Data Processing Addendum
The terms on which Loyal processes subscriber personal data on behalf of merchants.
Last updated 14 August 2026 Applies to the Loyal Shopify app
On this page
- Parties, scope and precedence
- Definitions
- Roles of the parties
- Details of the processing
- Instructions
- Confidentiality and personnel
- Security
- Personal data breach
- Subprocessors
- Assistance to the merchant
- International transfers
- Return and deletion
- Audit and information
- Liability
- Term, changes and general
- Contact Annex 1. Details of processing Annex 2. Technical and organisational measures Annex 3. Subprocessors
How to read this. This addendum applies whenever Loyal processes personal data about a merchant's subscribers. The merchant is the controller and we are the processor. It is part of the Terms of Service and is accepted automatically when a merchant installs Loyal. Nothing needs to be signed. If a merchant needs a countersigned copy for its own records, or needs the Standard Contractual Clauses executed separately, email support@slashcart.com.
1. Parties, scope and precedence
This Data Processing Addendum ("DPA") is between SlashCart Inc., a Delaware general corporation with a registered office at 131 Continental Drive, Suite 305, Newark, DE 19713, United States ("Loyal", "we", "us"), and the merchant who has installed Loyal on a Shopify store and accepted the Terms of Service ("merchant", "you").
This DPA applies to the processing of Subscriber Data by us on your behalf in connection with the Loyal app and related services. It does not apply to Merchant Data, which we process as a controller under the Privacy Policy.
This DPA forms part of the Terms of Service. If there is a conflict between this DPA and the Terms of Service or the Privacy Policy in relation to Subscriber Data, this DPA applies. If there is a conflict between this DPA and the Standard Contractual Clauses or the UK Addendum where they apply under section 11, the Standard Contractual Clauses or the UK Addendum apply.
2. Definitions
- Data Protection Law means all laws that apply to the processing of personal data under this DPA, including the GDPR, the UK GDPR and the Data Protection Act 2018, the Swiss Federal Act on Data Protection, the CCPA as amended by the CPRA, the comprehensive privacy laws of other United States states, PIPEDA, and any law that replaces or supplements them.
- GDPR means Regulation (EU) 2016/679. UK GDPR has the meaning given in the Data Protection Act 2018.
- CCPA means the California Consumer Privacy Act of 2018, as amended.
- Standard Contractual Clauses or SCCs means the clauses approved by European Commission Decision 2021/914, in the module described in section 11.
- UK Addendum means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner.
- Subscriber Data means personal data relating to your subscribers and customers that we process on your behalf, as described in Annex 1.
- Subprocessor means any third party we engage to process Subscriber Data on our behalf.
- Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Subscriber Data.
- Controller, processor, data subject, personal data, processing and supervisory authority have the meanings given in the GDPR. Under the CCPA, controller means business, processor means service provider or contractor, and data subject means consumer.
Other capitalised terms have the meanings given in the Terms of Service.
3. Roles of the parties
You are the controller of Subscriber Data. You decide what is collected, why, on what legal basis, and for how long, through your own privacy notice, your configuration of the app and your instructions to us.
We are your processor. We process Subscriber Data only on your documented instructions and only for the purposes in Annex 1. We do not determine the purposes or means of the processing.
Where Shopify processes Subscriber Data, it does so under its own agreement with you. Shopify is not our Subprocessor, and we are not Shopify's. Where a third party integration you connect receives Subscriber Data, it does so on your instruction and under your agreement with that provider. It is not our Subprocessor.
Under the CCPA, we are a service provider. We certify that we understand the restrictions in section 5 and will comply with them.
4. Details of the processing
The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.
5. Instructions
Your documented instructions are:
- the Terms of Service and this DPA;
- your configuration of the app, including the selling plans, notifications, retry rules, portal settings, retention settings and integrations you enable;
- any migration you request;
- any written instruction you give us through support, provided it is consistent with the Terms of Service.
