Data Processing Agreement

Effective date: 20 July 2026  ·  Last updated: 24 July 2026

⚠️ Before publishing: replace [LEGAL NAME], [POSTAL ADDRESS] and [SIRET / SIREN] with your registered details.

Confirm Annex 2 item 3 (encryption at rest) with your database host before publishing, and align the wording in the Privacy Policy to match. Then delete this box. This agreement has not been reviewed by a lawyer.

This Data Processing Agreement (“DPA”) forms part of the Terms of Service for Back-in-Stock (the “App”) and applies where you use the App to process personal data subject to the EU General Data Protection Regulation (“GDPR”) or the UK GDPR.

It is entered into between you, the merchant operating the Shopify store on which the App is installed (the “Controller”), and [LEGAL NAME], an individual entrepreneur registered in France ([SIRET / SIREN]), of [POSTAL ADDRESS] (the “Processor”, “we”, “us”).

By installing the App you accept this DPA. No signature is required. If you need a signed counterpart, write to [email protected].

1. Roles of the parties

You are the Controller of the personal data processed through the App, and we are your Processor. You determine the purposes and means of the processing; we act only on your documented instructions.

Your instructions are given by installing the App, by configuring it, and by these documents. You confirm that these instructions are lawful, and that you have a valid legal basis — ordinarily the data subject's own request — for the processing described in Annex 1.

Shopify is a separate controller or processor in its own right for the data it holds. This DPA does not cover Shopify's processing, which is governed by your agreement with Shopify.

2. Scope and duration

We process personal data only for the duration of your installation of the App, plus the retention periods set out in section 9. The subject matter, nature, purpose, data categories and data subjects are described in Annex 1.

3. Our obligations

We will:

We will promptly inform you if, in our opinion, an instruction from you infringes the GDPR or other data protection law.

4. Your obligations

You warrant that:

5. Sub-processors

You give us general written authorisation to engage the sub-processors listed in Annex 3.

We will impose on each sub-processor data protection obligations no less protective than those in this DPA, and we remain fully liable to you for their performance.

If we intend to add or replace a sub-processor, we will give you at least 30 days' notice by email to your store's contact address or by in-app notice. You may object on reasonable data protection grounds within that period; if we cannot resolve your objection, you may terminate by uninstalling the App, and any supporter subscription will be cancelled from the end of the current billing period.

6. International transfers

Where personal data is transferred outside the European Economic Area, we rely on an adequacy decision where one applies, and otherwise on the European Commission's Standard Contractual Clauses (Decision 2021/914) together with any transfer risk assessment and supplementary measures required.

The current hosting and processing locations for each sub-processor are stated in Annex 3.

7. Personal data breaches

We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting personal data processed on your behalf. The notification will describe, so far as known: the nature of the breach and the categories and approximate number of data subjects and records concerned; the likely consequences; and the measures taken or proposed.

Notifying a supervisory authority and, where required, the affected data subjects remains your responsibility as Controller. We will provide reasonable assistance.

Breach notices are sent to your Shopify store contact email. Keep it current.

8. Data subject requests

Every notification email contains exactly one working unsubscribe link, which lets a data subject withdraw consent and have their record erased without involving either of us.

This is enforced by the App, not left to configuration. If you supply a custom email template, the link is placed wherever you put the {{unsubscribe_url}} placeholder; if your template omits it, the App appends an unsubscribe footer automatically rather than sending an email with no way out. Templates that include the placeholder do not receive a duplicate link.

If a data subject contacts us directly regarding data we process for you, we will not respond on the substance, and will redirect them to you or forward the request without undue delay. If you need our help to locate, export, correct or erase a specific record, contact [email protected] and we will assist at no charge.

The App also implements Shopify's mandatory privacy webhooks — customers/data_request, customers/redact and shop/redact — so requests routed through Shopify are handled automatically.

9. Deletion and return

Deletion operates on two tracks.

Scheduled deletion. A purge runs every 24 hours and permanently deletes: notification emails delivered more than 90 days ago; emails abandoned after failing to send for more than 90 days; subscriptions whose alert was already sent more than 90 days ago; audit records older than 90 days; and expired OAuth state tokens. The retention window is configurable and set to 90 days.

Subscriptions still awaiting notification are excluded from this purge regardless of age. A variant may remain out of stock for longer than the retention window, and erasing a pending request would silently break the commitment made to the data subject.

Event-driven deletion. Data is also erased immediately when:

You can request a copy of your data before uninstalling by writing to [email protected]. Once deleted, data cannot be recovered.

Within the retention window, a subscription record is kept after its notification has been sent — marked as notified rather than deleted — so that the same person is not emailed twice for the same variant. If you want a subscriber's record removed sooner, use the unsubscribe link or contact us.

