1Parties and scope
This Data Processing Agreement (“DPA”) is entered into between:
- SAFETYCHECK, société par actions simplifiée with a share capital of €5,000, registered office 26 avenue Alfred Van Pelt, 62300 Lens, France, RCS Arras 909 494 882, VAT FR 79 909 494 882, trading as Starship Backup (“Starship”, the Processor); and
- the merchant who installs or uses the Starship Backup application (“Merchant”, the Controller).
It forms part of the Terms of Service (the “Principal Agreement”). Where this DPA conflicts with the Principal Agreement on the processing of personal data, this DPA prevails. It applies to all processing of Merchant Personal Data by Starship on the Merchant's behalf.
2Definitions
“Applicable Data Protection Law” means Regulation (EU) 2016/679 (GDPR), the French Data Protection Act of 6 January 1978, the UK GDPR and the Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US state privacy laws including the CCPA as amended by the CPRA, each to the extent it applies to the processing under this DPA.
“Merchant Personal Data” means the personal data contained in the Merchant's Shopify store that Starship processes on the Merchant's behalf, as described in Annex I.
“Controller”, “Processor”, “Data Subject”, “Personal Data Breach”, “Processing” and “Supervisory Authority” have the meanings given in the GDPR. “Sell”, “Share” and “Service Provider” have the meanings given in the CCPA.
3Roles
The Merchant is the Controller and Starship is the Processor of Merchant Personal Data. For the purposes of the CCPA, Starship is a Service Provider and processes Merchant Personal Data only for the business purposes set out in Annex I.
Starship processes the data of Starship portal accounts, and its own operational logs, as a Controller. That processing is outside this DPA and is described in the Privacy Policy.
4Starship's obligations
4.1Process only on documented instructions. Starship shall process Merchant Personal Data only on the Merchant's documented instructions, including with regard to international transfers, unless required to do otherwise by law, in which case Starship shall inform the Merchant before processing unless that law forbids it. The Principal Agreement, this DPA and the Merchant's use of the app's features are the Merchant's complete documented instructions. Starship shall inform the Merchant if, in its opinion, an instruction infringes Applicable Data Protection Law.
4.2Never sell or share it. Starship shall not sell or share Merchant Personal Data; shall not retain, use or disclose it for any purpose other than performing the Service; shall not combine it with personal data from another source except as permitted for a Service Provider; and shall not use it for its own commercial purposes, for advertising, or to train machine-learning models.
4.3Impose confidentiality. Starship shall ensure that every person authorised to process Merchant Personal Data is bound by a duty of confidentiality that survives the end of their engagement.
4.4Secure the data. Starship shall implement and maintain the technical and organisational measures set out in Annex II, and shall not materially reduce the protection they give during the term.
4.5Engage sub-processors only under clause 6.
4.6Assist with Data Subject requests.
Taking into account the nature of the processing, Starship shall assist the
Merchant by appropriate technical and organisational measures in responding
to requests from Data Subjects exercising their rights. Where a Data Subject
contacts Starship directly, Starship shall not answer on the merits, shall
refer them to the Merchant, and shall notify the Merchant without undue
delay. Starship records and acts on Shopify's
customers/data_request, customers/redact and
shop/redact requests as described in Annex II.
4.7Assist with security, breaches and impact assessments. Starship shall assist the Merchant in meeting its obligations under Articles 32 to 36 GDPR, taking into account the nature of the processing and the information available to Starship.
4.8Delete or return the data in accordance with clause 8.
4.9Make information available. Starship shall make available to the Merchant the information necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits under clause 9.
5Merchant's obligations
The Merchant warrants that it has a lawful basis for the processing it instructs, that it has given its Data Subjects the information Applicable Data Protection Law requires, and that its instructions comply with that law. The Merchant is responsible for the accuracy of the personal data in its store and for the consent and preference decisions recorded there.
6Sub-processors
6.1General authorisation. The Merchant gives Starship general written authorisation to engage the sub-processors named in Annex III.
6.2Changes. Starship shall give the Merchant at least 30 days' notice before adding or replacing a sub-processor, by email to the contact address of the Merchant's Shopify store and by updating Annex III on this page.
6.3Objection. The Merchant may object on reasonable data-protection grounds within that notice period, by writing to support@starshipsecurity.co. The parties shall discuss the objection in good faith; if it cannot be resolved, the Merchant may terminate the Service without penalty before the change takes effect.
