Legal
Last updated: 2 September 2026
Last updated: 2026-09-02
This Data Processing Agreement (“DPA”) is entered into between the merchant identified by the Shopify store that has installed the Tacey application (the “Controller”, “Merchant”, “you”) and ONDUTYOPS LLC, a Delaware limited liability company with a registered address at Coastal Highway, Lewes, Delaware 19958, United States, trading as Tacey (the “Processor”, “Tacey”, “we”, “us”), and forms part of, and is incorporated by reference into, the Tacey Terms of Service.
Where the Merchant is subject to the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection, or a comparable data protection law that requires specific contractual terms between a controller and a processor, this DPA supplies those terms. Where no such law applies to the Merchant, this DPA still governs how Tacey processes the Merchant’s shopper data, as a matter of contract.
“GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
“UK GDPR” means the GDPR as it forms part of the law of the United Kingdom by virtue of section 3 of the European Union (Withdrawal) Act 2018.
“Data Protection Laws” means the GDPR, the UK GDPR, the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, and any other data protection or privacy law applicable to the processing of personal data under this DPA, including US state privacy laws where applicable, in each case as amended or replaced from time to time.
“SCCs” means the standard contractual clauses for the transfer of personal data to third countries set out in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
“UK Addendum” means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner’s Office under section 119A of the UK Data Protection Act 2018, version B1.0, in force 21 March 2022.
“Controller”, “Processor”, “Sub-processor”, “Data Subject”, “Personal Data”, “Processing”, and “Personal Data Breach” have the meanings given in the GDPR, and, where UK Data Protection Laws apply, in the UK GDPR.
“Shopper Data” means the Personal Data of the Merchant’s own customers that Tacey Processes on the Merchant’s behalf in order to provide the Service, described in Annex I.
“Service” means the Tacey application, as described in the Tacey Terms of Service.
“Sub-processor” means any third party engaged by Tacey to Process Shopper Data in order to provide the Service, listed in Annex III.
The Merchant is the Controller of Shopper Data. Tacey is the Processor, acting only on the Merchant’s instructions as set out in this DPA and as expressed through the Merchant’s configuration of the Service (validation region scope, edit-window length, which optional tools are enabled, and similar settings).
Shopify operates as a separate, independent Controller and Processor in its own right for the same underlying data. Shopify’s own compliance obligations to the Merchant, under the Shopify Merchant Agreement, do not transfer to Tacey, and this DPA does not modify, supersede, or stand in for the Merchant’s separate agreement with Shopify. Tacey is not a party to that agreement, and Shopify is not a party to this one.
Separately from Shopper Data, Tacey acts as a Controller for the Merchant’s own account, billing, and support data, as described in the Tacey Privacy Policy. This DPA governs Tacey’s processing of Shopper Data only.
Tacey Processes Shopper Data for the duration of the Merchant’s use of the Service, that is, from the moment the Merchant installs Tacey until the Merchant’s data is deleted under Section 11. The subject matter, nature, purpose, categories of Data Subjects, and categories of Personal Data are set out in full in Annex I, which forms part of this DPA.
Tacey shall Process Shopper Data only on the Merchant’s documented instructions, including with regard to transfers of Personal Data to a third country, unless required to do so by a law to which Tacey is subject, in which case Tacey shall inform the Merchant of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest.
The Merchant’s documented instructions consist of: (a) this DPA; (b) the Tacey Terms of Service and the Service’s published documentation; and (c) the Merchant’s own configuration of the Service through its settings. Tacey shall inform the Merchant, without undue delay, if in Tacey’s opinion an instruction given by the Merchant infringes Data Protection Laws.
Tacey does not Process Shopper Data for its own purposes. Tacey does not use Shopper Data for its own marketing, does not build cross-merchant profiles from it, and does not sell it.
Tacey ensures that any person authorised by Tacey to Process Shopper Data, including Tacey’s own personnel and the personnel of any Sub-processor, is subject to a duty of confidentiality, whether contractual or statutory, and that access to Shopper Data is restricted to those who need it to provide the Service.
