ProofBolt StudiosProofBolt Studios

Data processing agreement

Last updated: October 10, 2026

This Data Processing Agreement ("DPA") is part of the agreement between Proofbolt LLC ("Processor", "we") and the merchant who installs ProofBolt Studios on a Shopify store ("Merchant", "Controller"). It covers the personal data of the Merchant's customers that the app processes. Installing or using the app means accepting this DPA. To get a signed copy, email admin@proofbolt.com.

1. Scope and roles

  1. The Merchant is the controller of its customers' personal data. Proofbolt LLC is a processor and processes it only to provide the app.
  2. Subject matter: providing custom-patch designers, production files and reorders for the Merchant's store.
  3. Duration: while the app is installed, plus the deletion period in section 7.
  4. Data subjects: the Merchant's customers and storefront visitors who use the designers.
  5. Personal data: Shopify customer id; order ids and line details; uploaded artwork and designs; a one-way hash of a guest's email; name and email read from Shopify only when needed (not stored); name, email and addresses in Shopify's order notifications (received but not stored). No special category data, payment data or phone numbers.

2. Instructions

  1. We process personal data only on the Merchant's documented instructions. Those are: this DPA, the app's settings and features as the Merchant uses them, and Shopify's privacy requests.
  2. We never use the data for our own purposes, for marketing or advertising, or sell or share it. If we think an instruction breaks the law, we tell the Merchant.

3. Confidentiality

Anyone at Proofbolt LLC who can access personal data is bound by confidentiality and gets access only when their work needs it.

4. Security

We keep appropriate technical and organizational measures, including:

5. Subprocessors

  1. The Merchant authorizes these subprocessors: Shopify (platform) and Amazon Web Services, Inc. (hosting and storage, United States).
  2. We'll give at least 30 days' notice in the app or by email before adding or replacing a subprocessor. The Merchant can object, and can stop using the app if we can't resolve the objection.
  3. Our subprocessors have to follow data protection terms at least as protective as these.

6. Data subject requests and help

We handle Shopify's privacy webhooks automatically:

We also help with any other request from a data subject, and with the Merchant's data protection impact assessments and regulator questions where they involve the app.

7. Deletion and return

After the Merchant uninstalls the app, Shopify sends shop/redact (48 hours later) and we delete the store's data. Backups expire within 35 days after that. The Merchant can ask for an export before uninstalling.

8. Personal data breaches

We notify the Merchant without undue delay, and within 72 hours of becoming aware of a breach affecting its data. We include what we know: what happened, the data and people affected, likely consequences, and the steps taken. We update the Merchant as we learn more.

9. Audits

We provide the information needed to show we follow this DPA, and answer reasonable security questionnaires once a year (or after a breach).

10. International transfers

Data is stored in the United States. Where the law requires it for transfers from the EU, UK or Switzerland, the European Commission's Standard Contractual Clauses (Module 2, controller to processor) and the UK Addendum apply and are incorporated by reference.

11. Order of precedence

If this DPA conflicts with our Terms about personal data, this DPA wins. Our Privacy policy describes the same practices for everyone.