • To respond to support requests.
  • To monitor App health and fix bugs.

We do not use customer data for marketing, and we do not sell merchant or customer data.

Who we share data with

We share data only with service providers that make the App work:

  • Shopify — the platform the App runs on.
  • Gadget (gadget.dev) — hosts the App's backend and database.
  • viesapi.eu — receives the VAT number to be checked and queries the European Commission's VIES system for the registered company name and address.

Data retention and deletion

  • VAT validation records expire 30 days after the last validation and are deleted automatically by a daily cleanup job. After that, the customer must validate again.
  • Merchant data is kept for as long as the App is installed. When a merchant uninstalls the App, Shopify sends the shop/redact webhook 48 hours later, and we delete the store's data.

Merchants can also ask for earlier deletion by emailing seaside@seasideapps.co.

GDPR compliance webhooks

As required by Shopify, the App subscribes to the three mandatory GDPR webhooks:

  • customers/data_request — we provide the merchant with any data we hold about the customer within 30 days.
  • customers/redact — we delete any data we hold about the customer.
  • shop/redact — we delete all data for the store.

Security

Data is transmitted over HTTPS and stored on Gadget's managed infrastructure. Data is scoped to the installing store and never combined with data from other stores. Access is limited to Seaside Studio staff who need it to operate and support the App.

Changes to this policy

We may update this policy as the App changes. The "Last updated" date at the top shows the most recent revision. Where changes are material, we will notify merchants by email or in the App.

Contact

Questions or requests about this policy, including requests to access, correct, or delete data, can be sent to:

Seaside Studio Ltd.
Shipka St. 18, office 203, Varna, Bulgaria
Email: seaside@seasideapps.co