Tacey implements the technical and organisational measures described in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the Processing, as well as the risk of varying likelihood and severity to the rights and freedoms of Data Subjects, consistent with Article 32 GDPR.
General authorisation. The Merchant gives Tacey general written authorisation to engage the Sub-processors listed in Annex III as of the date of this DPA, and to engage additional Sub-processors in accordance with this section.
Notice and objection. Where Tacey intends to add a new Sub-processor, or replace an existing one, Tacey will update the Subprocessors page (tacey.app/subprocessors) and provide notice to the Merchant, in advance of that Sub-processor beginning to Process Shopper Data, through the notification channel described on that page. If the Merchant has a reasonable, data-protection-related objection to the new Sub-processor, the Merchant may raise it, in writing, to the contact in Section 19 before the effective date stated in the notice. Tacey will work with the Merchant in good faith to address the objection, which may include not routing the Merchant’s data to that Sub-processor where technically feasible, or, if the objection cannot reasonably be resolved, permitting the Merchant to terminate the affected part of the Service without penalty. If the Merchant does not object within the notice period, the Merchant is deemed to have authorised the new Sub-processor.
Same obligations, flowed down. Tacey imposes data protection obligations on each Sub-processor, by contract, that are no less protective of Shopper Data than the obligations imposed on Tacey under this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures such that the Processing meets the requirements of Data Protection Laws. Tacey remains fully liable to the Merchant for a Sub-processor’s performance of its data protection obligations under such contract.
Taking into account the nature of the Processing, Tacey assists the Merchant, by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Merchant’s obligation to respond to requests for exercising a Data Subject’s rights under Chapter III of the GDPR (access, rectification, erasure, restriction, portability, and objection).
In practice, this assistance is substantially automated through the three Shopify-mandated privacy webhooks Tacey implements:
customers/data_request, Tacey does not contact a Data Subject directly, because Shopify’s API Terms restrict apps from contacting a Merchant’s customers by default, and because the Merchant, not Tacey, is the Controller with the primary obligation to respond. On receiving this webhook, Tacey compiles a count and description of the Shopper Data it holds for that customer so the Merchant can fulfil the underlying request.customers/redact, on receiving this webhook, Tacey deletes that Data Subject’s individually-identifiable address-validation and order-edit records.shop/redact, on receiving this webhook, sent by Shopify approximately 48 hours after the Merchant uninstalls Tacey, Tacey deletes the Merchant’s full data set as described in Section 11.A Merchant who needs help fulfilling a specific Data Subject request beyond what these mechanisms automate may contact Tacey using the details in Section 19.
Taking into account the nature of Processing and the information available to Tacey, Tacey assists the Merchant in ensuring compliance with the Merchant’s own obligations under Articles 32 to 36 of the GDPR (security of processing, breach notification to the supervisory authority and to Data Subjects, data protection impact assessments, and prior consultation with a supervisory authority), including by providing the information described in Annex II and by notifying the Merchant of a Personal Data Breach as described in Section 10.
Tacey notifies the Merchant without undue delay after becoming aware of a Personal Data Breach affecting Shopper Data, so that the Merchant can meet its own obligation to notify its supervisory authority within 72 hours of becoming aware of a breach, where required under Article 33 GDPR. Tacey’s notification includes, to the extent then known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. Where information is not available at the time of notification, Tacey provides it in phases without undue further delay as it becomes available.
At the Merchant’s choice, Tacey shall delete or return all Shopper Data to the Merchant after the end of the provision of the Service, and delete existing copies, unless a Data Protection Law requires storage of the Personal Data.
