Discount Rescue
Data Processing Agreement
This Data Processing Agreement (“DPA”) governs our processing of data on your behalf when you install the app on your Shopify store and use Discount Rescue. It takes effect automatically when you do, and no signature is required for it to bind us.
If your organisation requires a countersigned copy, or a copy on your own paper, write to support@orumio.com and we will provide one.
1. Parties and definitions
“Processor”, “we”, “us”: Orumio, represented by Masanori Iwata, Mitsuhashi Building 3F, 1-3-3 Kita-Aoyama, Minato-ku, Tokyo 107-0061, Japan, contact support@orumio.com.
“Controller”, “you”, “Merchant”: the operator of the Shopify store in which the App is installed.
“App”: Discount Rescue. “Personal Data”, “Processing”, “Data Subject”, “Personal Data Breach” and “Supervisory Authority” have the meanings given in the GDPR. “Data Protection Law” means every privacy or data protection law applicable to the Processing under this DPA, including the EU GDPR, the UK GDPR, Japan’s Act on the Protection of Personal Information (APPI), and the US state privacy laws addressed in Annex IV. “Merchant Commercial Data” means the non-personal business data the App processes for you — the failed discount-code events in your checkout, the cart subtotals recorded with them, the rescue codes the App issues and their outcomes, your settings, and the daily counters computed from all of it.
2. Roles and scope
You are the Controller of the Personal Data in your Shopify store. We are your Processor, and we process that Personal Data only to provide the App to you.
In practice there is very little of it: the App is built so that no Personal Data about a shopper is read or stored at all. What it handles are checkout identifiers, the truncated text typed into a discount field, amounts, and order-level fields carrying no customer attribute.
Shopify is an independent party to this DPA. Your relationship with Shopify, including Shopify’s own role in respect of your store data, is governed by your agreement with Shopify and not by this document.
This DPA applies for as long as the App has access to your Shopify store and survives uninstallation for as long as we hold any of your data.
3. Instructions
We process data only on your documented instructions, including in respect of transfers to a third country. Your instructions are: (a) this DPA, including Annex I; (b) the App’s documented functionality, which you direct by configuring the App’s rescue settings in your store; and (c) any further written instruction you give us that we accept.
We will tell you if, in our opinion, an instruction infringes Data Protection Law. We will not process your data for our own purposes — specifically not for marketing, advertising, profiling, resale, cross-customer benchmarking, or the training of machine-learning models.
If we are required by law to process data beyond your instructions, we will inform you of that legal requirement before processing, unless the law forbids us from doing so on important grounds of public interest.
4. Confidentiality
The App is operated by a single person, who is bound by a duty of confidentiality in respect of all data processed under this DPA. There are no staff accounts, contractors, or support agents with access to Merchant data. If that ever changes, we will ensure that any person authorised to process your data is placed under an equivalent obligation of confidentiality before access is granted.
Merchant Commercial Data is confidential business information even where it is not Personal Data. We apply the measures in Annex II to it in full, and we do not disclose it, aggregate it across customers, or use it for any purpose other than providing the App to you.
5. Security
We implement and maintain the technical and organisational measures set out in Annex II, which are appropriate to the risk, having regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of the Processing.
The primary measure is minimisation: the App stores no name, email address, phone number, postal address or card data, and requests no Level 2 protected customer data field from Shopify. We may update the measures in Annex II over time, but we will not reduce the overall level of security.
6. Sub-processors
You give us general written authorisation to engage sub-processors. The sub-processors engaged as at the effective date of this DPA are listed in Annex III.
Before we add or replace a sub-processor we will update Annex III and announce the change to customers with an active installation at least 30 days in advance. You may object on reasonable data protection grounds within that period; if we cannot resolve your objection, you may terminate by uninstalling the App, and we will delete your data in accordance with §10.
We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for each sub-processor’s performance.
