Sparkflow
ENDE

Data Processing Agreement

Under Art. 28 GDPR — Sparkflow: Advent Calendar & Countdown

Version of: 04 September 2026

This agreement governs the processing of personal data that we carry out on behalf of a merchant who uses the app “Sparkflow: Advent Calendar & Countdown” in their Shopify store.

The controller within the meaning of Art. 4(7) GDPR is the merchant. The processor within the meaning of Art. 4(8) GDPR is David Diallo, handelnd unter „Diallo Media“, Schwachhauser Heerstraße 18, 28209 Bremen, Deutschland. The agreement is formed on installation of the app; no separate signature is required (§ 14).

§ 1 Subject matter and duration

The subject matter is the processing of personal data by the processor in order to provide the services described in the Terms of Service: rendering advent calendars and countdowns in the controller's theme, reporting on door openings, and creating discount codes automatically.

The agreement begins on installation of the app and ends on its uninstallation. It does not end before the data has been fully deleted under § 10.

§ 2 Nature, scope and purpose of processing

Only what is necessary for the commissioned service is processed. There is no processing for the processor's own purposes.

Category of data subjectsTypes of dataPurpose
Store visitors who open a doorRandom session id generated in the browser; calendar handle; door number; timestamp. No IP address, no name, no email address, no Shopify customer id.Reporting on which doors were opened (paid plans only)
The controller's staff with access to the Shopify adminStore domain, Shopify access token, granted scopes, expiry. The name and email fields in the session schema stay empty because only offline access tokens are used.Calling the Shopify Admin API on the controller's behalf
Data subjects of content entered by the controllerFreely entered texts, links, image addresses, custom HTML and CSS in calendar and countdown configuration. Whether these contain personal data is decided solely by the controller.Rendering the blocks in the theme
  • No special categories of personal data under Art. 9 GDPR are processed. The controller does not enter such data into the app.
  • There is no automated decision-making and no profiling under Art. 22 GDPR.
  • No processing of order, payment or cart data. The `read_orders` scope was removed on 4 September 2026.

§ 3 Instructions of the controller

The processor processes the data solely on documented instructions from the controller. This agreement, the Terms of Service and the configuration the controller makes in the app constitute those instructions.

Individual instructions are addressed in text form to the contact address given below. The processor implements them as far as technically possible and legally permissible, and points out any additional effort in advance.

If the processor considers an instruction unlawful, it will say so without delay and may suspend execution until the matter is settled (Art. 28(3), third sentence, GDPR).

Processing outside these instructions takes place only where Union or Member State law requires it. In that case the processor informs the controller beforehand, unless that law prohibits it.

§ 4 Confidentiality

The processor binds the persons authorised to process the data to confidentiality unless they are already under a statutory obligation of secrecy. The obligation continues after the end of their activity.

Access to production data is granted only to those who need it to perform their duties.

§ 5 Technical and organisational measures (Art. 32 GDPR)

The following measures are implemented. They are not a statement of intent but describe the state of the application; they are updated as the application develops.

Protection goalMeasure
Confidentiality — access controlThe app authenticates exclusively through Shopify's OAuth token exchange. There are no passwords of our own and no user management of our own. Access tokens expire and are renewed.
Confidentiality — tenant separationEvery record hangs off the store it belongs to through a foreign key. Calendars, countdowns, clicks and discount records cannot be queried without that key. No matching across store boundaries takes place.
Confidentiality — transport encryptionAll connections run over HTTPS only. Admin interface cookies are set as `Secure`.
Integrity — authenticity of incoming callsEvery webhook call from Shopify is verified against its HMAC signature. If verification fails, the app responds 401 and processes nothing.
Integrity — input validationThe public tracking endpoint accepts only values matching a fixed pattern: store domain as `*.myshopify.com`, calendar handle as lowercase letters and digits, door number between 1 and 31, session id capped at 64 characters. Everything else is rejected with 400.
Integrity — filtering of entered contentCustom HTML is filtered server-side against an allow-list of permitted elements and attributes and capped at 20,000 characters; scripts and event attributes are removed. Custom CSS is stripped of `@import`, `expression()`, `javascript:`, `behavior` and `-moz-binding` and scoped to the calendar block. In the storefront, all dynamic values are escaped before output.
Availability — resilienceThe public tracking endpoint is limited to 60 reports per minute per sender. The application restarts automatically on failure. Database backups follow the procedure of the database provider (§ 6).
Data minimisationThe IP address is used transiently in memory for rate limiting only and never stored. Opening the same door repeatedly is counted only once per hour. On the Free plan nothing is recorded at all. The `read_orders` scope has been removed.
PseudonymisationReporting works exclusively with a random id generated in the browser. Because local storage is bound to the domain, each store produces its own id.
ErasabilityThree deletion paths are implemented: `app/uninstalled`, `shop/redact` and `customers/redact`. The database removes dependent records through foreign-key cascades.

§ 6 Sub-processors

The controller consents to the use of the following sub-processors. Agreements under Art. 28(4) GDPR are in place with all of them.

