Version: August 3, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between the Shopify merchant using Amamrefie Customer Portal & Loyalty ("Merchant") and Peter Nuako, operating as Amamrefie ("Provider"). It applies when Provider processes personal data on Merchant's behalf through the App.
1. Instructions and Purpose
Merchant instructs Provider to process personal data only as necessary to provide, secure, support, and improve the merchant-configured customer-account functions described in the Privacy Policy and the App. Provider will not sell personal data or process it for unrelated advertising.
2. Data and Individuals
Processing may concern the Merchant's Shopify customers and authorized merchant users. Data may include customer identity and contact details, addresses, order and fulfillment information, account preferences, return information, support communications, merchant configuration, and limited security records.
3. Duration and Retention
Processing continues while the App is installed and for the limited period needed to complete deletion, security, legal, or support obligations. Customer and order information displayed by the portal is read from Shopify on demand and is not permanently copied into the App database. Customer-linked operational records, if created, are retained no longer than 30 days unless required to complete an open request or comply with law. Shopify sessions are deleted on uninstall, and remaining shop data is deleted following Shopify's shop-redaction webhook.
4. Confidentiality and Security
Provider will limit personal-data access to persons and service providers who need it to perform the services and who are subject to appropriate confidentiality duties. Provider will maintain reasonable technical and organizational safeguards, including encryption in transit and at rest, access controls, managed secret storage, authenticated webhooks, and security monitoring.
5. Subprocessors
Merchant authorizes Shopify and Google Cloud as subprocessors for the functions described in the Privacy Policy. Provider remains responsible for selecting service providers that offer appropriate data-protection commitments. Provider will update the Privacy Policy before adding a materially different subprocessor that processes merchant customer data.
6. Customer Rights and Consent
Provider will reasonably assist Merchant with verified requests for access, correction, deletion, restriction, portability, consent withdrawal, and data-sale opt-out. Provider receives Shopify's mandatory privacy webhooks and will complete required action within 30 days. Provider does not sell personal data and does not perform automated decision-making with legal or similarly significant effects.
7. Incidents
Provider will notify affected Merchants without undue delay after confirming a personal-data breach affecting their data, provide information reasonably available about the incident, take reasonable containment and remediation measures, and cooperate with legally required notifications.
8. Deletion and Return
On termination or a valid deletion instruction, Provider will delete personal data processed on Merchant's behalf unless retention is required by law. Data maintained by Shopify remains subject to the Merchant's Shopify account and Shopify's terms.
9. International Transfers
Merchant authorizes processing in the United States and other locations used by Shopify, Google Cloud, and their subprocessors, subject to legally required transfer safeguards.
10. Audit and Information
Provider will make information reasonably necessary to demonstrate compliance with this DPA available to Merchant and will reasonably cooperate with a lawful audit request, subject to confidentiality, security, and proportionality limitations.
11. Merchant Responsibilities
Merchant is responsible for providing required notices, establishing a lawful basis for its processing, configuring the App consistently with customer choices, responding to customers, and using the App in compliance with applicable law. Merchant must not instruct Provider to process personal data unlawfully.
12. Conflict and Contact
If this DPA conflicts with general app terms on personal-data processing, this DPA controls. Questions may be sent to info@amamrefie.com.