We will process Subscriber Data only on those instructions, unless we are required to do otherwise by a law that applies to us, in which case we will tell you before processing unless the law prohibits it. If we believe an instruction breaches Data Protection Law, we will tell you promptly and may suspend the affected processing until the instruction is confirmed or changed. We are not obliged to carry out a legal review of your instructions.
We will not:
- sell Subscriber Data or share it for cross context behavioural advertising;
- retain, use or disclose Subscriber Data for any purpose other than the purposes in Annex 1, including any commercial purpose of our own;
- retain, use or disclose Subscriber Data outside the direct business relationship between you and us;
- combine Subscriber Data with personal data we receive from another merchant or from any other source, except as permitted by Data Protection Law for security, fraud prevention or the internal operation of the service;
- use Subscriber Data to train machine learning models;
- attempt to re identify de identified data.
6. Confidentiality and personnel
We will ensure that every person we authorise to process Subscriber Data is bound by a written confidentiality obligation or is under an appropriate statutory obligation, has received training appropriate to their role, and has access only to the Subscriber Data they need. Access is removed when a person stops working with us.
7. Security
We will implement and maintain the technical and organisational measures in Annex 2, which are appropriate to the risk of the processing having regard to the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing. The measures include encryption in transit and at rest, access control, environment separation, logging and backup.
We may update the measures from time to time, provided the update does not materially reduce the overall level of protection. Further detail is on the Security page.
You are responsible for the security of your Shopify account, for controlling who can act in the app on your behalf, and for the security of any system or integration that you connect to Loyal.
8. Personal data breach
8.1 Notice to you. If we become aware of a Personal Data Breach affecting Subscriber Data, we will notify you without undue delay and in any event within 48 hours of becoming aware of it. Notice goes to the email address on your Loyal account. Becoming aware means having a reasonable degree of certainty that a security incident has compromised Subscriber Data, not the first alert of a possible incident.
8.2 What the notice contains. The initial notice will describe, as far as we know at the time, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures we have taken or propose to take, and a contact point. Where we do not have all of this at first, we will provide it in phases as it becomes available, without waiting for the investigation to finish.
8.3 What we will do. We will investigate the breach, take reasonable steps to contain it and to reduce its effects, preserve evidence, and keep you updated at reasonable intervals until it is resolved. We will keep a record of every Personal Data Breach, including its facts, effects and the remedial action taken, and make that record available to you on request.
8.4 What we will not do. We will not notify a supervisory authority, a regulator or data subjects about a breach of Subscriber Data on your behalf unless you ask us to in writing or the law requires us to. Whether and how to notify them is your decision as controller. We will give you the information you need to make that decision and to meet your own deadlines, which may be as short as 72 hours under the GDPR.
8.5 Cooperation. We will cooperate with you and provide reasonable assistance in your investigation of the breach, your assessment of the risk to data subjects, and your response to any supervisory authority. We will not make a public statement about a breach that identifies you without your agreement unless the law requires it.
8.6 What is not a breach. An unsuccessful attempt that does not compromise Subscriber Data, such as a blocked login attempt, a port scan, a failed exploit or a denial of service that does not result in access, is not a Personal Data Breach and we are not obliged to notify it, although we may tell you about it.
8.7 Your obligations. If you become aware of a security incident affecting your Shopify account, your staff access or a connected integration that may affect Subscriber Data in Loyal, tell us promptly at support@slashcart.com so we can assist and take protective action.
Section 12 of the Privacy Policy refers to this section.
Decision needed before publishing. The 48 hour figure is a commitment and is shorter than the "without undue delay" wording that the GDPR requires of processors, because merchants have their own 72 hour deadline to the regulator and need time to act. Confirm that whoever is on call can meet 48 hours in practice, including at weekends. If not, change it here and on the Security page. Do not leave the two pages saying different numbers.
9. Subprocessors
9.1 Authorisation. You give us general authorisation to engage Subprocessors to process Subscriber Data, subject to this section. The current list, with the service each provides and the location of processing, is on the Subprocessors page and is summarised in Annex 3.
