Data Processing Agreement
Checkout King · Version 1.0 · Effective 25 August 2026
1. Who is who
You, the merchant, are the controller. You decide what rules run at your checkout, and therefore what personal data is processed.
We, Checkout King, are the processor. We process personal data only to provide the app and only on your instructions. Installing the app, configuring rules, and using its features are your instructions.
2. What we process
Data subjects: your customers and visitors who reach checkout.
- Email address — we read only the part after the
@, so rules can be written about a domain - Shipping address — country, province or state, postcode, street lines
- Order and cart contents: totals, line items, quantities, weights, products
- Whether the buyer is a guest, has an account, or is a business, and their previous order count and total spend where Shopify provides them
We do not process customer names or phone numbers. Neither is requested anywhere in the app.
No special category data is processed — nothing concerning health, race, religion, political opinion, trade union membership, sex life, sexual orientation, genetics or biometrics.
3. What we do with it
Two purposes, and no others:
- Running your rules. Evaluating the conditions you configured. This happens on Shopify's infrastructure — no request reaches our servers during a customer's checkout.
- Counting matches. After an order is placed, recomputing which of your rules matched, so you can see how often each applies.
We will not process personal data for any other purpose, and will not use it for our own purposes, unless you instruct us in writing.
4. What we keep
| Order data | Not retained. Read to count rule matches, then deleted. A scheduled job deletes anything missed within seven days. |
|---|---|
| Rule match counts | A count per rule per day, with no identifier. Not personal data. Kept while the app is installed. |
| Your account and rules | Deleted when you uninstall. |
| Erasure records | Shopify's pseudonymous customer reference only, retained as proof we honoured the request. |
On termination we delete personal data within 30 days, except where the law requires retention, and except the erasure records above — which exist to prove a deletion happened and would be self-defeating to delete.
5. Security
- Encryption in transit, at rest, and for backups
- Signature verification of every request received from Shopify
- Automatic redaction of tokens, email addresses, phone numbers and addresses from application logs
- Production access restricted to authorised personnel with two-factor authentication
- An access log covering reads of protected customer data
- A documented incident response policy and data loss prevention strategy, available on request
6. Sub-processors
| Render | Hosting, database, queue — United States |
|---|---|
| Resend | Delivering support messages you send us — United States |
We remain responsible for their performance. We will give you notice before adding or replacing a sub-processor, and you may object on reasonable data protection grounds — in which case you may terminate rather than accept the change.
Shopify is not a sub-processor. It is the source of the data and your own processor under your agreement with them.
7. International transfers
Data is processed in the United States. Where personal data originates in the EEA, the UK or Switzerland, transfers rely on the European Commission's Standard Contractual Clauses, incorporated by reference, with the UK Addendum where applicable.
8. Helping you meet your obligations
- Data subject requests. Shopify sends us the required requests for customer data access, customer deletion and store deletion, and we act on all three. Because the only customer-derived data we retain is an untraceable daily count, there is usually nothing to return or erase for an individual — we confirm that rather than claiming to have searched.
- Breach notification. We will tell you without undue delay after becoming aware of a personal data breach, with what we know at the time rather than waiting until we know everything.
- Assessments and audits. We will help with data protection impact assessments, and make available the information needed to demonstrate compliance. Audits on reasonable notice, no more than once a year unless a regulator or an incident requires otherwise.
9. Confidentiality
Anyone we authorise to process personal data is bound by confidentiality obligations.
10. Liability
Each party's liability under this agreement is subject to the limitations in our terms of service.