Persistent Cart · Legal

DATA PROCESSING AGREEMENT

Effective date: 2026-10-01

This Data Processing Agreement ("DPA") forms part of the Terms of Service for the Persistent Cart application ("App") and is entered into between:

PÉCI Kft., Aradi utca 5., 2119 Pécel, Hungary (Cg. 13-09-089813; EU VAT HU12761609) ("Processor", "we", "us"); and

the Merchant — the Shopify store owner who installs the App ("Controller", "you").

You accept this DPA together with the Terms of Service, in the acceptance step the App shows after installation and before its first use (Terms of Service, Section 3A). It is incorporated by reference into the Terms of Service and, on any question of data protection, prevails over the Terms of Service, the Privacy Policy and the Cookie Policy.


1. Definitions

Terms not defined here carry the meaning given in Regulation (EU) 2016/679 ("GDPR").

2. Roles of the parties

2.1 In respect of Customer Personal Data, the Controller is the controller and the Processor is the processor (GDPR Art.4(7)–(8)).

2.2 In respect of Merchant account, billing and usage data, the Processor acts as an independent controller. That processing is governed by the Privacy Policy, not by this DPA.

2.3 The Controller is responsible for establishing and maintaining a lawful basis for the processing it instructs, and for providing the notices its own customers are entitled to.

3. Subject-matter, duration, nature and purpose

3.1 Subject-matter and purpose. Providing cart persistence across devices, the Share a Cart link feature, and order attribution analytics, as further specified in Annex 1.

3.2 Duration. For as long as the App is installed, plus the retention periods set out in Annex 1.

3.3 Nature of processing. Collection, storage, retrieval, structuring, transmission to the Controller's own Shopify storefront, and erasure.

3.4 Categories of data subject and personal data. As set out in Annex 1.

4. Processor obligations

The Processor shall:

4.1 Process only on documented instructions from the Controller, including as to international transfers, unless required otherwise by Union or Member State law to which the Processor is subject; in that case the Processor shall inform the Controller before processing, unless that law prohibits it on important grounds of public interest. The Controller's documented instructions consist of this DPA, the Terms of Service, the App's configuration settings, and any further written instruction the parties agree.

4.2 Immediately notify the Controller if, in the Processor's opinion, an instruction infringes Applicable Data Protection Law (GDPR Art.28(3), final paragraph).

4.3 Ensure confidentiality. Personnel authorised to process Customer Personal Data are bound by contractual or statutory confidentiality obligations and process it only on the Controller's instructions (GDPR Art.32(4)).

4.4 Implement Art.32 security measures, as described in Annex 2.

4.5 Respect the conditions for engaging Sub-processors set out in Section 6.

4.6 Assist the Controller with data-subject requests, as set out in Section 7.

4.7 Assist the Controller with GDPR Art.32–36 obligations (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of processing and the information available to the Processor.

4.8 Delete or return Customer Personal Data at the end of the provision of services, and delete existing copies, as set out in Section 9.

4.9 Make available all information necessary to demonstrate compliance with Art.28, and allow for and contribute to audits, as set out in Section 10.

5. Controller obligations

5.1 The Controller warrants that it has a lawful basis for the processing it instructs, and that it has provided its customers with any notice required by Applicable Data Protection Law, including notice that the App is installed on its store.

5.2 Where the Controller's jurisdiction requires consent for any processing carried out through the App, the Controller is responsible for obtaining it. The App reads the customer's marketing consent from Shopify's Customer Privacy API: Share a Cart link clicks, and the order attribution built on them (Annex 1), are recorded only when marketing is allowed. An order is attributed only through the cart token recorded with the click; there is no strict or flexible mode. The Processor stores the cart token only as its one-way SHA-256 hash, never the raw token (data minimisation). Saving and restoring carts are strictly necessary and do not depend on consent.

5.3 The Controller is responsible for the content of any text it configures in the App that is displayed to its customers.

6. Sub-processors

6.1 General authorisation. The Controller grants the Processor general written authorisation to engage Sub-processors, subject to this Section.

