Legal

Data Processing Agreement

Auftragsverarbeitungsvertrag (AVV) — Effective Date: September 26, 2026

This Data Processing Agreement ("DPA"; German: Auftragsverarbeitungsvertrag, "AVV") forms part of the agreement between the merchant using our app (the "Controller") and 2690292 Ontario Inc., operating as Dash Checkout / DC Order Limits (the "Processor"), for the use of our Shopify apps (the "Service"). It reflects the parties' obligations under Article 28 of the EU General Data Protection Regulation ("GDPR" / DSGVO) and applies to merchants in the European Economic Area, the United Kingdom, and Switzerland.

This DPA is incorporated by reference into our Terms of Service and applies automatically to all merchants using the Service — no signature is required. Merchants who require a countersigned copy for their records may contact data@dashcheckout.io.


1. Parties & Roles

Controller: the merchant operating the Shopify store on which the Service is installed.

Processor: 2690292 Ontario Inc. (operating as Dash Checkout, DC Order Limits), 5345 Bullrush Drive, Mississauga, Ontario L5V 1Z2, Canada. Privacy contact: data@dashcheckout.io.


2. Subject Matter, Nature & Purpose of Processing

The Processor processes personal data on the Controller's behalf solely to provide the Service: enforcing merchant-configured purchase limits, order limits, and related storefront features on the Controller's Shopify store, and providing related merchant support.

Purpose limitation: the Processor does not use personal data processed on the Controller's behalf, including store customer data and the in-transit API data described in Section 3, to train artificial intelligence or machine learning models, and does not sell it. The Processor does not process this data for advertising, for its own marketing, or for any other purpose of its own beyond providing, securing, and supporting the Service, except where required by applicable law. Automated evaluation of a customer's order history occurs only to enforce the limits the Controller has configured.

Duration: processing continues for as long as the Service is installed on the Controller's store, plus the deletion period described in Section 8.


3. Categories of Data Subjects & Personal Data

Data subjects: the Controller's store customers, and the Controller's own staff/users.

Personal data processed on the Controller's behalf:

Shopify API access: to provide the Service, the app is granted read access to customer and order records through Shopify's authorized APIs, under the access scopes the Controller approves at installation (including read_customers and read_orders). These records can technically include customer names, email addresses, and order details as exposed by Shopify's API. The Service processes this data transiently in application memory, solely to evaluate the limits the Controller has configured. Apart from transiting our hosting infrastructure listed in Section 5, this data is not written to our database and is not intentionally sent to analytics or monitoring tools or to any other subprocessor. Error monitoring may incidentally capture fragments of a failing request; we configure these tools to minimize such capture, and any captured fragments are covered by the safeguards in Sections 5 and 10. The only value retained is the pseudonymous Shopify customer ID.

The Service is not designed or intended to process special categories of personal data (Art. 9 GDPR), and the Processor does not knowingly process such data. The Controller must not configure the Service in a way that requires processing of special category data.


4. Processor Obligations

The Processor shall:


5. Subprocessors

The Controller grants a general authorization for the Processor to engage the subprocessors listed below. The Processor imposes data protection obligations on each subprocessor that provide a level of protection substantially equivalent to this DPA, and remains responsible to the Controller for the performance of each subprocessor's data protection obligations. The Processor will update this page a reasonable period, normally at least 30 days, before adding or replacing a subprocessor that processes store customer data; Controllers may request email notification of subprocessor changes by writing to data@dashcheckout.io. The Controller may object on reasonable data protection grounds within that period, and may terminate the Service if the objection cannot be resolved.

What subprocessors receive: data passed to our subprocessors is limited to shop-level and merchant-level data: the shop domain and shop identifiers, session and technical identifiers, merchant staff names and email addresses, and technical telemetry (errors, performance metrics, admin usage events). Our hosting and database providers additionally process the pseudonymous Shopify customer IDs we store and the in-transit API data described in Section 3, as they run our infrastructure. Store customer personal data (names, email addresses, physical addresses, payment details) is not stored by us and is not intentionally sent to any monitoring, analytics, email, or support subprocessor. Two limited exceptions can occur: error monitoring may incidentally capture data present in a failing request, and support correspondence will contain customer details if the Controller includes them in a message to us.