6.4Flow-down and liability. Starship shall impose on each sub-processor data protection obligations that give a level of protection equivalent to this DPA, and remains fully liable to the Merchant for its sub-processors' performance of those obligations.
7Location and international transfers
Merchant Personal Data is stored in the European Union. Backups, archives and the audit log are held in Paris, France; the directory that maps each store to its organisation is held in Dublin, Ireland; the application that reads and writes the data runs in Paris. A workspace that requests Frankfurt, Dublin or Stockholm is served from Paris until that location opens. Locations outside the European Union cannot be chosen.
The sub-processors in Annex III are companies established in the United States. Where one of them, or one of its own sub-processors, processes Merchant Personal Data outside the European Economic Area, for example for support, security or operational logging, that transfer is governed by the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, as incorporated in that provider's data processing agreement, together with the UK International Data Transfer Addendum where the UK GDPR applies.
Starship shall not store backup content outside the European Union without first treating the change as a sub-processor change under clause 6.
8Deletion and return
Uninstalling the app stops scheduled backups immediately. Shopify then
sends Starship its shop/redact request, about 48 hours after
the uninstall. On receiving it, Starship deletes the store's records, keys
and backups from its database, and deletes the store's files from storage
at the next daily maintenance run. If the store has been reinstalled in the
meantime, nothing is deleted.
In any event, Starship shall delete Merchant Personal Data, including existing copies, within 90 days of the end of the Principal Agreement, unless Applicable Data Protection Law requires further storage, in which case Starship shall inform the Merchant and continue to protect the data under this DPA.
Return. Before uninstalling, the Merchant may ask support@starshipsecurity.co for a copy of its backed-up data, which Starship shall provide in a commonly used, machine-readable format.
Two records outlive the deletion and contain no customer record in the clear: the entries of the audit log, which prove what was done, and, for each erased customer, an identifier and a keyed hash of their email address, kept only so that no restore can bring them back.
9Audits
Starship shall make available to the Merchant, on reasonable written request and no more than once in any twelve-month period, the information necessary to demonstrate compliance with this DPA, including a description of the measures in Annex II.
Where that information does not reasonably demonstrate compliance, or where a Supervisory Authority requires it, the Merchant may have an audit carried out, at its own cost, by an independent auditor bound by confidentiality, on at least 30 days' written notice, during business hours and without access to other merchants' data. Audits of the infrastructure operated by the sub-processors in Annex III are carried out through the reports and certifications those providers make available.
Starship itself holds no third-party security audit or certification as at the date this DPA comes into force.
10Personal data breach
Starship shall notify the Merchant without undue delay, and in any event within 72 hours of becoming aware of a Personal Data Breach affecting Merchant Personal Data, by email to the contact address of the Merchant's Shopify store.
The notification shall describe, as far as is known: the nature of the breach; the categories and approximate number of Data Subjects and records concerned; its likely consequences; the measures taken or proposed; and a contact point for further information. Starship shall provide further information as it becomes available, and shall make no public statement identifying the Merchant without the Merchant's prior written consent, unless the law compels it.
11Liability and general
Each party's liability under this DPA is subject to the limitation in clause 14 of the Terms of Service, except where Applicable Data Protection Law does not allow it to be limited.
This DPA is governed by French law, and the parties submit to the exclusive jurisdiction of the Tribunal de commerce d'Arras. If any provision is held invalid, the rest remains in force.
Annex IDetails of the processing
- Subject matter
- Backup, integrity verification and restoration of the Merchant's Shopify store data.
- Duration
- For as long as the app is installed, plus the deletion period in clause 8.
- Nature and purpose
- Copying store records from the Shopify Admin API on a schedule (daily by default) and on demand; encrypting and storing them; verifying their integrity; writing supported objects back to the store when the Merchant requests a restore; keeping orders as an archive, never written back; and answering the privacy requests Shopify forwards. Personal data is processed for no other purpose.
- Frequency
- Continuous: on the backup schedule, and whenever the Merchant starts a backup or a restore.
Types of personal data
| Source | Personal data |
|---|---|
| Customers | Name, email address, phone numbers, postal addresses, tags, notes, the metafields attached to the customer, and the identifiers Shopify assigns |
| Orders | Line items and totals, and the customer, billing and shipping details recorded on the order, including the email and delivery address given at a guest checkout |
| Store content | Any personal data the Merchant has itself placed in pages, blog articles, theme files or metafields |
| Merchant staff | The identifier and email address of the staff member acting in the app, with the IP address and browser of the request, as recorded in the audit log |
Starship does not receive payment card data or bank details, and does not request government identifiers or special categories of personal data under Article 9 GDPR.
