Data Processing Agreement
Version 1.0 · 8 August 2026 · Forms part of the terms accepted on installing Emboss
This agreement applies between Yash Mehta ("Processor", "we"), operator of the Emboss Shopify app, and the merchant who installs it ("Controller", "you"). It governs personal data belonging to your customers that we process on your behalf. It takes effect when you install the app and remains in force while it is installed.
1. Roles
You are the controller of your shoppers' personal data. We are a processor acting only on your documented instructions. Installing and configuring the app constitutes your instruction to process the data described below for the purposes described below.
2. Subject matter, duration, nature and purpose
| Item | Detail |
|---|---|
| Subject matter | Providing product personalization and print-file generation within your Shopify store |
| Duration | For as long as the app is installed, plus the retention periods in section 6 |
| Nature | Collection, storage, rendering, and provision back to you of personalization content |
| Purpose | Producing the personalized product the shopper ordered, and the file needed to make it |
| Categories of data subject | Your shoppers who personalize a product |
| Categories of personal data | Text a shopper enters (often a name or initials); photos a shopper uploads; order and line-item identifiers |
| Special category data | None requested or required. Shoppers can upload arbitrary images, so you should not enable photo personalization for products where special-category content is likely |
3. Our obligations
- Process personal data only on your documented instructions, unless required otherwise by law.
- Ensure anyone authorised to process the data is bound by confidentiality.
- Implement the technical and organisational measures in section 5.
- Assist you, as far as reasonably possible, in responding to data subject requests and in meeting your security, breach-notification and impact-assessment obligations.
- Not engage a new sub-processor without notifying you and giving you a reasonable opportunity to object.
- Make available the information reasonably necessary to demonstrate compliance.
4. Sub-processors
You authorise the following sub-processors. We will give notice before adding others.
| Sub-processor | Purpose | Location |
|---|---|---|
| Oracle Cloud Infrastructure | Application and database hosting | UAE (Dubai) |
| Cloudflare R2 | Object storage for uploads and print files | Western Europe |
| Shopify | The platform the app operates within | Per Shopify's terms |
5. Security measures
- Encryption in transit — HTTPS/TLS throughout; storefront and webhook traffic additionally verified by HMAC signature.
- Encryption at rest — object storage and host disk encryption.
- Encrypted backups — the database is dumped nightly and encrypted before leaving the server, so the backup store holds only ciphertext. A restore is exercised weekly and verified, not merely attempted.
- No public access to files — the object store has no public URL. Every read is a short-lived signed link.
- Access logging — reads of print files are recorded.
- Least privilege — the app requests only the Shopify scopes it needs, and does not request customer name, email, phone or address fields.
- Environment-isolated secrets — credentials are never committed to source control or built into distributed artifacts.
6. Retention and deletion
- Shopper photos and rendered print files are deleted automatically 90 days after creation.
- Encrypted backups are retained 14 days.
- On uninstall, Shopify issues a shop redaction request and we delete your shop's data, including stored files.
- On a customer redaction request from Shopify, we delete that customer's stored personalization and the files derived from it.
7. Data subject requests
Because you are the controller, shoppers should direct requests to you. We will assist you in responding, and we act on the customer data request and redaction webhooks Shopify sends.
8. Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information available to us at the time, and will update you as more becomes known.
9. International transfers
Data is processed in the United Arab Emirates and Western Europe as set out in section 4. Where a transfer requires a lawful transfer mechanism, the parties will put an appropriate one in place.
10. Return and deletion on termination
On uninstall we delete your data per section 6. You should download any print files you need before uninstalling, as deletion is not reversible.
11. Contact
Yash Mehta — yashmehtabiz@gmail.com