Data Processing Agreement
Last updated: June 26, 2026 Effective date: June 26, 2026
1. Introduction
This Data Processing Agreement ("DPA") forms part of the Terms of Service (https://datacrow.app/terms) between Datacrow ("Processor", "we", "us") and the Shopify merchant that has installed and configured the Datacrow application ("Controller", "you", "Customer"). By installing Datacrow on your Shopify store, you accept this DPA.
This DPA applies to all Personal Data that Datacrow processes on behalf of the Controller in providing the Datacrow service, as further described in Annex I.
In the event of a conflict between this DPA and the Terms of Service, this DPA controls with respect to the processing of Personal Data.
2. Definitions
Capitalized terms have the meanings given in Annex I, in the GDPR, the UK GDPR, the CCPA/CPRA, or other applicable Data Protection Laws.
- "Data Protection Laws" means all laws and regulations applicable to the processing of Personal Data, including but not limited to:
- the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR")
- the UK Data Protection Act 2018 and the UK GDPR
- the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (collectively, "CCPA/CPRA")
- any other applicable data protection or privacy law in the jurisdictions where Personal Data is collected or processed
- "Personal Data" has the meaning given in the GDPR (or the equivalent term — "Personal Information", "personal data", etc. — under other Data Protection Laws).
- "Sub-processor" means any third party that Datacrow engages to process Personal Data on Controller's behalf in connection with the service. The current list is published at https://datacrow.app/subprocessors.
- "Standard Contractual Clauses" or "SCCs" means the Standard Contractual Clauses for the transfer of Personal Data to third countries adopted by the European Commission in its Implementing Decision (EU) 2021/914 of 4 June 2021.
- "UK IDTA" means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner's Office under section 119A of the UK Data Protection Act 2018.
3. Roles and scope of processing
3.1. With respect to Personal Data processed under this DPA:
- Controller is the data controller (under GDPR/UK GDPR) and a "business" (under CCPA/CPRA).
- Datacrow is the data processor (under GDPR/UK GDPR) and a "service provider" (under CCPA/CPRA).
3.2. The subject matter, nature, purpose, duration of processing, types of Personal Data, and categories of data subjects are described in Annex I.
3.3. Datacrow processes Personal Data only: (a) to provide the Datacrow service as configured by Controller; (b) on Controller's documented instructions, which are deemed given by installing the application, configuring destinations, and accepting these Terms; and (c) as required by applicable law, in which case we will notify Controller of the legal requirement before processing unless prohibited by law.
Datacrow will not: (d) "sell" Personal Data within the meaning of CCPA/CPRA; (e) "share" Personal Data for cross-context behavioral advertising; (f) retain, use, or disclose Personal Data outside of the direct business relationship with Controller or for any purpose other than performing the services specified in this DPA; (g) combine Personal Data received from or on behalf of Controller with Personal Data from any other source, except as necessary to provide the service; (h) use Personal Data to train, fine-tune, or improve any machine learning model, including any "artificial intelligence" model.
3.4. Datacrow certifies that it understands and will comply with the restrictions in §3.3 (this certification is required by CCPA Regulations §7051(a)(5)).
4. Confidentiality and personnel
4.1. Datacrow ensures that personnel authorized to process Personal Data are bound by appropriate confidentiality obligations and have received privacy and security training appropriate to their role.
4.2. Access to Personal Data is limited to personnel with a need to know for purposes of providing the service.
5. Security measures
5.1. Datacrow implements and maintains the technical and organizational measures described in Annex II, designed to protect Personal Data against unauthorized or unlawful processing, accidental loss, destruction, damage, or disclosure.
5.2. Datacrow may update these measures from time to time, provided that the level of protection is not reduced. Material updates will be reflected in Annex II and notified to Controllers via email and/or in-app notice.
6. Sub-processors
6.1. General authorization. Controller provides general written authorization for Datacrow to engage Sub-processors to process Personal Data, subject to the conditions in this Section 6.
