Data Processing Agreement
This DPA is a template offered to merchants who install DropScan Local. Have it reviewed by your counsel before relying on it for regulated jurisdictions. Installing / continuing to use the app constitutes acceptance of these processing terms together with our Privacy Policy.
1. Parties
- Controller: the Shopify merchant (store) that installs DropScan Local.
- Processor: BaseStation Private Limited (“Dropscan”, “we”), provider of DropScan Local.
2. Subject matter and duration
Processing of personal data as needed to provide local delivery package assignment, driver navigation, proof of delivery, and related Shopify fulfillment sync for the Controller’s store. Processing lasts for the term of the app installation and any post-termination retention described in the Privacy Policy, unless earlier deletion is required by Shopify compliance webhooks or law.
3. Nature and purpose of processing
Storage and use of delivery destination fields and delivery-proof scan metadata solely to operate DropScan Local for the Controller. No sale of personal data; no use for Processor marketing.
4. Types of personal data and data subjects
- Customers / recipients: name, phone, delivery address; associated Shopify order identifiers and line-item summary.
- Delivery staff (Controller’s users): name, email, optional phone; scan-time GPS / IP / user agent.
5. Controller instructions
The Processor processes personal data only on documented instructions
from the Controller, including: (a) use of the app features; (b)
Shopify Admin API / webhook payloads the Controller authorizes; (c)
Shopify mandatory compliance topics
(customers/data_request, customers/redact,
shop/redact).
6. Security measures
The Processor implements appropriate technical and organizational measures, including:
- Encryption in transit (HTTPS) and encryption at rest for database volumes
- Field encryption for Shopify access tokens and agency MFA secrets
- Access controls, least-privilege credentials, and mandatory MFA for agency (founder) access
- Automated retention scrubbing of customer delivery fields and scan PII (90 days)
- Logging of staff delivery scans and significant operational actions
- Documented incident response and data-loss-prevention practices
7. Sub-processors
The Controller authorizes the Processor to engage the infrastructure sub-processors listed in the Privacy Policy (currently Railway, Cloudflare, and Shopify as the platform). The Processor will notify merchants of material sub-processor changes via the privacy policy update or in-app notice where practicable.
8. Breach notification
The Processor will notify the Controller without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach affecting the Controller’s customer data, with available facts, likely consequences, and measures taken or proposed. See the Security Incident Response Policy.
9. Assistance with data subject rights
The Processor assists the Controller by implementing Shopify compliance
webhooks and by providing held-data exports for
customers/data_request through a controlled channel (not
public chat tools). Further assistance is available via
[email protected].
10. Deletion and return
On app uninstall, Shopify sends shop/redact (typically
~48 hours later). The Processor then deletes operational personal data
(packages, scans, staff, shifts, activity payloads, queued jobs for that
shop) while retaining merchant identity and non-PII billing summaries as
described in the Privacy Policy. Earlier deletion follows
customers/redact for specified orders.
11. Audits
Upon reasonable written request, the Processor will provide information necessary to demonstrate compliance with this DPA (e.g. policy documents, high-level architecture summary). On-site audits are by mutual agreement and at the Controller’s expense unless required by a supervisory authority finding of Processor non-compliance.
12. Liability and governing law
Liability allocation follows the Shopify App Store / Partner terms and any separate commercial agreement between the parties. This DPA is governed by the laws applicable to BaseStation Private Limited’s principal place of business unless mandatory local law provides otherwise for the Controller.
13. Contact
BaseStation Private Limited ·
[email protected]
Privacy Policy