Skip to content
VIVID INSIGHT
CompanyProducts
CompanyProducts
Products/Vivid Custom Fields Export for Shopify/Data Processing Addendum
Product policy

Data Processing Addendum

Data-processing terms, security measures, deletion commitments, and subprocessors for Vivid Custom Fields Export.

Effective date
11 September 2026
Version
1.1
Product
Vivid Custom Fields Export for Shopify

1. Parties and scope

This Data Processing Addendum (“DPA”) forms part of the agreement for Vivid Custom Fields Export (the “App”) between the Shopify merchant using the App (“Customer”) and VIVID INSIGHT UNIPESSOAL LDA, NIF 517951371, Rua Victor de Sá, 33, 4715-586 Braga, Portugal (“Provider”). It applies where Provider processes Personal Data on Customer’s behalf.

Customer is Controller, or a Processor authorized by the relevant Controller. Provider is Processor for Customer Personal Data processed through the App. Each party is independently responsible as Controller for personal data it processes for its own account, including business contacts, Shopify administration, billing, legal compliance, security, and support relationship records.

2. Definitions and instructions

“Applicable Data Protection Law” includes the GDPR, applicable Portuguese implementing law, and other privacy law that applies to the processing. “Customer Personal Data” means Personal Data processed by Provider on Customer’s behalf through the App. Controller, Processor, Data Subject, Personal Data, Processing, Personal Data Breach, and Supervisory Authority have the meanings in Applicable Data Protection Law.

Provider will process Customer Personal Data only to provide, secure, support, and maintain the App; according to Customer’s authenticated use and documented instructions; as described in this DPA; or where required by law after notifying Customer unless prohibited. The agreement, Customer’s use of the App, Shopify configuration, selected export range and custom fields, and authorized support requests are Customer’s documented instructions.

Customer is responsible for lawful instructions and for all rights, notices, legal bases, and authorizations needed for Customer Personal Data, including custom attributes that may contain personal or sensitive information.

3. Processing details

  • Subject matter and purpose: authenticated retrieval and transient transformation of supported Shopify order and line-item data into an Analyze result or deterministic CSV; subscription entitlement verification; shop-wide field-selection preferences; operation coordination; security; lifecycle cleanup; and authorized support.

  • Duration: while Customer has an active installation or entitlement, plus limited retention for session state, field-selection preferences, operational coordination, encrypted backups, support, and legal obligations as described below.

  • Data subjects: buyers, order recipients, merchant personnel, users, and other individuals whose information Customer or a third-party personalization app places in order or line-item custom attributes.

  • Data types: shop identifiers, Shopify session and token state, operation lease metadata, technical identifiers of excluded custom fields linked to the shop, order identifiers and dates, currency, product or variant details, SKU, and order-level or line-item custom-attribute keys and values. The App does not request direct customer name, email, postal address, or phone fields.

  • Special categories: not intentionally requested, but Customer or another app can place sensitive information in free-form custom attributes. Customer must not instruct processing of such data unless lawful and necessary.

  • Frequency: on installation and authenticated App access, and each time Customer runs Analyze or Download.

4. Confidentiality and security

Provider will limit access to authorized persons bound by confidentiality and will maintain technical and organizational measures proportionate to risk. Measures include HTTPS, authenticated Shopify session state, tenant identity derived only from verified Shopify context, minimal read_orders access, private PostgreSQL networking, restricted operational access, bounded in-memory processing, fail-closed incomplete-export behavior, sensitive-log exclusions, and encrypted off-server database backups.

Customer is responsible for securely administering its Shopify store, users, downloaded CSV files, production recipients, and retention practices.

5. Personal Data Breach

Provider will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data and will provide reasonably available information needed for Customer’s legal obligations. Information may be provided in phases. Notification is not an admission of fault. Incident contact: info@vividinsight.xyz.

6. Data-subject requests and compliance assistance

Taking into account the nature of processing, Provider will reasonably assist Customer with data-subject requests, security inquiries, data-protection impact assessments, prior consultations, and records of processing where required. If Provider receives a request about Customer-controlled order or CSV data, Provider may redirect the requester to Customer unless law requires otherwise.