7. Assistance with data subject rights
Because the App stores no shopper Personal Data, requests to access, rectify, erase, restrict, port or object usually require no action from us — the data lives in Shopify, under your control.
Where a Data Subject nonetheless contacts us directly, we will not respond substantively ourselves. We will refer them to you, and tell you promptly. Taking account of the nature of the Processing, we will assist you by appropriate technical and organisational measures, so far as possible, in fulfilling your obligation to respond.
We honour the Shopify mandatory compliance webhooks: customers/data_request (we return nothing, because we hold nothing), customers/redact (no action required, for the same reason — the App stores no customer identifier for one to match), and shop/redact (we delete your entire tenant, per §10).
8. Personal data breach
We will notify you of a Personal Data Breach affecting your data without undue delay after becoming aware of it, and in any event targeting within 72 hours of confirming it. The notification will describe, so far as it is known at the time: the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed. Where the information cannot be provided at once, we will provide it in phases without further undue delay rather than waiting for a complete root-cause analysis. We apply the same notification commitment to incidents affecting Merchant Commercial Data or your platform credentials.
We maintain a written security incident response policy covering detection, containment, assessment, notification, remediation and post-incident review, and we review it after every significant incident.
9. Data protection impact assessments
Taking into account the nature of the Processing and the information available to us, we will provide reasonable assistance with your data protection impact assessments and any prior consultation with a Supervisory Authority.
10. Deletion and return
- On uninstallation, we delete the stored Shopify credentials immediately and mark the installation as gone, so no further Processing can occur.
- On receipt of Shopify’s
shop/redactrequest (approximately 48 hours after uninstallation), we delete your installation record and everything attached to it — settings, checkout records, failed-code events, rescues, rescued orders and counters. - As a backstop against a lost webhook, the App deletes any installation that has been uninstalled for more than 30 days, with the same cascade.
- Independently of uninstallation, the App deletes checkout-level records after 90 days and rescues and rescued orders after 13 months, on a schedule, while the App is still installed.
- You may request earlier deletion at any time by writing to the contact address in §1.
Operational logs contain identifiers, classifications, counts and timestamps only, and no Personal Data; they expire on our hosting provider’s ordinary schedule.
11. Audits and information
We will make available to you all information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
In the first instance we will respond to a reasonable written request with our data protection policy, our incident response policy, and a written description of the measures in Annex II. An on-site inspection may be requested where that is not sufficient, on reasonable notice, no more than once in any twelve-month period except following a Personal Data Breach, and subject to confidentiality.
12. International transfers
We are established in Japan, and the App’s database and application servers are located in the United States (Annex III).
Where Personal Data protected by the EU GDPR is transferred to a country without an adequacy decision, the Standard Contractual Clauses approved by the European Commission (Implementing Decision (EU) 2021/914), Module Two (controller to processor) are incorporated into this DPA by reference and take precedence over it in the event of conflict. For the purposes of those Clauses: you are the data exporter and we are the data importer; the optional docking clause applies; the general authorisation for sub-processors in §6 applies with 30 days’ notice; the governing law is that of Ireland; disputes are resolved in the courts of Ireland; and Annexes I, II and III below serve as Annexes I, II and III to the Clauses.
Where Personal Data protected by the UK GDPR is transferred, the UK International Data Transfer Addendum to the EU SCCs (version B1.0) is incorporated by reference, with the information in Annexes I–III below completing its Tables.
Japan has received an adequacy decision from the European Commission, and the United Kingdom has made an equivalent finding.
13. Japan (APPI)
Where Japan’s Act on the Protection of Personal Information applies, we act as a party entrusted with the handling of personal data (委託先) under Article 27(5)(i), and you retain the supervisory obligation under Article 25. The measures in Annex II are the measures we take for that purpose, and §12 records the locations of the servers on which the data is held.
14. Term, precedence and liability
This DPA takes effect when you install the app on your Shopify store and continues until we hold no data of yours. Where it conflicts with any other agreement between us, this DPA prevails on data protection matters; where it conflicts with the Standard Contractual Clauses, those Clauses prevail.
