This addendum sets out how GrowMoe, LLC processes your customers’ personal data on your instructions, and what we commit to when we do.
1. Scope and roles
This Data Processing Addendum (“DPA”) forms part of theTerms of Service between GrowMoe, LLC, a Delaware limited liability company (“GrowMoe”, “we”, “Processor”) and the merchant using GrowMoe (“Merchant”, “you”, “Controller”). It applies whenever we process personal data on your behalf.
- You are the controller of the personal data in your Shopify store and in your GrowMoe account — your customers, their orders and carts, your company contacts, your support conversations. You decide why and how it is processed.
- We are the processor of that data. We process it only to run the Service for you.
- We are a controller for a narrow set of data we need to run our own business: your staff’s account records, billing and usage records, support correspondence with us, and security logs. Our Privacy Policy covers that, not this DPA.
Shopify is a separate controller and processor in its own right, under its own agreement with you. This DPA does not cover Shopify’s processing.
2. Definitions
“Personal data”, “processing”, “controller”, “processor”, “sub-processor”, “data subject” and “supervisory authority” have the meanings given in the GDPR. “Data Protection Laws” means the laws that apply to the processing under this DPA, including the EU GDPR, the UK GDPR and the UK Data Protection Act, the Swiss FADP, and US state privacy laws where they apply. “Merchant Personal Data” means personal data we process on your behalf under this DPA. “SCCs” means the Standard Contractual Clauses approved by the European Commission.
3. Details of processing
The subject matter, duration, nature, purpose, categories of data subjects and categories of personal data are set out in Annex 1.
4. Your instructions and your obligations
Your documented instructions to us are: this DPA, the Terms of Service, the Service documentation, and the configuration and actions you take in the app and API. We process Merchant Personal Data only on those instructions.
You confirm that:
- you have a lawful basis for the processing you ask us to perform, and have given your data subjects the notices Data Protection Laws require;
- you have collected and will honour the consents and preferences you rely on — including marketing consent, which the Service enforces at send time but cannot obtain for you;
- your instructions will not put us in breach of Data Protection Laws;
- you will not send us special-category data, payment card numbers, or government identifiers.
If we believe an instruction breaches Data Protection Laws, we will tell you and may pause that processing until it is resolved.
5. Our obligations as processor
We will:
- process Merchant Personal Data only on your documented instructions (section 4);
- not sell Merchant Personal Data, not share it for cross-context behavioural advertising, and not use it for our own purposes — including not using it to train models;
- keep it confidential, and make sure the people who access it are bound by confidentiality obligations and access it only as needed to do their job (section 6);
- apply the security measures in section 7 and Annex 2;
- only use sub-processors on the terms in section 8, and stay responsible for what they do;
- assist you with data subject requests as described in section 10;
- notify you of a personal data breach affecting Merchant Personal Data as described in section 11;
- assist you with data protection impact assessments and prior consultations as described in section 12;
- make available the information you reasonably need to show compliance, as described in section 13;
- delete or return Merchant Personal Data on termination, as described in section 14.
6. Confidentiality and personnel
Access to Merchant Personal Data is limited to personnel who need it to operate or support the Service. Those people are bound by written confidentiality obligations that survive the end of their engagement, and their access is logged (Annex 2). We remove access when it is no longer needed.
7. Security measures
We apply the technical and organisational measures described in Annex 2, taking into account the risk of the processing. The measures that matter most for this Service are: Shopify access tokens and other secrets encrypted at rest with AES-256-GCM, access to customer personal data logged, strict tenant isolation (every record scoped byorg_id, reachable only through a tenant-scoped database port), a single fixed and app-level-minimised set of Shopify access scopes requested at install (we do not request unused or overly broad scopes, but we do not yet vary the request by which capabilities a Merchant has switched on), and personal-data minimisation before anything is sent to a telemetry sub-processor.
What we do not claim. GrowMoe is a small vendor. We hold no SOC 2 report, no ISO 27001 certificate, and we do not currently commission third-party penetration testing. We have not appointed a data protection officer, and we have not appointed an EU or UK representative. If your procurement process requires any of these, tell us before you rely on the Service — we would rather say so now than imply otherwise.
We may change the measures in Annex 2 as the Service evolves, but will not reduce their overall level of protection.
