Retrics

LEGAL — DPA

Data Processing Addendum.

When you connect your store, you are the controller of your customers' data and Retrics is your processor. This addendum sets out, precisely, how we process that data on your behalf and the commitments we make to keep it safe.

LAST UPDATED · 31 JUL 2026

MATERIAL CHANGES TAKE EFFECT · 14 AUG 2026

01This revision

This document was last updated on 31 July 2026. Where this revision makes a material contractual change, that change takes effect on 14 August 2026. Until then the previous version governs the point it changed. Corrections that only make an existing practice clearer — naming a provider more precisely, describing a capability that is switched off — describe what is already true and are not held back to that date.

Sending from Retrics is unavailable in this release. Direct email to your customers, SMS, WhatsApp, scheduled delivery and the Klaviyo audience handoff are all switched off in code; no plan, setting, account connection or onboarding step turns them on. Where this document describes those channels, it describes a capability that is built and dormant, not one operating today. What is available is the campaign-safe CSV export: you download the frozen audience — with your global control already dropped — and send it from your existing platform.

Retrics also does not draft customer-facing message copy, does not upload any customer list to Google, and does not create, edit, pause or change any advertising campaign. Those are described in place below.

02Scope & roles

This Data Processing Addendum (“DPA”) forms part of the agreement between the merchant that installs and uses Retrics (“Customer”) and Retrics, the operator of Retrics (“Retrics”, “we”). It governs the processing of personal data that Retrics carries out on the Customer's behalf.

For the personal data processed under the service, the Customer is the controller and Retrics is the processor. Where the Customer is itself a processor for another party, Retrics acts as a subprocessor and the same terms apply down the chain.

This DPA applies to the extent Retrics processes personal data subject to data-protection laws including the EU and UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended (CCPA/CPRA), and comparable laws. Where this DPA conflicts with the main agreement on the subject of data protection, this DPA governs.

03Nature & purpose of processing

Retrics's base Shopify connection uses read-only scopes to provide retention and customer-intelligence analytics: computing cohorts, scoring lapse and repeat probability, building the audience for a retention send and holding a control group back from it, and measuring the outcome of the sends the Customer authorizes. Retrics does not deliver those sends in this release — the Customer exports the audience and delivers it through its own platform. The Customer writes the message content; Retrics does not generate outreach copy. If the Customer separately enables Shopify loyalty reward issuance, the Customer explicitly authorizes the additional discount-write scope used only to create requested reward codes. Nothing is sent to end customers without the Customer's explicit action.

Processing is limited to what is necessary to provide, secure, and support the service, and to comply with the Customer's documented instructions. Installing and configuring the app, and this DPA, constitute the Customer's documented instructions; the Customer may issue further reasonable instructions consistent with the agreement.

Retrics does not sell personal data, does not share it for cross-context behavioral advertising, and does not use it to build or train models that serve other customers. We retain no rights over the Customer's data beyond those needed to perform the service.

04Categories of data subjects & data

Data subjects: the Customer's own end customers, and the individuals authorized to administer the Customer's Retrics workspace.

Categories of personal data: customer and order records read from Shopify — names, email addresses, order and purchase history, order values, product and subscription details, and coarse location (such as country, region, or city) associated with orders.

Email addresses are stored alongside an irreversible hash. Core retention analytics and model scoring relate orders through internal customer and order identifiers; the hash supports suppression, audience, and cross-channel matching. Plain email is used where necessary for merchant-facing profiles and search, approved sends, and exports. We do not process payment card numbers, banking credentials, or Shopify passwords, and the service is not designed for special-category data.

05Sub-processing

The Customer authorizes Retrics to engage sub-processors to help deliver the service (for example, cloud hosting, database, and transactional-email providers; the customer-messaging delivery providers listed at retrics.ai/subprocessors receive no personal data in this release). Each sub-processor is bound by a written contract imposing data-protection obligations no less protective than this DPA, and Retrics remains responsible for their performance.

A current list of sub-processors is maintained at /subprocessors. We will give reasonable prior notice of any new or replacement sub-processor; the Customer may object on reasonable data-protection grounds, and if we cannot accommodate the objection the Customer may terminate the affected service.