9.2 Obligations. Before a Subprocessor processes Subscriber Data, we will carry out due diligence on its security and privacy practices and put in place a written contract that imposes data protection obligations no less protective than those in this DPA. We remain fully liable to you for the performance of each Subprocessor's obligations.
9.3 Changes. We will give you at least 30 days notice before we add or replace a Subprocessor, by updating the Subprocessors page and by email to the address on your Loyal account. The notice will identify the Subprocessor, the service it will provide and the location of processing.
9.4 Objection. If you have a reasonable objection on data protection grounds, tell us in writing at support@slashcart.com within the notice period, explaining the grounds. We will work with you in good faith to resolve the objection, for example by proposing a change to the service that avoids the Subprocessor. If we cannot resolve it within 30 days of your objection, you may terminate the affected part of the service by uninstalling the app, and we will refund any prepaid fees for the unused period. That is your sole remedy for an objection.
9.5 Removals. We may remove a Subprocessor at any time without notice, and will update the Subprocessors page.
10. Assistance to the merchant
10.1 Data subject requests. If we receive a request from a data subject about Subscriber Data, we will not respond except to acknowledge it and to tell the data subject that the request has been passed to you, and we will forward it to you promptly. We provide export, correction and deletion tools within the app so you can respond yourself. Where a request cannot be fulfilled with those tools, we will give reasonable assistance on request. Requests received through Shopify's privacy webhooks are handled automatically on the timescales in section 15 of the Privacy Policy.
10.2 Other assistance. Taking into account the nature of the processing and the information available to us, we will give you reasonable assistance in meeting your obligations under Data Protection Law regarding security, breach notification, data protection impact assessments and prior consultation with a supervisory authority.
10.3 Costs. Assistance under this section is included in your plan where it is reasonable in scope. Where a request is manifestly excessive or would require substantial engineering effort beyond the tools we already provide, we may charge a reasonable fee, and we will agree it with you before we start.
10.4 Authorities. If we receive a request from a court, regulator or law enforcement body for Subscriber Data, we will assess it, disclose only what is legally required, and notify you before disclosing unless the law prohibits it or the request is an emergency involving a risk to life. We will not disclose Subscriber Data voluntarily.
11. International transfers
We are established in the United States and our team and Subprocessors operate across more than one country. Subscriber Data may therefore be transferred to, and processed in, the United States and the other countries listed on the Subprocessors page.
11.1 EEA transfers. Where Subscriber Data is transferred from the European Economic Area to a country that does not have an adequacy decision, the transfer is made under the Standard Contractual Clauses, Module Two (controller to processor), which are incorporated into this DPA by reference. For the purposes of the SCCs: you are the data exporter and we are the data importer; Clause 7 (docking) applies; Option 2 of Clause 9 applies with the notice period in section 9.3; the optional language in Clause 11 does not apply; Clause 17 is governed by the laws of Ireland; disputes under Clause 18 are resolved in the courts of Ireland; Annex I and Annex II of the SCCs are completed by Annex 1 and Annex 2 of this DPA; Annex III is the Subprocessors page.
11.2 UK transfers. Where Subscriber Data is transferred from the United Kingdom, the SCCs apply as amended by the UK Addendum. Table 1 is completed with the party details in section 1 and Annex 1; Table 2 selects the SCCs as completed in section 11.1; Table 3 is completed by Annexes 1 to 3; in Table 4, either party may end the UK Addendum as set out in section 19 of it.
11.3 Swiss transfers. Where Subscriber Data is transferred from Switzerland, the SCCs apply with the adaptations required by the Federal Data Protection and Information Commissioner, including that references to the GDPR are read as references to the Swiss Federal Act on Data Protection, the competent supervisory authority is the FDPIC, and data subjects in Switzerland may enforce their rights in Switzerland.