Categories of Data Subjects
The Merchant's customers and guest buyers whose records exist in the Merchant's Shopify store, and the Merchant's staff who use the app.
Retention
- Backups are kept for 90 days, then deleted by a daily scheduled job.
- The customer and order archives hold the most recently captured version of each record, for as long as the store is connected, until that record is erased or the store's data is deleted under clause 8.
- The audit log is kept as evidence and is not purged. It holds no customer record.
Annex IITechnical and organisational measures
Starship maintains at least the following measures.
Encryption
- All traffic runs over TLS. The portal sends HTTP Strict Transport Security.
- Storage is encrypted at rest by the providers in Annex III. Customer records carry a second layer applied by the application before they reach the database: each is encrypted under a key belonging to that customer alone, wrapped by a key derived for the store. Orders without a customer account are encrypted under the store's key.
- Where a customer must be found by email address, a keyed hash of the address is stored rather than the address.
- Shopify access tokens are stored encrypted. The root encryption key is held in the hosting provider's protected configuration, never in the code or the database.
Separation and access control
- Every business table carries the organisation's identifier, and row-level security in the database confines each organisation to its own rows. Stores within an organisation are separated by their store identifier.
- Files are held in a private storage bucket, reachable only through short-lived signed URLs issued to a signed-in member of the owning workspace.
- Access to production systems is through named accounts protected by the provider's two-factor authentication; there are no shared logins. Access is limited to the staff who operate and support the Service.
Audit log
Backups, restores and reads of archives containing personal data are written to an append-only audit log. Each entry is hash-chained to the previous one, the database refuses updates and deletions, and the chain can be verified end to end, so a removed or altered entry is detectable. Direct database connections by operators are recorded in the database provider's logs, not in this audit log.
Environment separation
Production personal data does not reach development. Automated tests run against a Shopify client that refuses to reach any store unless the test installs a fake one.
Retention and erasure
- Expired backups are deleted automatically by a daily scheduled job.
-
customers/data_requestandshop/redactrequests are recorded before they are acted on. Acustomers/redactrequest is recorded once it has been carried out. -
On
customers/redact, Starship first records a guard that stops any restore from recreating that customer, then destroys the key that seals the customer's archived record and deletes that record. - Limit: an erasure request does not reliably reach orders. Orders without a customer account are sealed under the store's key, which cannot be destroyed for one person, and orders Shopify still returns after the request may be archived again at the next backup. Starship removes such orders manually on the Merchant's instruction.
-
Limit: a
customers/data_requestorcustomers/redactrequest that arrives while the application is uninstalled from the store is neither recorded nor acted on, although the store's data is still held untilshop/redactdeletes it, 48 hours after the uninstall, unless the application is installed again first. Starship carries out such a request manually on the Merchant's instruction. - On
shop/redact, the store's data is deleted as set out in clause 8.
Integrity
Each backup records its integrity findings, covering completeness and content hashes, and a backup that could not capture everything is shown as partial in the app. This is not a malware scan, and storage is not immutable.
Incidents and data loss prevention
Starship maintains a written security incident response procedure, including the notification in clause 10, and a written data loss prevention procedure covering what may leave the system, to where, and under which controls.
Certifications
Starship holds no third-party security audit or certification as at the date this DPA comes into force.
Annex IIIAuthorised sub-processors
This list is the one clause 6.2 refers to. It is updated here, with 30 days' notice, before a sub-processor is added or replaced.
| Sub-processor | What it does | Where |
|---|---|---|
| Supabase, Inc. | Database and file storage holding the encrypted backups, archives and audit log; the directory of organisations and connected stores | Paris, France (backups) · Dublin, Ireland (directory) |
| Vercel Inc. | Runs the Shopify app and its scheduled jobs, hosts the portal, and keeps request logs | Paris, France (application) · global network (portal, logs) |
| Clerk, Inc. | Sign-in and organisation membership for the portal: names, email addresses and sessions of portal users | United States |
Clerk processes only portal account data, for which Starship is Controller; it is listed so that the Merchant sees every provider involved in the Service. No email delivery provider and no artificial intelligence provider receives Merchant Personal Data.
Shopify is not a sub-processor. It is the Merchant's own platform, the source of the data and the destination of restores, under the Merchant's own agreement with Shopify.