Data Processing Agreement
Effective date: 20 July 2026 · Last updated: 24 July 2026
⚠️ Before publishing: replace
[LEGAL NAME], [POSTAL ADDRESS] and [SIRET / SIREN] with your
registered details.
Confirm Annex 2 item 3 (encryption at rest) with your database host before publishing, and align the wording in the Privacy Policy to match. Then delete this box. This agreement has not been reviewed by a lawyer.
This Data Processing Agreement (“DPA”) forms part of the Terms of Service for Back-in-Stock (the “App”) and applies where you use the App to process personal data subject to the EU General Data Protection Regulation (“GDPR”) or the UK GDPR.
It is entered into between you, the merchant operating the Shopify store on which the App is installed (the “Controller”), and [LEGAL NAME], an individual entrepreneur registered in France ([SIRET / SIREN]), of [POSTAL ADDRESS] (the “Processor”, “we”, “us”).
By installing the App you accept this DPA. No signature is required. If you need a signed counterpart, write to [email protected].
1. Roles of the parties
You are the Controller of the personal data processed through the App, and we are your Processor. You determine the purposes and means of the processing; we act only on your documented instructions.
Your instructions are given by installing the App, by configuring it, and by these documents. You confirm that these instructions are lawful, and that you have a valid legal basis — ordinarily the data subject's own request — for the processing described in Annex 1.
Shopify is a separate controller or processor in its own right for the data it holds. This DPA does not cover Shopify's processing, which is governed by your agreement with Shopify.
2. Scope and duration
We process personal data only for the duration of your installation of the App, plus the retention periods set out in section 9. The subject matter, nature, purpose, data categories and data subjects are described in Annex 1.
3. Our obligations
We will:
- process personal data only on your documented instructions, including for international transfers, unless required otherwise by EU or Member State law — in which case we will inform you before processing, unless that law prohibits it;
- ensure that anyone authorised to process the data is bound by an appropriate duty of confidentiality;
- implement the technical and organisational measures set out in Annex 2 (GDPR Art. 32);
- respect the conditions in section 5 for engaging sub-processors;
- assist you, so far as is reasonably possible and taking into account the nature of the processing, in responding to requests from data subjects exercising their rights under Chapter III GDPR;
- assist you with your obligations under Articles 32 to 36 GDPR, including security, breach notification and data protection impact assessments, taking into account the information available to us;
- delete or return the data at the end of the engagement, as set out in section 9;
- make available the information necessary to demonstrate compliance with Article 28 GDPR, and allow for audits as set out in section 10.
We will promptly inform you if, in our opinion, an instruction from you infringes the GDPR or other data protection law.
4. Your obligations
You warrant that:
- you have a lawful basis for the processing, and have provided the data subjects with any required privacy information;
- the email addresses processed through the App were collected through the App's own signup form, entered voluntarily by the data subject — you will not import or otherwise introduce addresses obtained elsewhere (see section 4.2 of the Terms);
- you will not use the App to send marketing or promotional content, which would change the lawful basis for the processing and is prohibited under the Terms;
- you will not configure the App to process special categories of personal data (Art. 9 GDPR) or criminal conviction data (Art. 10 GDPR). The App is not designed for such data, and Annex 2 has not been calibrated for it.
5. Sub-processors
You give us general written authorisation to engage the sub-processors listed in Annex 3.
We will impose on each sub-processor data protection obligations no less protective than those in this DPA, and we remain fully liable to you for their performance.
If we intend to add or replace a sub-processor, we will give you at least 30 days' notice by email to your store's contact address or by in-app notice. You may object on reasonable data protection grounds within that period; if we cannot resolve your objection, you may terminate by uninstalling the App, and any supporter subscription will be cancelled from the end of the current billing period.
6. International transfers
Where personal data is transferred outside the European Economic Area, we rely on an adequacy decision where one applies, and otherwise on the European Commission's Standard Contractual Clauses (Decision 2021/914) together with any transfer risk assessment and supplementary measures required.
