Last updated: July 20, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between the merchant ("Merchant", the data controller) and Promptly ("Promptly", "we", the data processor) governing Promptly's processing of personal data on the Merchant's behalf when the Merchant installs and uses the Promptly application. By installing Promptly, the Merchant agrees to this DPA. It supplements our Privacy Policy.
The Merchant is the controller of personal data relating to its customers, prospective customers, and store visitors. Promptly is the processor, processing that data only on the Merchant's documented instructions (which include the Merchant's configuration of the app) and as described in this DPA and our Privacy Policy.
| Data subjects | Personal data processed |
|---|---|
| The Merchant's customers, prospective customers, and store visitors | Email address, phone number, name (where a popup collects it), popup/quiz responses submitted by the visitor, marketing consent state and timestamp, and randomly-generated anonymous visitor identifiers with visit context (device, language, country, page URL, UTM parameters) |
Promptly does not process special categories of personal data and does not process customer addresses or payment data.
The Merchant authorises Promptly to engage the following sub-processors. We remain responsible for their performance and impose data-protection terms no less protective than this DPA.
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Application hosting (Workers) | Global edge |
| Neon, Inc. | Database (PostgreSQL) | United States |
| Shopify Inc. | Platform & customer records | Per Shopify |
| The Merchant's connected marketing platform (e.g. Klaviyo, Postscript, Attentive, Mailchimp) | Marketing sync — only when the Merchant connects it | Per provider |
We will give the Merchant notice of new sub-processors and an opportunity to object.
Encryption in transit (TLS) on all connections; encryption at rest for the database and encrypted managed backups; additional application-layer AES-256 encryption of stored third-party credentials and of subscriber contact details (email addresses and phone numbers); least-privilege access limited to the app operator; separation of test and production environments; and logging of access to personal data. Full detail: Security & Incident Response Policy.
Personal data is retained for the life of the installation. On an individual erasure request (Shopify customers/redact) we erase that customer's personal data. On uninstall / shop erasure (Shopify shop/redact) we delete all of the Merchant's store data. The Merchant may also disable Shopify customer sync at any time in the app settings.
We support Shopify's mandatory privacy webhooks (customers/data_request, customers/redact, shop/redact) and assist the Merchant in fulfilling access, correction, and deletion requests within applicable timeframes.
We will notify the Merchant without undue delay after becoming aware of a personal data breach affecting the Merchant's data, with the information the Merchant reasonably needs to meet its own notification obligations. See our incident response process in the Security Policy.
Where personal data is transferred across borders, we rely on appropriate safeguards (such as Standard Contractual Clauses) offered by our sub-processors.
On reasonable request, we will make available information necessary to demonstrate compliance with this DPA, including our sub-processors' third-party audit reports (e.g. SOC 2) where available.
Data protection enquiries: support@promptlyapp.co