TaxHoliday.app ← Back to site

Privacy Policy

Last updated: July 25, 2026

This Privacy Policy explains how TaxHoliday.app ("we", "us") handles data across our tax-holiday API service and our Shopify application, the TaxHoliday Badge. Our guiding principle is simple: we process the minimum data needed to tell shoppers when an item is tax-free, and we do not store customers' personal information.

The short version: To show a tax-holiday badge at checkout, our app reads only the shipping postal code (ZIP) and the product category of the items in the cart. We use these to look up whether a sales-tax holiday applies. We do not collect or store customer names, email addresses, phone numbers, street addresses, payment details, or IP addresses.

1. Information the Shopify app processes

When a buyer reaches checkout on a store that has installed the TaxHoliday Badge, the app processes, transiently:

This information is used only to return a tax-holiday result for that checkout. It is not used for advertising, profiling, or any other purpose, and it is not sold or shared with anyone.

2. Information we do not collect

We do not collect, request, or store the customer's name, email, phone number, full address, order contents beyond product category, payment information, or account credentials. The app has no customer-facing account and sets no tracking cookies.

3. Merchant (store) information we store

For each store that installs the app, we store only what is needed to operate it: the store's myshopify.com domain, the API key the merchant provides to connect to the TaxHoliday.app service, and the merchant's badge display settings. This is stored in our database and is deleted when the app is uninstalled.

4. How the tax lookup works

To perform a lookup, the shipping postal code is transmitted over an encrypted (HTTPS/TLS) connection to the TaxHoliday.app API. The postal code may appear transiently in our server request logs as part of the request, without any other identifying information — no customer name, email, or customer IP address is logged alongside it. These operational logs are retained for a limited period for security and reliability purposes and are not used to identify individuals.

5. Data retention

We do not retain customer personal data. Merchant configuration is retained for as long as the app is installed and is deleted on uninstall. Operational request logs are retained only for a short period and contain no customer-identifying information.

6. GDPR & CCPA compliance

We support Shopify's mandatory data-protection webhooks:

Because we do not store personal data about shoppers, requests to access, correct, or delete such data are satisfied inherently. If you are a merchant or a shopper with a question about your rights under the GDPR, CCPA, or similar laws, contact us using the details below.

7. Third parties

The app runs on the Shopify platform and communicates with the TaxHoliday.app API to perform tax-holiday lookups. We do not sell data to, or share personal data with, third-party advertisers or data brokers.

8. Security

All data in transit is encrypted using TLS. We limit access to our systems, separate our development and production environments, and store no customer personal data at rest.

9. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above.

10. Contact

Questions about this policy or your data? Email support@taxholiday.app.