Privacy
Privacy and data handling
This page explains how the VAT Sentinel plugin handles data in a WooCommerce store. It is general information for store owners and does not replace your own privacy policy.
What data the plugin handles
- Customer VAT number
- Country code
- Validation result
- Order reference
- Validation timestamp
- VIES request/consultation reference when available
- Merchant requester VAT number if configured
Where data goes
To validate a VAT number, VAT Sentinel sends the VAT number and country code to VIES. If configured, the merchant requester VAT number may also be sent so VIES can return a consultation reference.
Where data is stored
Validation records are stored in the merchant’s own WordPress database as part of the store’s order and tax records.
Who controls the data
The store owner is the data controller for customer VAT data processed through the plugin. Flexpoint Solutions does not receive customer VAT numbers through the plugin.
Telemetry
The free plugin does not send usage statistics or telemetry to Flexpoint Solutions.
Retention
VAT numbers and validation records may need to be retained as tax evidence. Retention periods differ by country. Store owners should set their own retention policy and describe it in their store privacy notice.
Uninstall
Uninstalling the plugin does not automatically delete validation records. This avoids accidental loss of tax evidence. Store owners can remove records from the database when appropriate.
Erasure requests
A VAT number can be personal data, especially for sole traders. Store owners should handle data-subject requests according to their own legal obligations. In some cases, tax-retention obligations may justify keeping records.
Website privacy
This website uses standard server logs for security and operation. It does not use advertising cookies.
VIES
VIES is operated by the European Commission as a separate service. Store owners should review the Commission’s VIES terms and privacy information where needed.