Data Processing Agreement
Last updated: 13 September 2026 · Applies to all Quiet Tools apps
This agreement applies between you, the merchant using a Quiet Tools app
("Controller"), and Quiet Tools ("Processor"). It takes effect when you install
the app and remains in force while it is installed. It forms part of the terms
under which the app is provided.
1. Subject matter and duration
The Processor processes personal data on behalf of the Controller solely to
provide the app's functionality. Processing lasts for the duration of the
installation and ends with the deletion described in section 7.
2. Nature and purpose
For Orderfold: identifying orders from the same customer that are going to the
same address and have not shipped, presenting them to the Controller as a
suggestion, and — only on the Controller's explicit confirmation — linking those
orders and applying a tracking number the Controller supplies.
3. Categories of data subjects and data
Data subjects: the Controller's customers, and the Controller's own staff insofar as store identifiers relate to them.
Personal data processed:
- Customer identifiers issued by Shopify (numeric IDs only).
- Shipping addresses — read in transit to compute a comparison hash;
stored only as a SHA-256 hash, never as text.
- Order identifiers, numbers, status, totals, item counts and weights.
The Processor does not request and cannot read customer names, email addresses
or telephone numbers.
Residual risk stated openly: free-form error text returned by
Shopify is stored for diagnostics and is not parsed, so it may occasionally
contain a fragment of an address. Such records are deleted after 30 days.
4. Instructions
The Processor processes personal data only on documented instructions from the
Controller. Installing and configuring the app constitutes those instructions.
The Processor will inform the Controller if, in its opinion, an instruction
infringes applicable data protection law.
5. Confidentiality
Access to personal data is limited to the Processor's sole operator, who is bound
by confidentiality. There are no other personnel with access.
6. Security measures
The measures in force are described in the
Security and Incident Response document, which forms
part of this agreement. In summary: data minimisation by design, TLS in transit,
a database not exposed to the internet, key-only server access, encrypted backups
with a separately held key and verified restores, automatic deletion of logs after
30 days, and an audit trail of data access.
7. Deletion and return
- On uninstall, all data belonging to the store is deleted within 48 hours.
- On a
shop/redact request from Shopify, all data belonging to the
store is deleted.
- On a
customers/redact request, all records relating to that
customer are deleted.
- The Controller may request deletion at any time in writing.
Because the Processor stores no customer-identifying data beyond Shopify
identifiers and an address hash, there is nothing meaningful to return; deletion
is the applicable remedy.
8. Sub-processors
The Controller gives general authorisation for the following sub-processors:
| Sub-processor | Purpose | Location |
| Contabo GmbH | Server hosting, storage and backups | Germany (EU) |
| Cloudflare, Inc. | Authoritative DNS for our domain | Global |
Shopify is not listed as a sub-processor: it is the source of the data and the
Controller's own processor under separate terms.
The Processor will announce any intended change of sub-processor on this page at
least 30 days in advance. If the Controller objects, the remedy is to uninstall
the app, which triggers deletion under section 7.
9. International transfers
Processing and storage take place within the European Union. Where a
sub-processor operates outside the EU, transfers are covered by the European
Commission's Standard Contractual Clauses as incorporated in that provider's terms.
10. Assistance to the Controller
The Processor assists the Controller, as far as reasonably possible, with
responding to data subject requests, with data protection impact assessments,
and with notifications to supervisory authorities. In practice most such requests
are answered by the fact that the Processor holds no directly identifying data.
11. Personal data breach
The Processor notifies the Controller without undue delay and in any event within
72 hours of becoming aware of a personal data breach affecting
the Controller's data, with the information described in the Security document.
12. Audit
The Processor makes available the information necessary to demonstrate compliance
with this agreement, and will respond to written questions from the Controller.
Given the scale of the operation, on-site audits are not offered; documentation
and written answers are.
Contact
Quiet Tools — support@quiettools.net