06International transfers

Where processing involves transferring personal data out of the EEA, the UK, or Switzerland to a country without an adequacy decision, such transfers are governed by the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum, where applicable), which are incorporated into this DPA by reference and completed with the details set out here.

Retrics will apply supplementary technical and organizational measures where needed to protect transferred data, and will assist the Customer with transfer-impact assessments on reasonable request.

07Security measures

Retrics maintains technical and organizational measures appropriate to the risk, including: encryption of personal data in transit (TLS) and at rest; irreversible email hashing for suppression, audience, and cross-channel matching; keyed, one-way selector hashes used solely to prevent a verified Shopify erasure from being undone by a later sync; role-based access controls with least-privilege access to production systems; audited and restricted production access; network isolation; and logging and monitoring of access to personal data.

Access to Customer data is limited to personnel who need it to operate or support the service and who are bound by confidentiality obligations. We review our security measures periodically and may update them, provided the level of protection is not materially reduced. A formal information-security audit program (SOC 2) is on our roadmap.

08Assisting with data-subject rights

Because Retrics analytics use Shopify-sourced records, internal identifiers, and hashed matching keys, the Customer's Shopify admin remains the system of record for end-customer requests. Taking account of the nature of the processing, Retrics will provide reasonable assistance — through appropriate technical and organizational measures — to help the Customer respond to requests to access, correct, delete, restrict, or port a data subject's personal data.

If a data subject, regulator, or third party contacts Retrics directly about the Customer's data, we will not respond on the Customer's behalf (except to confirm the request should be directed to the Customer) and will promptly forward the request, unless legally prohibited.

09Personal data breach notification

Retrics will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's personal data. The notice will describe, to the extent known, the nature of the breach, the categories and approximate volume of data and data subjects affected, the likely consequences, and the measures taken or proposed to address it.

Retrics will cooperate reasonably with the Customer's investigation and remediation and provide information reasonably needed for the Customer to meet its own breach-notification obligations. Notification is not an acknowledgment of fault or liability.

10Deletion & return on termination

After a verified workspace-deletion request, Retrics will delete the Customer's personal data from production systems within 30 days, except where retention is required by law. Subscription expiry or cancellation and disconnecting a store inside the service do not by themselves delete already-synced data. Uninstalling the Shopify app instead leads to Shopify's shop/redact process described below. Residual copies in secure backups are deleted on the ordinary backup-expiry cycle and remain protected in the meantime.

Retrics honors Shopify's mandatory compliance webhooks: a verified customers/redact request automatically deletes the matching customer record, removes the subject's identity from retained facts, and retains only keyed, one-way match hashes so a later sync cannot recreate the erased identity. Those prevention records contain no raw customer or order selector and are separate from delivery suppressions. The installation-scoped copy is purged with the installation on shop/redact; a limited workspace-scoped, non-reversible prevention receipt remains until workspace deletion so reinstalling or reauthorizing cannot undo the verified erasure. A shop/redact request purges the exact disconnected store connection, encrypted access token, and connection-owned synced graph following uninstall. A customers/data_request delivery creates a count-only receipt and an encrypted, privacy-minimized case. An authorized Customer owner/admin may compile current matching Retrics-held records as a no-store report; Retrics does not automatically deliver it. Case selectors expire at the earlier of the applicable deadline or seven days after first delivery. These requests are handled within the applicable Shopify and legal timeframes.

11Audit rights

Retrics will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior written notice and no more than once per year (unless required by a regulator or following a breach), will allow and contribute to audits conducted by the Customer or an independent auditor bound by confidentiality.

Audits will be conducted during business hours, without unreasonable disruption to Retrics's operations, and subject to reasonable confidentiality and security constraints. Where available, up-to-date certifications, reports, or summaries of independent assessments may be provided to satisfy an audit request.

12Governing law & contact

This DPA is governed by the laws of the State of Delaware, USA, except where mandatory data-protection law or the incorporated Standard Contractual Clauses require otherwise. It takes effect when the Customer accepts the agreement or installs the service and continues for as long as Retrics processes the Customer's personal data.

Data-protection questions or requests under this DPA: legal@retrics.ai.

See our subprocessors · Read the privacy policy · Read the terms of service