6.2. Current list and notification. The current list of authorized Sub-processors is published at https://datacrow.app/subprocessors. Datacrow will notify Controller of any intended addition or replacement of Sub-processors at least 30 days before the change takes effect by email and via posting an updated list. (See note: where a Sub-processor change is required to maintain service continuity, the notice period may be shorter; we will notify as soon as practically possible.)
6.3. Objection right. Controller may object to a proposed Sub-processor on reasonable grounds related to data protection within 14 days of notice. If the parties cannot resolve the objection in good faith within 30 days, Controller may terminate the service without penalty by uninstalling the application. Continued use of the service after the new Sub-processor takes effect constitutes acceptance.
6.4. Sub-processor obligations. Before any Sub-processor begins processing Personal Data, Datacrow will enter into a written agreement that imposes data protection obligations on the Sub-processor that are substantially the same as those imposed on Datacrow under this DPA, in particular including the obligations of confidentiality, security, sub-processor management, data subject rights cooperation, and breach notification. Datacrow remains fully liable to Controller for the acts and omissions of its Sub-processors.
6.5. Destination forwarding clarification. Datacrow's "destination API" Sub-processors (Meta, Google, Klaviyo, TikTok, Pinterest) receive Personal Data only when Controller has enabled the corresponding destination in Datacrow. Datacrow does not transmit Personal Data to a destination the Controller has not enabled. Each destination has its own data processing terms that the Controller separately accepts when configuring that destination's credentials; Datacrow acts as the forwarder under Controller's instructions and does not modify those independent contractual relationships.
7. Data subject rights
7.1. Taking into account the nature of the processing, Datacrow will assist Controller through appropriate technical and organizational measures, insofar as possible, in fulfilling Controller's obligations to respond to requests from data subjects to exercise their rights under Data Protection Laws (including rights of access, rectification, erasure, restriction, portability, objection, and the right not to be subject to automated decision-making).
7.2. Practical implementation. Datacrow implements the Shopify-mandated GDPR webhooks (customers/data_request, customers/redact, shop/redact) which Shopify uses to route shopper requests through Controller to Datacrow automatically. On receipt of:
customers/data_request: Datacrow will compile the requesting shopper's Personal Data and make it available to Controller within 30 days.customers/redact: Datacrow will delete the requesting shopper's Personal Data from all Datacrow systems within 30 days.shop/redact: Datacrow will delete all Personal Data associated with Controller's store within 48 hours of receipt, as required by Shopify.
7.3. If a data subject contacts Datacrow directly, we will forward the request to Controller without undue delay and not respond to the data subject ourselves except to confirm receipt and to direct them to Controller.
8. Personal Data breach notification
8.1. If Datacrow becomes aware of a Personal Data breach affecting Controller's Personal Data, Datacrow will notify Controller without undue delay and in any event within 72 hours of becoming aware of the breach.
8.2. The notification will include, to the extent known at the time: (a) the nature of the breach, including the categories and approximate number of data subjects and Personal Data records concerned; (b) the likely consequences of the breach; (c) the measures taken or proposed to address the breach and mitigate its possible adverse effects; (d) the contact point for further information.
8.3. Where it is not possible to provide all information within 72 hours, Datacrow will provide an initial notification followed by additional information as it becomes available, without further undue delay.
8.4. Datacrow will cooperate with Controller to fulfill any obligation Controller has under Data Protection Laws to notify supervisory authorities or affected data subjects.
8.5. Datacrow's incident response procedures, including detection sources and escalation paths, are documented at our internal incident response procedures.
9. International data transfers
9.1. Datacrow processes Personal Data in the United States. Where Personal Data is transferred from the European Economic Area, the United Kingdom, or Switzerland to the United States or any other third country, the transfer is governed by:
(a) the 2021 EU Standard Contractual Clauses, Module 2 (Controller-to-Processor), which are incorporated into this DPA by reference and deemed entered into between Controller (as Data Exporter) and Datacrow (as Data Importer). The optional clauses are completed as follows:
- Clause 7 (Docking clause): included.
