The short version: your store's customer data is yours. I handle it only to run the app you installed, I keep it safe, I tell you quickly if something goes wrong, and I delete it when you leave.
Plain English, not legal advice. I wrote this agreement in plain English so it is easy to check. It is not legal advice. If your business needs specific clauses or a signed copy, email me.
Who this is between
This agreement is between you, the merchant who installs PerkJar, RallyCrew, NextBatch or Wayfind, and TFC Business Solutions LLC, a Florida company run by Jamie Farrell ("I" and "me" below). It is part of the terms of service, so accepting the terms by installing an app includes this agreement. Where this agreement and the terms say different things about personal data, this agreement applies.
Roles
- You are the controller. You decide why your customers' data is used: to run your rewards, creator, subscription or quiz program.
- I am the processor. I process that data only on your behalf and on your instructions. Your instructions are the settings you choose in the app and this agreement.
- Shopify is the platform the apps run on. Your relationship with Shopify is covered by Shopify's own terms.
If a law ever requires me to process the data in some other way, I will tell you first unless that law forbids it.
What is processed
Each app processes only what it needs. The full lists are in each app's privacy policy.
| App | Whose data | What |
|---|---|---|
| PerkJar | Program members and referred friends | Shopify customer ID, first name, email, an optional birthday (month and day), points history, referral and reward codes, friends' emails, and a one-way hash of referral link clicks |
| RallyCrew | Creators | Name, email, application text, payout method and handle, and click counts with a one-way hash. No shopper personal data is stored |
| NextBatch | Subscribers | Shopify customer ID, name, email, delivery address, subscription details, billing attempt results, portal actions and cancellation notes |
| Wayfind | People who take a quiz | Quiz answers and result, a random visitor ID, an email and the consent choice if they leave one, and a Shopify customer ID |
For every app I also keep store details (domain, name, currency, plan and settings), the order facts needed to work out the 1% fee, and a log of staff views of personal data. No app stores card numbers or other payment details. Shopify handles payments.
Purpose limitation
- I use the data only to run the app you installed, to support you, and to work out that app's 1% usage fee.
- I never sell the data, share it with advertisers, or use it for anyone else's purposes.
- There are no third-party trackers, analytics tools or advertising pixels in the apps or their storefront blocks.
- Access is limited to what is needed to run and support the apps, and anyone with access must keep the data confidential.
Sub-processors and where data is kept
| Sub-processor | What it does |
|---|---|
| Spaceship | Web hosting for the copies of the apps you install from the Shopify App Store. Each app keeps its data in a database file on that server. |
| Railway | Hosting for private copies of the apps that I run for a few stores I work with directly. |
| Shopify | The platform the apps run on. To bill the 1% fee, the apps send Shopify the store's ID and an amount, nothing about shoppers. |
There are no other sub-processors. The apps are hosted in the United States, so if your store or your customers are elsewhere, the data is transferred to the United States to run the app. If I add or replace a sub-processor, I will update this page and tell you by email or in the app at least 30 days before the change. If you object, you can uninstall the app and its data will be deleted as described below.
Security measures
- In transit. Every connection between Shopify, your storefront and the apps uses HTTPS. Requests from Shopify are checked with Shopify's signatures before the app acts on them.
- At rest. The apps encrypt personal data themselves before it reaches the database, with AES-256-GCM and a key kept in the app's environment, never in the database or the code. Emails are looked up through a keyed one-way index, so finding a customer's records doesn't mean decrypting them.
- Less data to begin with. Each app stores only the fields listed above. RallyCrew stores no shopper data at all, and referral clicks are stored as a one-way hash, not a raw IP address.
- Access. Studio opens only through Shopify admin with short-lived signed tokens. It keeps a log of each time someone opens a list or record with personal data in it, or downloads an export.
Customer requests
When one of your customers asks you for their data, or asks to be deleted, Shopify tells the app. For a data request, the app gathers what it holds about that customer into a file that you download from Studio and send on. For a deletion request, the app deletes or anonymises that customer's data automatically. I will help with any request you can't complete in the app.
Retention and deletion
- While installed. Members, creators, subscriptions and quiz responses are kept while the app is installed, because they are your working records. You can delete them in Studio at any time.
- On uninstall. The app stops right away. Shopify asks apps to erase a store's data 48 hours after uninstall, and when that request arrives the app deletes everything it holds for your store.
- On request. When a customer asks to be deleted, the app deletes or anonymises their data as each privacy policy describes. If you want your whole store's data deleted sooner than the uninstall request, email me from the store owner's address and I will do it.
- Fixed periods. Customer data request files are deleted 30 days after you first download them, or 90 days after they were made if never downloaded. The staff access log is kept for 180 days. Backup copies, where they exist, are replaced within 14 days.
Security incidents
If I discover an actual or suspected breach of your store's data, I report it to Shopify within 24 hours, as Shopify's API terms require. I email you without undue delay, and no later than 72 hours after I confirm your store is affected, with what happened, which data was involved, what I have done, and what you may need to tell your customers. You decide on any notice to your customers, and I give you the facts you need for it.
Information and questions
I will answer reasonable written questions about how your store's data is handled, and give you the information you need to show that this agreement is followed. I don't hold third-party audits or certifications today.
How long this lasts
This agreement applies for as long as an app is installed on your store, and after that until the app has deleted your store's data.
Liability and governing law
The limits of liability in the terms of service apply to this agreement too. This agreement is governed by the laws of the State of Florida, USA, and any dispute will be handled in the courts located in Orange County, Florida, unless the law where you are says otherwise.
Changes and contact
If this agreement changes, I will update this page and the date at the top, and tell you by email or in the app before a change that matters takes effect. Questions or requests: him@thejamiefarrell.com, or write to TFC Business Solutions LLC, Orlando, Florida.