Privacy Policy

Reamly — invoicing and document printing for Shopify.
Last updated: 29 August 2026.

This policy explains what Reamly does with personal information. It is written to be read, not to be survived. If anything here is unclear, write to us and we will explain it in plain words.

1. Who we are

Reamly is operated by Syed Shahzaib Hassan, a sole trader based in Pakistan.

Privacy questions and data requestsprivacy@bpers.com
Supportsupport@bpers.com

We answer privacy mail within 5 working days, and always within the 30 days the GDPR allows.

2. What Reamly is, and whose data it touches

Reamly is an app that Shopify merchants install on their own store. It reads the store's orders and produces invoices, packing slips and credit notes as PDF files.

That means two different sets of people, and we have a different role for each:

Whose dataOur roleWhat that means
The merchant who installs Reamly Controller We decide how we handle their store domain, plan and settings, because that is our relationship with them.
The merchant's customers, whose names and addresses appear on an invoice Processor We only ever act on the merchant's instructions. The merchant is the controller of that data. We never decide to use it for our own purposes, and we never sell it.

If you are a shopper and want your data corrected or removed, contact the store you bought from. They control it; we act for them. If you contact us directly we will pass your request to them and tell you we have done so.

3. What we actually store

WhatWhy it existsHow long
The contents of an issued document — buyer name, billing and shipping address, the items bought, totals, and a VAT number if the merchant recorded one An invoice must reproduce identically years later. That is a legal requirement in most of the countries our merchants sell in, so the contents are frozen when the document is issued. Until the merchant uninstalls Reamly, or asks us to delete it
The generated PDF file The file the merchant prints or emails Automatically deleted after 90 days. The record stays so the document can be regenerated; the file does not.
A masked email address, in the form j***@example.com Proof that a document was sent, without keeping the address itself. The mask is a fixed width, so it does not leak the length of the real address either. With the sending record
The merchant's store domain, chosen plan, and app settings To run the app and bill correctly Until uninstall
An access token for the merchant's store Required to read orders at all Until uninstall, then deleted

What we deliberately do not hold

No payment card numbers. No bank details. No government identifiers. No passwords. Reamly never sees a card — all billing is handled by Shopify, and we receive only the name of the plan a merchant is on. There is no Reamly account and no password to store.

We also do not write personal data into our logs. Our logs record identifiers and status codes only — never a name, an address, an email, or the contents of an order. This is enforced by an automated check that runs on every change to the code.

4. Why we are allowed to hold it

For merchant data, our legal basis is performance of a contract — we cannot provide the app without it. For the customer data inside an invoice, the merchant is the controller and determines the basis; in practice it is their own legal obligation to issue and retain invoices.

5. Who else is involved

We use a small number of infrastructure providers. Each one is contractually a processor, and none of them is permitted to use the data for their own purposes.

ProviderWhat it doesWhere the data sits
ShopifyThe platform the app runs on; the source of the order data and the handler of all paymentsPer Shopify's own terms
NeonThe databaseFrankfurt, Germany (EU)
Cloudflare R2Storage for generated PDFsEU jurisdiction
Fly.ioRuns the application itselfFrankfurt, Germany (EU)
ResendSends invoice emails, only if the merchant turns that onIreland (EU)

We do not use advertising networks, analytics trackers or data brokers. Reamly sets no cookies beyond the session cookie Shopify requires for the app to load inside the admin.

6. Where your data lives, and transfers outside the EU

All of it stays in the European Union — the database in Frankfurt, the PDF storage in Cloudflare's EU jurisdiction, the application itself in Frankfurt, and email delivery in Ireland. We chose each of those regions deliberately.

The one exception is administration. Reamly is operated by one person, located in Pakistan, who can reach production systems in order to run and repair the service. Pakistan is not covered by a European Commission adequacy decision, so that access is a restricted transfer under Chapter V of the GDPR. It is covered by the Standard Contractual Clauses in our data processing agreement, together with the technical measures described in the next section.

Our Data Processing Agreement sets this out in full, including the Standard Contractual Clauses, the technical measures we operate and the list of sub-processors. It applies automatically when you install Reamly — you do not need to sign anything. If your auditor needs a countersigned copy, email privacy@bpers.com and we will sign and return it.

7. How it is protected

Our written staff access policy, including the gaps we have not yet closed, is available to merchants on request. We would rather tell you what is not yet done than claim a control we do not operate.

8. Deletion

You can also simply write to us and ask.

9. Your rights

If the GDPR or UK GDPR applies to you, you have the right to access your data, correct it, have it erased, restrict or object to how it is used, and receive it in a portable form. You may also complain to your national data protection authority.

Because we are a processor for shopper data, the fastest route is the store you bought from. For anything concerning a merchant account, write to us directly.

10. Children

Reamly is a business tool sold to merchants. It is not directed at children and we do not knowingly process children's data.

11. Changes

If we change this policy in a way that materially affects merchants, we will say so in the app before the change takes effect. The date at the top always reflects the current version.