This Data Processing Addendum (“DPA”) forms part of the Terms of Service between the Merchant (“Controller”) and Niogin LLC (“Processor”). Niogin (Pvt) Ltd is an affiliate subprocessor. It applies when Processor processes Merchant Personal Data to provide Shoptimizr.
If the parties sign a separate DPA, that signed document controls. This public DPA applies otherwise, including when you install the Shopify app.
Controller remains responsible for the lawfulness of its storefront, notices, and cookie consent. Processor does not act as controller of store-customer data except to the limited extent the law requires (for example, to handle a mandatory Shopify compliance webhook or a binding legal demand).
01Parties and roles
Merchant is the controller (or a processor itself, in which case Processor is a subprocessor and Merchant warrants it is authorised to appoint Processor). Processor will process Merchant Personal Data only on documented instructions, including these Terms, this DPA, product configuration, and Shopify’s mandatory privacy webhooks.
Processor’s personnel authorised to process Merchant Personal Data are under a confidentiality obligation.
02Definitions
“GDPR” means Regulation (EU) 2016/679 and, where applicable, the UK GDPR. “Merchant Personal Data” means personal data relating to Merchant’s customers, store visitors, and similar data subjects that Processor processes in the service. “Subprocessor” means a third party engaged by Processor to process Merchant Personal Data. Terms defined in GDPR have the same meaning here.
03Instructions
Processor shall:
- process Merchant Personal Data only to provide, secure, and support the service;
- not sell Merchant Personal Data or use it to train Processor’s own foundation models;
- inform Merchant if an instruction, in Processor’s opinion, infringes GDPR (without this being legal advice);
- not disclose Merchant Personal Data to third parties except subprocessors, as required by law, or with Merchant’s instruction.
LLM features may send brand, catalog, and diagnostic context to a model gateway. Merchant instructs Processor to do so when those features are enabled. Merchant should not put unnecessary shopper identifiers into free-text fields it controls.
04Confidentiality of personal data
Processor will treat Merchant Personal Data as Merchant’s confidential information and limit access to personnel who need it for the service.
05Security
Taking into account the state of the art, costs, and the nature of the processing, Processor will implement appropriate technical and organisational measures as described in Annex III. Merchant acknowledges that storefront pixels run in the shopper’s browser and are subject to the Merchant’s theme, CMP, and third-party scripts.
06Subprocessors
Merchant authorises the subprocessors in Annex II, including Niogin (Pvt) Ltd. Processor will impose data-protection obligations on subprocessors no less protective than this DPA, in substance.
Processor will post material changes to Annex II on this page. Merchant may object to a new subprocessor on reasonable data-protection grounds within 14 days of the posting. If the parties cannot resolve the objection, Merchant may terminate the affected service as its sole remedy.
Integrations the Merchant chooses (GA4, Klaviyo, Shopify itself) are Merchant’s processors as well; Processor accesses them on Merchant’s instruction.
07International transfers
Merchant Personal Data may be processed in Sri Lanka (Niogin-operated infrastructure) and countries where our subprocessors operate, including the United States and the European Economic Area. For restricted transfers, Processor will use a lawful mechanism (including Standard Contractual Clauses where required). Merchant authorises those transfers as necessary to provide the service.
08Assistance
Processor will, taking into account the nature of processing, assist Merchant with data-subject requests, data-protection impact assessments, and consultations with supervisory authorities, by providing the tools and information reasonably available in the product (including Shopify customer-data export and redact jobs).
Shopper requests should be directed to Merchant. Processor will not respond to a shopper as if Processor were the controller, except to redirect them or to comply with Shopify’s mandatory webhooks.
Processor may charge reasonable costs for assistance that goes beyond the standard product, unless the law forbids it.
09Personal data breach
Processor will notify Merchant without undue delay after becoming aware of a personal data breach affecting Merchant Personal Data, with information reasonably available to help Merchant meet Articles 33 and 34. Notification is not an admission of fault.
