Data Processing Agreement
When ShipOps processes personal data about your customers on your behalf, you are the data controller and we are your processor. This agreement sets out the terms of that processing. It forms part of, and is incorporated into, our Terms of Service.
1. Parties & roles
This Data Processing Agreement ("DPA") is between you, the merchant that installs ShipOps (the "Controller", "you"), and Smart Agent (SMC-Private) Limited, operator of ShipOps (the "Processor", "we", "us"). For personal data about your customers that we process to provide the Service, you are the Controller and we are your Processor. For data about you and your staff (your account, billing, and support interactions), we act as an independent controller as described in the Privacy Policy. This DPA is incorporated into and forms part of the Terms of Service; by installing or using the Service, you enter into and agree to this DPA.
2. Definitions
"Personal data", "processing", "data subject", "controller", "processor", and "sub-processor" have the meanings given under Applicable Data-Protection Law. "Protected Customer Data" has the meaning given by Shopify. "Applicable Data-Protection Law" means the data-protection and privacy laws that apply to your processing of personal data through the Service, which may include the EU/UK General Data Protection Regulation (GDPR) and Pakistan's data-protection legislation. Capitalised terms not defined here have the meaning given in the Terms of Service.
3. Scope & your instructions
We process customer personal data only: (a) to provide, secure, and support the Service; (b) on your documented instructions — which are set out in this DPA, the Terms, the Privacy Policy, and your configuration and use of the app; and (c) where required by law, in which case we will inform you first unless the law prohibits it. You are responsible for the accuracy and lawfulness of the personal data you make available to the Service and of your instructions, and for having a lawful basis to process it. If we believe an instruction infringes Applicable Data-Protection Law, we will tell you.
4. Nature, purpose & data
- Subject matter & purpose: providing cash-on-delivery (COD) delivery-operations software — syncing your orders, surfacing parcels that need action, enabling order-related WhatsApp and phone contact you initiate or configure, writing delivery status back to Shopify where you enable it, and reconciling courier payout receipts.
- Duration: for as long as the Service is installed, plus the deletion windows in Section 10.
- Data subjects: your customers.
- Categories of personal data: customer name, phone number, and shipping address; order metadata (order numbers, line items, totals, payment and fulfilment status, tags, timestamps); and courier tracking data.
- Minimisation: we do not process customer email, and we keep a PII-minimised copy of Shopify order data (city only, no street address on that record), as described in the Privacy Policy.
- No special-category data: the Service is not intended to process special categories of personal data, and you agree not to instruct us to.
5. Our obligations
As your Processor we will: (a) process customer personal data only as set out in Section 3; (b) ensure that people authorised to process it are bound by a duty of confidentiality; (c) implement the technical and organisational security measures in Section 6; (d) engage sub-processors only under Section 7; (e) taking into account the nature of the processing, assist you with data-subject requests (Section 8) and with your own obligations for security, breach notification, and data-protection impact assessments; (f) return or delete the personal data under Section 10; and (g) make available to you the information reasonably necessary to demonstrate compliance with this DPA (Section 12).
6. Security
We implement appropriate technical and organisational measures to protect personal data, including:
- encryption in transit (TLS) for all traffic;
- encryption of stored credentials and secrets with AES-256-GCM, and encryption at rest for the database host;
- access to production data limited to authorised operators, under strong authentication;
- per-store tenant isolation, so each store's data is scoped to that store;
- separation of test and production data; and
- a security incident-response procedure covering detection, containment, notification, and remediation.
A fuller description is on our Data Protection page, which is incorporated into this DPA by reference. We review these measures periodically and may update them, provided the level of protection is not materially reduced.
7. Sub-processors
You grant us general authorisation to engage sub-processors to provide the Service. Our current sub-processors are:
- Shopify — the platform ShipOps is embedded in, and the source of order data.
- Your courier partners (e.g. PostEx, TCS) — parcel tracking and delivery instructions, called with your own courier token.
- WhatsApp / Meta — order-related messaging you initiate or configure.
- Contabo (Germany, European Union) — hosting and database infrastructure.
We impose data-protection obligations on each sub-processor that are no less protective than this DPA, and we remain responsible for their performance. We will make the current list available and give you a reasonable way to learn of, and object to, intended additions or replacements before they process your data.
8. Data-subject requests
Requests from customers to exercise their rights (access, correction, deletion, and similar) should be directed to you as Controller. Taking into account the nature of the processing, we assist you through:
customers/data_request— we compile the data we hold about a customer and make it available to you within 30 days;customers/redact— we erase that customer's name, phone, and address, and the raw courier payload containing them; and- support@shipops.app — for manual assistance at any time.
9. Personal-data breaches
We will notify you without undue delay after becoming aware of a personal-data breach affecting your customers' data, provide the information reasonably available to help you meet your own notification obligations, and take reasonable steps to contain and remediate the breach in line with our incident-response procedure.
10. Return & deletion
On uninstall, background syncing stops immediately. About 48 hours later, Shopify sends a shop/redact request, on receipt of which we permanently delete all personal data we hold for your store. You may also request earlier deletion by emailing support@shipops.app. We delete or anonymise customer personal data on termination except to the limited extent, and for the limited period, that retention is required by law.
11. International transfers
Customer personal data is stored and processed on infrastructure located in the European Union (Contabo, Germany) and may be accessed by our authorised operators in Pakistan, where we operate. Where a transfer of personal data is subject to a cross-border transfer restriction under Applicable Data-Protection Law, we rely on an appropriate transfer mechanism (such as an adequacy decision or standard contractual clauses). [Confirm the transfer mechanism with counsel for your target markets before publishing.]
12. Audit & records
We will make available to you the information reasonably necessary to demonstrate compliance with this DPA. On reasonable prior written notice, no more than once per year (or following a personal-data breach affecting your data), you or an auditor you mandate may verify our compliance, subject to confidentiality obligations and provided the audit does not disrupt the Service or the data of other merchants.
13. Shopify Protected Customer Data
Customer name, phone, and address are Protected Customer Data under Shopify's requirements. We access and process them only to the extent needed to provide the Service, in accordance with Shopify's Protected Customer Data requirements and the data-minimisation principle in Section 4.
14. General
This DPA forms part of, and is governed by, the Terms of Service, including their limitation-of-liability and governing-law provisions. If there is a conflict between this DPA and the rest of the Terms regarding the processing of customer personal data, this DPA controls to the extent of that conflict. If any provision of this DPA is held unenforceable, the remaining provisions stay in effect. We may update this DPA to reflect changes in the Service, our sub-processors, or the law; material changes will be reflected in the "last updated" date and, where appropriate, notified in-app.
15. Contact
Data-protection questions, sub-processor objections, or requests for a countersigned copy of this DPA: support@shipops.app.