In practice, this obligation is discharged as follows:
shop/redact webhook approximately 48 hours after uninstallation. On receiving it, Tacey deletes every database row scoped to the Merchant’s shop, across every shop-scoped table, and separately sweeps the Merchant’s archived raw order webhook payloads out of Tacey’s object storage.shop/redact deletion described above takes effect.shop/redact under the same mechanism described above, unless a longer retention is separately required by law.Tacey makes available to the Merchant all information reasonably necessary to demonstrate compliance with the obligations in this DPA, and allows for and contributes to audits, including inspections, conducted by the Merchant or an auditor mandated by the Merchant, subject to the following:
Tacey does not currently hold a SOC 2, ISO 27001, or comparable third-party security certification of its own, and states this plainly rather than implying otherwise; Annex II identifies which controls are Tacey’s own and which are inherited, and attributed, from its infrastructure provider.
Tacey and its Sub-processors are located in, and Process Shopper Data in, the United States. Where the Merchant is established in the European Economic Area, or otherwise transfers Personal Data subject to Chapter V of the GDPR to Tacey in the United States, the parties agree that the transfer is governed by the SCCs, with Module Two (Controller to Processor) applying, as follows:
The full text of the SCCs, as set out in the Annex to Commission Implementing Decision (EU) 2021/914, is incorporated into this DPA by reference and is available at eur-lex.europa.eu. Where the terms of the SCCs conflict with the body of this DPA, the SCCs prevail with respect to the international transfer of Personal Data they govern.
Each of Tacey’s Sub-processors relies on its own onward-transfer mechanism, either self-certification under the EU–US Data Privacy Framework, or its own Standard Contractual Clauses, as set out in Annex III.
Where the Merchant transfers Personal Data subject to the UK GDPR to Tacey in the United States, the parties agree that the UK Addendum applies, and is incorporated into and forms an integral part of this DPA, populated as follows:
The full text of the UK Addendum, International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, issued by the UK Information Commissioner’s Office, version B1.0, in force 21 March 2022, is incorporated into this DPA by reference.
Where the Federal Act on Data Protection of Switzerland (“FADP”) applies to a transfer of Personal Data under this DPA, the SCCs described in Section 13 apply to that transfer with the following modifications: references to the “GDPR” are understood as references to the FADP insofar as the transfer is subject to the FADP; references to personal data also cover data relating to an identified or identifiable legal entity, until the entry into force of revisions to the FADP; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner, insofar as the relevant transfer is governed by the FADP alone; and the SCCs are governed by the laws of Switzerland insofar as the transfer is governed by the FADP alone.
Each party’s liability arising out of or in connection with this DPA, whether in contract, tort, or otherwise, is subject to the limitations and exclusions of liability set out in the Tacey Terms of Service, to the extent permitted by applicable Data Protection Laws. Nothing in this DPA limits or excludes either party’s liability for infringements of Data Protection Laws where such limitation or exclusion is not permitted under those laws.
If there is a conflict between this DPA and the Tacey Terms of Service, this DPA prevails with respect to the parties’ data protection obligations. If there is a conflict between this DPA and the SCCs or the UK Addendum, the SCCs or the UK Addendum, as applicable, prevail with respect to the international transfer of Personal Data. If there is a conflict between this DPA and the Tacey Privacy Policy, this DPA prevails as between the Merchant and Tacey with respect to Shopper Data; the Privacy Policy remains the operative document describing Tacey’s processing of Merchant account data as a Controller.
Term. This DPA takes effect on the date the Merchant installs the Service (or, if later, the date the Merchant otherwise agrees to it), and remains in effect for as long as Tacey Processes Shopper Data on the Merchant’s behalf.
Changes. Tacey may update this DPA to reflect a change in Data Protection Laws, a change to its Sub-processors, or an improvement to its security measures, by posting the updated DPA at tacey.app/dpa with a revised “Last updated” date and, where the change is material, providing notice as described in Section 7 (for a Sub-processor change) or through the notice mechanism in the Tacey Terms of Service (for any other material change).
Severability. If any provision of this DPA is held unenforceable, the remaining provisions remain in full effect, and the unenforceable provision is modified to the minimum extent necessary to make it enforceable.
Governing law. Except where the SCCs or the UK Addendum specify their own governing law for the matters they cover, this DPA is governed by the laws of the State of Delaware, United States, consistent with the Tacey Terms of Service.