8. Sub-processors
You give us general authorisation to use sub-processors to provide the Service. Our current authorised sub-processors, what each one does, and where each is located, are listed at/legal/subprocessors. That list is part of this DPA.
For every sub-processor we use, we will:
- carry out reasonable diligence on its security and privacy practices before engaging it;
- put a written contract in place imposing data protection obligations no less protective than this DPA;
- contractually prohibit that sub-processor from using Merchant Personal Data to train or fine-tune any AI or machine-learning model, for itself or anyone else — the same unconditional commitment we make ourselves in section 5 and in ourPrivacy Policy, with no carve-out;
- remain responsible to you for its performance, as if we had done the processing ourselves.
Notice of changes. Before we add or replace a sub-processor, we will update the list at /legal/subprocessors and give notice at least [counsel: notice period — e.g. 30 days] before the change takes effect, by [counsel: notice mechanism — e.g. email to the account contact, or a dated change on the sub-processors page]. You may object on reasonable data protection grounds within that period; we will work with you to find a solution, and if we cannot, you may stop using the affected capability or terminate by uninstalling the app under the Terms, with no further payment obligation for the unused period.
9. International transfers
GrowMoe is established in the United States and processes Merchant Personal Data in the United States and in the locations its sub-processors operate from. If you are in the EEA, the UK or Switzerland, that means personal data is transferred outside your jurisdiction.
Where such a transfer takes place and no adequacy decision covers it, our intent is that the transfer be made under the Standard Contractual Clauses — Module Two (controller to processor), the ordinary case where you are the controller of your customers’ data, or Module Three where you are yourself processing personal data on behalf of another party. For UK transfers, the SCCs are intended to apply as varied by the UK International Data Transfer Addendum. For Swiss transfers, the SCCs are intended to apply with references to the GDPR and its supervisory authorities read as references to the Swiss FADP and the Federal Data Protection and Information Commissioner, and with the courts of Switzerland available to a data subject who habitually resides there. [counsel: everything in this section is a drafted proposal, not yet confirmed — see the items below.]
Execution (proposed). Our intent is that, by accepting this DPA — the same act that accepts the Terms of Service — each party would be deemed to have signed the SCCs at the relevant signature block in Annex I to the Appendix of the SCCs, using the same click-to-accept mechanism the rest of this DPA is accepted through, without a separate signature ceremony. That mechanism still depends on the party details inAnnex 1 being complete first — they are not yet (see the [bracketed] item there) — and if your procurement process needs a countersigned copy instead, ask us.
Populating the SCCs (proposed). Our approach, so we are not stating the same facts twice, is for this DPA’s own annexes to do double duty as the SCCs’ required annexes: Annex 1 (details of processing) as Annex I to the Appendix to the SCCs; Annex 2 (technical and organisational measures) as Annex II; the list at /legal/subprocessors as Annex III (authorised sub-processors). We also propose including the docking clause (so a GrowMoe affiliate could join as a party later) and, for Clause 17 (governing law) and Clause 18 (forum), the law and courts of Ireland for any EU transfer.
[counsel: this whole section needs review before any Merchant can rely on it, same as the rest of this draft — the Terms of Service currently say the same thing in different words, that a DPA is not yet in effect. In particular: (a) whether cross-referencing this DPA’s own Annex 1/Annex 2 and the subprocessors page actually satisfies the SCCs’ own Annex I/II/III requirements, or whether the formal SCC annexes need to be separately completed and attached instead; (b) that the Module Two/Module Three split above correctly covers every way a Merchant might use the Service; (c) the proposed docking-clause election; (d) the proposed Ireland governing-law/forum choice — the common pick for a US company’s SCCs (an English-speaking EU member state) but not the only option; (e) the UK IDTA’s own required tables, which are not yet completed; (f) whether a transfer impact assessment must be published or supplied on request; (g) do not state data-residency regions or specific hosting locations anywhere in this section until they are confirmed and contractually committed — the application supports a per-organisation data region setting, but no residency promise is made here.]
