Data Processing Agreement
This applies whenever a boutique connects its Shopify store to us. The boutique is the controller of its customers’ personal data; we are a processor acting on its instructions. It takes effect on installation and ends when the app is uninstalled.
What we process, and why
Only what is needed to attribute a sale to a shopper we referred and to calculate the commission on it. In practice that is two things from an order:
- The Shopify customer identifier.
- The customer’s email address — which is hashed with SHA-256 the moment it arrives and is never written to storage in readable form. We keep the hash so we can recognise a returning shopper; a hash cannot be turned back into an address, and it lets us do nothing else.
We do not read, receive or store a customer’s name, telephone number or shipping address at any point. Order records retain only the order identifier, its totals, its currency and our own referral reference.
How long we keep it
Referral records are deleted thirty days after they are created, by a job that runs daily. Abandoned baskets have their personal columns cleared after ninety days. Delivery records for messages we have sent are deleted after ninety days. Nothing personal is kept indefinitely.
Security measures
- Encrypted in transit — TLS on every connection, with no unencrypted path.
- Encrypted at rest — database storage and its backups, using managed keys.
- Your Shopify access token is encrypted a second time, in the application, with AES-256-GCM before it is stored — so a copy of the database alone does not give anyone access to your store.
- The database is not reachable from the public internet.
- Access to infrastructure requires multi-factor authentication and is logged.
- Development never runs against production data.
Sub-processors
Amazon Web Services (hosting and database, United States) and Shopify itself. We will tell you before adding another.
Your customers’ rights
We answer Shopify’s customers/data_request, customers/redact and shop/redact webhooks, so a request made through your Shopify admin reaches us automatically and is acted on. Uninstalling erases your store’s data.
If something goes wrong
We will notify you without undue delay, and within 72 hours, of any breach affecting personal data you have entrusted to us — with what happened, what was affected and what we have done about it.
Getting a signed copy
Write to info@nomadleadgen.com and we will countersign this for your records.