Nothing in this DPA limits either party’s liability to a Data Subject or to a Supervisory Authority under Data Protection Law.
15. Governing law
This DPA is governed by the laws of Japan, and the Tokyo District Court has exclusive jurisdiction as the court of first instance over any dispute arising from it. §12 governs the law and forum applicable to the Standard Contractual Clauses themselves.
Annex I — Details of the processing
A. Parties
Data exporter / Controller: the Merchant, being the operator of the Shopify store in which the App is installed. Contact details are those held in the Merchant’s Shopify account. Role: controller.
Data importer / Processor: Orumio, represented by Masanori Iwata, Mitsuhashi Building 3F, 1-3-3 Kita-Aoyama, Minato-ku, Tokyo 107-0061, Japan, contact support@orumio.com. Activities: providing the Discount Rescue app. Role: processor.
B. Description of the processing
| Categories of Data Subjects | Shoppers checking out in the Merchant’s store; the Merchant’s own staff who use the App |
|---|---|
| Categories of Personal Data | None by design. The App processes the checkout identifier, the text entered into the discount field (stored as its first four characters and its length when longer than eight), the cart subtotal, and — where Shopify has granted access — order-level fields (order identifier, name, total, discount codes, checkout identifier). No name, email address, phone number, postal address or card data is requested, read or stored, and no Level 2 protected customer data field is declared to Shopify |
| Sensitive data | None. The App neither requests nor processes special categories of data |
| Frequency | Continuous while the App is installed: on each checkout in which a discount code is refused, and once per order created in the store |
| Nature and purpose | Detecting a refused discount code in the Merchant’s checkout, deciding against the Merchant’s configured limits whether to offer an alternative, issuing and withdrawing single-use discount codes, and reporting the outcome to the Merchant. Order data is processed for one purpose only: to identify which orders carried a rescue code |
| Retention | Checkout-level records: 90 days. Rescues and rescued orders: 13 months. Aggregate daily counters, containing no identifier: for the duration of installation. On uninstallation, all of it is deleted per §10 (Shopify redaction at approximately 48 hours; 30-day backstop) |
| Sub-processor processing | As set out in Annex III, for the duration of the relationship |
C. Competent supervisory authority
The supervisory authority of the EU/EEA Member State in which the Merchant, as data exporter, is established; or, where the Merchant is not established in the EU/EEA but is subject to the GDPR under Article 3(2), the supervisory authority of the Member State in which the Merchant’s Article 27 representative is established.
Annex II — Technical and organisational measures
These are the measures actually implemented in the App, in order of how much risk each removes.
- Data minimisation as the primary control. No shopper name, email address, phone number, postal address or card data is read or stored at any point, and no Level 2 protected customer data field is declared to Shopify. Card field values are redacted by Shopify before the App can observe them; the discount-field text, which can be a gift card number, is truncated to its first four characters and its length before it is written. Data that was never stored cannot be exfiltrated from storage, exposed in a backup, or disclosed by a database compromise.
- A sandboxed collector that forwards a fixed list. The checkout pixel runs in Shopify’s strict sandbox and forwards four event kinds — checkout started, discount-field input, the displayed alert, checkout completed. Every other checkout event is dropped inside the sandbox and never reaches our server.
- Issuance requires the App’s own checkout block, authenticated. The block’s reports and its reads of a rescue carry the checkout session token Shopify signs with the App’s secret for that store; the App refuses a request without a valid one. A discount code is issued only for a checkout on which the block has so reported itself live.
- Deterministic rate limits. At most sixty rescues per store per rolling minute, at most five hundred per store per UTC day — past which the App switches rescue off for that store and says so to the Merchant — at most five discount-code alerts per checkout, and at most three hundred recorded alerts per store per minute. All are counted from stored rows rather than from process memory, so they hold across a serverless fleet.