The App authenticates Shopify’s customers/data_request, customers/redact, and shop/redact webhooks. Customer, order, custom-attribute, and CSV contents are not persisted, so customer-specific webhooks require no local content deletion. shop/redact deletes the shop’s Session, BulkOperationState, and ShopFieldExclusion records.

7. Subprocessors

Customer gives general authorization for Provider to use the subprocessors listed below. Provider will impose appropriate data-protection obligations and remains responsible for their performance to the extent required by law. Provider will give reasonable advance notice of a material new subprocessor where required, and Customer may object on reasonable data-protection grounds.

  • Hetzner Online GmbH — dedicated production compute and private database hosting in Helsinki, Finland.

  • Cloudflare, Inc. — DNS, reverse proxy, TLS, network-security, delivery, and aggregate website analytics services using a global network.

  • Google LLC — storage of encrypted logical database backups. Backups can contain Shopify session state, operation lease metadata, and technical identifiers of excluded custom fields, but not original custom-field names or values, order contents, or generated CSV content.

Shopify is Customer’s selected commerce platform and source of authenticated order data, installation, compliance webhooks, and billing entitlement. Contentful and Cloudflare Pages host public documentation and do not receive Customer Personal Data from the App’s export path.

8. International transfers

Provider will ensure that transfers subject to Chapter V GDPR use an applicable adequacy decision, standard contractual clauses, or another lawful mechanism. Provider will provide relevant transfer information reasonably required by Customer.

9. Return, deletion, and retention

Order, line-item, custom-attribute, and generated CSV contents are transient in memory and are not intentionally persisted by Provider. Shopify session state is retained while needed for the installation. Operation leases are short-lived. Shop-wide field-selection preferences are retained as technical identifiers of excluded fields until the fields are re-enabled or the installation is removed. The identifiers remain shop-linked configuration, not anonymous data; original custom-field names and values are not retained in these preferences. On authenticated app/uninstalled or shop/redact, Provider deletes the shop’s Session, BulkOperationState, and ShopFieldExclusion rows. Encrypted database backups are retained for up to 30 days and then expire through the backup retention process. Genuinely anonymous aggregate data may be retained.

10. Audits and information

Provider will make information reasonably necessary to demonstrate compliance available to Customer. Customer may request an audit no more than once annually unless required by a Supervisory Authority or a confirmed incident. Audits must protect other customers, confidentiality, security, and business continuity. Provider may satisfy a request with current policies, summaries, questionnaires, or independent reports where appropriate. Extensive assistance may be subject to reasonable fees unless caused by Provider’s breach.

11. Liability, precedence, and termination

Liability under this DPA is subject to the agreement’s limitations to the extent permitted by law. If this DPA conflicts with the agreement on processing of Customer Personal Data, this DPA controls. The DPA ends when Provider no longer processes Customer Personal Data for Customer, subject to backup expiry and legal retention.

12. Contact

Privacy and DPA contact: VIVID INSIGHT UNIPESSOAL LDA, Rua Victor de Sá, 33, 4715-586 Braga, Portugal; info@vividinsight.xyz.

On this page
  • 1. Parties and scope
  • 2. Definitions and instructions
  • 3. Processing details
  • 4. Confidentiality and security
  • 5. Personal Data Breach
  • 6. Data-subject requests and compliance assistance
  • 7. Subprocessors
  • 8. International transfers
  • 9. Return, deletion, and retention
  • 10. Audits and information
  • 11. Liability, precedence, and termination
  • 12. Contact
VIVID INSIGHT

Focused integration software for technical teams.

Products
  • Vivid Connector for Jira and Telegram
  • Vivid Custom Fields Export for Shopify
Resources
  • Products
  • Privacy Policy — Vivid Connector for Jira and Telegram
  • Terms of Use and End User License Agreement
  • Data Processing Addendum
  • Support Policy — Vivid Connector for Jira and Telegram
© 2026 Vivid Insight Unipessoal LDAIndependent software company