Data Processing Addendum
Last updated: August 3, 2026
This addendum forms part of the Terms of Service and applies whenever Trussfy processes personal data on a merchant's behalf through the StockPulse app. It is accepted when you install the app.
1. Roles
The merchant is the controller. Trussfy is the processor, acting only on the merchant's documented instructions — those instructions being: analyze my inventory and show me the result. Shopify is an independent controller for the store data it holds.
2. Subject matter, duration, nature and purpose
Subject matter: providing inventory risk analysis. Duration: for as long as the app is installed. Nature and purpose: reading catalog, inventory, unit prices and order line-item data through the Shopify API in order to compute sales velocity, estimated stockout dates and the revenue a stockout would put at risk.
3. Categories of data subjects and personal data
Data subjects: the merchant and its staff (through the Shopify OAuth session). The app does notprocess data identifying the merchant's customers: it never reads names, email addresses, phone numbers or postal addresses.
Order line items are classified by Shopify as protected customer data because they relate to a purchase. StockPulse reads only the variant identifier, the quantity and the processing date of each line.
Read from the store — the kept column states what survives the request:
| Data | Why | Retention |
|---|---|---|
| Active products and their variants — id, title, SKU, created date, featured image preview, available inventory quantity, unit price | List what you sell, how much stock remains, and how much revenue a stockout would put at risk | Stored as an inventory snapshot, replaced by the next reading and deleted when you uninstall |
| Orders processed in the last 30 days — processed date, cancelled status, and per line item: variant id and quantity | Compute sales velocity and estimate stockout dates | Only the resulting daily unit counts per variant are kept. The orders themselves are never stored — no order id, no order total, no customer |
| Shop — name, currency, timezone | Display your figures in your own currency and local time | Never written to our database — read at each page load |
Reading a full catalogue takes Shopify several minutes, so it happens in the background and the result is stored as a snapshot, refreshed at least once a day. Between two refreshes your dashboard reads that snapshot rather than querying Shopify again. “Re-run analysis” forces a fresh direct reading straight away.
Stored until uninstall:
| Data | Why | Retention |
|---|---|---|
| Shopify OAuth session — access token, shop domain, granted scopes, token expiry | Authenticate the app against your store, as required by Shopify | Until you uninstall the app, then deleted |
| App settings — risk thresholds, supplier lead time, daily-report preference, onboarding flag, creation and update timestamps | Remember your own configuration between visits | Until you uninstall the app, then deleted |
| Inventory snapshot — per variant: id, product title, SKU, image URL, units in stock, unit price, product creation date, and units sold per calendar day over the last 30 days | Shopify cannot return a full catalogue inside a single web request. The complete reading runs in the background and is stored so your dashboard can open instantly and be correct on stores of any size | Replaced by each new reading (at least daily); deleted when you uninstall |
4. Processor obligations
- Process personal data only on the controller's documented instructions, and not for our own purposes.
- Never sell, rent or share personal data with third parties beyond the subprocessors listed below.
- Bind everyone with access to confidentiality obligations.
- Implement the security measures set out in article 6.
- Assist the controller with data subject requests and with security incident notifications.
- Delete all personal data on uninstall or upon request — no copies retained.
- Make available the information needed to demonstrate compliance, and allow audits on reasonable notice.
5. Subprocessors
The controller authorizes the following subprocessors. We will announce any addition by email before it takes effect, and the merchant may object by uninstalling the app.
- Supabase — Database hosting (OAuth token and app settings). European Union — Paris (eu-west-3).
- Vercel — Application and website hosting. European Union region for the marketing site.
- Shopify — Source of all store data; the app runs inside Shopify Admin. Per Shopify's own terms.
6. Security measures
- Data minimisation by design — no personal data of your customers is ever read or written: no name, no email address, no phone number, no postal address, no order identifier, no order total. What we keep is a single current picture of your merchandise — variants, units in stock, unit prices and daily units sold. It is overwritten by each new reading rather than accumulated, so there is no history of your store to breach, and it is deleted on uninstall.
- Encryption — TLS in transit; encryption at rest on the database.
- Access control — the OAuth token and settings tables are unreachable from any browser client (no public grants, row level security enabled); only the server can read them.
- Logging — server logs contain error messages and the shop domain only; no store data and no customer data.
- Deletion — the
app/uninstalledandshop/redactwebhooks delete the session and the settings immediately and unconditionally.
7. International transfers
Personal data we store is hosted in the European Union. Where a subprocessor operates outside the EEA, transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision.
8. Data subject requests and incidents
Because we hold no data about the merchant's customers, a customers/data_request or customers/redact webhook has nothing to return or erase; we confirm receipt and take no further action. Any personal data breach affecting merchant data is notified without undue delay to the address on the Shopify account.
9. Return and deletion
On uninstall, all personal data we hold about the store is deleted automatically. Since no store data is retained, there is nothing to return. A written confirmation of deletion is available on request at contact@trussfy.com.
10. Relationship with other documents
This addendum supplements the Terms of Service and the privacy policy. In case of conflict on data protection matters, this addendum prevails.