The current hosting and processing locations for each sub-processor are stated in Annex 3.
7. Personal data breaches
We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting personal data processed on your behalf. The notification will describe, so far as known: the nature of the breach and the categories and approximate number of data subjects and records concerned; the likely consequences; and the measures taken or proposed.
Notifying a supervisory authority and, where required, the affected data subjects remains your responsibility as Controller. We will provide reasonable assistance.
Breach notices are sent to your Shopify store contact email. Keep it current.
8. Data subject requests
Every notification email contains exactly one working unsubscribe link, which lets a data subject withdraw consent and have their record erased without involving either of us.
This is enforced by the App, not left to configuration. If you supply a custom email template, the link is
placed wherever you put the {{unsubscribe_url}} placeholder; if your template omits it, the App
appends an unsubscribe footer automatically rather than sending an email with no way out. Templates that
include the placeholder do not receive a duplicate link.
If a data subject contacts us directly regarding data we process for you, we will not respond on the substance, and will redirect them to you or forward the request without undue delay. If you need our help to locate, export, correct or erase a specific record, contact [email protected] and we will assist at no charge.
The App also implements Shopify's mandatory privacy webhooks — customers/data_request,
customers/redact and shop/redact — so requests routed through Shopify are handled
automatically.
9. Deletion and return
Deletion operates on two tracks.
Scheduled deletion. A purge runs every 24 hours and permanently deletes: notification emails delivered more than 90 days ago; emails abandoned after failing to send for more than 90 days; subscriptions whose alert was already sent more than 90 days ago; audit records older than 90 days; and expired OAuth state tokens. The retention window is configurable and set to 90 days.
Subscriptions still awaiting notification are excluded from this purge regardless of age. A variant may remain out of stock for longer than the retention window, and erasing a pending request would silently break the commitment made to the data subject.
Event-driven deletion. Data is also erased immediately when:
- A data subject unsubscribes — their subscription record is deleted immediately.
- Shopify sends
customers/redact— every subscription and every queued email for that customer's address is deleted. - You uninstall the App — your store's access token is removed when the
app/uninstalledwebhook is received. - Shopify sends
shop/redact, approximately 48 hours after uninstall — the remainder of your shop's data is deleted, including subscriber records, audit records and invoices.
You can request a copy of your data before uninstalling by writing to [email protected]. Once deleted, data cannot be recovered.
Within the retention window, a subscription record is kept after its notification has been sent — marked as notified rather than deleted — so that the same person is not emailed twice for the same variant. If you want a subscriber's record removed sooner, use the unsubscribe link or contact us.
10. Audits
On reasonable written request, and no more than once a year unless required by a supervisory authority or following a breach, we will provide the information reasonably necessary to demonstrate compliance with Article 28. Given the scale of the service, we will ordinarily satisfy audit requests by written response rather than an on-site inspection. Any audit must respect the confidentiality and security of other merchants' data.
11. Liability and precedence
The limitations of liability in section 12 of the Terms of Service apply to this DPA, except where GDPR Article 82 provides otherwise — nothing here limits a data subject's rights or either party's statutory liability to a supervisory authority.
If there is a conflict, this DPA prevails over the Terms of Service in respect of the processing of personal data. The Standard Contractual Clauses prevail over both in respect of restricted transfers.
12. Governing law
This DPA is governed by French law, and the jurisdiction provisions in section 14 of the Terms of Service apply.
Annex 1 — Details of the processing
Subject matter: providing back-in-stock notification functionality to the Controller's online store.
Duration: for as long as the App is installed, plus the retention periods in section 9.
Nature and purpose: collecting a customer's request to be notified about a specific product variant; storing that request; monitoring inventory changes reported by Shopify; and sending a single transactional email when the variant is restocked; and recording a single timestamp when the product link in that email is clicked, so the Controller can see which alerts were acted on. The App does not profile data subjects and takes no automated decisions producing legal or similarly significant effects.
Categories of data subjects: customers and prospective customers of the Controller's store who voluntarily submit a restock alert request.
