Data Processing Addendum
Loyara for Shopify
This Addendum governs the processing of personal data by Loyara (the “Processor”) on behalf of the merchant (the “Controller”) when the merchant installs and uses Loyara on their Shopify store. Merchants accept it by installing the app.
1. Roles
The merchant is the data controller of their customers’ personal data. Loyara is a data processor acting only on the merchant’s documented instructions, providing the loyalty program’s functionality.
2. Scope of processing
Loyara processes only the data needed to run the loyalty program: the customer identifier, email, loyalty points balance and history, and, if the customer provides it, their birthday. It does not process customer names, phone numbers, addresses, or payment data.
3. Purpose limitation
Personal data is used solely to operate the loyalty program. It is never sold, rented, or used for the app’s own marketing, advertising, or profiling.
4. Sub-processors
Shopify (platform & billing), our hosting provider (application hosting), and Resend (transactional email delivery, only when the merchant enables email notifications). Each processes data only to provide their service.
5. Security
Encryption in transit (TLS) and at rest, encrypted offsite backups, access control (2FA, SSH keys, least privilege), environment separation, and a documented incident response policy.
6. Data subject rights & Shopify GDPR webhooks
Loyara honors Shopify’s mandatory privacy webhooks: customers/data_request, customers/redact, and shop/redact, and deletes all shop data on uninstall.
7. Retention
Personal data is retained only while the app is installed and the program is active, and is deleted on uninstall or a redact request.
8. Breach notification
We will notify the merchant without undue delay (and within any legally required window, e.g. 72 hours under GDPR) upon becoming aware of a personal-data breach affecting their customers.
Contact
This Addendum supplements the Loyara Privacy Policy. It is not legal advice.