- Clause 9 (Sub-processors), Option 2 (General authorization): applies, with the 30-day notice period in §6.2.
- Clause 11 (Redress): the optional independent dispute resolution body is not included.
- Clause 17 (Governing law): the law of the Republic of Ireland.
- Clause 18 (Choice of forum): the courts of the Republic of Ireland.
- Annex I of the SCCs corresponds to Annex I of this DPA.
- Annex II of the SCCs corresponds to Annex II of this DPA.
- Annex III of the SCCs is the Sub-processor list at https://datacrow.app/subprocessors.
(b) for transfers from the United Kingdom, the UK International Data Transfer Addendum (IDTA) issued by the UK ICO, which is deemed entered into and which modifies the SCCs as set out in the IDTA. The version is "Version A 1.0", in force 21 March 2022.
(c) for transfers from Switzerland, the Swiss Federal Act on Data Protection (revFADP) is deemed to apply with appropriate modifications to the SCCs (references to GDPR, to EU supervisory authorities, and to EU member states are read to include the corresponding Swiss equivalents).
9.2. Each party warrants that it has no reason to believe the laws and practices of its destination country prevent the Data Importer from fulfilling its obligations under the SCCs.
10. Audits
10.1. Datacrow will, upon Controller's reasonable written request, make available to Controller information necessary to demonstrate compliance with this DPA, including:
- A description of Datacrow's technical and organizational measures (Annex II)
- A summary of any third-party security certifications or audit reports Datacrow holds
- Responses to a reasonable security questionnaire
10.2. No more than once per twelve-month period (or more frequently if required by Data Protection Laws or by Controller's competent supervisory authority), Controller may request a remote audit, subject to: (a) reasonable advance notice (at least 30 days); (b) confidentiality obligations; (c) limitations to avoid disrupting Datacrow's business or other customers' data; (d) Controller bearing its own costs and Datacrow's reasonable costs of providing audit support.
10.3. Where any third-party audit report addresses the audit scope reasonably requested, Datacrow may satisfy this obligation by providing the report under appropriate confidentiality terms.
11. Return and deletion of data
11.1. On termination of the service (whether by uninstall, account closure, or otherwise), Datacrow will, at Controller's choice and subject to applicable law: (a) delete all Personal Data processed under this DPA; or (b) return Personal Data to Controller in a structured, commonly used, machine-readable format.
11.2. Default behavior, absent explicit instruction, is deletion. Personal Data is deleted within 30 days of uninstall, except where retention is required by applicable law (e.g., for billing records, fraud prevention, or legal obligations), in which case Datacrow will continue to apply this DPA to such retained data until deletion is possible.
11.3. On receipt of a Shopify shop/redact webhook, deletion is accelerated to 48 hours regardless of the default.
12. CCPA / CPRA-specific provisions (Annex CA)
12.1. For purposes of CCPA/CPRA, Controller is a "business" and Datacrow is a "service provider." The Personal Information processed under this DPA is for the limited and specified purposes set out in Annex I.
12.2. Datacrow certifies that it understands the restrictions in §3.3 and will comply with them, as required by CCPA Regulations §7051(a)(5).
12.3. If Datacrow can no longer meet its obligations under CCPA/CPRA, it will notify Controller in writing.
12.4. Controller has the right, upon notice and consultation, to take reasonable and appropriate steps to: (a) ensure that Datacrow uses the transferred Personal Information in a manner consistent with Controller's CCPA/CPRA obligations; and (b) stop and remediate any unauthorized use of Personal Information.
13. General
13.1. Order of precedence. In the event of conflict, the order of precedence is: (i) the SCCs (where applicable); (ii) this DPA; (iii) the Terms of Service.
13.2. Term. This DPA takes effect when Controller installs Datacrow and remains in effect until all Personal Data has been deleted or returned in accordance with §11.
13.3. Liability. Each party's liability under this DPA is subject to the limitations of liability set out in the Terms of Service.