For any question about this DPA, a Data Subject request, a Sub-processor notice, or an audit request:
Email: hello@taceysupport.app
Postal address: Coastal Highway, Lewes, Delaware 19958, United States
Data exporter: the Merchant, identified by the Shopify store that installed Tacey, its legal entity name, and its contact details as recorded in its Shopify Partner/Admin account. Role: Controller.
Data importer: ONDUTYOPS LLC, trading as Tacey, Coastal Highway, Lewes, Delaware 19958, United States. Contact: hello@taceysupport.app. Role: Processor.
Categories of Data Subjects whose Personal Data is transferred:
Categories of Personal Data transferred:
| Category | Detail |
|---|---|
| Shipping address | Name, street address, city, state/province, postal code, country, and phone number where provided, on an order |
| Order metadata | Order number, line items, quantities, totals, currency, and fulfillment status |
| Shopper contact information | The shopper’s email address |
| Validation results | The deliverability verdict, confidence classification, and any corrected or standardized version of the address |
| Edit history | What was changed on an order, when, by whom, and, where money moved, the reconciliation-ledger record of that movement |
| Raw order webhook payloads | The complete, unmodified JSON Shopify sends for orders/create, archived for reprocessing |
Special categories of data transferred, and applied restrictions: none. Tacey does not process, and its design does not request or infer, any special category of Personal Data (Article 9 GDPR) or any criminal offence or conviction data (Article 10 GDPR).
The frequency of the transfer: continuous, for as long as the Merchant’s store generates orders and the Merchant has the Service installed, principally triggered by the Shopify orders/create webhook and subsequent Admin API reads and writes.
Nature of the processing: collection, storage, validation (matching an address against a third-party validation provider), transmission (via transactional email to the shopper), correction (where the shopper or merchant edits an order), and erasure, of the categories of data listed above.
Purpose of the processing: to validate the deliverability of a shipping address on an order; to let the shopper view and, where the Merchant has enabled it, correct their own order on Shopify’s own order-status page; to notify the shopper by email of an address requiring review, a link to review or edit their order, and a reminder before an edit window closes; and to record every edit made to an order, whether money moved, and how much, in a reconciliation ledger.
The period for which the Personal Data will be retained, or the criteria used to determine that period: for the life of the Merchant’s installation of the Service, and deleted upon the mandatory shop/redact webhook (sent by Shopify approximately 48 hours after uninstallation), as described in Section 11. An individual Shopper’s records are deleted earlier, on an individual basis, on a valid customers/redact request. Reconciliation ledger entries are retained for the life of the Merchant’s installation and deleted with the rest of the Merchant’s data on shop/redact.
For transfers to (sub-)processors, the subject matter, nature, and duration of the processing: as set out for each Sub-processor in Annex III, for the same duration as this DPA.
As set out in Section 13 of this DPA.
These measures reflect what Tacey’s application and infrastructure actually do, not a generic template. Where a measure is inherited from Tacey’s infrastructure provider rather than operated by Tacey directly, it is attributed as such and never claimed as Tacey’s own certification.
Encryption in transit. Every connection to and within the Service uses TLS. There is no unencrypted path in or out of the system.
Encryption at rest. Data stored in Tacey’s database, object storage, and session storage is encrypted at rest by Tacey’s infrastructure provider, Cloudflare, Inc., under Cloudflare’s default infrastructure controls. This is an infrastructure-layer control provided by Cloudflare, not a measure Tacey independently certifies.
Least-privilege access to Shopify data. Tacey requests only the Shopify API scopes required for the features it provides. Each scope is disclosed to the Merchant at install time and enforced by Shopify itself, not by Tacey, a boundary Tacey cannot bypass even if it wished to.
No payment credentials in scope. Tacey never collects, transmits, processes, or stores payment card numbers, bank details, or any other payment credential. Payment for a shopper’s order and for a Merchant’s Tacey subscription both run entirely through Shopify’s own payment rails. This removes an entire category of data, and the corresponding PCI-DSS obligation, from Tacey’s systems entirely.
