Data Processing Agreement
Effective Date: 26 August 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Kayease Global Solutions LLP of 3rd Floor, RSEB officers Colony, 11B, Ram Marg, opp. Inox, D-Block, RSEB Colony, Amrapali Circle, Vaishali Nagar, Jaipur, Rajasthan 302021, trading as Retrace ("Retrace", "Processor"), and the merchant installing the Retrace Shopify application ("Controller", "you"). It applies whenever Retrace processes personal data on your behalf. Installing Retrace constitutes acceptance of this DPA.
1. Roles
You are the controller of the personal data in your Shopify store. Retrace is a processor, acting only on your documented instructions. Your instructions are given by installing the app, configuring its settings, and requesting restores and exports.
2. Subject matter, nature and purpose
Retrace maintains an encrypted version history of your store's data so that you can review what changed and recover records that were altered or deleted. The processing consists of reading data from the Shopify Admin API, storing it in encrypted form, presenting it back to you, and — for supported resource types — writing an earlier version back to your store at your explicit request.
3. Duration
Processing continues for as long as Retrace is installed on your store, and ends when the app is uninstalled, subject to the deletion terms in section 8.
4. Categories of data subjects
Your customers and prospective customers, and the staff whose actions are recorded in your store's data.
5. Types of personal data
Retrace processes the minimum required for backup and recovery:
- Customer records — customer ID, first and last name, email address,
phone number, billing and shipping addresses, marketing consent state, notes, tags, account state, and customer metafields.
- Order records — order identifiers, totals, line items, financial and
fulfilment status, notes, tags, shipping address, and the associated customer reference. Shopify permits Retrace to read orders placed in the last 60 days only, so each backup captures orders within that window and older orders are never fetched. Orders are captured for reference and export only.
- Merchant contact data — your
.myshopify.comdomain and the email
address used for backup alerts, stored encrypted.
Retrace does not process payment card data, complete payment profiles, or any special category data.
6. Limits on processing
Retrace processes personal data only to provide the service described above. Specifically, Retrace does not:
- sell, rent, share or otherwise disclose personal data to any third party for
their own purposes;
- use personal data for advertising, marketing, audience building or
profiling;
- use personal data for automated decision-making of any kind;
- use personal data to train machine learning models;
- write customer records back to your store. Customer data is read-only in
Retrace: the restore engine refuses the customer resource type by name (server/restore/restorable.ts). Orders are likewise never restored, because recreating a deleted order would manufacture a financial record.
7. Security measures
Retrace maintains the following technical and organisational measures:
| Measure | Implementation |
|---|---|
| Encryption at rest | AES-256-GCM. Each shop's data is encrypted under its own data encryption key (DEK), itself wrapped by a master key held outside the database. |
| Encryption in transit | TLS for all traffic to Shopify, between services, and to the database. |
| Integrity | Authenticated encryption (GCM) — a tampered blob fails to decrypt rather than returning corrupted data. |
| Access control | Staff have no path to read merchant content. The internal admin surface exposes counts, sizes, timestamps, statuses and store domains only. |
| Key separation | Per-shop keys mean no single credential exposes more than one store's data. |
| Audit logging | An append-only activity log records every action the application takes. Rows are never updated or deleted. |
| Credential handling | Shopify access tokens and merchant email addresses are encrypted at rest as separate secrets. |
| Staff accounts | Multi-factor authentication and strong password requirements on all accounts with production access. |
| Environment separation | Development and testing use Shopify development stores and synthetic data. Production data is never copied into development or staging environments. |
| Incident response | Documented in the Security Incident Response Policy, which is published alongside this DPA. |
8. Retention and deletion
Personal data is retained only for the retention window of your plan, after which a scheduled job deletes the aged versions. The windows are 7 days on the Free plan and for a store with no plan assigned, 30 days on Starter, 90 days on Professional and 365 days on Business. You choose that window by choosing your plan, you may shorten it from the app's settings, and you can delete your history from the Retrace dashboard at any time. The newest saved version of any item is never deleted by ageing. The effect of a downgrade — the previous window is honoured for a further 7 days — and the full table are in section 8 of the Terms of Service.
On uninstall, nothing is deleted immediately, so a reinstall recovers your history. Shopify then sends the shop/redact webhook, normally about 48 hours after the uninstall, and on receiving it Retrace deletes every object held for your store from object storage, deletes the stored records, and destroys your shop's data encryption key, rendering anything that could survive those deletions permanently unreadable. Your store's domain and the timestamps that prove the erasure happened are the only things kept.
On `customers/redact`, Retrace deletes the identified shopper's customer record and its version history, deletes the stored copies of every order named in the request, rewrites every other stored order so that it no longer carries the shopper's name, address or phone number, and destroys any export archive that contained them. Shopify keeps the shopper on orders it did not name, so a later backup of a still-installed store may capture those orders again; the erasure covers what is held at the moment it is carried out.
9. Assisting you with data subject requests
Retrace supports Shopify's mandatory compliance webhooks — customers/data_request, customers/redact and shop/redact — and acts on them automatically. On customers/data_request, Retrace identifies exactly which stored records concern the shopper and provides that to you, the controller, who owes the shopper an answer within 30 days. Where a data subject request cannot be satisfied through those channels, contact sunny@kayease.com and Retrace will assist you within the timeframes applicable law places on you as controller.
10. Where your data is held, and by whom
- The application and its PostgreSQL database run on a server provided by
Hostinger, in India (Mumbai).
- Encrypted blob storage — backup snapshots, theme and file assets, and export
archives — is provided by MinIO, in India (Mumbai).
- Transactional alert email is delivered by Google (Gmail SMTP), sending from
Global (Google data centres).
Retrace uses the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Hostinger | Application hosting — the server behind retrace.kayease.com — and the PostgreSQL database on it | India (Mumbai) |
| MinIO | Encrypted blob storage: backup snapshots, theme and file assets, and export archives | India (Mumbai) |
| Google (Gmail SMTP) | Transactional alert email to merchants | Global (Google data centres) |
Retrace gives you notice before adding or replacing a sub-processor, and imposes data protection obligations on each that are no less protective than this DPA.
Shopify itself is not listed above: Shopify is the source of the data and your own processor for it, under your agreement with them rather than under this one.
11. International transfers
Merchant data is held in the regions named in section 10. Where personal data is transferred outside the jurisdiction in which it was collected, Retrace relies on an appropriate transfer mechanism under applicable law, including the Standard Contractual Clauses where required.
12. Personal data breach
Retrace notifies you without undue delay, and in any event within 72 hours of confirming a personal data breach affecting your data, with the information you need to meet your own notification obligations. See the Security Incident Response Policy.
13. Audit
On reasonable written request, and no more than once a year unless required by a supervisory authority, Retrace will provide the information necessary to demonstrate compliance with this DPA.
14. Contact
Kayease Global Solutions LLP, 3rd Floor, RSEB officers Colony, 11B, Ram Marg, opp. Inox, D-Block, RSEB Colony, Amrapali Circle, Vaishali Nagar, Jaipur, Rajasthan 302021.
Data protection matters: sunny@kayease.com. Anything else: sunny@kayease.com, or raise a request from the Help & support screen inside the app.