Data Processing Agreement
Under Art. 28 GDPR — Sparkflow: Advent Calendar & Countdown
Version of: 04 September 2026
This agreement governs the processing of personal data that we carry out on behalf of a merchant who uses the app “Sparkflow: Advent Calendar & Countdown” in their Shopify store.
The controller within the meaning of Art. 4(7) GDPR is the merchant. The processor within the meaning of Art. 4(8) GDPR is David Diallo, handelnd unter „Diallo Media“, Schwachhauser Heerstraße 18, 28209 Bremen, Deutschland. The agreement is formed on installation of the app; no separate signature is required (§ 14).
§ 1 Subject matter and duration
The subject matter is the processing of personal data by the processor in order to provide the services described in the Terms of Service: rendering advent calendars and countdowns in the controller's theme, reporting on door openings, and creating discount codes automatically.
The agreement begins on installation of the app and ends on its uninstallation. It does not end before the data has been fully deleted under § 10.
§ 2 Nature, scope and purpose of processing
Only what is necessary for the commissioned service is processed. There is no processing for the processor's own purposes.
| Category of data subjects | Types of data | Purpose |
|---|---|---|
| Store visitors who open a door | Random session id generated in the browser; calendar handle; door number; timestamp. No IP address, no name, no email address, no Shopify customer id. | Reporting on which doors were opened (paid plans only) |
| The controller's staff with access to the Shopify admin | Store domain, Shopify access token, granted scopes, expiry. The name and email fields in the session schema stay empty because only offline access tokens are used. | Calling the Shopify Admin API on the controller's behalf |
| Data subjects of content entered by the controller | Freely entered texts, links, image addresses, custom HTML and CSS in calendar and countdown configuration. Whether these contain personal data is decided solely by the controller. | Rendering the blocks in the theme |
- No special categories of personal data under Art. 9 GDPR are processed. The controller does not enter such data into the app.
- There is no automated decision-making and no profiling under Art. 22 GDPR.
- No processing of order, payment or cart data. The `read_orders` scope was removed on 4 September 2026.
§ 3 Instructions of the controller
The processor processes the data solely on documented instructions from the controller. This agreement, the Terms of Service and the configuration the controller makes in the app constitute those instructions.
Individual instructions are addressed in text form to the contact address given below. The processor implements them as far as technically possible and legally permissible, and points out any additional effort in advance.
If the processor considers an instruction unlawful, it will say so without delay and may suspend execution until the matter is settled (Art. 28(3), third sentence, GDPR).
Processing outside these instructions takes place only where Union or Member State law requires it. In that case the processor informs the controller beforehand, unless that law prohibits it.
§ 4 Confidentiality
The processor binds the persons authorised to process the data to confidentiality unless they are already under a statutory obligation of secrecy. The obligation continues after the end of their activity.
Access to production data is granted only to those who need it to perform their duties.
§ 5 Technical and organisational measures (Art. 32 GDPR)
The following measures are implemented. They are not a statement of intent but describe the state of the application; they are updated as the application develops.
| Protection goal | Measure |
|---|---|
| Confidentiality — access control | The app authenticates exclusively through Shopify's OAuth token exchange. There are no passwords of our own and no user management of our own. Access tokens expire and are renewed. |
| Confidentiality — tenant separation | Every record hangs off the store it belongs to through a foreign key. Calendars, countdowns, clicks and discount records cannot be queried without that key. No matching across store boundaries takes place. |
| Confidentiality — transport encryption | All connections run over HTTPS only. Admin interface cookies are set as `Secure`. |
| Integrity — authenticity of incoming calls | Every webhook call from Shopify is verified against its HMAC signature. If verification fails, the app responds 401 and processes nothing. |
| Integrity — input validation | The public tracking endpoint accepts only values matching a fixed pattern: store domain as `*.myshopify.com`, calendar handle as lowercase letters and digits, door number between 1 and 31, session id capped at 64 characters. Everything else is rejected with 400. |
| Integrity — filtering of entered content | Custom HTML is filtered server-side against an allow-list of permitted elements and attributes and capped at 20,000 characters; scripts and event attributes are removed. Custom CSS is stripped of `@import`, `expression()`, `javascript:`, `behavior` and `-moz-binding` and scoped to the calendar block. In the storefront, all dynamic values are escaped before output. |
| Availability — resilience | The public tracking endpoint is limited to 60 reports per minute per sender. The application restarts automatically on failure. Database backups follow the procedure of the database provider (§ 6). |
| Data minimisation | The IP address is used transiently in memory for rate limiting only and never stored. Opening the same door repeatedly is counted only once per hour. On the Free plan nothing is recorded at all. The `read_orders` scope has been removed. |
| Pseudonymisation | Reporting works exclusively with a random id generated in the browser. Because local storage is bound to the domain, each store produces its own id. |
| Erasability | Three deletion paths are implemented: `app/uninstalled`, `shop/redact` and `customers/redact`. The database removes dependent records through foreign-key cascades. |
§ 6 Sub-processors
The controller consents to the use of the following sub-processors. Agreements under Art. 28(4) GDPR are in place with all of them.