6.2 Current Sub-processors at the effective date:

Sub-processorRoleData sharedRegionTransfer safeguard
Vercel Inc.Application hosting and edge deliveryAll data in transit; transient IP addresses at the edgeUnited StatesEU–US Data Privacy Framework and/or Standard Contractual Clauses
Neon, LLC (a Databricks, Inc. company)PostgreSQL database hosting (provisioned via Vercel Marketplace)All persisted dataUnited StatesDatabricks/Neon EU–US Data Privacy Framework certification; SCCs as fallback
Amazon Web Services (Amazon Simple Email Service)Delivery of the customer data e-mail to the Controller when Shopify forwards a customer's access request (customers/data_request)The data the App holds about the requesting customer, in transit onlyeu-west-1 (Ireland, EU)Processed within the EU; no third-country transfer for this processing

6.3 Shopify is not a Sub-processor. Shopify is the independent platform on which both parties operate and, in respect of storefront customer data, acts as an independent controller under its own terms. Data reaches the App from Shopify; Shopify does not process on the Processor's instruction.

6.4 Changes. The Processor shall give the Controller at least 30 days' prior notice, by email to the store's contact e-mail address, of any intended addition or replacement of a Sub-processor. The Controller may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection, the Controller may terminate the affected part of the service by uninstalling the App, with a pro-rata refund of any prepaid fees for the unused period.

6.5 Flow-down and liability. The Processor shall impose on each Sub-processor, by written contract, data-protection obligations no less protective than those in this DPA, and remains fully liable to the Controller for the Sub-processor's performance.

7. Data-subject requests

7.1 The App implements Shopify's mandatory GDPR webhooks. Requests routed through Shopify (customers/data_request, customers/redact, shop/redact) are handled automatically, as described in Annex 1.

7.2 Where a data subject contacts the Processor directly, the Processor shall not respond on the substance but shall refer the data subject to the Controller and inform the Controller without undue delay.

7.3 Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller's obligation to respond to requests under GDPR Chapter III.

8. Personal data breach

8.1 The Processor shall notify the Controller without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting Customer Personal Data.

8.2 The notification shall describe, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the information cannot be provided at once, it shall be provided in phases without undue further delay.

8.3 Notification is not an acknowledgement of fault or liability.

9. Deletion and return of data

9.1 On uninstall or shop/redact. The Processor purges Merchant and shop personal data and all Shopify access tokens promptly — within 30 days of the triggering event, and typically within 48 hours of receiving the webhook. This is subject to Sections 9.2 (order-attribution records), 9.3 (uninstall record) and 9.4 (compliance records), which set out everything within this DPA that is not purged at once. Merchant account records that the Processor keeps longer as its own records (the usage summary for 30 days after uninstall, the record of the Controller's acceptance of the Terms of Service for 5 years after uninstall) are governed by the Privacy Policy (Section 2.2).

9.2 Order-attribution records. Order-attribution records (OrderConversion) are deleted on customers/redact (the records matched by the customer's cart tokens or by the orders Shopify lists in the request) and on shop/redact (all records of the shop). Records that no redact webhook reaches are deleted 365 days after creation, and those of an uninstalled shop 30 days after the uninstall.

9.3 Uninstall record. A single record (shop domain, last plan name, uninstall timestamp) is retained for 30 days after the uninstall, so that a reinstall within that period is recognised and recorded with the previous plan, and then deleted. It contains no customer personal data and no access tokens.

9.4 Retained compliance records. The App keeps an event log (AuditLog). Its ordinary operational entries are retained for 90 days and are deleted on shop/redact, or, if that webhook does not arrive, 30 days after the uninstall. Three entry types are the exception: the records of GDPR webhook handling (customers/data_request, customers/redact, shop/redact), which are retained for 3 years and survive a shop redaction.

The reason, stated plainly: Shopify sends shop/redact roughly 48 hours after an uninstall, so deleting these entries with the rest would destroy, within two days, the Processor's proof that an erasure requested earlier was actually carried out — and that proof is the entire purpose of the record. By accepting this DPA, the Controller instructs the Processor to keep these entries for that period, so that the Processor can demonstrate, under GDPR Art.28(3)(h), that the Controller's erasure instructions were carried out. These entries hold Shopify's own request identifiers (x-shopify-webhook-id, the data-request id) and row counts, enforced by an allowlist in the code; they carry no customer identifier. The shop domain does remain in them, which is a business identifier of the Controller; where the Merchant is an individual trader, it may also be the Merchant's personal data.

