Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the agreement between the merchant using FlatCart (the "Controller") and the FlatCart operator (the "Processor") and applies to the extent the Processor processes personal data on the Controller's behalf under the GDPR or UK GDPR.
1. Subject matter and duration
Processing is limited to operating the FlatCart app for the Controller's Shopify store and lasts for the duration of the app's installation plus a 48-hour deletion window.
2. Nature and purpose of processing
- Storing the Controller's app configuration.
- Transiently reading order and refund webhook payloads to compute anonymous, aggregate analytics (counts and revenue totals per day).
- Counting anonymous storefront and checkout events.
3. Categories of data and data subjects
- Merchant data: store domain, staff account metadata contained in Shopify OAuth sessions (the installing user's name and email).
- Customer data: order line details (price, quantity, line properties) are processed transiently only and never persisted. No customer identity, contact, or payment data is stored. Data subjects: the Controller's staff; the Controller's customers (transient only).
4. Controller instructions
The Processor processes personal data only to provide the app's documented functionality and per documented merchant settings. The app's data practices are documented in the privacy policy, which forms part of this DPA.
5. Confidentiality and security
The Processor implements appropriate technical and organisational measures, including: EU-hosted infrastructure; encryption in transit (TLS) for all endpoints; Shopify-verified authentication on every surface (session tokens for the admin, HMAC verification for webhooks, signed proxy requests for storefront telemetry); least-privilege API scopes; and no storage of customer personal data by design.
6. Sub-processors
The Processor may update the list with notice. Current sub-processors: Shopify (platform), Railway (application hosting and database, EU region), and Sentry for error monitoring (request bodies excluded).
7. Data subject rights assistance
Because no customer personal data is retained, data subject requests
concerning customer data can be answered by the Controller without
Processor involvement; the Processor will confirm deletion status on
request and honours Shopify's mandatory GDPR webhooks
(customers/data_request, customers/redact,
shop/redact) automatically.
8. Deletion
On uninstallation, access tokens are revoked immediately and all stored
data for the Controller's store is permanently deleted within 48 hours
(sooner if Shopify's shop/redact webhook arrives first).
9. International transfers
Primary processing occurs in the EU. Where a sub-processor processes data outside the EU or EEA, transfers rely on the sub-processor's Standard Contractual Clauses.
10. Audit
The Processor makes available, on reasonable request, the information necessary to demonstrate compliance with this DPA.
Contact
Questions about this DPA: support@flatcart.app.