Deluxe Customer Accounts

    GDPR Compliance

    Last updated: September 5, 2026

    At Deluxe Customer Accounts, protecting the privacy of merchants and their customers is something we build into how the app works, not just something we write about. We only ever collect what's actually needed to run the app's features, and everything we do with that data is governed by our Privacy Policy and Data Processing Agreement.

    This article explains how Deluxe complies with the General Data Protection Regulation (GDPR) to protect the rights of Data Subjects.

    1. What is GDPR?

    The General Data Protection Regulation is the EU's core data protection law, extended into UK domestic law through the Data Protection Act 2018 (together, "UK-GDPR"). It sets obligations for any organization handling personal data belonging to people in the EU or UK, no matter where that organization itself is located. Throughout this article, "GDPR" refers to both frameworks together, and "Europe" refers to the EU and UK combined.

    2. Deluxe's role as a Data Processor

    When a merchant installs Customer Accounts Deluxe, they act as the Data Controller for their own customers' personal data — meaning they carry ultimate responsibility for honoring the data rights of any customer based in the EU or UK (including requests to access, correct, delete, or restrict use of their data).

    We, in turn, act as a Data Processor: we handle that data strictly on the merchant's instructions, and our role in supporting their compliance obligations includes:

    • Retrieving and providing the customer data we hold, when a merchant or their customer requests it (supports the right of access)
    • Reflecting any corrections a merchant or customer makes to a customer record through the app (supports the right to rectification)
    • Removing a customer's account data — both within our own systems and, where feasible, within the merchant's Shopify environment — once a deletion request is verified (supports the right to erasure)
    • Exporting a customer's data in a structured, portable format on request (supports the right to data portability)

    Because relevant data can span more than one system, these requests go through manual review today rather than an automated pipeline. In line with Article 12 GDPR, we aim to complete verified requests within one month, extendable by a further two months for complex requests — in which case we'll let you know about the extension, and why, within that first month.

    3. Deluxe's role as a Data Controller

    There are cases where we're the ones deciding how and why data gets used — for instance, when a merchant's staff member sets up an account with us, submits billing details, or writes in to our support team. In those situations, Deluxe is the Data Controller.

    Where that applies, and as far as applicable law allows, you're entitled to:

    • Get a copy of whatever personal data we hold on you
    • Have inaccurate information corrected
    • Ask us to delete data we hold about you
    • Receive your data in a portable, machine-readable format

    Reach out to [email protected] to act on any of these.

    4. Data Processing Agreement (DPA)

    Our Data Processing Agreement sets out the terms under which we process personal data on behalf of merchants, including our obligations, security commitments, and the framework governing international data transfers where applicable.

    You can read our current DPA here: Deluxe Customer Accounts — Data Processing Agreement.

    5. Subprocessors

    We engage a limited number of third-party subprocessors to operate specific features of the app — for example, transactional email delivery, SMS verification, optional reviews integrations, and infrastructure hosting. Subprocessors are only ever given the minimum data necessary for their specific function.

    We do not publish a named list of our subprocessors on this page. A current, named list is available on request — contact us at [email protected] and we'll be glad to share it. We'll also notify merchants at least 7 days before bringing on a new subprocessor, so there's a real window to raise any concerns before it starts processing data.

    6. Security and location of our infrastructure

    All of our infrastructure runs within the European Union. On the technical side, we encrypt the connection between the app and its database, serve everything over HTTPS, route merchant staff logins through Shopify's own OAuth system, and cryptographically verify every incoming Shopify webhook to rule out tampering. Customer passwords never touch our servers at all — Shopify's own systems handle that authentication entirely.

    We keep working on tightening these measures further, including broadening how much stored data is encrypted at rest.


    Questions about privacy or this article? Contact us at [email protected].