10. Assisting with data subject rights
You are responsible for responding to your data subjects. We will help, and the Service implements the Shopify data-subject webhooks so that most requests are handled automatically:
| Request | Mechanism | What happens |
|---|---|---|
| Access / portability | customers/data_request | We assemble the personal data we hold for that customer and make it available for you to give to the data subject. |
| Erasure | customers/redact | We scrub that customer’s personal data across the records we own and the records we mirror from Shopify, and propagate the erasure to the sub-processors that hold data for that person. Non-personal aggregates may be retained. |
| Store-wide purge | shop/redact | On uninstall, PII-classified fields are scrubbed promptly, and the store’s full data is deleted after a 30-day grace period. See section 14. |
For rectification, restriction, objection and portability requests that the webhooks do not cover, you can act directly in the app, or emailprivacy@growmoe.com and we will assist within a reasonable time. If a data subject contacts us directly, we will not respond on your behalf — we will refer them to you and tell you about it.
11. Personal data breach
If we become aware of a personal data breach affecting Merchant Personal Data, we will notify you without undue delay and give you the information you reasonably need to meet your own notification obligations — what we know about the nature of the breach, the categories and approximate volume of data and data subjects affected, the likely consequences, and the steps we are taking to address it and limit the damage. We will send follow-up information as the investigation progresses.
We will not notify a supervisory authority or a data subject about a breach of Merchant Personal Data on your behalf unless the law requires us to, or you ask us to in writing.
Our notification is not an admission of fault.
12. Data protection impact assessments
If you need to carry out a data protection impact assessment or a prior consultation with a supervisory authority about processing performed by the Service, we will give you the information we reasonably hold about how the Service processes personal data — the details in Annex 1, the measures in Annex 2, the sub-processor list, and answers to written questions about data flows. We may charge for assistance that goes materially beyond responding to reasonable written questions, and we will tell you before we do.
13. Audit and information rights
On written request, and no more than once a year unless a supervisory authority or a breach requires otherwise, we will:
- provide the documentation we hold about our security and privacy practices, including Annex 2 and the sub-processor list;
- answer a reasonable written security questionnaire about the processing under this DPA;
- confirm in writing the measures we have in place and any material change to them.
We do not offer on-site audits or direct access to our systems or production data. Granting third-party auditors access to a multi-tenant system would put other merchants’ data at risk, and we are a small team. Written responses and documentation are the audit mechanism we can genuinely support. If your obligations require more than this, raise it before you rely on the Service.
14. Retention, deletion and return
- While you are a customer, we keep Merchant Personal Data for as long as the Service needs it to work for you.
- Raw high-volume events — storefront and cart events, custom events, usage events and automation run records — are retained for a bounded window, currently a default of400 days, after which they are rolled up into non-personal aggregates or deleted. The window is configurable per organisation, subject to a floor enforced by your plan.
- On a customer erasure request, that person’s personal data is scrubbed as described in section 10.
- On uninstall or account closure, Shopify’s
shop/redactwebhook triggers prompt scrubbing of PII-classified fields, and the store’s full data is deleted after a 30-day grace period, propagating the deletion to sub-processors holding that data. Export anything you want to keep before you uninstall. - Return instead of deletion. If you ask before you uninstall, we will provide a machine-readable export of Merchant Personal Data rather than only deleting it.
- Exceptions. We may keep data we are required by law to keep, and de-identified aggregates that cannot be linked back to a data subject. Anything retained stays protected by this DPA. Backups age out on their own cycle and are not selectively edited.
15. Liability
Each party’s liability under this DPA is subject to the limitation of liability in theTerms of Service, except where Data Protection Laws or the SCCs do not permit that limit.
16. Term, precedence and changes
This DPA takes effect when you accept the Terms of Service and continues while we process Merchant Personal Data. If this DPA conflicts with the Terms of Service or the Privacy Policy on the processing of Merchant Personal Data, this DPA wins. If this DPA conflicts with the SCCs, the SCCs win.
We may update this DPA where a change in the Service or in Data Protection Laws requires it, so long as the change does not reduce the protection it gives you. Material changes are notified as described in the Terms of Service, and the “Last updated” date above is changed.
