Deluxe Customer Accounts
Data Processing Agreement
Last updated: September 5, 2026
This Data Processing Agreement ("DPA") is entered into between Deluxe Customer Accounts ("Processor," "we," "us," or "our") and the merchant identified in the applicable order form, subscription agreement, or Shopify App Store installation ("Controller," "you," or the "Merchant"), and forms part of, and is incorporated by reference into, the agreement governing the Merchant's use of the Customer Accounts Deluxe application (the "App," and together with this DPA, the "Agreement").
This DPA reflects the parties' agreement with respect to the Processing of Personal Data in connection with the Merchant's use of the App, and is intended to satisfy the requirements of Article 28 of the EU General Data Protection Regulation ("GDPR") and equivalent provisions of other applicable data protection laws, including the UK GDPR as implemented by the UK Data Protection Act 2018.
1. Definitions
Terms such as "Personal Data," "Processing," "Data Controller," "Data Processor," "Data Subject," "Supervisory Authority," and "Personal Data Breach" shall have the meanings given to them under the GDPR. "Subprocessor" means any third party engaged by the Processor to Process Personal Data on behalf of the Controller in connection with the App. "SCCs" means the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as may be amended, replaced, or superseded from time to time.
2. Roles of the parties
The parties acknowledge that, with respect to Personal Data of the Merchant's customers Processed through the App, the Merchant is the Data Controller and the Processor acts as a Data Processor, Processing such Personal Data solely on behalf of, and in accordance with, the Merchant's documented instructions, as set out in this DPA and the underlying Agreement, except where otherwise required by applicable law.
3. Subject matter, duration, and purpose of processing
Subject matter: the Processor's provision of customer account, loyalty, store credit, wishlist, returns/exchange, and related functionality to the Merchant via the App.
Duration: Processing shall continue for the duration of the Merchant's use of the App, and thereafter only to the extent, and for so long as, described in Section 8 (Retention and Deletion) of this DPA.
Purpose: Processing is carried out solely to provide and support the functionality of the App as configured and used by the Merchant. Further detail is set out in Annex I.
4. Categories of data subjects and personal data
Categories of Data Subjects: the Merchant's customers, and the Merchant's own staff or authorized users of the App's administrative interface.
Categories of Personal Data: contact details (name, email, phone number); account authentication identifiers, including those issued by third-party social login providers where used; date of birth; gender (where voluntarily provided); profile image; language preference; order and purchase history; loyalty program status and points balance; store credit balance and transaction history; wishlist contents; and any additional custom fields configured by the Merchant. Further detail is set out in Annex I.
5. Obligations of the processor
The Processor shall:
- Process Personal Data only on the documented instructions of the Controller, including with regard to international data transfers, unless required to do otherwise by applicable law, in which case the Processor shall inform the Controller of that legal requirement before Processing, unless prohibited from doing so;
- Ensure that persons authorized to Process Personal Data are subject to appropriate confidentiality obligations;
- Implement appropriate technical and organizational measures as described in Section 7 and Annex II of this DPA;
- Engage Subprocessors only in accordance with Section 6 of this DPA;
- Provide reasonable assistance to the Controller, taking into account the nature of Processing, in responding to requests from Data Subjects exercising their rights under applicable data protection law;
- Notify the Controller without undue delay upon becoming aware of a Personal Data Breach affecting Personal Data Processed under this DPA;
- Make available to the Controller information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by the Controller or a mutually agreed third-party auditor, subject to reasonable notice and confidentiality obligations;
- At the Controller's election, delete or return all Personal Data to the Controller following the end of the provision of services relating to Processing, and delete existing copies, except where applicable law requires storage of the Personal Data.
6. Subprocessors
The Controller provides general authorization for the Processor to engage Subprocessors to Process Personal Data in connection with the App, subject to the Processor imposing data protection obligations on such Subprocessors that are no less protective than those set out in this DPA. Categories of Subprocessors currently engaged are set out in Annex III.
A current, named list of Subprocessors is available to the Merchant upon written request to [email protected]. The Processor shall notify the Merchant at least 7 days before engaging a new Subprocessor to Process Personal Data on its behalf. A new Subprocessor may begin Processing during this notice period; if the Merchant raises a valid, documented objection on data protection grounds within that period, the Merchant's remedy shall be to terminate the affected feature, service, or the Agreement, as applicable.