Some operational entries carry a Shopify customer ID: the cart-session events (cart_session_created, cart_session_rejected, which also carry the cart token), the share-link event (create_short_url), the saved-cart events (saved_cart_restored, saved_cart_cleaned_up_on_order) and the order events (order_converted_exact, order_no_attribution, which also carry the order id and cart token). Every entry carrying the customer's ID is deleted on customers/redact for the customer concerned; all operational entries are deleted after 90 days.

9.5 Return. The App has no self-service export. Before uninstalling, the Controller may request a copy of its data (the categories in Annex 1) by email to privacy@peci.io. The Processor sends the copy only to the store's contact e-mail address or to the e-mail address of the store owner's account, and otherwise asks for confirmation first. It provides the copy as a machine-readable (JSON) file, without access tokens, within 30 days. Uninstalling the App is the Controller's instruction to delete under Section 9.1; after deletion, return is no longer possible.

10. Audit

10.1 The Processor shall make available to the Controller all information necessary to demonstrate compliance with GDPR Art.28, on written request and no more than once per twelve-month period, unless required more frequently by a supervisory authority, following a personal data breach, where the Controller has reasonable grounds to suspect non-compliance, or where the Controller needs the information to answer a request of a data subject or of a supervisory authority, or otherwise to demonstrate its own compliance under Applicable Data Protection Law.

10.2 The Processor may satisfy this obligation by providing its security documentation and, where available, third-party certifications or audit reports of its Sub-processors.

10.3 On-site audits shall be at the Controller's expense, on at least 30 days' written notice, during business hours, subject to confidentiality undertakings, and conducted so as not to disrupt the Processor's business or the confidentiality of other customers' data.

11. International transfers

11.1 Customer Personal Data is hosted by Sub-processors in the United States, as set out in Section 6.2.

11.2 Transfers are made under the EU–US Data Privacy Framework where the recipient is certified, and otherwise under the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Three (processor to processor), which are incorporated into this DPA by reference. Where the Controller is established outside the European Economic Area, Customer Personal Data that the Processor returns or sends to the Controller (including the customer data e-mail described in Annex 1 and a copy under Section 9.5) is transferred under Module Four (processor to controller) of the same Clauses, likewise incorporated by reference.

11.3 Where the UK GDPR applies, the UK International Data Transfer Addendum to the SCCs applies.

11.4 The Processor shall conduct and document transfer impact assessments as required, and shall notify the Controller if it becomes unable to comply with this Section.

12. United States state privacy terms

12.1 This Section applies where the Controller is subject to the California Consumer Privacy Act as amended ("CCPA"), or to the consumer privacy statutes of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or other US states with materially similar processor/service-provider requirements.

12.2 Service provider / processor status. The Processor acts as a "service provider" (CCPA) or "processor" (other states) with respect to Customer Personal Data.

12.3 Restrictions (CCPA §1798.140(ag), §7051 of the CCPA Regulations). The Processor shall not:

12.4 The Processor certifies that it understands and will comply with the restrictions in Section 12.3. The Processor shall comply with all applicable sections of the CCPA and its regulations with respect to Customer Personal Data, and shall provide the same level of privacy protection as the CCPA requires of the Controller (11 CCR §7051(a)(5)).

12.5 The Processor shall notify the Controller if it determines it can no longer meet its obligations under Applicable Data Protection Law, and the Controller may take reasonable steps to stop and remediate unauthorised use.

12.6 Controller's right to verify. The Controller may take reasonable and appropriate steps to ensure that the Processor uses Customer Personal Data consistently with the Controller's obligations under the CCPA, including the information and audit rights in Section 10, which apply to CCPA compliance as they apply to GDPR Art.28 (11 CCR §7051(a)(6)).

12.7 Deidentified data. Where the Processor holds deidentified data, it shall maintain it in deidentified form and shall not attempt to reidentify it.

12.8 Other US state laws. Where the Controller is subject to a US state law named in Section 12.1, Sections 4.7, 7.3 and 10 apply to the Controller's obligations under that law as they apply under the GDPR. In particular, the Processor assists the Controller in responding to consumer requests and in conducting data protection assessments, and makes available, on the Controller's reasonable request, the information necessary to demonstrate compliance with the processor obligations of that law.

12.9 Assessments. The Controller, or an assessor it designates, may conduct reasonable assessments under Section 10.3. Alternatively, the Processor may arrange, at its own cost, for a qualified and independent assessor to assess its policies and technical and organisational measures against an appropriate and accepted control standard, at least once a year, and provides the report to the Controller on request.

