Data Processing Addendum
Last updated: August 11, 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between Ozeefy (“Processor”) and the customer entity that uses Smart Analytics (“Controller”) for processing of personal data in connection with the Service.
1. Scope
Processor processes personal data only to provide Smart Analytics: account administration, integration sync, dashboards, and reporting delivery as configured by Controller. Processing is limited to analytics and reporting. Processor does not sell personal data and does not use Shopify protected customer data for CRM, email marketing, or advertising to end-customers.
2. Categories of data
Typical categories include workspace user names and work email addresses, role assignments, and platform reporting metrics. For Shopify specifically:
- Shopify’s
shopifyqlQueryAPI requires Level 2 protected customer data fields (name, address, email, phone) at the API access level. Processor uses that access only to retrieve aggregated Admin Analytics metrics and does not store or display raw name, email, phone, or street address. - Order-line reporting may store shipping country code and commercial line fields (product, quantities, revenue)—not full street addresses or contact details.
- Compliance webhook audit rows may retain shop domain, topic, and Shopify IDs needed to fulfill mandatory privacy requests—not customer email or phone from the webhook body.
Controller determines what accounts are connected.
3. Instructions
Processor processes personal data only on documented instructions from Controller, including through product configuration (integrations, users, report recipients), unless required by law.
4. Security
Processor implements appropriate technical and organizational measures described on the Security page, including encryption in transit (HTTPS), managed-database access controls and provider encryption for data at rest, and secret handling for OAuth tokens.
5. Sub-processors
Processor may use infrastructure sub-processors (hosting, database, email delivery) to operate the Service. A current list is available on request at legal@ozeefy.com.
6. International transfers
Where personal data is transferred internationally, Processor relies on appropriate safeguards required for that transfer.
7. Deletion & return
Disconnecting an integration stops further sync and clears OAuth tokens. Shopify reporting rows are purged automatically 90 days after disconnect. Upon Shopify shop/redact or uninstall, Processor deletes or disconnects shop-linked Shopify reporting data as described in the Privacy Policy. Controller may also request deletion or export of workspace data subject to legal retention requirements. Shopify customers/data_request exports are delivered to the store owner when a workspace email is available.
8. Related policies
This DPA should be read with our Privacy Policy, Security, and Terms of Service.
9. Contact
Privacy: privacy@ozeefy.com. Legal: legal@ozeefy.com.