| Company | Seat | Service | Place of processing | Basis for third-country transfer |
|---|---|---|---|---|
| Shopify Inc. | Canada | Operation of the store platform, storage of metafields, creation of discount codes, plan billing | Canada and Shopify's data centres | European Commission adequacy decision for Canada (commercial organisations) |
| Railway Corp. | USA | Operation of the application (hosting) | Railway-Region us-west2 (US West Metal), Kalifornien, USA | Railway Corporation, 548 Market St PMB 68956, San Francisco, Kalifornien 94104, USA. Es gilt Railways Auftragsverarbeitungsvertrag nach Art. 28 DSGVO. Die Übermittlung in die USA stützt sich auf die Standardvertragsklauseln der EU-Kommission (Modul zwei), die dieser Vertrag einbezieht. |
| Database provider | Railway Corporation, verwaltetes PostgreSQL im selben Projekt, Region us-west2, Kalifornien, USA | PostgreSQL database | Railway Corporation, verwaltetes PostgreSQL im selben Projekt, Region us-west2, Kalifornien, USA | Derselbe Anbieter und derselbe Auftragsverarbeitungsvertrag wie beim Hosting: Railway Corporation, USA, Übermittlung auf Grundlage der Standardvertragsklauseln der EU-Kommission (Modul zwei). |
- There are no other sub-processors. No analytics service, no error reporting service, no newsletter sender and no ad network is integrated.
- Klaviyo and Mailchimp are expressly not sub-processors. A merchant on a Pro plan can store API keys, but no data is transmitted to those services. This agreement will be amended before any such transmission is set up.
- Replacement or addition of a sub-processor is announced in the app at least 30 days in advance. The controller may object for good cause; if the service cannot then be provided, the controller may end the agreement as of the date of the change.
§ 7 Transfers to third countries
Transfers to a third country take place only to the sub-processors named in § 6 and only on a basis under Chapter V GDPR. The basis for each provider is given in the table.
There are no other transfers to third countries.
§ 8 Assistance with data subject rights
If a data subject approaches the processor directly, the processor refers them to the controller and does not answer the request itself.
The processor assists the controller in fulfilling requests for access, rectification, erasure, restriction, portability and objection (Art. 12 to 22 GDPR) and with data protection impact assessments and prior consultations (Art. 35, 36 GDPR).
The three privacy signals prescribed by Shopify are implemented:
- `customers/data_request` — access request. No personal customer data is stored; there is nothing to hand out. The request is logged and acknowledged.
- `customers/redact` — erasure request for an individual. There are no person-linked records; the anonymous session ids cannot be attributed to a customer.
- `shop/redact` — deletion of all of a store's data, 48 hours after uninstall. Sessions, store record, calendars, countdowns, clicks and discount records are permanently removed.
§ 9 Personal data breaches
The processor notifies the controller of any personal data breach that comes to its attention without undue delay, and at the latest within 48 hours of becoming aware of it (Art. 33(2) GDPR).
The notification is sent in text form to the controller's address held in the Shopify account and contains, as far as known: the nature of the incident, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken and proposed.
The processor assists the controller with its own notification duties under Art. 33 and 34 GDPR.
§ 10 Deletion and return
Data is not returned automatically before deletion. The controller can view and save their configuration in the app before uninstalling. Restoration after deletion is not possible.
Retention beyond the periods stated takes place only where Union or Member State law requires it.
| Data | Period |
|---|---|
| Sessions and store record | without delay on the `app/uninstalled` signal, i.e. on uninstallation |
| Calendars, countdowns, door clicks, discount records | together with the store record through foreign-key cascades |
| All data of a store, second pass | on the `shop/redact` signal, which Shopify sends 48 hours after uninstall |
| Data of an individual data subject | on the `customers/redact` signal. There are no personal records that would need deleting |
| Shop metafields in the `sparkflow` namespace | removed by Shopify when the app is uninstalled; they fall within Shopify's responsibility |
| Discount codes in the store | remain in place and are managed by the controller in the Shopify admin |
| IP addresses | not stored, used transiently for rate limiting only |
§ 11 Evidence and audits
On request the processor makes available to the controller the information necessary to demonstrate compliance with Art. 28 GDPR and allows for audits (Art. 28(3)(h) GDPR).
Evidence is provided primarily by information in text form and by this documentation of the technical and organisational measures. An on-site audit is possible after prior arrangement with reasonable notice, must not unreasonably disrupt operations, and is limited to once a year unless there is specific cause.
A record of processing activities under Art. 30(2) GDPR is maintained.
§ 12 Liability
Art. 82 GDPR applies. As between the parties, the liability rules of the Terms of Service apply in addition.
§ 13 Changes to this agreement
Changes are announced in the app at least 30 days before they take effect. If the controller does not object before they take effect and continues to use the app, they are deemed accepted; this is pointed out separately in the announcement.
The version currently in force is identified by the date at the top of this page. Without that date it would not be possible to establish which version was accepted.
§ 14 Formation and final provisions
This agreement is formed when the app is installed in the controller's Shopify store. It forms part of the Terms of Service. No separate signature is required; the controller may print this page or save it as a file and present it to their supervisory authority.
In case of conflict between this agreement and the Terms of Service, this agreement prevails as far as the processing of personal data is concerned.
If a provision is invalid, the remainder of the agreement stays in force; the statutory rule takes the place of the invalid provision.
Processor contact
Send instructions, requests for evidence and notifications under this agreement to:
David Diallo, handelnd unter „Diallo Media“Schwachhauser Heerstraße 18, 28209 Bremen, Deutschland
daviddiallo@web.de