Skip to content
Salorworks.← Back to Salor Invoice

Salor Invoice

Privacy Policy

Last updated: July 26, 2026

This policy explains how Salor Invoice handles information when a Shopify merchant installs or uses the app.

Who operates Salor Invoice

Salor Invoice is operated by Salor Works, Dubai, United Arab Emirates. In this policy, “Salor Invoice,” “we,” “us,” and “our” refer to Salor Works.

For personal data contained in a merchant's Shopify store or supplier invoices, the merchant generally determines why the data is processed and Salor Invoice processes it on the merchant's instructions. We may act as a controller for support, security, and business-administration information that we collect directly.

Information we access and process

Depending on the features a merchant uses, Salor Invoice processes:

  • Shopify shop data:shop domain, shop and installation identifiers, locale, app plan, and the access credentials required to connect the app to the merchant's store;
  • Product and inventory data: products, variants, SKUs, barcodes, inventory-item and location identifiers, quantities, selling prices, and product costs needed to match invoice rows and prepare merchant-approved updates;
  • Invoice data: supplier invoice files submitted as PDFs or images and extracted information such as supplier details, invoice number and date, currency, taxes, product descriptions, SKUs, barcodes, quantities, unit prices, discounts, and line totals;
  • Usage and operational data: upload time, page and invoice counts, extraction and matching status, updates approved by the merchant, error information, and events needed to operate plan limits and troubleshoot the service; and
  • Support data: contact details and information a merchant includes in a support request.

Salor Invoice is not designed to access Shopify customer or order data. Supplier invoices can nevertheless contain personal data chosen by the merchant or supplier, such as a contact name, email address, phone number, or delivery address. Merchants should submit only information needed for invoice processing.

Store owner and staff data

When a merchant installs Salor Invoice, Shopify's platform automatically grants apps baseline access to store and owner identity information, such as the store owner's name, email address, phone number, and address. This platform-level access is granted by Shopify to all apps and is not something Salor Invoice specifically requests.

Salor Invoice does not read, store, process, or transmit store owner or staff personal data obtained through this baseline access. The app accesses and uses only:

  • Product data: product titles, variants, barcodes, and SKUs;
  • Inventory data: inventory items, unit costs, and quantities; and
  • Merchant-uploaded data: supplier invoices, which are processed in memory by Salor Invoice and are not stored as original files.

We access this data only to match supplier invoice line items to Shopify products and prepare merchant-approved cost and inventory updates. Store-owner contact details are not accessed as part of the app's functionality. Contact information a merchant chooses to provide in a support request is handled separately as support data.

How we use the information

We process information to:

  • authenticate and connect the app to the correct Shopify store;
  • read invoice files and extract structured invoice line items;
  • match supplier items to Shopify products and variants;
  • show costs, quantities, taxes, and margin information for review;
  • update product costs or inventory only after the merchant selects the relevant options and chooses Apply;
  • prevent duplicate processing, enforce usage limits, and maintain import history;
  • provide support, diagnose errors, and protect the service; and
  • meet legal, accounting, security, and Shopify platform obligations.

Invoice extraction and AI sub-processors

Invoice files are processed in memory by Salor Invoice and are not stored in our database or file storage. Files are sent to Microsoft Azure Document Intelligence in the East US region to perform optical character recognition and document analysis. Extracted text and relevant invoice context are then sent to the OpenAI API in the United States to structure, normalize, or validate invoice fields and line items. Microsoft and OpenAI act as sub-processors for these operations.

Salor Works does not opt in to using invoice content to train third-party models. Microsoft states that data submitted to prebuilt Azure Document Intelligence models is not used to train those models. OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer expressly opts in.

Although Salor Invoice does not persist invoice files, Azure Document Intelligence temporarily stores submitted documents and analysis results in the service region for up to 24 hours unless the result is deleted sooner through its API. Salor Invoice uses the OpenAI API's default data controls. OpenAI may retain abuse-monitoring logs, including API inputs and outputs, for up to 30 days. No app-specific Zero Data Retention or Modified Abuse Monitoring configuration is enabled.

