Data Processing Agreement

DropScan Local · BaseStation Private Limited
Effective: 20 July 2026 · Version 1.0
Contact: [email protected]

This DPA is a template offered to merchants who install DropScan Local. Have it reviewed by your counsel before relying on it for regulated jurisdictions. Installing / continuing to use the app constitutes acceptance of these processing terms together with our Privacy Policy.

1. Parties

2. Subject matter and duration

Processing of personal data as needed to provide local delivery package assignment, driver navigation, proof of delivery, and related Shopify fulfillment sync for the Controller’s store. Processing lasts for the term of the app installation and any post-termination retention described in the Privacy Policy, unless earlier deletion is required by Shopify compliance webhooks or law.

3. Nature and purpose of processing

Storage and use of delivery destination fields and delivery-proof scan metadata solely to operate DropScan Local for the Controller. No sale of personal data; no use for Processor marketing.

4. Types of personal data and data subjects

5. Controller instructions

The Processor processes personal data only on documented instructions from the Controller, including: (a) use of the app features; (b) Shopify Admin API / webhook payloads the Controller authorizes; (c) Shopify mandatory compliance topics (customers/data_request, customers/redact, shop/redact).

6. Security measures

The Processor implements appropriate technical and organizational measures, including:

7. Sub-processors

The Controller authorizes the Processor to engage the infrastructure sub-processors listed in the Privacy Policy (currently Railway, Cloudflare, and Shopify as the platform). The Processor will notify merchants of material sub-processor changes via the privacy policy update or in-app notice where practicable.

8. Breach notification

The Processor will notify the Controller without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach affecting the Controller’s customer data, with available facts, likely consequences, and measures taken or proposed. See the Security Incident Response Policy.

9. Assistance with data subject rights

The Processor assists the Controller by implementing Shopify compliance webhooks and by providing held-data exports for customers/data_request through a controlled channel (not public chat tools). Further assistance is available via [email protected].

10. Deletion and return

On app uninstall, Shopify sends shop/redact (typically ~48 hours later). The Processor then deletes operational personal data (packages, scans, staff, shifts, activity payloads, queued jobs for that shop) while retaining merchant identity and non-PII billing summaries as described in the Privacy Policy. Earlier deletion follows customers/redact for specified orders.

11. Audits

Upon reasonable written request, the Processor will provide information necessary to demonstrate compliance with this DPA (e.g. policy documents, high-level architecture summary). On-site audits are by mutual agreement and at the Controller’s expense unless required by a supervisory authority finding of Processor non-compliance.

12. Liability and governing law

Liability allocation follows the Shopify App Store / Partner terms and any separate commercial agreement between the parties. This DPA is governed by the laws applicable to BaseStation Private Limited’s principal place of business unless mandatory local law provides otherwise for the Controller.

13. Contact

BaseStation Private Limited · [email protected]
Privacy Policy