Data Processing Agreement — Kustomly: Product Personalizer
1. Parties and scope
This Data Processing Agreement ("DPA") applies between Sellerportals, 51 Monash St, Sunshine VIC 3020, Australia ("we", "us", the "Processor") and the merchant operating the Shopify store on which the Kustomly: Product Personalizer app (the "App") is installed ("you", the "Controller").
It takes effect when you install the App, forms part of the terms on which the App is supplied, and continues while we process personal data for you. It satisfies Shopify's requirement that app developers enter into a data protection agreement with the merchants they serve. Accepting it requires no signature.
"Data Protection Laws" means the laws applicable to our processing, including the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss FADP, the California Consumer Privacy Act as amended ("CCPA"), and the Privacy Act 1988 (Cth). "Customer Data" means personal data about your customers that we process for you through the App, described in Annex A. Other defined terms carry the meaning given in the EU GDPR.
If this DPA conflicts with our other terms, this DPA wins on data protection. The Standard Contractual Clauses in section 11 win over both.
2. Roles
You are the controller of Customer Data and decide why and how it is processed. We are your processor and process it only for you.
Shopify is not our sub-processor — it is your own processor, and the source and destination of the data the App handles. Your relationship with Shopify is governed by your agreement with Shopify, not by this DPA.
Where we use your staff's contact details to provide support or send service notices, we act as a controller for that limited purpose, under our Privacy Policy.
3. What we process
Annex A describes the subject matter, purposes, data categories, data subjects and retention periods. In short: we process the minimum needed to run the App, and we never request your customers' surname, address, phone number or payment details from Shopify.
We do not sell or share Customer Data, and do not use it for advertising, profiling, automated decision-making, or to train machine-learning models.
4. Your instructions and your responsibilities
Your instructions to us are this DPA, our terms, and your configuration of the App — which fields you display, whether uploads are held pending an order, whether proof emails are sent, and whether you publish a customer's design.
You are responsible, and you warrant to us, that:
(a) you have a lawful basis for the processing you instruct, and have given your customers every notice and obtained every consent required for it; (b) the personalization questions you configure do not solicit special category data, criminal conviction data, government identifiers, payment card details or data about children — the App is not designed for those categories and our security measures are not calibrated to them; (c) you will respond to your own customers' privacy requests, and to any regulator, as the controller; and (d) your use of the App complies with applicable law and with Shopify's rules.
We will tell you if we think an instruction breaks Data Protection Laws, and may pause the affected processing until you confirm, change or withdraw it.
5. Our commitments
We will:
- process Customer Data only on your documented instructions, including as to international transfers, unless a law requires otherwise — in which case we will tell you first, unless that law prohibits it;
- ensure the people who process Customer Data are bound by confidentiality and have access only where their role needs it;
- keep the security measures in Annex B in place, and not reduce the level of security if we update them;
- use sub-processors only on the terms in section 7;
- help you respond to data subject requests, as described in section 8;
- help you with your obligations under Articles 32 to 36 of the EU GDPR (security, breach notification, impact assessments, prior consultation), taking into account the nature of the processing and what we know;
- delete or return Customer Data when we stop providing the App, as described in section 10; and
- give you the information you need to show we comply with Article 28 of the EU GDPR, and allow audits on the terms in section 12.
We keep a record of the processing we carry out for you, as Article 30(2) requires. If a public authority makes a legally binding demand for Customer Data, we will tell you before disclosing anything unless the law forbids it, and will disclose only the minimum the demand reasonably requires.
6. Security and Shopify Protected Customer Data
We apply the technical and organisational measures in Annex B, which take into account the state of the art, the cost, and the risk to the people the data is about.
The App operates under Shopify's Protected Customer Data requirements at Level 2. We access order data and exactly two customer fields — email address and first name — each tied to a feature named in Annex A, and we log every read of protected data by field name, never by value. You can review that log in the App under Settings → Privacy.
We maintain a written incident response policy and a data loss prevention strategy, and will provide either on request.
7. Sub-processors
You give us general authorisation to use sub-processors. Those we use today are listed in Annex C.
