Legal
Data Processing Agreement
This Data Processing Agreement (DPA) describes how SutraApps processes personal data on behalf of Shopify merchants who install our apps, and the commitments we make when handling that data.
Last updated: 4 September 2026
This DPA is provided for information and is subject to final legal review. Merchants requiring a signed copy can request one by email.
1. Parties
This DPA applies between SutraApps (the processor) and the merchant who installs a SutraApps app (the controller). It takes effect when a merchant installs one of our apps.
2. Scope
This DPA covers all personal data processed by SutraApps apps on behalf of a merchant, including data accessed through Shopify APIs and data submitted through app interfaces.
3. Definitions
"Personal data", "processing", "controller", "processor" and "data subject" have the meanings given to them under applicable data protection law. "Shopify protected customer data" refers to customer data made available through Shopify APIs that Shopify designates as protected.
4. Processing of Personal Data
SutraApps processes personal data only on the documented instructions of the merchant, which include the merchant's use and configuration of the app, unless required otherwise by law.
5. Purpose of Processing
We process personal data solely to provide the relevant app functionality to the merchant, to provide support, to maintain security and reliability, and for the related purposes stated in our Privacy Policy. We do not process merchant or customer data for our own independent purposes, for advertising, or for training unrelated models.
6. Categories of Personal Data
Depending on the app and configuration, processing may involve:
- Merchant account and store contact details
- App configuration created by merchant staff
- Order and line item identifiers
- Customer name and email address where required for app functionality
- Gift message content and gifting selections entered by customers
- Technical data such as log entries and error reports
7. Categories of Data Subjects
Merchants and their staff users, and customers of the merchant's store who interact with app functionality.
8. Merchant Responsibilities
The merchant is responsible for having a lawful basis for processing, for providing required privacy notices to customers, for configuring the app appropriately, and for ensuring that any data entered into the app may lawfully be processed.
9. SutraApps Responsibilities
We process data only as instructed, apply appropriate technical and organisational security measures, limit access to authorised personnel, assist the merchant with data subject requests and security incidents, and delete or return data as described below.
10. Data Minimization
We request the narrowest Shopify scopes needed for app functionality and store only the fields required to deliver features. Where a feature can work with an identifier instead of personal data, we prefer the identifier.
11. Security Measures
We use encryption in transit, restricted and authenticated access to production systems, separation of development and production environments, logging and monitoring, and regular review of dependencies. Further detail is set out on our Security page.
12. Confidentiality
Personnel with access to personal data are bound by confidentiality obligations and access is granted only where needed to operate or support the service.
13. Sub-processors
We use infrastructure and service providers to host and operate our apps. Sub-processors are bound by written obligations no less protective than those in this DPA. A current list of sub-processors is available on request at sutraapps.team@gmail.com, and we will inform merchants of material changes so they can object.
14. International Transfers
Where personal data is transferred across borders, we put appropriate safeguards in place for the transfer as required by applicable law.
15. Data Retention
Personal data is retained only for as long as it is needed to provide the app to the merchant or as required by law. Under current Wraply practice, completed gift-order personal information is subject to a 90-day retention and anonymization process. Longer retention applies only where legally required or documented. Anonymization removes personal identifiers while preserving appropriate non-personal operational and aggregate records.
16. Data Deletion and Anonymization
On app uninstall or upon verified merchant request, we delete or anonymize associated store personal data in accordance with applicable platform requirements and data protection laws, except where longer retention is legally required.
17. Data Subject Requests
We provide reasonable assistance to merchants responding to requests from data subjects to access, correct, delete or port their data. Requests received directly from a merchant's customers are referred to the merchant.
18. Security Incidents
If we become aware of a personal data breach affecting a merchant's data, we will notify the merchant without undue delay, share the information available to us, and take reasonable steps to contain and remediate the incident.
19. Cooperation
We will provide information reasonably necessary to demonstrate compliance with this DPA and cooperate with merchant requests relating to data protection impact assessments and regulator enquiries.
20. Termination
This DPA remains in effect for as long as SutraApps processes personal data on the merchant's behalf. On termination, data is deleted or anonymized as described above.
21. Changes
We may update this DPA to reflect changes in our apps, sub-processors or legal requirements. The date at the top of this page shows the latest revision.
22. Contact
Data protection enquiries can be sent to sutraapps.team@gmail.com.
Questions about this document? Email sutraapps.team@gmail.com.