10. Audits

On reasonable written request, and no more than once a year unless required by a supervisory authority or following a breach, we will provide the information reasonably necessary to demonstrate compliance with Article 28. Given the scale of the service, we will ordinarily satisfy audit requests by written response rather than an on-site inspection. Any audit must respect the confidentiality and security of other merchants' data.

11. Liability and precedence

The limitations of liability in section 12 of the Terms of Service apply to this DPA, except where GDPR Article 82 provides otherwise — nothing here limits a data subject's rights or either party's statutory liability to a supervisory authority.

If there is a conflict, this DPA prevails over the Terms of Service in respect of the processing of personal data. The Standard Contractual Clauses prevail over both in respect of restricted transfers.

12. Governing law

This DPA is governed by French law, and the jurisdiction provisions in section 14 of the Terms of Service apply.


Annex 1 — Details of the processing

Subject matter: providing back-in-stock notification functionality to the Controller's online store.

Duration: for as long as the App is installed, plus the retention periods in section 9.

Nature and purpose: collecting a customer's request to be notified about a specific product variant; storing that request; monitoring inventory changes reported by Shopify; and sending a single transactional email when the variant is restocked; and recording a single timestamp when the product link in that email is clicked, so the Controller can see which alerts were acted on. The App does not profile data subjects and takes no automated decisions producing legal or similarly significant effects.

Categories of data subjects: customers and prospective customers of the Controller's store who voluntarily submit a restock alert request.

Categories of personal data:

Special categories: none. The App is not designed to process data under Articles 9 or 10 GDPR.

Merchant account data: we also process the Controller's own shop domain, shop display name, access token, sender address and configuration. This is business account data rather than customer personal data, and is covered by the Privacy Policy.

Annex 2 — Technical and organisational measures

The measures below reflect what the App implements today. They are stated as facts, not aspirations; where a control depends on infrastructure we do not operate, that is said explicitly.

  1. Encryption in transit. Outside local development, HTTP requests are redirected to HTTPS, and outbound SMTP connections to our email provider use TLS.
  2. Authentication and access control. Admin access uses Shopify session tokens or an administrative key; every endpoint requires an authenticated principal by default, with anonymous access granted only to the specific routes that must be reachable before authentication.
  3. Encryption at rest. The application does not perform column-level encryption of stored data. Any encryption at rest is provided by the underlying database hosting layer. [If your database host has transparent data encryption or volume encryption enabled, state that here and in the Privacy Policy; otherwise leave this as written.]
  4. Tenant isolation. Application logic is cloistered per shop: queries are scoped to the authenticated store, so one merchant cannot read another merchant's subscribers or notifications.
  5. Storefront request authentication. Public storefront endpoints are authenticated by Shopify App Proxy signature verification. Signature and webhook HMAC checks fail closed — a missing or unverifiable signature is rejected rather than trusted.
  6. Rate limiting. Storefront endpoints are rate limited per verified shop, and input lengths and volumes are bounded to resist abuse and enumeration.
  7. Credential management. Secrets are supplied by environment or secure configuration and are never hardcoded in source or written to logs. Shopify access tokens expire and are refreshed.
  8. Logging and monitoring. Security-relevant events are logged, with secret values excluded from log output. Audit records are retained for 1 year.
  9. Data minimisation. Only the fields in Annex 1 are collected. The App does not collect customer names, addresses, phone numbers or payment data, and does not use advertising or tracking cookies.
  10. Right to object, technically enforced. Every notification carries exactly one unsubscribe link, added automatically if a custom template omits it, and publishes List-Unsubscribe and List-Unsubscribe-Post headers so recipients can opt out in one click directly from Gmail or Apple Mail without opening the message.
  11. Deletion. A scheduled purge runs every 24 hours and enforces the 90-day retention window described in section 9. Shopify's privacy webhooks — customers/redact and shop/redact — are implemented and delete the corresponding records on receipt. Automated tests assert that subscriptions still awaiting notification are never removed by the purge.
  12. Development practice. Changes are covered by an automated test suite, including tests that specifically assert the access-control and fail-closed behaviours above, so a regression that reopens one of these controls fails the build.

Limitation. No system is completely secure. These measures are appropriate to the nature and scale of the processing, and are reviewed as the App evolves; they are not a guarantee against every possible compromise.

Annex 3 — Authorised sub-processors

Sub-processor Purpose Data processed Location
Shopify Inc. Platform, product and inventory data, billing Shop domain, access tokens, product and inventory data Canada / United States
OVH SAS Outbound SMTP delivery of notification emails Recipient email address, email content France (EU)
Application and database hosting Running the App and storing its data All data described in Annex 1 [CONFIRM PROVIDER AND REGION]

If a merchant configures a custom sender address, outbound mail may instead be routed through that merchant's own email provider. That provider is engaged by the merchant, not by us, and is outside this Annex.

Contact

Privacy and data requests: [email protected]
Data Protection Officer: [email protected]
General support: [email protected]

See also: Terms of Service · Privacy Policy · FAQ