We will give you reasonable advance notice before adding or replacing one, by email to your store's registered address or by notice in the App. You may object on reasonable data protection grounds. If we cannot resolve your objection, your remedy is to uninstall the App, which ends the processing.
We impose data protection obligations on each sub-processor that are at least equivalent to ours under this DPA, and we remain responsible to you for their performance of those obligations.
8. Data subject requests
We help you respond to your customers through the App itself, at no charge:
- a
customers/data_requestfrom Shopify makes the App compile a report of what it holds for the orders named, ready for you under Settings → Privacy. The report describes holdings — filenames, dimensions, counts, whether an email address is held — rather than reproducing the data; - a
customers/redactfrom Shopify makes the App erase what it holds for those orders: held upload bytes, published designs, and proof records including the encrypted email address; - you can delete any individual shopper upload or published design yourself, at any time, from the App.
If a customer contacts us directly, we will refer them to you and will not respond substantively without your authorisation.
Where you ask for assistance beyond what the App provides, we will give it, and may charge you our reasonable costs for doing so.
9. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Data, with the information we have at the time, and will follow up as we learn more. We will help you meet your own notification duties — including under Article 33 of the EU GDPR, where your 72-hour clock runs from your awareness, and under Part IIIC of the Privacy Act 1988 (Cth).
We will not notify a regulator or your customers on your behalf unless you ask us to. Notifying you of a breach is not an admission of fault or liability.
10. Deletion
When we stop providing the App, we delete or return Customer Data at your choice and delete our copies, unless a law requires us to keep them.
In practice this happens by itself. Uninstalling clears your sessions
immediately. Shopify sends a shop/redact 48 hours after an uninstall that is
not reversed, and on receiving it the App erases all of your store's data. You
can also ask us in writing.
Between uninstall and shop/redact we keep your own configuration — settings,
profiles, onboarding progress — so a reinstall restores your setup. Data in
encrypted backups is deleted on the backup cycle in Annex B.
11. International transfers
We are in Australia, and process data in the countries listed in Annex C.
11.1 EU transfers. Where your transfer of Customer Data to us is a restricted transfer under the EU GDPR, the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914 (the "SCCs") are incorporated into this DPA and completed as follows:
| SCC provision | Election |
|---|---|
| Module | Module Two (controller to processor). Module Three where you are yourself a processor |
| Clause 7 (docking) | Applies |
| Clause 9 (sub-processors) | Option 2, general written authorisation, with the notice period in section 7 |
| Clause 11 (independent dispute body) | Does not apply |
| Clause 17 (governing law) | Option 2 — the law of the exporter's Member State; failing that, Ireland |
| Clause 18(b) (forum) | The courts of Ireland, or of the Member State whose law governs |
| Annexes I, II, III to the SCCs | Populated by Annexes A, B and C to this DPA |
The parties are treated as having signed the SCCs when this DPA takes effect.
11.2 UK transfers. The ICO's International Data Transfer Addendum (version B1.0) is incorporated. Table 1 is populated by Annex A; Tables 2 and 3 by section 11.1 and Annexes A to C. In Table 4, the exporter may end the Addendum if the Approved Addendum changes.
11.3 Swiss transfers. The SCCs apply with the FDPIC as supervisory authority, references to the GDPR read as references to the FADP where the FADP applies, and without preventing a data subject in Switzerland from suing in Switzerland.
11.4 If a transfer mechanism is amended or invalidated, we will work with you in good faith to put an alternative in place without undue delay.
11.5 Supervisory authority. For the SCCs, the competent authority is that of the Member State where you are established; where you are not established in the EU but fall within Article 3(2), that of the Member State where your Article 27 representative is. For the UK, the ICO. For Switzerland, the FDPIC.
12. Audits
We will give you what you need to verify our compliance: this DPA, our Privacy Policy, our incident response policy, our data loss prevention strategy, the access log in the App, and written answers to your questions.