11.4 Supplementary measures. In addition to the SCCs, we apply the measures in Annex 2, including encryption in transit and at rest, and we commit to the handling of government requests in section 10.4. We have assessed the laws and practices of the destination countries and do not believe they prevent us from meeting our obligations under the SCCs. We will tell you if that changes.
11.5 Other transfers. Where any other Data Protection Law restricts transfers, we will rely on a mechanism recognised by that law, and will enter into any additional terms the law requires on request.
A copy of the SCCs as completed is available on request from support@slashcart.com.
12. Return and deletion
12.1 During the term. You can export Subscriber Data at any time using the export tools in the app, as described in section 21 of the Terms of Service.
12.2 On uninstall. When you uninstall Loyal, we delete Subscriber Data from live systems within 14 days, or within 48 hours of Shopify sending a shop redaction request, whichever is sooner. We do not retain a copy except as set out in 12.4.
12.3 On a redaction request. When Shopify sends a customer redaction request, we delete or irreversibly de identify the affected Subscriber Data within 30 days.
12.4 Backups and legal retention. Data already written to an encrypted backup is not individually removed from that backup. It remains encrypted, is not restored into live systems except in a disaster recovery event, and is destroyed when the backup expires on a rolling 35 day cycle. We may retain Subscriber Data for longer where a law that applies to us requires it, in which case we will continue to protect it under this DPA and will process it for no other purpose.
12.5 Certification. On written request within 30 days of uninstall, we will confirm in writing that deletion has been completed from live systems.
Section 11 of the Privacy Policy sets out the same schedule.
13. Audit and information
13.1 Information. We will make available to you the information reasonably necessary to demonstrate our compliance with this DPA. In the first instance that means the Security page, the Subprocessors page, this DPA, our completed security questionnaire, and any third party report or certification we hold at the time, which we will provide on request under confidentiality.
13.2 Audit. Where the information in 13.1 is not sufficient to satisfy a requirement of Data Protection Law or a supervisory authority, you or an independent auditor you appoint and we reasonably approve may audit our compliance with this DPA, subject to the following: no more than once in any 12 month period unless a supervisory authority requires it or a Personal Data Breach has occurred; at least 30 days written notice; during business hours; without unreasonable disruption to our operations; limited to systems and records that process Subscriber Data; not extending to other merchants' data or to our Subprocessors' premises; and subject to confidentiality. You bear your own costs, and we may charge a reasonable fee for our time where an audit exceeds two working days.
13.3 Findings. Where an audit identifies a material non compliance, we will remediate it within a reasonable time and tell you when we have done so.
14. Liability
Each party's liability arising out of or relating to this DPA, including the SCCs where they apply, is subject to the limitations and exclusions in section 22 of the Terms of Service, except that nothing in this DPA or the Terms of Service limits either party's liability to a data subject under Data Protection Law or under Clause 12 of the SCCs.
Our aggregate liability under this DPA and the Terms of Service together is a single cap, not two.
15. Term, changes and general
This DPA takes effect when you install Loyal and lasts for as long as we process Subscriber Data on your behalf, including the deletion period in section 12. Section 12 survives until deletion is complete, and section 14 survives indefinitely.
We may update this DPA where the product, our Subprocessors, the SCCs or Data Protection Law change. Where a change materially affects you, we will give at least 30 days notice by email or in the app, as set out in section 25 of the Terms of Service. If you do not agree, uninstall before the change takes effect. Changes required by law or by a new version of the SCCs may take effect sooner.
Where Data Protection Law requires a term that this DPA does not contain, that term is treated as included to the extent required. Where this DPA is silent on a matter, the Terms of Service apply.
16. Contact
SlashCart Inc. 131 Continental Drive, Suite 305 Newark, DE 19713 United States
All enquiries, including privacy, security and requests for a countersigned copy of this DPA: support@slashcart.com
Annex 1. Details of processing
Data exporter. The merchant identified by the Shopify store on which Loyal is installed. Contact details: the merchant's account details in Shopify. Role: controller.
