Data Processing Agreement

Effective Date: 26 August 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Kayease Global Solutions LLP of 3rd Floor, RSEB officers Colony, 11B, Ram Marg, opp. Inox, D-Block, RSEB Colony, Amrapali Circle, Vaishali Nagar, Jaipur, Rajasthan 302021, trading as Retrace ("Retrace", "Processor"), and the merchant installing the Retrace Shopify application ("Controller", "you"). It applies whenever Retrace processes personal data on your behalf. Installing Retrace constitutes acceptance of this DPA.

1. Roles

You are the controller of the personal data in your Shopify store. Retrace is a processor, acting only on your documented instructions. Your instructions are given by installing the app, configuring its settings, and requesting restores and exports.

2. Subject matter, nature and purpose

Retrace maintains an encrypted version history of your store's data so that you can review what changed and recover records that were altered or deleted. The processing consists of reading data from the Shopify Admin API, storing it in encrypted form, presenting it back to you, and — for supported resource types — writing an earlier version back to your store at your explicit request.

3. Duration

Processing continues for as long as Retrace is installed on your store, and ends when the app is uninstalled, subject to the deletion terms in section 8.

4. Categories of data subjects

Your customers and prospective customers, and the staff whose actions are recorded in your store's data.

5. Types of personal data

Retrace processes the minimum required for backup and recovery:

phone number, billing and shipping addresses, marketing consent state, notes, tags, account state, and customer metafields.

fulfilment status, notes, tags, shipping address, and the associated customer reference. Shopify permits Retrace to read orders placed in the last 60 days only, so each backup captures orders within that window and older orders are never fetched. Orders are captured for reference and export only.

address used for backup alerts, stored encrypted.

Retrace does not process payment card data, complete payment profiles, or any special category data.

6. Limits on processing

Retrace processes personal data only to provide the service described above. Specifically, Retrace does not:

their own purposes;

profiling;

Retrace: the restore engine refuses the customer resource type by name (server/restore/restorable.ts). Orders are likewise never restored, because recreating a deleted order would manufacture a financial record.

7. Security measures

Retrace maintains the following technical and organisational measures:

MeasureImplementation
Encryption at restAES-256-GCM. Each shop's data is encrypted under its own data encryption key (DEK), itself wrapped by a master key held outside the database.
Encryption in transitTLS for all traffic to Shopify, between services, and to the database.
IntegrityAuthenticated encryption (GCM) — a tampered blob fails to decrypt rather than returning corrupted data.
Access controlStaff have no path to read merchant content. The internal admin surface exposes counts, sizes, timestamps, statuses and store domains only.
Key separationPer-shop keys mean no single credential exposes more than one store's data.
Audit loggingAn append-only activity log records every action the application takes. Rows are never updated or deleted.
Credential handlingShopify access tokens and merchant email addresses are encrypted at rest as separate secrets.
Staff accountsMulti-factor authentication and strong password requirements on all accounts with production access.
Environment separationDevelopment and testing use Shopify development stores and synthetic data. Production data is never copied into development or staging environments.
Incident responseDocumented in the Security Incident Response Policy, which is published alongside this DPA.

8. Retention and deletion

Personal data is retained only for the retention window of your plan, after which a scheduled job deletes the aged versions. The windows are 7 days on the Free plan and for a store with no plan assigned, 30 days on Starter, 90 days on Professional and 365 days on Business. You choose that window by choosing your plan, you may shorten it from the app's settings, and you can delete your history from the Retrace dashboard at any time. The newest saved version of any item is never deleted by ageing. The effect of a downgrade — the previous window is honoured for a further 7 days — and the full table are in section 8 of the Terms of Service.

On uninstall, nothing is deleted immediately, so a reinstall recovers your history. Shopify then sends the shop/redact webhook, normally about 48 hours after the uninstall, and on receiving it Retrace deletes every object held for your store from object storage, deletes the stored records, and destroys your shop's data encryption key, rendering anything that could survive those deletions permanently unreadable. Your store's domain and the timestamps that prove the erasure happened are the only things kept.

On `customers/redact`, Retrace deletes the identified shopper's customer record and its version history, deletes the stored copies of every order named in the request, rewrites every other stored order so that it no longer carries the shopper's name, address or phone number, and destroys any export archive that contained them. Shopify keeps the shopper on orders it did not name, so a later backup of a still-installed store may capture those orders again; the erasure covers what is held at the moment it is carried out.

9. Assisting you with data subject requests

Retrace supports Shopify's mandatory compliance webhooks — customers/data_request, customers/redact and shop/redact — and acts on them automatically. On customers/data_request, Retrace identifies exactly which stored records concern the shopper and provides that to you, the controller, who owes the shopper an answer within 30 days. Where a data subject request cannot be satisfied through those channels, contact sunny@kayease.com and Retrace will assist you within the timeframes applicable law places on you as controller.

10. Where your data is held, and by whom

Hostinger, in India (Mumbai).

archives — is provided by MinIO, in India (Mumbai).

Global (Google data centres).

Retrace uses the following sub-processors:

Sub-processorPurposeLocation
HostingerApplication hosting — the server behind retrace.kayease.com — and the PostgreSQL database on itIndia (Mumbai)
MinIOEncrypted blob storage: backup snapshots, theme and file assets, and export archivesIndia (Mumbai)
Google (Gmail SMTP)Transactional alert email to merchantsGlobal (Google data centres)

Retrace gives you notice before adding or replacing a sub-processor, and imposes data protection obligations on each that are no less protective than this DPA.

Shopify itself is not listed above: Shopify is the source of the data and your own processor for it, under your agreement with them rather than under this one.

11. International transfers

Merchant data is held in the regions named in section 10. Where personal data is transferred outside the jurisdiction in which it was collected, Retrace relies on an appropriate transfer mechanism under applicable law, including the Standard Contractual Clauses where required.

12. Personal data breach

Retrace notifies you without undue delay, and in any event within 72 hours of confirming a personal data breach affecting your data, with the information you need to meet your own notification obligations. See the Security Incident Response Policy.

13. Audit

On reasonable written request, and no more than once a year unless required by a supervisory authority, Retrace will provide the information necessary to demonstrate compliance with this DPA.

14. Contact

Kayease Global Solutions LLP, 3rd Floor, RSEB officers Colony, 11B, Ram Marg, opp. Inox, D-Block, RSEB Colony, Amrapali Circle, Vaishali Nagar, Jaipur, Rajasthan 302021.

Data protection matters: sunny@kayease.com. Anything else: sunny@kayease.com, or raise a request from the Help & support screen inside the app.