Legal
Data Processing Agreement
Auftragsverarbeitungsvertrag (AVV) — Effective Date: September 26, 2026
This Data Processing Agreement ("DPA"; German: Auftragsverarbeitungsvertrag, "AVV") forms part of the agreement between the merchant using our app (the "Controller") and 2690292 Ontario Inc., operating as Dash Checkout / DC Order Limits (the "Processor"), for the use of our Shopify apps (the "Service"). It reflects the parties' obligations under Article 28 of the EU General Data Protection Regulation ("GDPR" / DSGVO) and applies to merchants in the European Economic Area, the United Kingdom, and Switzerland.
This DPA is incorporated by reference into our Terms of Service and applies automatically to all merchants using the Service — no signature is required. Merchants who require a countersigned copy for their records may contact data@dashcheckout.io.
1. Parties & Roles
Controller: the merchant operating the Shopify store on which the Service is installed.
Processor: 2690292 Ontario Inc. (operating as Dash Checkout, DC Order Limits), 5345 Bullrush Drive, Mississauga, Ontario L5V 1Z2, Canada. Privacy contact: data@dashcheckout.io.
2. Subject Matter, Nature & Purpose of Processing
The Processor processes personal data on the Controller's behalf solely to provide the Service: enforcing merchant-configured purchase limits, order limits, and related storefront features on the Controller's Shopify store, and providing related merchant support.
Purpose limitation: the Processor does not use personal data processed on the Controller's behalf, including store customer data and the in-transit API data described in Section 3, to train artificial intelligence or machine learning models, and does not sell it. The Processor does not process this data for advertising, for its own marketing, or for any other purpose of its own beyond providing, securing, and supporting the Service, except where required by applicable law. Automated evaluation of a customer's order history occurs only to enforce the limits the Controller has configured.
Duration: processing continues for as long as the Service is installed on the Controller's store, plus the deletion period described in Section 8.
3. Categories of Data Subjects & Personal Data
Data subjects: the Controller's store customers, and the Controller's own staff/users.
Personal data processed on the Controller's behalf:
- Stored: pseudonymous Shopify customer IDs (numeric identifiers) linked to purchase-limit records. We do not store customer names, email addresses, physical addresses, phone numbers, or payment details.
- Processed in transit only: to enforce limits, the Service has read access to customer and order data through Shopify's authorized APIs (per the access scopes approved at installation). This data is used transiently in memory to evaluate the merchant-configured limits and is not written to our database; only the pseudonymous Shopify customer ID is retained.
- Merchant data: shop domain, locale preferences, and correspondence when the Controller contacts support.
Shopify API access: to provide the Service, the app is granted read access to customer and order records through Shopify's authorized APIs, under the access scopes the Controller approves at installation (including read_customers and read_orders). These records can technically include customer names, email addresses, and order details as exposed by Shopify's API. The Service processes this data transiently in application memory, solely to evaluate the limits the Controller has configured. Apart from transiting our hosting infrastructure listed in Section 5, this data is not written to our database and is not intentionally sent to analytics or monitoring tools or to any other subprocessor. Error monitoring may incidentally capture fragments of a failing request; we configure these tools to minimize such capture, and any captured fragments are covered by the safeguards in Sections 5 and 10. The only value retained is the pseudonymous Shopify customer ID.
The Service is not designed or intended to process special categories of personal data (Art. 9 GDPR), and the Processor does not knowingly process such data. The Controller must not configure the Service in a way that requires processing of special category data.
4. Processor Obligations
The Processor shall:
- process personal data only on the Controller's documented instructions (the Service configuration and this DPA constitute those instructions), unless required otherwise by applicable law;
- ensure persons authorized to process the data are bound by confidentiality obligations;
- implement appropriate technical and organizational measures as described in Section 9 (Art. 32 GDPR);
- respect the subprocessor conditions in Section 5;
- assist the Controller, insofar as reasonably possible, in responding to data subject requests (Section 6) and in meeting the Controller's obligations under Articles 32–36 GDPR;
- delete personal data at the end of the Service as described in Section 8;
- make available the information reasonably necessary to demonstrate compliance (Section 10);
- inform the Controller if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.
5. Subprocessors
The Controller grants a general authorization for the Processor to engage the subprocessors listed below. The Processor imposes data protection obligations on each subprocessor that provide a level of protection substantially equivalent to this DPA, and remains responsible to the Controller for the performance of each subprocessor's data protection obligations. The Processor will update this page a reasonable period, normally at least 30 days, before adding or replacing a subprocessor that processes store customer data; Controllers may request email notification of subprocessor changes by writing to data@dashcheckout.io. The Controller may object on reasonable data protection grounds within that period, and may terminate the Service if the objection cannot be resolved.