Automated extraction can be incomplete or inaccurate. The app presents extracted and matched data to the merchant for review before any approved update is sent to Shopify.

Storage and retention

Original invoice files are processed without being retained by Salor Invoice or stored in Supabase. Extracted invoice data, product matches, import history, mappings, settings, and limited operational events are stored in our Supabase-hosted database in the South Asia (Mumbai) region in India.

  • Extracted invoice data and import history: retained for 12 months from processing by default. Merchants can select a 6-month retention period or delete this data sooner.
  • Product and supplier mappings and app settings: retained while the app remains installed because they support ongoing matching and store configuration.
  • Identifiable operational, error, and security events: retained for up to 90 days. Older statistics may be retained only after they have been irreversibly anonymized.
  • Support correspondence: retained for up to 12 months after the support request is closed, unless a longer period is required to establish or defend legal claims.

When data is deleted from the active database, residual copies may remain in routine provider backups until those backups expire under the provider's normal backup lifecycle. Merchants may delete stored invoice data through the app where that control is available, or request deletion through our Support page, subject to information we must retain by law.

Uninstall, GDPR requests, and deletion

Salor Invoice implements and honors Shopify's mandatory compliance webhooks: customers/data_request, customers/redact, and shop/redact. We verify these requests and respond as required by Shopify.

  • Because Salor Invoice is not designed to access customer or order data, customer data requests will normally return no customer-level data. If relevant personal data is identified, we will provide or delete it as required.
  • After uninstall, Shopify sends a shop/redactrequest. We delete or irreversibly anonymize the affected shop's access credentials, mappings, settings, invoice-derived data, and other merchant data within 30 days of receiving the verified request, unless retention is legally required.
  • A merchant can also request access, correction, export, restriction, objection, or deletion by using an available in-app deletion control or contacting support. We may ask for information needed to verify that the requester is authorized to act for the store.

Where GDPR applies, individuals may also have the right to data portability, to withdraw consent where processing relies on consent, and to complain to their local data-protection authority. If a request concerns data controlled by a Shopify merchant, the individual should normally contact that merchant first; we will assist the merchant as its processor.

How we share data

We do not sell personal data, rent it, or use invoice content for third-party advertising. We disclose data only as needed to operate the app, follow a merchant's instructions, comply with law, or protect rights and security.

Current service providers and sub-processors include:

  • Shopify - ecommerce platform, app installation, and store APIs;
  • Microsoft Azure - Document Intelligence OCR and invoice analysis in East US;
  • OpenAI - API-based structuring and validation of extracted invoice data;
  • Supabase - application database and related managed services hosted in the South Asia (Mumbai) region in India; and
  • Vercel - application and website hosting and delivery through its global infrastructure.

These providers may process data outside the merchant's country. Where required, we rely on contractual protections and other lawful safeguards for international transfers.

Security

We use technical and organizational measures intended to protect data, including encrypted network connections, restricted server-side access, separation of merchant data by Shopify shop, and verification of Shopify requests. No online service can guarantee absolute security.

Changes to this policy

We may update this policy when the app, service providers, or legal requirements change. We will post the revised policy at this URL and update the date above. If a change materially affects how existing merchant data is used, we will provide additional notice where required.

Privacy contact

Submit privacy and data-deletion requests through the Salor Invoice Support page or email hello@salorworks.app.

Salor Works
Dubai, United Arab Emirates

Salorworks.

Salor Invoice is a focused Shopify workflow from Salorworks.

Salor Invoice

App overviewPrivacy PolicyTerms of ServiceSupport

Contact

hello@salorworks.appDubai, United Arab Emirates
© 2026 Salor Works.Shopify is a trademark of Shopify Inc.