Data Processing Addendum
Last updated September 6, 2026
1. Definitions
"Data Protection Laws" means all laws applicable to the processing of Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended by the CPRA ("CCPA"), and comparable US state privacy laws.
"Controller," "Processor," "Data Subject," "Personal Data," and "processing" have the meanings given in the GDPR. "Business," "Service Provider," and "sale" have the meanings given in the CCPA. "Merchant Personal Data" means Personal Data contained in Shopify data that we process on your behalf under the Agreement, described in Annex I. "Sub-processor" means any third party engaged by us to process Merchant Personal Data.
2. Roles of the parties
For Merchant Personal Data, you are the Controller (or a Processor acting for another Controller) and Business, and we are your Processor and Service Provider. We process Merchant Personal Data only to provide and support the app, and only on your documented instructions, including as set out in this DPA and the app's configuration options. If we are legally required to process Merchant Personal Data for another purpose, we will tell you first unless the law prohibits it.
We act as an independent Controller for a limited set of data we need to run the business — Merchant account and staff contact details, authentication records, billing records, security and audit logs, and aggregate, non-identifying usage statistics. Our handling of that data is described in the Privacy Policy and is not governed by this DPA's Processor terms.
3. Scope, nature, and purpose of processing
The subject matter, duration, nature and purpose of the processing, the categories of Personal Data, and the categories of Data Subjects are set out in Annex I. Processing continues for the duration of the Agreement and until deletion in accordance with Section 9.
Subscription Concierge is designed to minimize the Personal Data it processes. We do not copy a subscriber's name, email address, telephone number, or postal address into our database. Each customer record we hold is keyed to Shopify's opaque customer identifier; the underlying contact details remain in Shopify as the source of truth. We access Shopify's Customer and Order resources only through Protected Customer Data-gated APIs and only for the identifiers and subscription, order, and product data needed to operate the features you enable.
4. Merchant instructions and compliance
- We will process Merchant Personal Data only on your instructions and will not sell or share it, retain, use, or disclose it outside the direct business relationship, or combine it with Personal Data from other sources, except as permitted by Data Protection Laws.
- You are responsible for the accuracy, quality, and lawfulness of Merchant Personal Data and for having a valid legal basis to make it available to us, including providing any required notices to and obtaining any required consents from your customers.
- We will promptly inform you if, in our opinion, an instruction infringes Data Protection Laws; we may suspend processing of the affected instruction until it is amended or confirmed.
5. Confidentiality
We restrict access to Merchant Personal Data to personnel who need it to provide or support the app, who are bound by written confidentiality obligations and trained on their data-protection responsibilities. Access by our personnel to records that identify an individual customer or subscription is logged.
6. Security measures
We implement and maintain the technical and organizational measures set out in Annex II, designed to protect Merchant Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. We may update those measures over time provided the overall level of protection is not reduced.
7. Sub-processors
- You grant general authorization for us to engage the Sub-processors listed in Annex III.
- We impose data-protection obligations on each Sub-processor that are no less protective than those in this DPA, and we remain responsible to you for each Sub-processor's performance.
- We will give you at least 10 days' notice (by updating this page and, where you have asked for it, by email) before adding or replacing a Sub-processor. You may object on reasonable data-protection grounds within that period; if we cannot resolve the objection, you may terminate the Agreement for the affected app functionality.
8. Assistance to the Merchant
- Data Subject requests. Taking into account the nature of the processing, we
will assist you by appropriate technical and organizational measures, so far as possible, to
respond to requests to exercise Data Subject rights. Subscription Concierge honours Shopify's
mandatory privacy webhooks —
customers/data_request,customers/redact, andshop/redact— and will forward to you any request it receives directly from a Data Subject rather than responding to it itself. - DPIAs and consultation. We will provide you with reasonably available information needed for your data protection impact assessments and prior consultations with supervisory authorities relating to your use of the app.
9. Personal data breach notification
We will notify you without undue delay, and no later than 72 hours, after confirming a Personal Data breach affecting Merchant Personal Data. The notice will describe the nature of the breach, the data and, where known, the Data Subjects affected, the likely consequences, and the measures taken or proposed. We will cooperate with you and take reasonable steps to mitigate and remediate the breach.
10. Return and deletion
On termination of the Agreement, or on your earlier written request, we will delete Merchant Personal Data within 30 days, except where retention is required by law. When you uninstall the app or an erasure request comes through Shopify, the subscription, queue, dunning, gift, skip, and access-log records for the affected shop or customer are deleted. Independently of any request, canceled-subscription history and staff access-log entries are automatically purged after 365 days. Backups containing Merchant Personal Data are overwritten on their normal rotation cycle and are not restored except for disaster recovery.
11. International transfers
Merchant Personal Data is processed and stored in the United States. Where Merchant Personal Data originates in the European Economic Area, the United Kingdom, or Switzerland, the transfer to us and our Sub-processors is made under the European Commission's Standard Contractual Clauses (Module Two or Module Three as applicable), the UK International Data Transfer Addendum, and the Swiss addendum, which are incorporated into this DPA by reference and completed with the information in the Annexes. By installing the app you instruct us to carry out that transfer. We rely on the data-processing agreements and transfer mechanisms of the Sub-processors in Annex III for onward transfers.
