Data Processing Agreement
Last updated: September 17, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between the merchant ("Controller", "you") and TrustPulse Review ("Processor", "we", "us") for use of the TrustPulse Review Shopify app (the "Service"). It governs our processing of personal data on your behalf and applies where data protection laws such as the EU General Data Protection Regulation (GDPR), the UK GDPR, or comparable laws apply. If any term here conflicts with our Terms of Service, this DPA controls for matters of data protection.
1. Roles of the parties
For personal data relating to your customers, you are the Controller and we are the Processor. You determine the purposes and means of processing; we process such data only on your behalf and in accordance with this DPA.
2. Subject matter, nature, and purpose
We process personal data to provide the Service: collecting, moderating, and displaying product reviews; verifying purchases; sending review-request emails; and providing analytics and related tools. Processing continues for as long as you use the Service, unless a shorter period is required by your instructions or by law.
3. Types of personal data and data subjects
- Data subjects: your customers and store visitors who submit reviews or receive review-request emails.
- Personal data: name, email address, IP address (for spam prevention), review content, uploaded review photos, and order/purchase information used to verify purchases and schedule review requests.
4. Our obligations as Processor
- Instructions. We process personal data only on your documented instructions, including as set out in this DPA and the app's configuration, unless required otherwise by law (in which case we will inform you where legally permitted). If we believe that an instruction from you infringes applicable data protection law, we will inform you without undue delay.
- Confidentiality. Personnel authorized to process personal data are bound by appropriate confidentiality obligations.
- Security. We implement appropriate technical and organizational measures, including encryption in transit (HTTPS), access controls, and use of reputable infrastructure providers.
- Assistance. Taking into account the nature of processing, we assist you in responding to data-subject requests and in meeting your security, breach-notification, and impact-assessment obligations.
5. Sub-processors
You authorize us to engage the following sub-processors to provide the Service:
- Shopify — app platform and source of store data.
- Supabase — database and file storage.
- Resend — transactional email delivery.
- Hostinger — application hosting.
These providers operate globally; depending on each provider's configuration, personal data may be processed in the United States, the European Union, or other regions. We remain responsible for our sub-processors' performance of their data-protection obligations. We will give you reasonable notice of any intended addition or replacement of a sub-processor, giving you the opportunity to object on reasonable data-protection grounds.
6. International transfers
Personal data may be processed in countries outside your own, including outside the EU/UK. Where required, such transfers are made under appropriate safeguards, such as the European Commission's Standard Contractual Clauses or an equivalent mechanism.
7. Data-subject rights
Taking into account the nature of the processing, we assist you by appropriate technical
and organizational measures, insofar as possible, in fulfilling your obligation to respond to
requests from data subjects to exercise their rights (access, rectification, erasure,
restriction, portability, and objection). We honor Shopify's mandatory
customers/data_request, customers/redact, and
shop/redact webhooks as described in our Privacy Policy.
8. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting personal data we process on your behalf, and provide information reasonably available to us to help you meet your notification obligations.
9. Deletion and return of data
- On a customers/redact request, we delete the relevant customer's personal data (including review photos) within 30 days.
- On uninstall, Shopify sends a shop/redact request after 48 hours; on receipt we delete the store's personal data, with deletion completed within 30 days.
- On termination of the Service, at your choice we will delete or return all personal data we process on your behalf, and delete existing copies, unless retention is required by law.
10. Audits
On reasonable prior written request, and subject to confidentiality, we will make available information necessary to demonstrate compliance with this DPA and contribute to audits or inspections conducted by you or an auditor you mandate, to the extent proportionate and consistent with our security obligations to other customers.
11. Term
This DPA takes effect when you install the Service and continues while we process personal data on your behalf. Provisions that by their nature should survive termination will survive.
12. Contact
Data-protection questions and requests under this DPA can be sent to support@trustpulsereview.com.
Annex 1 — Technical and organizational measures
We maintain technical and organizational measures appropriate to the risk, including:
- Encryption in transit — all data is transmitted over HTTPS/TLS.
- Access control — access to production data is limited to authorized personnel on a need-to-know basis, and access to the Shopify API is scoped to the permissions the merchant grants.
- Authentication — administrative access to infrastructure is protected by strong authentication.
- Reputable infrastructure — data is hosted with established providers (Supabase, Hostinger) that maintain their own security programs.
- Data minimization — we collect only the data needed to provide the Service and do not use it for advertising.
- Logging and monitoring — application activity is logged to support operations and detect issues.
- Confidentiality — personnel with access to personal data are bound by confidentiality obligations.
- Deletion — data is deleted in response to redact requests and on termination as described in this DPA and our Privacy Policy.