CompanySeatServicePlace of processingBasis for third-country transfer
Shopify Inc.CanadaOperation of the store platform, storage of metafields, creation of discount codes, plan billingCanada and Shopify's data centresEuropean Commission adequacy decision for Canada (commercial organisations)
Railway Corp.USAOperation of the application (hosting)Railway-Region us-west2 (US West Metal), Kalifornien, USARailway Corporation, 548 Market St PMB 68956, San Francisco, Kalifornien 94104, USA. Es gilt Railways Auftragsverarbeitungsvertrag nach Art. 28 DSGVO. Die Übermittlung in die USA stützt sich auf die Standardvertragsklauseln der EU-Kommission (Modul zwei), die dieser Vertrag einbezieht.
Database providerRailway Corporation, verwaltetes PostgreSQL im selben Projekt, Region us-west2, Kalifornien, USAPostgreSQL databaseRailway Corporation, verwaltetes PostgreSQL im selben Projekt, Region us-west2, Kalifornien, USADerselbe Anbieter und derselbe Auftragsverarbeitungsvertrag wie beim Hosting: Railway Corporation, USA, Übermittlung auf Grundlage der Standardvertragsklauseln der EU-Kommission (Modul zwei).
  • There are no other sub-processors. No analytics service, no error reporting service, no newsletter sender and no ad network is integrated.
  • Klaviyo and Mailchimp are expressly not sub-processors. A merchant on a Pro plan can store API keys, but no data is transmitted to those services. This agreement will be amended before any such transmission is set up.
  • Replacement or addition of a sub-processor is announced in the app at least 30 days in advance. The controller may object for good cause; if the service cannot then be provided, the controller may end the agreement as of the date of the change.

§ 7 Transfers to third countries

Transfers to a third country take place only to the sub-processors named in § 6 and only on a basis under Chapter V GDPR. The basis for each provider is given in the table.

There are no other transfers to third countries.

§ 8 Assistance with data subject rights

If a data subject approaches the processor directly, the processor refers them to the controller and does not answer the request itself.

The processor assists the controller in fulfilling requests for access, rectification, erasure, restriction, portability and objection (Art. 12 to 22 GDPR) and with data protection impact assessments and prior consultations (Art. 35, 36 GDPR).

The three privacy signals prescribed by Shopify are implemented:

  • `customers/data_request` — access request. No personal customer data is stored; there is nothing to hand out. The request is logged and acknowledged.
  • `customers/redact` — erasure request for an individual. There are no person-linked records; the anonymous session ids cannot be attributed to a customer.
  • `shop/redact` — deletion of all of a store's data, 48 hours after uninstall. Sessions, store record, calendars, countdowns, clicks and discount records are permanently removed.

§ 9 Personal data breaches

The processor notifies the controller of any personal data breach that comes to its attention without undue delay, and at the latest within 48 hours of becoming aware of it (Art. 33(2) GDPR).

The notification is sent in text form to the controller's address held in the Shopify account and contains, as far as known: the nature of the incident, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken and proposed.

The processor assists the controller with its own notification duties under Art. 33 and 34 GDPR.

§ 10 Deletion and return

Data is not returned automatically before deletion. The controller can view and save their configuration in the app before uninstalling. Restoration after deletion is not possible.

Retention beyond the periods stated takes place only where Union or Member State law requires it.

DataPeriod
Sessions and store recordwithout delay on the `app/uninstalled` signal, i.e. on uninstallation
Calendars, countdowns, door clicks, discount recordstogether with the store record through foreign-key cascades
All data of a store, second passon the `shop/redact` signal, which Shopify sends 48 hours after uninstall
Data of an individual data subjecton the `customers/redact` signal. There are no personal records that would need deleting
Shop metafields in the `sparkflow` namespaceremoved by Shopify when the app is uninstalled; they fall within Shopify's responsibility
Discount codes in the storeremain in place and are managed by the controller in the Shopify admin
IP addressesnot stored, used transiently for rate limiting only

§ 11 Evidence and audits

On request the processor makes available to the controller the information necessary to demonstrate compliance with Art. 28 GDPR and allows for audits (Art. 28(3)(h) GDPR).

Evidence is provided primarily by information in text form and by this documentation of the technical and organisational measures. An on-site audit is possible after prior arrangement with reasonable notice, must not unreasonably disrupt operations, and is limited to once a year unless there is specific cause.

A record of processing activities under Art. 30(2) GDPR is maintained.

§ 12 Liability

Art. 82 GDPR applies. As between the parties, the liability rules of the Terms of Service apply in addition.

§ 13 Changes to this agreement

Changes are announced in the app at least 30 days before they take effect. If the controller does not object before they take effect and continues to use the app, they are deemed accepted; this is pointed out separately in the announcement.

The version currently in force is identified by the date at the top of this page. Without that date it would not be possible to establish which version was accepted.

§ 14 Formation and final provisions

This agreement is formed when the app is installed in the controller's Shopify store. It forms part of the Terms of Service. No separate signature is required; the controller may print this page or save it as a file and present it to their supervisory authority.

In case of conflict between this agreement and the Terms of Service, this agreement prevails as far as the processing of personal data is concerned.

If a provision is invalid, the remainder of the agreement stays in force; the statutory rule takes the place of the invalid provision.

Processor contact

Send instructions, requests for evidence and notifications under this agreement to:

David Diallo, handelnd unter „Diallo Media“
Schwachhauser Heerstraße 18, 28209 Bremen, Deutschland
daviddiallo@web.de
HomePrivacyTerms of ServiceLegal notice