If that is genuinely not enough, you or an independent auditor we accept may inspect: on at least 30 days' written notice, during business hours, no more than once in any 12 months unless a regulator requires it or a breach has affected you, under confidentiality, and without disrupting our operations or exposing another merchant's data. You bear your own costs and our reasonable costs of assisting.
13. Liability
- 13.1 We provide the App as is. We do not warrant that it will be uninterrupted or error-free, and we give no service level commitment, except as Data Protection Laws or non-excludable consumer guarantees require.
- 13.2 Our total aggregate liability arising out of or in connection with this DPA, whether in contract, tort (including negligence), statute or otherwise, is limited to the greater of the fees you paid us for the App in the 12 months before the event giving rise to the claim, and AUD 500.
- 13.3 Neither party is liable for indirect or consequential loss, lost profits, lost revenue, lost goodwill, or loss or corruption of data, however caused.
- 13.4 You indemnify us against claims, fines, losses and reasonable legal costs arising from: your instructions; the content of the personalization questions you configure; your failure to give your customers the notices or obtain the consents required by section 4; your publication of a customer's design; or your breach of this DPA or of Data Protection Laws.
- 13.5 Nothing in this DPA limits liability that cannot lawfully be limited, including: rights a data subject has as a third-party beneficiary under the SCCs; liability under the Australian Consumer Law where the consumer guarantees cannot be excluded (in which case our liability is limited, where permitted, to resupplying the App or paying the cost of resupply); and liability for fraud, death or personal injury caused by negligence.
- 13.6 section 13.2 does not limit our responsibility under section 7 for our sub-processors' performance.
14. General
- 14.1 Governing law. Victoria, Australia, and its courts have non-exclusive jurisdiction. This does not displace the law and forum governing the SCCs under section 11.1, nor any mandatory right of a data subject or regulator to bring proceedings elsewhere.
- 14.2 Contact. Data protection enquiries, audit requests, breach correspondence and referred data subject requests: kustomly@sellerportals.com, or Sellerportals, 51 Monash St, Sunshine VIC 3020, Australia. We contact you at your store's registered email address or in the App.
- 14.3 Changes. We may update this DPA where Data Protection Laws, Shopify's requirements, or the App's processing change. We will give reasonable advance notice of a material change. If you do not accept it, uninstall the App.
- 14.4 Survival and severance. sections 5(7), 9, 10, 12, 13 and 14 survive termination. If any provision is invalid, the rest stands and the provision is read down to the minimum extent needed to make it valid.
- 14.5 No third-party rights, except a data subject's third-party beneficiary rights under the SCCs and anything Data Protection Laws require.
Annex A — The processing
Parties. Exporter/Controller: the merchant operating the Shopify store, identified by the store's Shopify account details, at the address and email registered with Shopify; activity — running a Shopify store selling personalized products. Importer/Processor: Sellerportals, 51 Monash St, Sunshine VIC 3020, Australia, kustomly@sellerportals.com; activity — supplying and operating the App.
Subject matter. Product personalization functionality on your Shopify storefront and admin.
Duration. While the App is installed, plus the retention periods below.
Nature. Collection, recording, storage, retrieval, transmission, display, erasure and destruction, by automated means. Frequency: continuous.
Purposes. Rendering personalization fields to shoppers; capturing their answers onto your Shopify orders; receiving shopper-uploaded images and delivering them to your Shopify Files (holding them temporarily where you enable that setting); showing you which personalized items to make; producing PII-free order summary rows for your analytics; sending proof-approval emails and recording responses where you enable them; publishing a customer's design where you enable it and the shopper opted in; authenticating your staff; and providing you support.
Data subjects. Your customers and store visitors who complete a personalization field, upload an image, or receive a proof email; and your own staff who use the App.