12.10 Security duties. The Processor is responsible for the security of the App and its infrastructure, as described in Annex 2. The Controller is responsible for the security of its Shopify store and of access to its store account.

12.11 Subcontractors. Section 6 applies to any subcontractor the Processor engages to process Customer Personal Data under the CCPA: the Controller is notified under Section 6.4, and each subcontractor is bound by written contract to the restrictions in Section 12.3.

13. Liability and order of precedence

13.1 Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except that nothing in this DPA or the Terms of Service limits either party's liability under GDPR Art.82 or any other liability that cannot lawfully be excluded or limited.

13.2 In the event of conflict, this DPA prevails over the Terms of Service, the Privacy Policy and the Cookie Policy on any question of data protection.

14. Term and termination

14.1 This DPA takes effect when the Controller accepts the Terms of Service in the App and continues until the App is uninstalled and the deletion obligations in Section 9 are complete.

14.2 Sections that by their nature should survive termination — including Sections 4.3, 8, 9, 10, 12.3, 12.7 and 13 — survive.

15. Governing law

15.1 This DPA is governed by Hungarian law, and the courts identified in the Terms of Service have jurisdiction.


ANNEX 1 — Details of processing

Categories of data subject: end-customers of the Controller's Shopify store who add items to a cart, and recipients of a shared cart link.

Categories of personal data:

CategoryField(s)PurposeRetention
Shopify customer identifierShopify customer ID (numeric, pseudonymous)Keying a saved cart to a customer accountCart expiry or redact webhook. The window is plan-dependent (2, 7, 30 or 60 days by default), and on the Pro and Advanced plans the Controller may select 7, 14, 30 or 60 days in the App settings. 60 days is the maximum on every plan
Cart token (stored hashed)The one-way SHA-256 hash of the Shopify cart token; the raw token is never stored at restRetrieving the correct cart on any deviceAs above
Cart contentsProduct variant ids, quantitiesRestoring the cartAs above
Share link dataReference to the short link, or the cart token for a click through a cart-token link, or, for a checkout-direct link, the checkout token (each token stored only as its one-way hash); referring channel (a category, not the web address); variant ids; click timestamp (LinkClick)Attribution of shared linksLink expiry (deleted in cascade with the short URL); for a click through a cart-token link, the daily cleanup after that cart token expires; uninstall; redact webhooks
Order attributionShopify order id, order name, total price, attribution method, cart token, referring channel, link-click reference, conversion timestamp (OrderConversion — no Shopify customer ID is stored; the order id is a pseudonymous identifier and the cart token is stored only as its one-way hash)Attributing completed orders to recovered cartsDeleted on redact (see Section 9.2); otherwise deleted after 365 days, or 30 days after the uninstall for an uninstalled shop
App event logShop domain, action type, timestamp, structured detail (AuditLog). The cart-session, share-link, saved-cart and order events carry a Shopify customer ID (see Section 9.4); the GDPR compliance entries carry Shopify request ids and row counts only, no customer identifierDebugging, quota enforcement, and proof that GDPR webhooks were handled90 days for operational entries (deleted on customers/redact where they name that customer); 3 years for the GDPR compliance entries, which survive shop/redact (see Section 9.4)

Data NOT collected or stored: customer names, email addresses, postal addresses, telephone numbers, payment data, device fingerprints. Customer IP addresses are not written to the App's database; transient processing at the hosting/edge layer is an unavoidable part of routing an internet request.

Special categories of data: none. The Controller shall not instruct processing of special-category data through the App.

Automated GDPR webhook handling:

Shopify webhookProcessor action
customers/data_requestCompile the data the App holds about that customer and send it by e-mail to the Controller's store contact address, stating so where nothing is held (Section 7.3); where no contact address is set, the Processor sends it itself within 30 days. A compliance entry records Shopify's request ids and the outcome only
customers/redactDelete the customer's cart tokens, saved carts, short links, and the link clicks made through them; delete the event-log entries naming that customer; delete their order-attribution records, matched by the customer's cart tokens or by the orders listed in the request (Section 9.2). One compliance entry is written, carrying request ids and counts only
shop/redactPurge all shop data and access tokens; delete order-attribution records; delete the operational event-log entries. The GDPR compliance entries and the uninstall record are retained (Sections 9.3, 9.4)

ANNEX 2 — Technical and organisational measures (Art.32)

Further information on residual risks and compensating measures is available to the Controller on request (Section 10).