What subprocessors receive: data passed to our subprocessors is limited to shop-level and merchant-level data: the shop domain and shop identifiers, session and technical identifiers, merchant staff names and email addresses, and technical telemetry (errors, performance metrics, admin usage events). Our hosting and database providers additionally process the pseudonymous Shopify customer IDs we store and the in-transit API data described in Section 3, as they run our infrastructure. Store customer personal data (names, email addresses, physical addresses, payment details) is not stored by us and is not intentionally sent to any monitoring, analytics, email, or support subprocessor. Two limited exceptions can occur: error monitoring may incidentally capture data present in a failing request, and support correspondence will contain customer details if the Controller includes them in a message to us.
| Subprocessor | Purpose | Location | Data involved |
|---|---|---|---|
| Heroku (Salesforce, Inc.) | Application hosting | United States | Pseudonymous customer IDs; shop domain; in-transit checkout data |
| Crunchy Data Solutions, Inc. | Managed PostgreSQL database | United States | Pseudonymous customer IDs; shop domain; limit records |
| Rollbar, Inc. | Error monitoring | United States | Shop domain and technical error context; error payloads may incidentally include pseudonymous IDs or fragments of a failing request |
| Scout APM (Scout Server Monitoring, Inc.) | Application performance monitoring | United States | Technical performance metrics; no stored customer data |
| Functional Software, Inc. (Sentry) | Frontend error monitoring (merchant admin UI) | United States | Shop domain, merchant email, and technical error context; no store customer data |
| PostHog, Inc. | Product usage analytics (merchant admin UI) | United States | Shop domain, merchant staff name/email, and merchant admin usage events; no store customer data |
| Twilio SendGrid | Transactional email delivery | United States | Merchant email addresses and email content |
| Help Scout, Inc. | Merchant support helpdesk | United States | Merchant contact details and support correspondence |
Shopify Inc. is not a subprocessor of ours; Shopify processes store data under the Controller's direct agreement with Shopify. Google Analytics is used on our marketing website only and never receives store customer data.
6. Data Subject Rights
Taking into account the nature of the processing, the Processor will assist the Controller with appropriate technical and organizational measures in fulfilling requests under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection). Because we store only pseudonymous customer IDs, most requests can be fulfilled by the Controller directly in Shopify; where deletion of our limit records is required, we action it on request and via Shopify's mandatory GDPR webhooks.
7. Personal Data Breach Notification
The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's personal data, and will provide reasonable information and cooperation so the Controller can meet its obligations under Articles 33 and 34 GDPR.
8. Deletion & Return of Data
Upon uninstallation of the Service, all stored data for the Controller's store — including all pseudonymous customer IDs — is deleted automatically via Shopify's mandatory GDPR webhooks, generally within 48 hours. Earlier deletion may be requested at any time at data@dashcheckout.io. Given the pseudonymous nature of the stored data, return of data prior to deletion is available on request in a structured, commonly used format. Residual copies may persist in encrypted database backups for a limited period until those backups expire in the ordinary rotation cycle; backups are not used for any other purpose.
9. Technical & Organizational Measures (Art. 32 GDPR)
- Data minimization by design: only pseudonymous Shopify customer IDs are stored.
- Encryption in transit: all connections use TLS (HTTPS).
- Encryption at rest: databases and backups are encrypted at rest by our hosting providers.
- Access control: production access is limited to authorized personnel with authentication.
- Isolation: data is scoped per shop; access controls are designed so that each merchant can access only its own store's data.
- Telemetry hygiene: error, performance, and analytics tooling is configured to receive shop-level context only; we do not intentionally send store customer personal data to monitoring or analytics subprocessors.
- Automatic deletion: uninstall and GDPR webhooks trigger deletion without manual steps.
- Vendor security: our hosting subprocessors (Heroku, Crunchy Data) publish information about their independent security certifications and audit reports (such as SOC 2); current details are available from those providers.
10. International Transfers
The Processor is located in Canada. The EU Commission has issued a partial adequacy decision for Canada covering personal data handled by commercial organizations subject to Canada's federal private sector privacy law (PIPEDA). The Processor handles personal data in the course of commercial activities within the scope of PIPEDA.
Subprocessors listed in Section 5 are located in the United States; for transfers to them we rely on the EU-U.S. Data Privacy Framework where the subprocessor maintains an active certification, and otherwise on the EU Standard Contractual Clauses as included in that subprocessor's data processing terms, supported in each case by the data minimization and pseudonymization described above. Information about the mechanism applicable to a specific subprocessor is available on request.
Where the UK GDPR or Swiss data protection law applies, the UK Addendum to the Standard Contractual Clauses or the Swiss amendments apply as required, and references in this DPA to the GDPR include the UK GDPR and the Swiss Federal Act on Data Protection.
11. Audit & Information Rights
On written request (no more than once per year, unless required by a supervisory authority or following a personal data breach), the Processor will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of relevant subprocessor certifications. Where this is insufficient, the Controller may conduct or mandate an audit at its own expense, with reasonable prior notice and without disrupting the Processor's operations or compromising other merchants' data.
12. General
- This DPA prevails over conflicting terms of the Terms of Service with respect to the processing of personal data.
- Liability under this DPA is subject to the limitations in the Terms of Service, to the extent permitted by applicable data protection law.
- The Controller is responsible for the lawfulness of the processing it instructs, including having a valid legal basis and providing any notices required to data subjects.
- We may update this DPA to reflect changes in law or in our subprocessors; material changes will be published on this page.
13. Contact
Questions about this DPA, requests for a countersigned copy, or subprocessor objections: data@dashcheckout.io. See also our Privacy Policy.