Data Processing Agreement
Last updated: 5 September 2026
This Data Processing Agreement ("DPA") forms part of the agreement between you ("Controller", "Merchant") and Avery ("Processor", "we", "us") for the use of Avery’s conversion rate optimisation service.
1. Definitions
- Personal Data means any information relating to an identified or identifiable natural person, as defined in Article 4(1) of the GDPR.
- Processing means any operation performed on Personal Data, as defined in Article 4(2) of the GDPR.
- Subprocessor means a third party engaged by us to process Personal Data on your behalf.
2. Scope and roles
You are the Controller of your store data. We are the Processor. We process Personal Data only on your documented instructions, which are the service features you activate (connecting your store, running analysis, requesting code suggestions, installing the web pixel).
3. Categories of data processed
| Category | Data subjects | Retention |
|---|---|---|
| Store owner email and domain | Merchant | Until disconnection + Shopify erasure |
| Product catalogue metadata | Not personal data (business data) | Until disconnection + Shopify erasure |
| Web pixel events (browser-scoped visitor ID, page URLs, viewport, referrer, order value) | Store visitors (pseudonymised) | 90 days |
| Aggregated daily funnel and order metrics | No individual data | Indefinite |
4. Subprocessors
We use the following subprocessors. We will notify you before adding a new subprocessor or materially changing one.
| Subprocessor | Location | Purpose |
|---|---|---|
| Neon Inc. | United States | PostgreSQL database hosting (encrypted at rest) |
| Fly.io Inc. | United States | Application hosting and secret management |
| Anthropic PBC | United States | AI analysis and code generation (receives store domain, performance scores, product metadata, finding summaries, and theme file contents; does not receive access tokens, shopper data, or order details) |
| Google LLC | United States | PageSpeed Insights API (receives public storefront URLs) |
| Stripe, Inc. | United States | Subscription billing (receives store owner email and an account identifier; payment details are entered directly with Stripe) |
| Resend, Inc. | United States | Transactional and digest email delivery (receives store owner email, store domain, and email contents) |
| Functional Software, Inc. (Sentry) | United States | Error monitoring (receives error reports with store domain and record identifiers; any report containing an access token is dropped before sending) |
5. Security measures
- OAuth access tokens encrypted at rest using AES-256-GCM with key rotation support.
- All data in transit encrypted with TLS 1.2+.
- Database access restricted to the application layer only.
- Access tokens never loaded into page responses, API outputs, or logs (enforced by code-level guards).
- Theme edits pass through mechanical guardrails before preview or publish.
- Rate limiting on authentication and analysis endpoints.
6. Data subject rights
We will assist you in responding to data subject requests. The mechanisms available:
- Access and portability - the data export feature produces a complete export of store data, excluding access tokens.
- Erasure - the delete function in Settings removes all data immediately. The Shopify
shop/redactwebhook also triggers complete erasure. - Shopper data - we hold no data that identifies individual shoppers. The web pixel uses Shopify’s browser-scoped
clientId, not personal identifiers. Shopify’scustomers/data_requestandcustomers/redactwebhooks are handled; we confirm that no customer-identifiable data is held.
7. Data breach notification
We will notify you without undue delay, and in any case within 72 hours, of becoming aware of a Personal Data breach affecting your data. Notification will include the nature of the breach, categories of data affected, and measures taken.
8. International transfers
Our subprocessors are located in the United States. For transfers from the EEA/UK, we rely on Standard Contractual Clauses (SCCs) as adopted by the European Commission, incorporated by reference into our agreements with each subprocessor.
9. Audit rights
You may audit our compliance with this DPA by requesting a summary of our security practices, subprocessor list, and data handling procedures. We will respond within 30 days.
10. Term and termination
This DPA applies for as long as we process your Personal Data. On termination of the service, we delete all Personal Data within the retention periods stated above, or immediately on your request.
DPA inquiries: privacy@useavery.ai