Trackable

Data Processing Agreement (DPA) — Trackable

Version: 1.0 · Effective: August 20, 2026

This Data Processing Agreement ("DPA") is entered into between Jins Mathew (trading as WorkFlicks), Cherukarayalunkal, Channaplavu, Koruthodu PO, Kottayam, Kerala, India – 686513 ("Processor", "we") and the Shopify merchant that installs the Trackable app ("Controller", "Merchant"), and governs the processing of Personal Data by the Processor on behalf of the Controller.

1. Definitions

"Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Supervisory Authority" have the meanings in the EU General Data Protection Regulation 2016/679 ("GDPR"). "Applicable Data Protection Law" means the GDPR, UK GDPR, the California Consumer Privacy Act as amended by the CPRA ("CCPA"), India's Digital Personal Data Protection Act 2023 ("DPDP"), and other laws applicable to the Processing. "Customer Data" means Personal Data of the Controller's customers Processed by the Processor via the App.

2. Roles & subject matter

The Merchant is the Controller and Trackable is the Processor for Customer Data. The Processor processes Customer Data only to provide the App's functionality: branded order tracking, self-service order lookup, and transactional shipping notifications. The subject matter, duration, nature, and purpose of Processing, and the categories of data and Data Subjects, are described in Annex I.

3. Processor obligations

The Processor shall:

  1. Process Customer Data only on the Controller's documented instructions (including via the App's configuration and Shopify's APIs), unless required by law.
  2. Process the minimum Personal Data necessary and only for the purposes in Annex I.
  3. Ensure persons authorized to process Customer Data are bound by confidentiality.
  4. Implement the technical and organizational measures in Annex II.
  5. Assist the Controller, insofar as possible, in responding to Data Subject requests (access, rectification, erasure, restriction, portability, objection).
  6. Assist the Controller with security, breach notification, DPIAs, and consultations with Supervisory Authorities (GDPR Arts. 32–36).
  7. At the Controller's choice, delete or return all Customer Data at the end of the provision of services, and delete existing copies unless legally required to retain.
  8. Make available information necessary to demonstrate compliance and allow for audits as set out in Section 7.

4. Sub-processors

The Controller provides general authorization for the Processor to engage the sub-processors listed in Annex III. The Processor shall impose data protection obligations on sub-processors no less protective than this DPA and remains liable for their performance. The Processor will give the Controller at least 30 days' notice of intended changes to sub-processors (via email or the App's listing page); the Controller may object on reasonable data-protection grounds.

5. International transfers

Application data is hosted in the EU (Helsinki, Finland); the Processor is located in India. Where Processing involves transfer of Personal Data outside the EEA/UK to a country without an adequacy decision, the parties rely on the EU Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), incorporated by reference, with the Processor as data importer.

6. Data Subject requests & compliance webhooks

The Processor honors Shopify's mandatory privacy webhooks: customers/data_request (surfaces the minimal stored record), customers/redact (erases the Data Subject's shipment records), and shop/redact (erases all shop data 48 hours after uninstall). Requests received directly by the Processor will be redirected to the Controller without undue delay.

7. Audit

The Processor will make available, on reasonable written request and no more than once per year (unless required by a Supervisory Authority), documentation sufficient to demonstrate compliance with this DPA. On-site audits, if required, are subject to reasonable notice, confidentiality, and the Processor's security policies.

8. Personal data breach

The Processor shall notify the Controller without undue delay, and no later than 72 hours after becoming aware of a Personal Data breach affecting Customer Data, with the information reasonably available to enable the Controller to meet its notification obligations.

9. Liability & term

This DPA is effective for as long as the Processor processes Customer Data on behalf of the Controller. Liability is subject to the limitations in the parties' main agreement / the App's terms of service. In case of conflict on data protection matters, this DPA prevails.


Annex I — Description of Processing

  • Nature & purpose: provide order tracking, self-service lookup, and transactional shipping notifications to the Controller's customers.
  • Duration: for the term of the App installation; deleted per Section 6 / retention.
  • Categories of Data Subjects: the Controller's customers who place orders, and visitors who use the tracking page.
  • Categories of Personal Data: order number, order line items, fulfillment/shipment status, carrier, tracking number and URL, and customer email address (stored as a salted hash for lookup and AES-256-GCM encrypted for notifications; never in plaintext).
  • Special category data: none.

Annex II — Technical & organizational measures

  • Encryption in transit (TLS/HTTPS) for all connections.
  • Customer email stored as salted HMAC-SHA256 (lookup) and AES-256-GCM encrypted (notifications); never in plaintext. Encryption key held separately from the database.
  • Database at rest on an encrypted volume.
  • Read-only Shopify scopes (read_orders, read_fulfillments); no write access.
  • HMAC signature verification on every inbound webhook; idempotent processing.
  • Least-privilege access; secrets in environment/secret storage, not source control.
  • Data minimization and defined retention with automated deletion on redact webhooks.
  • Encrypted backups with a 30-day retention and a tested restore procedure.

Annex III — Approved sub-processors

Sub-processor Purpose Location
Shopify Inc. Source platform / store data Global
Hetzner Online GmbH App & database hosting Helsinki, Finland (EU)
Resend (if shipping emails enabled) Transactional email delivery EU / US

Signatures. By installing and using the App, the Merchant agrees to this DPA. For a countersigned copy, contact hello@workflicks.online.

Processor: Jins Mathew (trading as WorkFlicks) · Cherukarayalunkal, Channaplavu, Koruthodu PO, Kottayam, Kerala, India – 686513 · hello@workflicks.online

Privacy · DPA · hello@workflicks.online