SubprocessorPurposeLocationData involved
Heroku (Salesforce, Inc.)Application hostingUnited StatesPseudonymous customer IDs; shop domain; in-transit checkout data
Crunchy Data Solutions, Inc.Managed PostgreSQL databaseUnited StatesPseudonymous customer IDs; shop domain; limit records
Rollbar, Inc.Error monitoringUnited StatesShop domain and technical error context; error payloads may incidentally include pseudonymous IDs or fragments of a failing request
Scout APM (Scout Server Monitoring, Inc.)Application performance monitoringUnited StatesTechnical performance metrics; no stored customer data
Functional Software, Inc. (Sentry)Frontend error monitoring (merchant admin UI)United StatesShop domain, merchant email, and technical error context; no store customer data
PostHog, Inc.Product usage analytics (merchant admin UI)United StatesShop domain, merchant staff name/email, and merchant admin usage events; no store customer data
Twilio SendGridTransactional email deliveryUnited StatesMerchant email addresses and email content
Help Scout, Inc.Merchant support helpdeskUnited StatesMerchant contact details and support correspondence

Shopify Inc. is not a subprocessor of ours; Shopify processes store data under the Controller's direct agreement with Shopify. Google Analytics is used on our marketing website only and never receives store customer data.


6. Data Subject Rights

Taking into account the nature of the processing, the Processor will assist the Controller with appropriate technical and organizational measures in fulfilling requests under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection). Because we store only pseudonymous customer IDs, most requests can be fulfilled by the Controller directly in Shopify; where deletion of our limit records is required, we action it on request and via Shopify's mandatory GDPR webhooks.


7. Personal Data Breach Notification

The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's personal data, and will provide reasonable information and cooperation so the Controller can meet its obligations under Articles 33 and 34 GDPR.


8. Deletion & Return of Data

Upon uninstallation of the Service, all stored data for the Controller's store — including all pseudonymous customer IDs — is deleted automatically via Shopify's mandatory GDPR webhooks, generally within 48 hours. Earlier deletion may be requested at any time at data@dashcheckout.io. Given the pseudonymous nature of the stored data, return of data prior to deletion is available on request in a structured, commonly used format. Residual copies may persist in encrypted database backups for a limited period until those backups expire in the ordinary rotation cycle; backups are not used for any other purpose.


9. Technical & Organizational Measures (Art. 32 GDPR)


10. International Transfers

The Processor is located in Canada. The EU Commission has issued a partial adequacy decision for Canada covering personal data handled by commercial organizations subject to Canada's federal private sector privacy law (PIPEDA). The Processor handles personal data in the course of commercial activities within the scope of PIPEDA.

Subprocessors listed in Section 5 are located in the United States; for transfers to them we rely on the EU-U.S. Data Privacy Framework where the subprocessor maintains an active certification, and otherwise on the EU Standard Contractual Clauses as included in that subprocessor's data processing terms, supported in each case by the data minimization and pseudonymization described above. Information about the mechanism applicable to a specific subprocessor is available on request.

Where the UK GDPR or Swiss data protection law applies, the UK Addendum to the Standard Contractual Clauses or the Swiss amendments apply as required, and references in this DPA to the GDPR include the UK GDPR and the Swiss Federal Act on Data Protection.


11. Audit & Information Rights

On written request (no more than once per year, unless required by a supervisory authority or following a personal data breach), the Processor will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of relevant subprocessor certifications. Where this is insufficient, the Controller may conduct or mandate an audit at its own expense, with reasonable prior notice and without disrupting the Processor's operations or compromising other merchants' data.


12. General


13. Contact

Questions about this DPA, requests for a countersigned copy, or subprocessor objections: data@dashcheckout.io. See also our Privacy Policy.

Install on Shopify