10Deletion and return
During the term, Merchant may export tenant data using the product’s export job where available. After termination or Shopify uninstall:
- Processor marks the Shopify install inactive immediately;
- Processor processes
customers/data_requestandcustomers/redactas implemented in the product; - Processor processes
shop/redactby marking the shop uninstalled. Automated deletion of remaining shop data after that webhook is still being completed; Merchant may request deletion in writing to [email protected].
Processor may retain copies required by law, for dispute resolution, or in encrypted backups until they rotate, provided the data remains subject to this DPA.
11Audits
Upon reasonable written notice, no more than once per 12 months (unless a supervisory authority or a documented breach requires more), Merchant may audit Processor’s compliance with this DPA. Audits are limited to information reasonably necessary, conducted during business hours, and must not compromise other tenants’ security. Processor may satisfy the audit by providing current documentation, questionnaires, and a call with a knowledgeable engineer. On-site or production-access audits require a mutually agreed scope and confidentiality terms.
12Liability and term
Liability under this DPA is subject to the limitations in the Terms, except that nothing in this DPA limits either party’s liability to a data subject under GDPR Article 82 where that liability cannot be limited. This DPA lasts for the term of the Terms and survives as long as Processor retains Merchant Personal Data.
Governing law and courts are those in the Terms. For questions: [email protected].
A1Annex I — Description of processing
Subject matter
Conversion intelligence, attribution, experimentation, and LLM visibility for the Merchant’s Shopify store(s).
Duration
The term of the service, plus the retention periods in the Privacy Policy.
Nature and purpose
Ingest of webhooks and pixel events; identity stitching; reporting; experiment assignment; generation of diagnostics and hypotheses; Shopify privacy-webhook handling.
Types of data subjects
Store visitors, customers, checkout users, and (if Klaviyo is connected) members of Merchant’s email segments.
Types of personal data
Visitor identifiers; URLs, referrers, and campaign parameters; product and cart interaction; checkout and order metadata; email addresses (hashed, and currently sometimes in raw event payloads); Shopify customer and order IDs; GA4 and Klaviyo identifiers the Merchant authorises.
Special categories
Not sought. Incidental inclusion in free-text order notes is possible.
A2Annex II — Subprocessors
As of 8 September 2026:
| Name | Role | Location |
|---|---|---|
| Niogin (Pvt) Ltd | Hosting, engineering, support | Sri Lanka |
| Shopify Inc. and affiliates | Commerce platform, app, pixel, webhooks | Canada, United States, Ireland (Shopify’s regions) |
| Google LLC | GA4 APIs (when connected); Workspace SSO for Niogin staff; font delivery on shoptimizr.com | United States and Google’s regions |
| OpenRouter, Inc. (and the model provider for a given request) | LLM inference for diagnostics, hypotheses, citation parsing | United States and the model provider’s regions |
| Resend (production email) / SMTP as configured | Transactional email | United States (Resend) or the configured SMTP region |
| Klaviyo, Inc. | Email/SMS analytics when Merchant connects Klaviyo | United States |
| Niogin-operated PostgreSQL, Redis, Kafka, OpenSearch, Qdrant, MinIO | Primary stores and queues | Sri Lanka (Niogin infrastructure) |
A3Annex III — Technical and organisational measures
- TLS for data in transit on the public site and APIs.
- Tenant isolation, including PostgreSQL row-level security keyed to tenant context.
- Role-based access in the dashboard; Niogin staff access limited to operations roles.
- Hashed authentication tokens; per-tenant salt for email hashes used in stitching.
- HMAC verification of Shopify webhooks and OAuth callbacks.
- Audit logging of mutating dashboard actions.
- Retention jobs for raw webhooks (30 days) and hot events/sessions (24 months).
- Application-layer encryption helpers for selected secrets; Shopify tokens stored in the application database.
These measures will evolve. They are not a representation that every PRD control (for example per-tenant envelope keys in a separate vault, or CMP gating of the pixel) is already in production.
See also the Privacy Policy.