1. Parties and scope
This Data Processing Agreement ("DPA") forms part of the AttribGate Terms of Service between the Shopify merchant ("Merchant") and the individual software developer based in the People's Republic of China who operates AttribGate under the public service name SkyMork ("Processor"). SkyMork is not presented as an incorporated company. Legal operator details are available on a valid contractual, regulatory, or legal request. This DPA applies when Processor handles personal data on Merchant's behalf in providing AttribGate.
2. Roles
Merchant is the controller or business for Shopify order, merchant-customer, and affiliate relationship data. Processor acts as Merchant's processor or service provider for that data. Each party is independently responsible for personal data it controls outside this processing relationship.
3. Merchant instructions
Processor will process personal data only on Merchant's documented instructions, including the Terms, configuration choices, connected-network actions, support requests, and instructions required by law. Processor will notify Merchant if an instruction appears to violate applicable data-protection law unless prohibited by law. Merchant is responsible for the lawfulness, accuracy, and scope of its instructions.
4. Confidentiality and access
Processor will keep personal data confidential and limit access to people and service providers who need it to operate, secure, or support AttribGate and who are subject to appropriate confidentiality obligations. AttribGate is operated by a solo developer; no merchant data is shared with unrelated personnel.
5. Security
Processor maintains measures appropriate to the current service and risk, including TLS in transit, AES-256-GCM encryption for affiliate credentials, tenant-scoped application and database access, authenticated Shopify sessions and webhooks, separated staging data, restricted database and service credentials, data-minimized logs, dependency controls, seven-day object-storage lifecycle deletion, and merchant-confirmed writeback. Processor may update measures without materially reducing overall protection.
6. Subprocessors
Merchant gives general authorization for the subprocessors listed on the Subprocessors and connected services page. Processor will require subprocessors to protect personal data consistently with this DPA. Processor will provide at least 30 days' notice through that page or the Merchant's available contact channel before adding a new material subprocessor where practicable. Merchant may object on reasonable data-protection grounds by contacting us during that period. If the parties cannot resolve the objection, Merchant may stop the affected processing and terminate use of AttribGate.
7. Assistance
Taking account of the nature of processing, Processor will reasonably assist Merchant with authenticated data-subject requests, security inquiries, impact assessments, regulator consultations, and demonstrations of compliance. Merchant remains responsible for responding to data subjects and regulators. AttribGate acknowledges Shopify's mandatory privacy webhooks and does not retain buyer identity fields in its business tables.
8. Security incidents
Processor will notify Merchant without undue delay after confirming a personal-data breach affecting Merchant data, unless law prohibits notice. The notice will include available information about the nature, likely consequences, affected data, containment, and contact point. Processor's notice is not an admission of fault. Merchant is responsible for notices it must make to data subjects, regulators, or other parties.
9. Return and deletion
During the service, Merchant may request available information through the app or support channel. On uninstall and authenticated shop erasure, Processor deletes tenant-scoped active database rows, Shopify sessions, encrypted credentials, and tenant-prefixed export objects, except data required by law or a documented legal hold. Business audit data is otherwise retained for a default rolling period of 395 days, and export objects for seven days. Deleted data in backups is isolated from ordinary use and ages out under the applicable provider schedule; any restoration must replay outstanding erasure obligations before merchant access is restored.
10. Audits
On reasonable written request, no more than once annually unless required following a confirmed incident or regulator request, Processor will provide information reasonably necessary to demonstrate compliance. Any further audit must protect other merchants and system security, occur during normal business hours, and avoid unreasonable disruption. Merchant bears its audit costs unless the audit identifies a material breach by Processor.
11. International transfers
Processing may occur outside Merchant's country, including in China and locations used by the listed service providers. This DPA does not by itself adopt a jurisdiction-specific international transfer mechanism. If applicable law requires Standard Contractual Clauses, a UK addendum, a PRC cross-border mechanism, or another instrument, the parties must execute the required instrument before the affected transfer. Until then, Merchant must not instruct Processor to handle data for which no valid transfer basis exists.
12. Processing details
- Subject matter: Shopify affiliate attribution review and commission audit.
- Duration: For the Merchant's use of AttribGate and the deletion periods described above.
- Nature and purpose: Collection from Shopify and merchant-connected networks, normalization, storage, comparison, recommendation, display, synchronization, support, and separately confirmed network action.
- Data subjects: Merchant staff, Shopify buyers represented by order-level evidence, affiliates or publishers, and support contacts.
- Personal data: Shop and staff session details; order identifiers, status, dates, amounts, currencies, discounts, refunds, and minimized attribution evidence; affiliate transaction and publisher identifiers; merchant decisions; operational identifiers; and support communications.
- Excluded fields: Buyer name, email, phone, address, payment credentials, and full Shopify Customer records are not stored in business tables.
- Special-category data: Not intentionally collected. Merchant must not instruct Processor to process it.
13. Order of precedence and contact
If this DPA conflicts with the Terms on personal-data processing, this DPA controls. A signed transfer addendum controls for its covered transfer. Otherwise, the governing-law and dispute clauses in the Terms apply. Data-protection notices: service@skymork.com.