7. Security measures
The Processor implements the technical and organizational measures described in Annex II of this DPA, and shall continue to review and enhance these measures over time, including expanding encryption coverage for Personal Data at rest, updating this DPA to reflect material changes to its security posture.
8. Retention and deletion
- Merchant staff session data and access tokens are deleted immediately upon uninstallation of the App.
- Customer account records maintained within the Processor's own systems, including loyalty and store credit balances recorded there, are deleted immediately upon uninstallation of the App.
- Personal Data stored within the Merchant's own Shopify environment (including loyalty status, store credit history, wishlist contents, date of birth, gender, profile image, language preference, and referral tracking data) resides on the Shopify platform under the Merchant's own account, and is therefore not automatically deleted upon uninstallation of the App. The Merchant may request assistance with removal of such data by contacting [email protected], or may manage it directly within their own Shopify administration panel.
- Verification codes (one-time passcodes, password reset tokens) expire automatically within a short window (10–15 minutes).
9. Assistance with data subject requests
Taking into account the nature of Processing, the Processor shall provide reasonable assistance to the Controller in fulfilling its obligations to respond to requests from Data Subjects exercising their rights under applicable data protection law. Given that relevant Personal Data may be located across multiple systems, including the Merchant's own Shopify environment, such requests are currently reviewed and actioned manually to ensure completeness and accuracy. In line with Article 12 GDPR, the Processor aims to complete such assistance within one month of a documented request from the Controller, extendable by a further two months where the request is complex, in which case the Controller will be informed of the extension and the reason for it within the first month.
10. International data transfers
The Processor's infrastructure is hosted within the European Union. Certain Subprocessors identified in Annex III may, in connection with their specific function, Process Personal Data outside the European Economic Area ("EEA"). Where the Processor transfers Personal Data originating in the EEA or UK to a Subprocessor located in a country not subject to an adequacy decision of the European Commission (or, as relevant, the UK Government), such transfer shall be governed by the SCCs, which are incorporated into this DPA by reference and deemed executed between the Controller (as "data exporter") and the relevant Subprocessor (as "data importer") upon the effective date of this DPA, completed as follows:
- Module Two (Controller to Processor) applies where the Processor itself is the data importer outside the EEA/UK;
- Module Three (Processor to Processor) applies where a Subprocessor engaged by the Processor is the data importer outside the EEA/UK;
- Clause 7 (the optional docking clause) is not used;
- In Clause 9, Option 2 (general written authorization) is selected, with a minimum notice period of 7 days as further described in Section 6 above;
- In Clause 11, the optional language permitting Data Subjects to lodge complaints with an independent dispute resolution body is not used;
- In Clause 17, the SCCs are governed by the law of Ireland;
- In Clause 18(b), disputes shall be resolved before the courts of Ireland;
- The details required under Annex I and Annex II of the SCCs are as set out in Annex I and Annex II of this DPA respectively.
For UK transfers, the International Data Transfer Addendum to the SCCs, issued by the UK Information Commissioner's Office, is incorporated on the same basis, in place of, or in addition to, the SCCs as required.
11. Personal data breach notification
The Processor shall notify the Controller without undue delay, and in any event within a timeframe that allows the Controller to meet its own regulatory notification obligations, upon becoming aware of a Personal Data Breach affecting Personal Data Processed under this DPA. Such notification shall include, to the extent reasonably available to the Processor, a description of the nature of the breach, the categories and approximate number of Data Subjects and records concerned, and the measures taken or proposed to address the breach.
12. Audit rights
Upon written request, and only where such request is supported by (a) a specific, documented data protection concern, or (b) a binding requirement of a competent Supervisory Authority or applicable law, the Processor shall make available to the Controller written documentation reasonably necessary to demonstrate compliance with this DPA. The Processor shall not be required to permit on-site inspection of its systems or infrastructure, and may satisfy this obligation through summary compliance documentation, subject to confidentiality obligations and without disclosure of information relating to the Processor's other customers.