13.4. Governing law and jurisdiction. Except as set out in §9 (SCCs) and §12 (CCPA/CPRA), this DPA is governed by the laws of the State of North Carolina, United States, without regard to its conflict-of-laws principles.
13.5. Severability. If any provision of this DPA is held invalid or unenforceable, the remaining provisions remain in full force and effect.
13.6. Updates. Datacrow may update this DPA from time to time to reflect changes in Data Protection Laws or service practices. Material updates will be notified to Controller at least 30 days before they take effect; continued use of the service constitutes acceptance.
13.7. Notices. Notices to Datacrow under this DPA should be sent to privacy@datacrow.app. Notices to Controller will be sent to the email address on file for the Shopify store and/or via in-app notification.
Annex I — Details of processing
| Item | Detail |
|---|---|
| Subject matter | Server-side forwarding of Shopify storefront events and order/refund webhooks to merchant-configured advertising and analytics destinations |
| Nature of processing | Collection, structuring, storage, transmission, deduplication, and deletion of canonical event records |
| Purpose of processing | To provide the Datacrow service as described in the Terms of Service |
| Duration of processing | Until the merchant uninstalls the application or otherwise terminates the service, plus the deletion/return period in §11 |
| Types of Personal Data | Identifiers (email, phone, customer ID), pseudonymous identifiers (Datacrow anonymous ID, session ID, marketing cookies), marketing click identifiers (gclid, gbraid, wbraid, fbclid, ttclid), technical metadata (IP, user-agent, page URL, referrer), commerce data (products, orders, totals) |
| Categories of data subjects | Shoppers who visit and transact on the Controller's Shopify store |
| Frequency of transfer | Continuous (event-driven, as shoppers interact with the store) |
| Retention period | 90 days for canonical events and delivery logs (global default, configurable by Datacrow); until uninstall + 30 days for merchant metadata; immediate on customers/redact or shop/redact webhook |
Annex II — Technical and organizational measures
Datacrow implements the following measures, current as of the last update date:
Encryption
- Personal Data encrypted in transit using TLS 1.2 or higher for all internal and external traffic.
- Destination credentials encrypted at rest using AES-256-GCM with a versioned, service-managed encryption key.
- Database backups encrypted at rest by the Railway-managed PostgreSQL provider.
Access controls
- Multi-factor authentication required on all administrative accounts (Shopify Partner Dashboard, Railway, GitHub, destination provider accounts).
- Per-merchant data isolation enforced at the database layer through
store_idforeign-key partitioning. - Principle of least privilege applied to internal service accounts.
Backup and recovery
- Automated daily database backups, retained 30 days.
- Backups stored in the same region as primary data with the same encryption controls.
- Quarterly restore tests.
Test/production separation
- Production environment isolated from development and CI environments at the network, credential, and database level.
- No production data used in development or testing.
Monitoring and logging
- Application logs shipped to Axiom (or stdout fallback) for retention of 30 days.
- Logs filtered to exclude shopper PII; merchant identifiers and request IDs only.
- Anomaly thresholds configured for failed-auth spikes, unusual error rates, and queue depth.
Vulnerability management
- Dependencies monitored via GitHub Dependabot.
- Security advisories triaged within 7 days; critical patches applied within 24 hours of confirmed exploitability.
Personnel
- Personnel (currently sole operator) bound by confidentiality obligations as a matter of professional standard.
- Background suitable for processing Personal Data.
Incident response
- Documented incident response procedures: our internal incident response procedures.
- 72-hour breach notification commitment to Controllers (this DPA, §8).
Data minimization
- Only the data fields required for each destination's API are transmitted to that destination.
- Identifier hashing performed per each destination's specification (SHA-256 for Meta, Google, TikTok, Pinterest; passthrough for Klaviyo where their API requires plaintext).
Annex III — Sub-processors
Current list published at https://datacrow.app/subprocessors.
This DPA is published in plain English on purpose. If anything in it is unclear, please email privacy@datacrow.app before installing the application.