Data processing addendum
This Data Processing Addendum (“DPA”) supplements the StackLens Terms of Service when StackLens processes personal data on behalf of a Shopify merchant (“Merchant”).
Roles and instructions
To the extent store data is personal data, Merchant is the controller and StackLens is the processor. StackLens processes that data only to provide, secure, support, and maintain the service under the Merchant's documented instructions in the Terms, app settings, and support requests. StackLens acts as a controller for limited account, billing, security, and business-administration data where applicable.
Processing details
- Subject matter
- Read-only discount configuration monitoring.
- Duration
- For the installation term and the bounded retention periods in the Privacy Policy.
- Purpose
- Normalize discount configuration, generate findings and history, authenticate the store, enforce plan access, and operate the service.
- Data subjects
- Store administrators or staff whose limited account actions appear in operational records; StackLens does not request customer records.
- Data types
- Shop identifiers and timezone, Shopify sessions, merchant-visible discount titles and configuration snapshots, plan state, settings, scans, findings, and bounded logs.
Confidentiality and security
Personnel and contractors authorized to process Merchant data are bound by confidentiality obligations. StackLens maintains controls appropriate to the limited processing, including encrypted transport, tenant-scoped database access, server-only secrets, authenticated Shopify sessions, restricted logs, and tested deletion workflows.
Subprocessors
Merchant authorizes Shopify (platform, authentication, APIs, and App Pricing), Vercel (hosting and scheduled functions), Neon (managed PostgreSQL), and Google (support email) as subprocessors. StackLens remains responsible for subprocessors' performance of their data-protection obligations to the extent required by applicable law. Material subprocessor changes will be disclosed through an updated DPA or in-app notice when appropriate.
Requests and assistance
Taking into account the nature of processing, StackLens will reasonably assist Merchant with data-subject requests, security obligations, and regulator inquiries. StackLens does not hold Shopify customer records, so customer access and redaction requests ordinarily return no data. Merchant should email cadosy@gmail.com and avoid attaching access tokens or raw exports.
Incident notice
StackLens will notify affected Merchants without undue delay after becoming aware of a confirmed personal-data breach involving Merchant data, and will provide available information reasonably needed for the Merchant's response obligations.
Deletion and return
Upon uninstall or a verified Shopify shop-redaction request, StackLens deletes shop settings, sessions, tokens, snapshots, findings, exports, entitlements, schedules, and shop-keyed operational records. Normal plan retention is described in the Privacy Policy. StackLens does not retain a shop-identifying tombstone after completed erasure.
International transfers and audit information
Where required, StackLens and its subprocessors rely on valid transfer mechanisms provided by applicable law and provider contracts. On reasonable written request, StackLens will provide information needed to demonstrate compliance with this DPA, subject to confidentiality, security, and proportionality limits.
Priority and contact
If this DPA conflicts with the Terms on processing personal data, this DPA controls. All other Terms remain in effect. Contact cadosy@gmail.com for a DPA question.