Data Processing Agreement

Last updated: July 20, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between the merchant ("Merchant", the data controller) and Promptly ("Promptly", "we", the data processor) governing Promptly's processing of personal data on the Merchant's behalf when the Merchant installs and uses the Promptly application. By installing Promptly, the Merchant agrees to this DPA. It supplements our Privacy Policy.

1. Roles

The Merchant is the controller of personal data relating to its customers, prospective customers, and store visitors. Promptly is the processor, processing that data only on the Merchant's documented instructions (which include the Merchant's configuration of the app) and as described in this DPA and our Privacy Policy.

2. Subject matter, duration, nature and purpose

3. Categories of data subjects and personal data

Data subjectsPersonal data processed
The Merchant's customers, prospective customers, and store visitorsEmail address, phone number, name (where a popup collects it), popup/quiz responses submitted by the visitor, marketing consent state and timestamp, and randomly-generated anonymous visitor identifiers with visit context (device, language, country, page URL, UTM parameters)

Promptly does not process special categories of personal data and does not process customer addresses or payment data.

4. Processor obligations

5. Sub-processors

The Merchant authorises Promptly to engage the following sub-processors. We remain responsible for their performance and impose data-protection terms no less protective than this DPA.

Sub-processorPurposeLocation
Cloudflare, Inc.Application hosting (Workers)Global edge
Neon, Inc.Database (PostgreSQL)United States
Shopify Inc.Platform & customer recordsPer Shopify
The Merchant's connected marketing platform (e.g. Klaviyo, Postscript, Attentive, Mailchimp)Marketing sync — only when the Merchant connects itPer provider

We will give the Merchant notice of new sub-processors and an opportunity to object.

6. Security measures

Encryption in transit (TLS) on all connections; encryption at rest for the database and encrypted managed backups; additional application-layer AES-256 encryption of stored third-party credentials and of subscriber contact details (email addresses and phone numbers); least-privilege access limited to the app operator; separation of test and production environments; and logging of access to personal data. Full detail: Security & Incident Response Policy.

7. Retention and deletion

Personal data is retained for the life of the installation. On an individual erasure request (Shopify customers/redact) we erase that customer's personal data. On uninstall / shop erasure (Shopify shop/redact) we delete all of the Merchant's store data. The Merchant may also disable Shopify customer sync at any time in the app settings.

8. Data subject requests

We support Shopify's mandatory privacy webhooks (customers/data_request, customers/redact, shop/redact) and assist the Merchant in fulfilling access, correction, and deletion requests within applicable timeframes.

9. Personal data breach

We will notify the Merchant without undue delay after becoming aware of a personal data breach affecting the Merchant's data, with the information the Merchant reasonably needs to meet its own notification obligations. See our incident response process in the Security Policy.

10. International transfers

Where personal data is transferred across borders, we rely on appropriate safeguards (such as Standard Contractual Clauses) offered by our sub-processors.

11. Audit

On reasonable request, we will make available information necessary to demonstrate compliance with this DPA, including our sub-processors' third-party audit reports (e.g. SOC 2) where available.

12. Contact

Data protection enquiries: support@promptlyapp.co