Data Processing Agreement
Last updated 2026-08-07
This Data Processing Agreement (“DPA”) forms part of the agreement between Quarter Commerce Labs LTD. (“Quarter”, “we”) and the merchant installing our apps (“you”) and applies whenever we process personal data on your behalf. It takes effect when you install one of our apps; no signature is required. If you need a countersigned copy, email hello@quarter.dev.
Notices. Notices under this DPA are given by email: to you, at the address on your Shopify account; to us, at hello@quarter.dev. We will provide our registered address on request, and to any merchant who needs it for the Standard Contractual Clauses.
1. Roles
You are the controller of personal data relating to your customers. We are a processor acting on your instructions. Shopify is a separate party under its own agreement with you; this DPA does not alter that relationship.
For the anonymous, aggregated usage counters described in our privacy policy, no personal data is involved and this DPA does not apply to them.
2. Scope and instructions
We process personal data only on your documented instructions. Your instructions are: the app’s ordinary operation as described in its documentation and our privacy policy, plus anything else you reasonably direct in writing. The details required by Article 28(3) of the UK and EU GDPR are set out in Annex I.
We will tell you if, in our opinion, an instruction infringes applicable data protection law. We will not process the data for our own purposes, and we will not sell it or share it for advertising.
3. Confidentiality
Everyone we allow to access personal data is bound by confidentiality obligations and gets access only where it is needed to run or support the service.
4. Security
We implement appropriate technical and organisational measures under Article 32, described in Annex II. Both parties acknowledge that the most significant measure is architectural: the app is designed not to collect customer-identifying data at all.
5. Subprocessors
You give general authorisation for the subprocessors listed in Annex III. We impose data protection obligations on each of them no less protective than those in this DPA, and we remain liable to you for their performance.
We will give you at least 30 days’ notice by email before adding or replacing a subprocessor. If you reasonably object on data protection grounds within that period, we will work with you to find a solution; if none is available, you may terminate by uninstalling the app, and we will erase your data as set out in section 9.
6. Assisting you with data subject requests
Taking account of the nature of the processing, we will help you respond to requests from data subjects exercising their rights. In practice this is mostly automatic: Shopify sends us the mandatory customer data request, customer redaction and shop redaction webhooks, and the app acts on all three without anyone intervening.
If a data subject contacts us directly about your store, we will not respond substantively. We will forward the request to you promptly.
7. Personal data breaches
We will notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting your data. The notice will describe what we know: the nature of the breach, the categories and approximate number of records, the likely consequences, and the measures taken or proposed. Where we cannot provide everything at once, we will send it in phases as the picture becomes clear.
8. Impact assessments
We will provide reasonable assistance with data protection impact assessments and any prior consultation with a supervisory authority, to the extent these relate to our processing and you cannot reasonably get the information elsewhere.
9. Deletion and return
On uninstall we delete your session and bundle configuration data. Sales records are erased when Shopify sends the shop redaction request (normally around 48 hours after uninstall) or when they reach the end of the retention period in our privacy policy, whichever comes first. You may request earlier deletion at any time by emailing us. We keep nothing after that except where law requires it, and anonymous aggregates that contain no personal data.
10. Audit
We will make available the information reasonably necessary to demonstrate compliance with this DPA and, on reasonable written notice and no more than once a year, allow an audit by you or an independent auditor you appoint who is not our competitor. Audits are at your cost, must not disrupt the service, and are subject to confidentiality. Where an existing report or questionnaire answers your questions, we may offer that instead.
11. International transfers
We are established in Canada, which the European Commission recognises as providing adequate protection for personal data transferred from the EEA to recipients subject to PIPEDA. Data is stored in the United States (Oregon) by our hosting subprocessor, so adequacy alone does not cover the full chain and the Clauses below do the work for that leg.
Where a transfer of personal data protected by the EU GDPR is not covered by that adequacy decision, the parties adopt the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor), which are incorporated by reference. Annex I to this DPA populates their Annex I, Annex II populates their Annex II, and Annex III lists the authorised subprocessors. The optional docking clause applies; the governing law and forum are those stated in section 13 to the extent the Clauses permit.
For personal data protected by the UK GDPR, the International Data Transfer Addendum issued by the Information Commissioner (version B1.0) is incorporated, with the Clauses above as its Approved EU SCCs. Neither party may end the Addendum under its Section 19.
12. Liability and precedence
Liability under this DPA is subject to the limitations in our main terms. Where this DPA conflicts with those terms, this DPA governs for matters of data protection. Where this DPA conflicts with the Standard Contractual Clauses, the Clauses govern.
13. Term and governing law
This DPA runs for as long as we process personal data on your behalf. It is governed by the laws of British Columbia and the federal laws of Canada applicable there, and the courts of British Columbia have exclusive jurisdiction — except where the Standard Contractual Clauses require otherwise for the transfers they cover.
Annex I — Details of the processing
| Parties | Controller: the merchant installing the app, at the contact details on their Shopify account. Processor: Quarter Commerce Labs LTD., incorporated in British Columbia, Canada, contactable at hello@quarter.dev and providing its registered address on request |
|---|---|
| Subject matter | Providing the Quarter Bundles (Shopify) application to the merchant’s Shopify store |
| Duration | For as long as the app is installed, plus the retention periods in section 9 |
| Nature and purpose | Storing bundle configuration; recording bundle sales per order so the merchant can see their own reporting; responding to Shopify privacy webhooks |
| Categories of data subjects | The merchant’s customers who purchase a bundle, and the merchant’s own staff who use the app |
| Categories of personal data | Shopify order identifiers, and the bundle, quantity, revenue, refund and timestamp values attached to them. Staff data is limited to the store domain and the Shopify-issued access token. No names, email addresses, postal addresses, telephone numbers or customer identifiers are stored |
| Special category data | None |
| Frequency | Continuous, on order and configuration events |
| Retention | As set out in section 9 and the privacy policy |
Annex II — Technical and organisational measures
- Data minimisation by design. The app requests only the order fields it needs for reporting and requests none of the protected customer fields. Order webhook payloads containing customer details are read for a single identifier and never stored or logged.
- Encryption in transit. HTTPS/TLS for all traffic between the store, the app and its database.
- Encryption at rest. Provided by our managed database host as described in Annex III.
- Access control. Production access is limited to personnel who require it, over authenticated accounts with multi-factor authentication.
- Tenant isolation. Every stored record is keyed by store, and all queries are scoped to the authenticated store’s session.
- Authentication. Requests from the Shopify admin are verified by Shopify’s session tokens; storefront requests are verified through Shopify’s signed app proxy; webhooks are verified by HMAC signature.
- Automated erasure. Shopify’s customer data request, customer redaction and shop redaction webhooks are implemented and act without manual intervention, alongside a scheduled purge enforcing the retention period.
- Backups and availability. Managed database backups provided by our host, restorable in the event of loss.
- Change management. Changes are version-controlled and reviewed before deployment.
Annex III — Authorised subprocessors
| Subprocessor | Processing | Location |
|---|---|---|
| Shopify Inc. | Source of the data. The app runs as a Shopify app and reads store data through Shopify's APIs under the merchant's own agreement with Shopify. | Canada, United States and other regions per Shopify |
| Render Services, Inc. | Application hosting and managed PostgreSQL. All data the app stores is stored here. | United States (Oregon, US West) |