- Encryption in transit. The App is served exclusively over HTTPS/TLS. The database connection requires TLS.
- Encryption at rest. The database provider encrypts all data and backups at rest (AES-256, provider-managed). No self-managed backup, export or snapshot pipeline exists, so no unencrypted copy of the database exists anywhere.
- Application-layer encryption of the store credential. The Shopify access and refresh tokens are additionally encrypted by the App before they are written, with AES-256-GCM under a key held in the runtime environment and never in the database. The store’s domain is bound in as additional authenticated data, so a record moved between stores fails authentication rather than decrypting. A copy of the database alone does not yield a usable credential for any store.
- Tenant isolation. Row-level tenancy: every domain record reaches the installation record by foreign key and every query filters through it.
- Bounded egress. While processing your data, the App communicates server-side with one destination: the Shopify Admin API. One further request carries none of it — the public pages on this domain are fetched from Orumio’s own hub site, which receives no store data. There is no analytics SDK and no error-reporting service receiving payloads.
- Log hygiene. Logs record identifiers, classifications, counts and timestamps only. Fields whose names indicate a credential are replaced with a marker before the line is written, and checkout identifiers are truncated, so a log line cannot be replayed against the App.
- Endpoint authorisation. Merchant routes require an authenticated Shopify admin session; the scheduled job requires a bearer secret and refuses to run when the secret is unset; webhook routes reject an invalid HMAC signature before the payload is parsed.
- Order access gated per store. Order data is read only where Shopify has granted protected customer data access to that store. A store without it has its order notifications acknowledged and discarded unread, and the App stores nothing about any order.
- Client exposure boundary. Credentials never leave the server. Route loaders return only the fields the interface renders; raw platform responses are never shipped to the browser.
- Scheduled destruction of the codes we create. Rescue discount codes are single-use, expire thirty minutes after issue, and are deleted from the Merchant’s admin by a scheduled job — including the applied ones, once the rescue has settled.
- Access control. Single operator; no staff accounts, contractors or support agents. Every account in scope is protected by two-factor authentication and a unique password generated and stored in a password manager. Access is reviewed whenever the operator set changes.
- Governance. A written data protection policy and a written security incident response policy are maintained and reviewed at each release gate and after every significant incident.
Annex III — Sub-processors
| Sub-processor | Purpose | Location | Data |
|---|---|---|---|
| Vercel Inc. | Application hosting, the scheduled cleanup job and runtime logs | United States | Data in transit while a request is served, plus the runtime logs described under logging |
| Neon Inc. | Database (Postgres), encrypted at rest with automated backups | United States | Everything the app stores, as listed above, at rest |
Shopify is not listed as a sub-processor: it is the platform on which your store and its checkout run, and the source from which we read, under your own separate agreement with Shopify. The App engages no affiliate network, no email provider and no analytics service, so there is nothing else to name here.
Annex IV — United States state privacy laws
Where the California Consumer Privacy Act as amended (CCPA/CPRA) or a comparable US state privacy law applies, we act as a service provider (or processor, where that is the statutory term) and:
- we do not sell or share personal information, as those terms are defined in the CCPA, and we receive no consideration for it;
- we do not retain, use, or disclose personal information for any purpose other than the business purposes specified in this DPA, including not for our own commercial purposes;
- we do not combine personal information received from you with personal information received from any other source, except as permitted by the CCPA;
- we will notify you if we determine we can no longer meet these obligations;
- you may take reasonable and appropriate steps to stop and remediate any unauthorised use of personal information.
The App performs no cross-context behavioural advertising, no profiling for advertising or marketing purposes, and no automated decision-making producing legal or similarly significant effects.
Discount Rescue · Version 1.0, 6 September 2026 · Privacy Policy
Discount Rescue is an independent product of Orumio and is not affiliated with, endorsed by, or sponsored by Shopify Inc. Shopify is a trademark of its owner.