Data processing agreement
Last updated: October 10, 2026
This Data Processing Agreement ("DPA") is part of the agreement between Proofbolt LLC ("Processor", "we") and the merchant who installs ProofBolt Studios on a Shopify store ("Merchant", "Controller"). It covers the personal data of the Merchant's customers that the app processes. Installing or using the app means accepting this DPA. To get a signed copy, email admin@proofbolt.com.
1. Scope and roles
- The Merchant is the controller of its customers' personal data. Proofbolt LLC is a processor and processes it only to provide the app.
- Subject matter: providing custom-patch designers, production files and reorders for the Merchant's store.
- Duration: while the app is installed, plus the deletion period in section 7.
- Data subjects: the Merchant's customers and storefront visitors who use the designers.
- Personal data: Shopify customer id; order ids and line details; uploaded artwork and designs; a one-way hash of a guest's email; name and email read from Shopify only when needed (not stored); name, email and addresses in Shopify's order notifications (received but not stored). No special category data, payment data or phone numbers.
2. Instructions
- We process personal data only on the Merchant's documented instructions. Those are: this DPA, the app's settings and features as the Merchant uses them, and Shopify's privacy requests.
- We never use the data for our own purposes, for marketing or advertising, or sell or share it. If we think an instruction breaks the law, we tell the Merchant.
3. Confidentiality
Anyone at Proofbolt LLC who can access personal data is bound by confidentiality and gets access only when their work needs it.
4. Security
We keep appropriate technical and organizational measures, including:
- Encryption in transit (TLS only) and at rest: DynamoDB with AWS KMS, S3 with AES-256, backups encrypted the same way. Shopify access tokens are additionally encrypted by the app with AES-256-GCM.
- Least-privilege access: the app's server role can only reach its own tables, storage bucket and secrets. No public access to storage; no bulk export tools.
- Per-store separation of data.
- Logging of access to personal data, at the app level and through AWS CloudTrail data events.
- Staff accounts with strong unique passwords and multi-factor authentication.
- Point-in-time recovery (35 days) for databases and file versioning for storage.
- A written security incident response plan.
5. Subprocessors
- The Merchant authorizes these subprocessors: Shopify (platform) and Amazon Web Services, Inc. (hosting and storage, United States).
- We'll give at least 30 days' notice in the app or by email before adding or replacing a subprocessor. The Merchant can object, and can stop using the app if we can't resolve the objection.
- Our subprocessors have to follow data protection terms at least as protective as these.
6. Data subject requests and help
We handle Shopify's privacy webhooks automatically:
- customers/data_request: we export everything the app holds about that customer to the Merchant.
- customers/redact: we delete that customer's data.
We also help with any other request from a data subject, and with the Merchant's data protection impact assessments and regulator questions where they involve the app.
7. Deletion and return
After the Merchant uninstalls the app, Shopify sends shop/redact (48 hours later) and we delete the store's data. Backups expire within 35 days after that. The Merchant can ask for an export before uninstalling.
8. Personal data breaches
We notify the Merchant without undue delay, and within 72 hours of becoming aware of a breach affecting its data. We include what we know: what happened, the data and people affected, likely consequences, and the steps taken. We update the Merchant as we learn more.
9. Audits
We provide the information needed to show we follow this DPA, and answer reasonable security questionnaires once a year (or after a breach).
10. International transfers
Data is stored in the United States. Where the law requires it for transfers from the EU, UK or Switzerland, the European Commission's Standard Contractual Clauses (Module 2, controller to processor) and the UK Addendum apply and are incorporated by reference.
11. Order of precedence
If this DPA conflicts with our Terms about personal data, this DPA wins. Our Privacy policy describes the same practices for everyone.