Data Processing Addendum (DPA)
Effective Date: January 2025 Last Updated: January 2025
This Data Processing Agreement (“Agreement” or “DPA”) is entered into between:
By installing FraudFighter, you acknowledge that you have read, understood, and agree to be bound by this Agreement.
| Term | Definition |
|---|---|
| Personal Data | Any information relating to an identified or identifiable natural person, including customer email addresses and order information |
| Processing | Any operation performed on Personal Data, including collection, use, storage, disclosure, or deletion |
| Controller | The Merchant who determines the purposes and means of processing Personal Data |
| Processor | FraudFighter, which processes Personal Data on behalf of the Controller |
| Data Subject | An individual whose Personal Data is processed (e.g., your customers) |
| Sub-processor | Any third party engaged by FraudFighter to process Personal Data |
| Applicable Data Protection Law | GDPR, CCPA/CPRA, PIPEDA, and other applicable privacy regulations |
FraudFighter processes Personal Data solely to provide fraud detection and prevention services, specifically:
| Category | Data Elements | Storage |
|---|---|---|
| Merchant Data | Shop domain, OAuth tokens, user name, email | Stored securely |
| Customer Data | Email addresses, order identifiers | Processed in memory only, NOT stored |
| Configuration Data | App settings and preferences | Stored as Shopify metafields |
| Activity | Description | Data Retained |
|---|---|---|
| Email pattern matching | Check if customer email ends with buyforme.amazon domain | No |
| Order tagging | Add tags to orders via Shopify API | No |
| Order cancellation | Cancel orders via Shopify API | No |
| Session management | Maintain merchant authentication | Yes (merchant data only) |
As the Controller, you are responsible for:
As the Processor, we are responsible for:
FraudFighter may process data in the following locations:
For transfers of Personal Data outside the European Economic Area (EEA), we rely on:
Because FraudFighter does not store customer Personal Data, the data transfer risks are minimized. Customer email addresses are:
We implement the following security controls:
The most effective security measure is our architectural decision to not store customer Personal Data. This eliminates risks associated with:
| Sub-processor | Purpose | Location |
|---|---|---|
| Shopify Inc. | Platform hosting, API services, metafield storage | Global (US/EU) |
| Cloud hosting provider | Application infrastructure | As configured |
We will notify you of any intended changes to sub-processors. You may object to such changes within 30 days. If we cannot accommodate your objection, you may terminate your use of the service.
As the Controller, you must:
We will assist you in responding to data subject requests by:
We have implemented Shopify’s mandatory compliance webhooks:
| Webhook | Response |
|---|---|
customers/data_request | Confirmation that no customer data is stored |
customers/redact | Confirmation that no customer data exists to delete |
shop/redact | Deletion of merchant session data |
Retention Period: None (0 seconds)
Customer Personal Data is processed in real-time and immediately discarded. We do not retain customer email addresses, order details, or any other customer information.
| Data Type | Retention Period |
|---|---|
| Session/OAuth tokens | Until app uninstallation + 48 hours |
| User information | Until app uninstallation + 48 hours |
| App configuration | Managed by Shopify (metafields) |
Server logs containing operational data are retained for a maximum of 30 days for debugging and security purposes. Customer email addresses are masked in production logs.
In the event of a data breach affecting your Personal Data, we will:
Data breaches will be communicated to the email address associated with your Shopify account.
Upon reasonable request, we will provide:
You may request an audit of our data processing practices with reasonable notice. We will cooperate with such audits, subject to reasonable confidentiality requirements.
When you uninstall FraudFighter:
Because we do not store customer data, no customer data deletion is required upon termination.
Upon request, we will certify in writing that all your data has been deleted in accordance with this Agreement.
This Agreement is governed by:
By installing and using FraudFighter, you:
For questions about this Agreement or our data protection practices:
FraudFighter Data Protection Email: support@fraudfighter.pro
For EU-specific inquiries, you may also contact your local supervisory authority.
We may update this Agreement to reflect changes in:
Material changes will be communicated via the email associated with your Shopify account. Continued use of FraudFighter after such updates constitutes acceptance of the revised Agreement.
This Data Protection Agreement is part of the FraudFighter Terms of Service and should be read in conjunction with our Privacy Policy.