Data Processing Agreement
Last updated: 2026-09-10
These are the processor terms required by Article 28(3) GDPR. They form part of the Terms of Service and take effect when you install the app — you do not need to sign or return anything. If your organisation requires a countersigned copy, email gimbernat13@gmail.com and we will provide one.
1. The parties
Controller: you, the merchant that installed the app.
Processor: Capyo, operated by an individual developer.
Operator legal name and address: see the Privacy Policy.
Shopify is a separate processor for you, under Shopify's own data processing addendum, which governs the Shopify-to-merchant relationship and is unaffected by this document. Store data we process reaches us through Shopify; events we relay onward reach OpenAI at your own instruction, through your own Conversions API key, as described in section 8.
2. Subject matter, duration, nature and purpose
- Subject matter: providing the Capyo: ChatGPT Ads Pixel & ROAS Shopify app — installing and operating the storefront pixel, relaying events to your OpenAI Ads account, building and delivering your product feed, computing the revenue report, and raising alerts.
- Duration: from installation until the app is uninstalled and the deletion in section 11 completes.
- Nature of processing: collection from Shopify's API and from your storefront's pixel, storage, structured retrieval, transmission to OpenAI at your instruction, report generation, and erasure.
- Purpose: solely to deliver the app to you and keep it secure. Never for our own marketing, never for profiling, never for training models, never for sale.
3. Types of personal data
Most of what the app stores is store configuration and order-attribution data rather than personal data about an identifiable person. Where it is personal data, it is one of two kinds:
- Business-contact and account data about you and your staff: the shop's
.myshopify.comdomain, Shopify OAuth access tokens, your alert email address, and store configuration (locale, plan, setup flags and timestamps). - Transient technical data from your storefront visitors: IP address and user agent from
the pixel's
/collectrequest, held in memory for up to 10 minutes to attach to the outbound Conversions API event and then discarded — never written to disk or to the database. The anonymous attribution values described in section 8 (a browser-generated client id, the ad platform'sopprefvalue, a checkout token) are not, by themselves, sufficient to identify a person.
Excluded by design: customer name, email address, postal address or phone number; payment or card data; a product's full description; your theme code. The app requests no Shopify scope that would give it access to any of these.
4. Categories of data subjects
The merchant and the merchant's staff and collaborators who use the app; and, only for the transient IP-address/user-agent handling in section 3, storefront visitors — no persistent record is kept that identifies them.
5. Your instructions
We process personal data only on your documented instructions. Installing the app, pasting your own OpenAI Pixel ID and Conversions API key, and configuring the feed and alerts are those instructions; the Privacy Policy describes their scope. Sending your store's events to OpenAI is itself carried out on your instruction and with your own credentials — we never route events through an OpenAI account of our own. Further or different instructions can be sent to gimbernat13@gmail.com; if one would require disproportionate effort or a change to the service, we will say so rather than silently not do it.
If EU or member-state law obliges us to process beyond your instructions, we will tell you before doing so, unless that law forbids telling you. If we believe an instruction infringes the GDPR, we will inform you.
6. Confidentiality
Access is limited to the operator, who is bound by a duty of confidentiality that survives the end of this agreement. There are no other staff. Should that change, anyone given access will be bound by an equivalent written obligation before receiving it.
7. Security measures (Art. 32)
- TLS on every connection to the app and to this website; no plaintext endpoint exists.
- Your Conversions API key and SFTP password are encrypted at rest (AES-256-GCM), never logged, and shown again only as a masked placeholder.
- The database is closed to the public internet: the firewall accepts PostgreSQL connections only from the application server's IP address, over an encrypted connection with password authentication.
- Shopify access tokens are stored only in that database and are never logged or displayed.
- Administrative access to server and database is limited to the operator, over SSH with key authentication.
- Shopify webhooks are verified by HMAC signature before any action is taken.
- Minimum scopes: read orders, read products, manage pixels, read customer events — nothing that reads customer names, emails, addresses or phone numbers.
- IP address and user agent from the storefront pixel are held in memory only, for up to 10 minutes, and are never persisted.
We hold no ISO 27001 or SOC 2 certification and do not claim application-level encryption at rest beyond what the hosting providers apply to their own storage.
