Data Processing Addendum
GDPR / UK GDPR style addendum for Shopify merchants. Last updated: August 1, 2026.
1. Parties & roles
Merchant (“Controller”) installs Reverse Bundle Pro (“Processor”) on Shopify. Shopify remains a separate independent controller/processor under Shopify’s terms. This DPA applies to personal data the App processes on the Merchant’s behalf inside the App infrastructure.
2. Subject matter & duration
Processing is limited to providing pack-rule matching, Order Edit / tagging, analytics, billing enforcement, optional notifications, and Shopify GDPR webhook compliance. Duration equals the installation period plus short retention for security/audit as described in the Privacy Policy.
3. Nature & purpose
Automated processing of order and catalog identifiers to convert kit lines to a warehouse pack SKU; logging conversion outcomes; optional email/Slack alerts configured by Merchant.
4. Types of data & data subjects
- Shop staff / account contacts (email if provided)
- Order IDs, line-item SKUs/variant IDs, quantities, tags, conversion status
- Customer PII only insofar as Shopify includes it in Admin API payloads we must process for Order Edit (we do not market to end customers)
5. Processor obligations
- Process only on documented instructions (install + in-app settings + Shopify APIs)
- Confidentiality for personnel with access
- Appropriate technical and organizational measures (HTTPS, access control, secrets)
- Assist with GDPR webhooks Shopify requires of apps
- Delete or return App merchant data on uninstall / shop redact, subject to legal holds
6. Subprocessors
Merchant authorizes the subprocessors listed at /subprocessors. Material changes will be reflected on that page.
7. International transfers
Infrastructure may process data outside the Merchant’s country. Where required, safeguards rely on provider contractual terms and Shopify’s platform.
8. Security incidents
We will notify Merchant without undue delay after becoming aware of a personal-data breach affecting App-processed data, with facts then known and mitigation steps.
9. Audits
Upon reasonable written request (max once per 12 months), we provide security summary information appropriate to an App Store SaaS. On-site audits are not offered; SOC reports of subprocessors may be shared when available under their NDAs.