Data importer. SlashCart Inc., 131 Continental Drive, Suite 305, Newark, DE 19713, United States. Contact: support@slashcart.com. Role: processor.
Subject matter. The operation of a subscription programme on the merchant's Shopify store using Loyal.
Duration. For as long as the merchant keeps Loyal installed, plus the deletion period in section 12.
Nature and purpose of the processing. Creating and managing subscription contracts and selling plans; scheduling, instructing and recording recurring charges; retrying failed payments according to rules the merchant configures; operating a customer portal where subscribers manage their own subscriptions; sending transactional notifications the merchant enables; sending data to integrations the merchant connects; producing analytics for the merchant; performing a migration the merchant instructs; providing support; and maintaining security and preventing abuse. Section 7 of the Privacy Policy lists these purposes.
Categories of data subjects. The merchant's customers who hold or have held a subscription, and customers whose records are read by the app in the course of managing subscriptions.
Categories of personal data.
- Identity and contact: name, email address, phone number
- Addresses: shipping and billing addresses
- Subscription and commercial: subscription contracts, selling plans, products, quantities, prices, discounts, next billing dates, billing cycles, order and draft order references
- Payment: opaque payment mandate identifiers held by Shopify; charge outcomes, amounts, currencies and dates; during a migration, gateway or network token references. No full card numbers or security codes.
- Portal activity: actions taken, timestamps, and the session and identifier data needed to authenticate a subscriber
- Any other customer metafields the merchant has chosen to expose to the app
Special category data. None. The merchant must not send special category data, government identification numbers, financial account credentials or full card numbers, as set out in section 4.6 of the Privacy Policy.
Frequency of transfer. Continuous, for as long as the app is installed.
Retention. As set out in section 12 and in section 11 of the Privacy Policy.
Subprocessor transfers. As set out in the Subprocessors page, for the purposes stated there.
Competent supervisory authority (SCCs Annex I.C). Where the merchant is established in an EEA member state, the supervisory authority of that member state. Where the merchant is not established in the EEA but has appointed a representative, the supervisory authority of the member state where the representative is established. Otherwise, the supervisory authority of the member state where the data subjects are located.
Annex 2. Technical and organisational measures
The following measures are in place at the date of this DPA. The Security page contains further detail and is updated more often than this annex.
- Encryption in transit. All connections to and from Loyal, including to Shopify, to Subprocessors and to the customer portal, use TLS 1.2 or above.
- Encryption at rest. Databases, file storage and backups are encrypted at rest using industry standard algorithms managed by our hosting provider.
- Access control. Access to production systems is limited to the people who need it for their role, is granted individually rather than through shared accounts, requires multi factor authentication, is reviewed periodically, and is removed when a person stops working with us or changes role.
- Environment separation. Production is separated from development and test environments. Real subscriber data is not used in testing.
- Logging and monitoring. Access and error logs are kept for 12 months. Production systems are monitored for availability and for anomalous activity.
- Vulnerability management. Dependencies are kept patched. Code changes are reviewed before deployment. Security relevant issues are prioritised over feature work.
- Backups and recovery. Encrypted backups are taken regularly and retained on a rolling 35 day cycle. Recovery procedures exist and are tested.
- Data minimisation. We request the minimum Shopify access scopes needed and read only the fields required for a stated purpose.
- Personnel. Staff and contractors with access to Subscriber Data are bound by confidentiality obligations and receive security and privacy training.
- Incident response. A documented process exists for detecting, containing, investigating and notifying security incidents, with the notification commitments in section 8.
- Subprocessor management. Subprocessors are assessed before engagement and bound by written contract.
- Deletion. Automated deletion runs on the schedule in section 12, and Shopify's mandatory privacy webhooks are implemented.
Annex 3. Subprocessors
The authorised Subprocessors, the service each provides and the location of processing are listed on the Subprocessors page, which is incorporated into this DPA and kept current under section 9. That page is the authoritative list.