13. Liability
Each party's liability arising out of or related to this DPA shall be subject to the limitations and exclusions of liability set out in the underlying Agreement between the parties.
14. Term and termination
This DPA shall remain in effect for as long as the Processor Processes Personal Data on behalf of the Controller under the Agreement, and shall automatically terminate upon termination of the Agreement, without prejudice to any provisions of this DPA which by their nature should survive termination (including confidentiality and liability provisions).
15. Governing law
This DPA shall be governed by, and construed in accordance with, the laws of Italy, the jurisdiction in which the Processor is established. Any disputes arising under this DPA shall be subject to the exclusive jurisdiction of the courts of Italy, unless otherwise agreed by the parties or required by applicable mandatory law. This Section 15 does not affect the governing law and jurisdiction provisions of the SCCs themselves, as specified in Section 10 above.
16. Contact
For any questions regarding this DPA, please contact:
Annex I — Details of Processing
A. List of parties
Data exporter: the Merchant, as identified in the Merchant's Shopify account and the underlying Agreement. Role: Controller.
Data importer: Deluxe Customer Accounts. Role: Processor. Contact: [email protected].
B. Description of processing
| Category | Description |
|---|---|
| Categories of data subjects | Customers of the Merchant; Merchant staff and authorized users of the App |
| Categories of personal data | Contact details; account authentication identifiers; date of birth; gender (optional); profile image; language preference; order and purchase history; loyalty status and points balance; store credit balance and history; wishlist contents; Merchant-configured custom fields |
| Sensitive data (if any) | None processed by design; the App does not request special category data under Art. 9 GDPR |
| Frequency of transfer | Continuous, for as long as the App remains installed |
| Nature of processing | Collection, storage, retrieval, use, and deletion in connection with customer account, loyalty, store credit, wishlist, and returns/exchange functionality |
| Purpose of processing | Provision of the App's functionality to the Merchant, as described in Section 3 of this DPA |
| Duration of processing | For the duration of the Agreement, and thereafter as described in Section 8 (Retention and Deletion) |
C. Competent supervisory authority
Where required under Clause 13 of the SCCs, the competent supervisory authority shall be determined in accordance with the SCCs, based on the Controller's country of establishment or the location of its EU representative.
Annex II — Technical and Organizational Security Measures
The Processor implements the following measures to ensure a level of security appropriate to the risk:
- Encrypted (TLS/SSL) connections between the App and its database infrastructure.
- HTTPS encryption for all data transmitted to and from the App.
- Authentication of Merchant staff via Shopify's OAuth authentication framework.
- Customer account credentials are never stored by the Processor; authentication is managed entirely by Shopify's own systems.
- Cryptographic verification (HMAC signature validation) of all incoming Shopify webhook communications, to prevent tampering or spoofing.
- Infrastructure hosted within the European Union.
- Access to production systems restricted to authorized personnel.
The Processor continues to review and enhance these measures, including expanding the scope of encryption applied to Personal Data at rest, and will update this Annex to reflect material changes.
Annex III — Subprocessors
The Processor currently engages Subprocessors within the following categories. Each Subprocessor is authorized to Process only the data necessary for its specific function.
| Category | Function |
|---|---|
| Transactional email delivery | Delivery of password reset and account verification communications |
| SMS / OTP delivery | Delivery of one-time passcodes for phone-based verification |
| Social authentication providers | Facilitating customer sign-in via third-party accounts, at the customer's election |
| Reviews platform integration (optional) | Synchronizing product reviews with loyalty rewards, where enabled by the Merchant |
| AI-assisted support tooling | Powering an in-admin assistant used by Merchant staff |
| Product analytics (admin interface only) | Understanding Merchant staff interaction with the App's administrative dashboard |
| Billing and subscription management | Processing of Merchant subscription and billing status |
| Cloud infrastructure and hosting | Hosting of application and database infrastructure |
A current, named list of Subprocessors — including each Subprocessor's identity, location, and the specific data it processes — is available to the Controller upon written request to [email protected]. This Annex III is not intended to be an exhaustive public disclosure, but a summary of Subprocessor categories currently in use; the named list provided on request constitutes the operative and complete record for purposes of Section 6 of this DPA.