Categories of personal data:
- email address submitted by the data subject;
- product interest — Shopify product ID and variant ID, product and variant title, and the product's URL and image URL, used to build the notification email;
- subscription metadata — creation timestamp, and locale where available;
- notification status — whether an alert has been sent, and when; and whether the product link in the alert email was clicked, and when (a single timestamp; no IP address or device data);
- email delivery records — the recipient address, sender address and name, subject, the rendered HTML body of the email, the number of delivery attempts, the time sent, and the last error message where delivery failed.
Special categories: none. The App is not designed to process data under Articles 9 or 10 GDPR.
Merchant account data: we also process the Controller's own shop domain, shop display name, access token, sender address and configuration. This is business account data rather than customer personal data, and is covered by the Privacy Policy.
Annex 2 — Technical and organisational measures
The measures below reflect what the App implements today. They are stated as facts, not aspirations; where a control depends on infrastructure we do not operate, that is said explicitly.
- Encryption in transit. Outside local development, HTTP requests are redirected to HTTPS, and outbound SMTP connections to our email provider use TLS.
- Authentication and access control. Admin access uses Shopify session tokens or an administrative key; every endpoint requires an authenticated principal by default, with anonymous access granted only to the specific routes that must be reachable before authentication.
- Encryption at rest. The application does not perform column-level encryption of stored data. Any encryption at rest is provided by the underlying database hosting layer. [If your database host has transparent data encryption or volume encryption enabled, state that here and in the Privacy Policy; otherwise leave this as written.]
- Tenant isolation. Application logic is cloistered per shop: queries are scoped to the authenticated store, so one merchant cannot read another merchant's subscribers or notifications.
- Storefront request authentication. Public storefront endpoints are authenticated by Shopify App Proxy signature verification. Signature and webhook HMAC checks fail closed — a missing or unverifiable signature is rejected rather than trusted.
- Rate limiting. Storefront endpoints are rate limited per verified shop, and input lengths and volumes are bounded to resist abuse and enumeration.
- Credential management. Secrets are supplied by environment or secure configuration and are never hardcoded in source or written to logs. Shopify access tokens expire and are refreshed.
- Logging and monitoring. Security-relevant events are logged, with secret values excluded from log output. Audit records are retained for 1 year.
- Data minimisation. Only the fields in Annex 1 are collected. The App does not collect customer names, addresses, phone numbers or payment data, and does not use advertising or tracking cookies.
- Right to object, technically enforced. Every notification carries exactly one
unsubscribe link, added automatically if a custom template omits it, and publishes
List-UnsubscribeandList-Unsubscribe-Postheaders so recipients can opt out in one click directly from Gmail or Apple Mail without opening the message. - Deletion. A scheduled purge runs every 24 hours and enforces the 90-day retention
window described in section 9. Shopify's privacy webhooks —
customers/redactandshop/redact— are implemented and delete the corresponding records on receipt. Automated tests assert that subscriptions still awaiting notification are never removed by the purge. - Development practice. Changes are covered by an automated test suite, including tests that specifically assert the access-control and fail-closed behaviours above, so a regression that reopens one of these controls fails the build.
Limitation. No system is completely secure. These measures are appropriate to the nature and scale of the processing, and are reviewed as the App evolves; they are not a guarantee against every possible compromise.
Annex 3 — Authorised sub-processors
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| Shopify Inc. | Platform, product and inventory data, billing | Shop domain, access tokens, product and inventory data | Canada / United States |
| OVH SAS | Outbound SMTP delivery of notification emails | Recipient email address, email content | France (EU) |
| Application and database hosting | Running the App and storing its data | All data described in Annex 1 | [CONFIRM PROVIDER AND REGION] |
If a merchant configures a custom sender address, outbound mail may instead be routed through that merchant's own email provider. That provider is engaged by the merchant, not by us, and is outside this Annex.
Contact
Privacy and data requests: [email protected]
Data Protection Officer: [email protected]
General support: [email protected]
See also: Terms of Service · Privacy Policy · FAQ