Categories of data.
| Category | Processed | Stored by us |
|---|---|---|
| Personalization answers — may contain names, dates, messages | Yes | Only inside a proof record or a published design; otherwise they live on your Shopify order |
| Shopper-uploaded images — may show identifiable people | Yes | In your own Shopify Files. Where you enable "only keep uploads from completed orders", we hold the bytes until an order claims them |
| Order data — line items, properties, totals, fulfilment status | Read live | No copy of the order. One PII-free summary row: counts, totals, field names, no customer identifier |
| Customer email address | Only where proof approval is on | Yes — encrypted, inside the proof record |
| Customer first name | Only where proof approval is on | Yes — inside the proof record |
| Surname, address, phone, payment details | No | No |
| Staff session identifiers and Shopify access tokens | Yes | Yes — encrypted |
Special categories. None requested; you undertake in section 4(b) not to solicit them. We cannot inspect what a shopper types into a free-text field or what an uploaded image shows; anything volunteered is processed only as incidental content, protected by Annex B, and erased on the schedule below.
Retention. Enforced by automated erasure in the App, not by policy alone.
| Data | Kept for |
|---|---|
| Order summary rows | The period you set — 24 months by default, configurable 1–120 months under Settings → Privacy |
| Proof records, including the encrypted email address and first name | The same period as order summaries. The approval link stops working after 60 days |
| Shopper images held pending an order | Until an order claims them, or your configured period (14 days by default) passes |
| Images transferred to your Shopify Files | Yours — delete them any time from the App |
| Published customer designs | Until you remove them, or a redaction request arrives |
| Protected-data access log | 12 months, fixed |
| Sessions | Cleared on uninstall |
On customers/redact we erase everything held for the orders named. On
shop/redact we erase all of your store's data.
Annex B — Security measures
In force at the effective date; may be updated without reducing the level of security.
Minimisation. Orders are read live, never copied — what we store per order is one row of counts, totals and field names with no customer identifier. Surname, address, phone and payment details are never requested from Shopify. The access log records field names, never values. Data-request reports describe holdings rather than duplicating them.
Encryption. HTTPS/TLS on all connections, including to the database. The database, including the bucket holding shopper images, is stored on encrypted block storage. Backups are encrypted on the server before upload, under a key the server itself does not hold. Shopify access tokens and proof email addresses are additionally encrypted with AES-256-GCM before being written, under a key held only in the application environment.
Confidentiality and integrity. Every collection is scoped to a single store, so one store's data cannot be returned by a query for another's. Shopify webhooks are HMAC-verified, App Proxy requests are signature-verified, and admin API calls carry a verified session token. Shopper-facing errors are sanitised. Proof pages and held upload bytes are reachable only by unguessable, expiring token on your own domain. Secrets live in the deployment environment, never in source control.
Availability and recovery. Automated encrypted backups held off the server. Key rotation and backup restoration are planned together, since a backup restored after a key rotation would contain unreadable sessions and proof email addresses; and any restore is followed by re-applying every redaction request received since that backup was taken.
Access control. The server, the database and the provider consoles are administered by a single named operator and by no one else. Server access is by SSH key only; password authentication is not used. Two-factor authentication is enabled on every provider account that holds customer data.
Auditability. Every read of protected customer data is logged with the surface, purpose, field names, time and responsible session, and is visible to you in the App. A failure to write a log entry is raised as an explicit error.
Separation. Development and production use separate databases and separate file storage. The App checks its environment against the database name at connection time and refuses to start on a mismatch. There is no analytics pipeline, no error reporter carrying request bodies, and no bulk export; the only outbound path carrying customer personal data is the proof email in Annex C.
Testing. The incident response policy and the data loss prevention strategy are each reviewed at least annually, and whenever the App begins processing a new category of personal data.
Sub-processors are bound by written terms at least equivalent to this Annex.
Annex C — Sub-processors
| Sub-processor | Purpose | Data it can access | Location |
|---|---|---|---|
| DigitalOcean, LLC | Application hosting and compute, and the encrypted block storage on which our database runs | Configuration; images held pending an order; encrypted proof email addresses; proof names and answers; published designs | New York, United States (NYC region) |
| Resend, Inc. | Proof-approval email delivery | The customer's email address and the proof message, at the moment of sending | United States |
Resend receives an email address only where you have enabled proof approval, and only for that message. If you never enable it, no customer email address is collected, so none can be transferred. Shopify is not our sub-processor — see section 2.