8. Sub-processors and the OpenAI relay
You give general authorisation for the sub-processors below.
| Sub-processor | Company country | Purpose | Where the servers are |
|---|---|---|---|
| Shopify International Ltd | Ireland | Platform, source of all store data, and billing | Per Shopify's own DPA |
| OpenAI | United States | Receives relayed events at your instruction, through your own Pixel ID and Conversions API key, into your own OpenAI Ads account | Per OpenAI's own terms |
| Resend | United States | Alert email delivery — not active until a sending domain is verified; no data reaches Resend before then | Per Resend's own terms |
| Hostinger International Ltd | Cyprus | Application hosting (virtual server) | Boston, Massachusetts, United States |
| netcup GmbH | Germany | Database hosting (PostgreSQL) | Manassas, Virginia, United States |
| GitHub, Inc. | United States | Hosting of this public website only; no app data reaches it | GitHub Pages infrastructure |
OpenAI receives data because you instructed the app to relay it, using credentials only you hold — this is different from a conventional sub-processor relationship, and we describe it here for completeness and transparency rather than because we control what OpenAI does with your account's own data. We remain fully liable to you for the performance of the sub-processors listed above that we do engage directly.
Changes. Before a new sub-processor starts processing, a listed one is replaced, or a hosting location moves — including Resend becoming active — we update this table with a new date at the top of the page. You may object on reasonable data-protection grounds by writing to gimbernat13@gmail.com; if we cannot accommodate the objection, you may uninstall the app and stop paying, with a pro-rata refund of any prepaid period through Shopify.
9. International transfers (GDPR Chapter V)
Merchant data processed through the app is stored on servers located in the United States: the application server in Boston, Massachusetts and the PostgreSQL database in Manassas, Virginia. The companies operating them are European (Hostinger International Ltd, Cyprus; netcup GmbH, Germany), but the processing takes place outside the EEA.
Those transfers rely on the Standard Contractual Clauses included in the providers' data processing terms, together with the providers' technical and organisational security commitments and the measures in section 7. Events relayed to OpenAI, and any future alert email through Resend, likewise involve processing in the United States.
The app stores no end-customer personal data, so no consumer data is transferred beyond the anonymous, short-lived attribution values in section 3. The transferred data is the store configuration, order-attribution records, feed data, generated reports, usage events and access tokens described in section 3.
Hosting locations may change, including a move to an EU region. Any such change is announced on this page before it takes effect, under the notice rule in section 8. Shopify's own transfers are governed by its DPA and transfer mechanisms.
10. Assistance to you
- Data-subject requests. If a data subject contacts us directly about data we process for you, we forward it and do not answer on your behalf. We help you respond, taking into account the nature of the processing and the information available to us.
- Security incidents. We notify you without undue delay and in any event within 48 hours of becoming aware of a personal-data breach affecting your data, with what we know: what happened, which categories of data, likely consequences, and the measures taken.
- DPIAs and prior consultation. We provide the information you reasonably need for an assessment under Art. 35 or a consultation under Art. 36.
11. Deletion at the end of the agreement
Sessions are deleted immediately on the app/uninstalled webhook. All remaining data about
your shop is deleted when Shopify sends the shop/redact webhook, 48 hours after uninstall
(purge order in the Privacy Policy, section 7), or earlier if you
ask us in writing. Server logs age out within 30 days. Nothing is retained afterwards except where EU or
member-state law requires it; there is no backup copy kept for our own purposes.
12. Audit
On written request we provide the information needed to demonstrate compliance with Article 28 — the current sub-processor list, the security measures in section 7, the data model, and answers to a reasonable security questionnaire — once per twelve months, or more often after a breach affecting your data or where a supervisory authority requires it. Because the service is small and single-tenant per shop, we do not host on-site audits; where a controller's law requires an inspection, we will agree a proportionate remote alternative in good faith.
13. Order of precedence
Where this document conflicts with the Terms of Service on a matter of personal-data processing, this document wins. The GDPR wins over both.
14. Contact
gimbernat13@gmail.com. See also the Privacy Policy and the Terms of Service.