12. Audit
On reasonable written request, no more than once per year (unless required by a supervisory authority or following a Personal Data breach), we will make available information necessary to demonstrate compliance with this DPA and allow for and contribute to audits. Audits will be conducted during business hours, with reasonable advance notice, subject to confidentiality obligations, and in a manner that does not disrupt our operations or compromise other customers' data. We may satisfy an audit request by providing third-party reports or questionnaires where available.
13. California and US state privacy terms
We act as a Service Provider (and, under other US state laws, a "processor" or "contractor"). We will not: (a) sell or share Merchant Personal Data; (b) retain, use, or disclose it for any purpose other than performing the services in the Agreement, or as otherwise permitted by the CCPA; (c) retain, use, or disclose it outside the direct business relationship; or (d) combine it with Personal Data received from another source, except as the CCPA permits for a Service Provider. We certify that we understand and will comply with these restrictions. You may take reasonable steps to stop and remediate unauthorized use of Merchant Personal Data.
14. Liability and precedence
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. If there is no separate Agreement with a liability cap, each party's aggregate liability arising out of this DPA is limited to the greater of the fees paid or payable for the app in the 12 months before the event giving rise to the claim, or USD 100. In the event of a conflict, this DPA prevails over the rest of the Agreement and the Privacy Policy on the subject of Processor obligations for Merchant Personal Data; the Standard Contractual Clauses prevail over this DPA.
15. Governing law
This DPA is governed by the law stated in the Agreement, or, if none is stated, the laws of the State of Utah, United States, without regard to its conflict-of-laws rules, except that the Standard Contractual Clauses are governed by the law they specify.
Annex I — Details of processing
| Item | Detail |
|---|---|
| Roles | Merchant: Controller / Business. Provider: Processor / Service Provider. |
| Subject matter | Provision of the Subscription Concierge app for managing recurring-order subscription programs on the Merchant's Shopify store. |
| Duration | The term of the Agreement, plus the deletion period in Section 10. |
| Nature and purpose | Storing, organizing, retrieving, using, and erasing data to operate subscription management, the customer self-service portal, queue and anchor management, dunning and payment-recovery notifications, checkout and post-purchase upsells, retention offers, product recommendations, and merchant analytics. |
| Categories of Data Subjects | The Merchant's customers who hold or held a subscription; the Merchant's staff who use the merchant dashboard. |
| Categories of Personal Data — customers | Shopify customer identifier; subscription, contract, and queue state; billing cycle dates and status; associated product and variant identifiers; order identifiers and line items for fulfilled orders; cancellation reasons voluntarily provided. Name, email, phone, and address are not stored by the app unless the Merchant later enables a feature that requires them and access is granted. |
| Categories of Personal Data — staff | Work email address, assigned role (Admin / Viewer), authentication session records, and access-log entries (who viewed which record, and when). |
| Special category data | None requested or intentionally processed. |
| Frequency | Continuous for the duration of the Agreement. |
| Competent supervisory authority | Determined by the Merchant's establishment or the SCCs; where the Merchant is EEA-established, its lead supervisory authority. |
Annex II — Technical and organizational measures
- Encryption in transit — all traffic to the app's API and dashboard is served over TLS.
- Encryption at rest — Shopify OAuth access and refresh tokens are encrypted before being written to the database; the database and its storage volumes are encrypted at rest by the hosting provider.
- Encrypted backups — database backups are encrypted with a public key whose private counterpart is stored offline, separately from the systems that produce the backups.
- Access control — least-privilege access for personnel; infrastructure credentials held in a managed secrets store; production access limited to named administrators.
- Staff access logging — every view of a customer- or subscription-identifying record through the merchant dashboard is logged (identity, record, timestamp) and visible to Merchant admins in the dashboard's Access Log.
- Tenant isolation — every record is scoped to a single shop; one Merchant's data is not accessible to another.
- Webhook authentication — inbound webhooks are verified by HMAC signature before processing.
- Data minimization — the app is architected to avoid storing customer contact details; it holds opaque identifiers and subscription state only.
- Retention limits — automated purge of canceled-subscription history and access logs after 365 days; deletion on uninstall and on Shopify erasure webhooks.
- Resilience — managed, multi-tenant cloud infrastructure with redundant database deployment and infrastructure defined as code for reproducible recovery.
- Change management and monitoring — version-controlled deployments, application metrics and structured logs, and alerting on error conditions.
Annex III — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services, Inc. | Cloud hosting and compute (managed Kubernetes), managed PostgreSQL database, message queue and event routing, object storage, managed model inference for product recommendations, and secrets management. | United States |
| Cloudflare, Inc. | DNS, TLS termination, content delivery, edge security, aggregate traffic analytics, and inbound email routing for the support address. | Global (edge); configuration in the United States |
| Transactional email provider (Amazon SES) | Delivery of transactional email such as failed-payment notices. Engaged only where the Merchant enables a feature that sends email to identified recipients; not used while such features are disabled. | United States |
Shopify Inc. is the platform on which the app runs and the source of the data processed; it is the Merchant's own processor under the Merchant's agreements with Shopify and is not a Sub-processor of Provider.
Contact
Questions about this DPA, Sub-processor notifications, or data-protection matters: [email protected].
Legal notices to Provider: Subscription Concierge LLC, 11045 Lamasa Cir., Sandy, UT 84092, attention Data Protection, with a copy by email to the address above.