Webhook authenticity verification. Every inbound Shopify webhook is verified against its HMAC signature before being processed; a request that fails verification is rejected and not acted upon.
Compliance webhook handlers. Tacey implements all three Shopify-mandated privacy webhooks, customers/data_request, customers/redact, and shop/redact, so that a Data Subject’s or a Merchant’s erasure and access rights are honored through an automated, tested code path rather than a manual process.
Offline-token handling. Because a customer-triggered order edit runs without an active Merchant session, the access token used for that purpose is short-lived (currently a 60-minute expiry), is refreshed rather than persisted indefinitely in a static form, and its refresh failure modes are handled explicitly rather than silently falling back to a stale credential.
Tenancy isolation. Every database query affecting shop-scoped data carries an explicit shop identifier, so that one Merchant’s Shopper Data cannot be returned in response to a request scoped to a different Merchant.
Fail-open on validation, fail-closed on entitlement. Address validation is designed so that a third-party validation provider’s outage or error never blocks a shopper’s purchase; a plan-entitlement check that cannot resolve a Merchant’s plan resolves to the lowest tier rather than the highest, so an unknown state never silently grants access beyond what a Merchant is paying for.
Access controls. Internal access to production systems and data is restricted to personnel who need it to operate the Service.
Confidentiality. Personnel authorised to Process Shopper Data are subject to confidentiality obligations, as described in Section 5.
Certifications held by Tacey directly: none. Tacey does not hold SOC 2, ISO 27001, ISO 27017, PCI-DSS, or any other third-party security certification, and no such thing as a general-purpose “GDPR certification” exists for any company to hold. Where Tacey’s infrastructure provider, Cloudflare, Inc., holds SOC 2 Type 2 and ISO 27001 certification, that certification applies to Cloudflare’s infrastructure layer and is attributed to Cloudflare here for transparency, it is not, and is never represented as, a certification of Tacey’s own application or organisation.
Matches the Subprocessors page (tacey.app/subprocessors) as of the date at the top of this DPA. Tacey will keep this Annex current with that page.
| Sub-processor | Function | Categories of data received | Location | Transfer mechanism |
|---|---|---|---|---|
| Cloudflare, Inc. | Application hosting, database (D1), object storage (R2), session storage (KV), message queues | All application data that passes through or is stored by the Service | United States (global edge network) | EU Standard Contractual Clauses, incorporated into Cloudflare’s own customer-facing SCC addendum |
| Google LLC (Address Validation API, Geocoding API) | Address validation and geocoding (Mexico and international addresses) | The shipping address being validated (no name or email) | United States | Google’s own EU Standard Contractual Clauses and Data Processing Addendum for Google Cloud/Maps Platform services |
| Geocodio, LLC | Address validation (United States and Canada) | The shipping address being validated (no name or email) | United States | EU Standard Contractual Clauses under Geocodio’s Data Processing Agreement |
| Postmark (a Postmark/ActiveCampaign product) | Sending transactional emails to shoppers and merchants | Recipient email address, order reference, and email content | United States | EU Standard Contractual Clauses under Postmark’s Data Processing Addendum |
| Mixpanel, Inc. | Product analytics | Usage events, not shipping addresses or payment data | United States | Certified under the EU–US Data Privacy Framework, and EU Standard Contractual Clauses under its DPA |
| Intercom, Inc. | Merchant lifecycle tracking (install and account events) | Shop domain, Shopify plan tier, store country | United States | EU Standard Contractual Clauses and the UK International Data Transfer Addendum under its Data Processing Agreement |
| Customer.io, Inc. | Merchant lifecycle messaging | Merchant contact email, owner name, store name, shop domain, Shopify plan tier, currency, country, time zone, locale | United States | Self-certified under the EU–US Data Privacy Framework, and EU Standard Contractual Clauses under its DPA |
Intercom and Customer.io receive Merchant account data, not Shopper Data, and are included in this Annex for completeness and because they are engaged as processors of Merchant data on the same subprocessor list published to Merchants; they do not process any Shopper Data described in Annex I.