Data Processing Agreement
Last updated 10 August 2026.
This Data Processing Agreement (“DPA”) governs how Synthweave LLC (“Sutton,” “we,” “us”) processes personal data on behalf of a merchant (“Merchant,” “you”) that installs and uses the Sutton Connect Shopify app. It forms part of, and is incorporated into, the agreement between you and us for the app. Where this DPA conflicts with that agreement on the processing of personal data, this DPA controls. It works alongside our Privacy Policy.
1. Roles
For personal data contained in your store’s orders, you are the controller and we are your processor. We process that data only to provide the analytics and reporting service you engaged us for, and only on your documented instructions, which include your configuration of the app, this DPA, and the data-subject requests Shopify passes to us on your behalf. We are the controller only for the limited data you provide to us directly (for example, your account and billing contact details), which is covered by our Privacy Policy rather than this DPA.
2. Subject matter, duration, nature and purpose
- Subject matter & purpose. Reading your store’s order data through the Shopify Admin API to produce your private sales analytics (revenue, orders, refunds, and per-customer repeat-purchase and lifetime-value reporting), and reading your product and inventory catalog to build and maintain your Google Merchant Center product feed.
- Duration. For as long as the app is installed, and until the data is erased under Section 8.
- Nature. Read-only ingestion, storage, computation, and reporting. We make no automated decision that has a legal or similarly significant effect on any data subject.
3. Categories of data subjects and personal data
- Data subjects: your customers (the people who placed the orders we read).
- Personal data: the customer email address carried on an order, and only that. We do not process customer names, phone numbers, or shipping/billing addresses: the app is approved to read only the email field, Shopify withholds the other protected fields, and we additionally strip them before anything is written to storage. Product and inventory data contains no customer personal data.
4. Our obligations as processor
- Process personal data only on your documented instructions, including for international transfers, unless required by law (in which case we will inform you unless the law forbids it).
- Ensure that personnel authorized to process the data are bound by confidentiality.
- Implement the technical and organizational security measures in Section 5.
- Not engage a sub-processor except as permitted by Section 6.
- Assist you, taking into account the nature of processing, in responding to data-subject requests (Section 7) and in meeting your security, breach-notification, and data-protection-impact-assessment obligations.
- Delete or return the personal data as set out in Section 8.
- Make available the information reasonably necessary to demonstrate compliance with this DPA (Section 9).
5. Security measures
- Data minimization to a single protected field (the order email).
- Encryption in transit (TLS) and encryption at rest with our data platform.
- Store access tokens held only in an encrypted secrets vault (1Password), never in our application database and never alongside customer data.
- OAuth-based connections with short-lived, automatically rotated access tokens, revoked on uninstall. No shared passwords or pasted API keys.
- Cryptographic (HMAC) verification of all data and requests received from Shopify; requests that fail verification are rejected.
- Per-merchant isolation: each merchant’s data is stored in a separate, isolated workspace and never combined with another merchant’s.
- Least-privilege staff access to protected customer data, and an access log of reads.
- A documented security incident-response policy and data-loss-prevention strategy.
6. Sub-processors
You authorize us to engage the sub-processors below, each of which processes personal data only on our instructions and under terms no less protective than this DPA. We will give you a reasonable opportunity to object before adding or replacing a sub-processor that processes order personal data.
- Shopify: the source of the order data, at your direction.
- Synthweave: our data platform, where your commercial records and raw source payloads are stored.
- 1Password: encrypted storage of credentials only (no customer data).
- Our application host: the server that runs the app’s connection and background-sync processes.
- Resend: transactional email.
Cloudflare and Vercel provide network delivery and hosting for our website; Slack carries internal operational alerts that contain aggregate figures and status only, not shopper personal data.
7. Data-subject requests and Shopify compliance webhooks
We assist you in fulfilling data-subject rights. In particular we honor the three standard requests Shopify passes to us on your behalf:
- Data access request (
customers/data_request): we provide the personal data we hold about the identified customer to you within 30 days. - Customer erasure (
customers/redact): we erase that customer’s personal data from both our structured records and our raw source archive within 30 days. - Store erasure (
shop/redact): on your uninstall we stop collecting immediately, revoke stored credentials, and erase the store’s data within 30 days of Shopify’s notification.
8. Retention, deletion and return
We retain the order email and the reporting derived from it only for as long as the app is installed and the data is needed to provide the reporting you engaged us for. There is no separate secondary use that would extend retention. On a valid erasure request, on uninstall, or on your instruction, we delete the personal data (and, on request, provide it back to you) within 30 days, save for any copy we are required by law to retain.
9. Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information reasonably available to help you meet your own notification obligations, and we will take reasonable steps to mitigate and remediate.
10. Audit
On reasonable prior request, and no more than once a year unless required by a supervisory authority or following a breach, we will make available the information reasonably necessary to demonstrate compliance with this DPA and cooperate with a proportionate audit conducted by you or an independent auditor bound by confidentiality.
11. International transfers
We are based in the United States and our sub-processors may process data in the United States and elsewhere. Where a transfer requires a lawful mechanism, it relies on appropriate safeguards such as the European Commission’s standard contractual clauses (and the UK addendum where applicable), which are incorporated by reference.
12. Contact
Privacy and data-processing questions: privacy@getsutton.ai.