Data processing addendum

Effective July 19, 2026

This Data Processing Addendum (“DPA”) supplements the StackLens Terms of Service when StackLens processes personal data on behalf of a Shopify merchant (“Merchant”).

Roles and instructions

To the extent store data is personal data, Merchant is the controller and StackLens is the processor. StackLens processes that data only to provide, secure, support, and maintain the service under the Merchant's documented instructions in the Terms, app settings, and support requests. StackLens acts as a controller for limited account, billing, security, and business-administration data where applicable.

Processing details

Subject matter
Read-only discount configuration monitoring.
Duration
For the installation term and the bounded retention periods in the Privacy Policy.
Purpose
Normalize discount configuration, generate findings and history, authenticate the store, enforce plan access, and operate the service.
Data subjects
Store administrators or staff whose limited account actions appear in operational records; StackLens does not request customer records.
Data types
Shop identifiers and timezone, Shopify sessions, merchant-visible discount titles and configuration snapshots, plan state, settings, scans, findings, and bounded logs.

Confidentiality and security

Personnel and contractors authorized to process Merchant data are bound by confidentiality obligations. StackLens maintains controls appropriate to the limited processing, including encrypted transport, tenant-scoped database access, server-only secrets, authenticated Shopify sessions, restricted logs, and tested deletion workflows.

Subprocessors

Merchant authorizes Shopify (platform, authentication, APIs, and App Pricing), Vercel (hosting and scheduled functions), Neon (managed PostgreSQL), and Google (support email) as subprocessors. StackLens remains responsible for subprocessors' performance of their data-protection obligations to the extent required by applicable law. Material subprocessor changes will be disclosed through an updated DPA or in-app notice when appropriate.

Requests and assistance

Taking into account the nature of processing, StackLens will reasonably assist Merchant with data-subject requests, security obligations, and regulator inquiries. StackLens does not hold Shopify customer records, so customer access and redaction requests ordinarily return no data. Merchant should email cadosy@gmail.com and avoid attaching access tokens or raw exports.

Incident notice

StackLens will notify affected Merchants without undue delay after becoming aware of a confirmed personal-data breach involving Merchant data, and will provide available information reasonably needed for the Merchant's response obligations.

Deletion and return

Upon uninstall or a verified Shopify shop-redaction request, StackLens deletes shop settings, sessions, tokens, snapshots, findings, exports, entitlements, schedules, and shop-keyed operational records. Normal plan retention is described in the Privacy Policy. StackLens does not retain a shop-identifying tombstone after completed erasure.

International transfers and audit information

Where required, StackLens and its subprocessors rely on valid transfer mechanisms provided by applicable law and provider contracts. On reasonable written request, StackLens will provide information needed to demonstrate compliance with this DPA, subject to confidentiality, security, and proportionality limits.

Priority and contact

If this DPA conflicts with the Terms on processing personal data, this DPA controls. All other Terms remain in effect. Contact cadosy@gmail.com for a DPA question.