Annex 1 — Details of processing
| Subject matter | Provision of the GrowMoe Service to the Merchant: a B2B sales and customer platform that syncs data from the Merchant’s Shopify store and adds CRM, quoting, deals, support, marketing, subscriptions and analytics capabilities. |
|---|---|
| Duration | From installation until the app is uninstalled or the account is closed, plus the deletion window in section 14 (PII scrubbed promptly; full data deleted after a 30-day grace period following uninstall). |
| Nature of processing | Receiving data from Shopify webhooks and the Shopify Admin API; storing it; indexing and linking records into customer and company profiles; generating derived records (segments, scores, timelines, rollups); presenting it in the app and API; sending messages the Merchant instructs; deleting and exporting on request. |
| Purpose of processing | Solely to provide, secure and support the Service for the Merchant, and to follow the Merchant’s instructions. No independent use, no sale, no advertising, no profiling for our own purposes. |
| Categories of data subjects | The Merchant’s customers and prospective customers; contacts at the Merchant’s business customers (B2B company contacts); visitors to the Merchant’s storefront who are tracked with consent; the Merchant’s own staff who use the Service. |
| Categories of personal data | Identity and contact data (name, email, phone, addresses); company and role data; commerce data (orders, line items, carts, quotes, payment and fulfilment status — no card numbers); interaction data (support messages, notes, activity timeline, email engagement); consent and marketing-preference records; storefront behavioural events tied to a pseudonymous identifier; account data for the Merchant’s staff (name, email, role, audit trail). |
| Special categories of data | None. The Service is not built for special-category data, and the Merchant must not upload it (see the acceptable-use and customer-data sections of theTerms of Service). |
| Frequency of processing | Continuous, for as long as the app is installed: webhook-driven and near real-time, plus scheduled syncs and backfills. |
| Recipients | GrowMoe personnel on a need-to-know basis, and the sub-processors listed at/legal/subprocessors. |
Roles: the Merchant is the controller (or, where the Merchant processes on behalf of another party, the processor) and GrowMoe, LLC is the processor. Contact for both parties on data protection matters: privacy@growmoe.com for GrowMoe; the Merchant’s account contact for the Merchant.
[counsel: the SCCs (see section 9) require each party’s full legal name, address, contact person’s name/position/details, and signature. GrowMoe’s postal address and named contact person are still to be supplied here, and the Merchant’s details need a fill-in mechanism (a form field in the app, or a countersigned copy) — until they are, the deemed-signature mechanism section 9 proposes has nothing to point at.]
Annex 2 — Technical and organisational measures
These are the measures actually in place. Nothing is listed here aspirationally.
| Encryption | Shopify access tokens and other secrets are encrypted at rest with AES-256-GCM before storage. [counsel: confirm whether the platform-level storage encryption Cloudflare D1 provides for the remainder of Merchant Personal Data should be represented here — it is not independently documented or committed to elsewhere in our own materials.] Data in transit between the Merchant, Shopify and the Service is encrypted with TLS. |
|---|---|
| Tenant isolation | Every record belonging to a Merchant carries an org_id, and application code can only reach data through a tenant-scoped database port that applies that scope. There is no code path that reads across organisations. |
| Access logging | Access to customer personal data is logged. Writes are captured as field-level change records and entity snapshots, attributed to the acting user or system principal. |
| Access control | Access inside the Service is role-based: each operation declares the roles that may run it, and the check runs centrally on every write. Internal administrative access is limited to the personnel who need it and is attributed to a named principal. |
| Data minimisation at the integration boundary | We request one fixed set of Shopify access scopes for every install, minimised at the app level — for example, we do not request read_users orread_all_orders. We do not yet vary that request by which capabilities a given Merchant has switched on, including for Protected Customer Data; per-capability scope minimisation is not implemented today. |
| Minimisation in telemetry | Product-analytics and error-tracking sub-processors receive personal-data-minimised payloads only: pseudonymous identifiers, event names, non-personal properties, tags and opaque ids. Personal data is stripped before send using a hand-maintained list of personal-data field names (email, phone, name fields, address, IP), filtered out of every event payload. Session replay is disabled in the client — there is currently no code path to enable it. |
| No card data | We never receive or store payment card numbers or security codes. Billing runs through Shopify’s Billing API; card data is handled and tokenised by the billing rail, and we hold only references. |
| Erasure and retention controls | Automated handling of Shopify’s data-subject webhooks (see section 10), a bounded retention window for raw high-volume events (see section 14), and propagation of erasure to sub-processors that hold the affected data. |
| Change control | All changes to the Service are version-controlled and reviewed before release, with automated checks in continuous integration. |
17. Contact
Data protection questions, data subject request assistance, sub-processor objections and DPA requests: privacy@growmoe.com.
GrowMoe, LLC — a Delaware limited liability company.