Data Processing Addendum
Last updated: July 19, 2026
This Data Processing Addendum ("DPA") supplements and is incorporated by reference into the Terms of Use and the Privacy Policy of Hoppy Apps ("Hoppy Apps", "we", "us", or "our"). It governs the processing of Merchant Customer Personal Data (as defined below) by Hoppy Apps in connection with your use of our Shopify applications and services (the "Services").
Important: By installing or using any of our apps, you (the "Merchant") agree to this DPA. You act as the Data Controller and Hoppy Apps acts as the Data Processor with respect to Merchant Customer Personal Data. In case of any conflict between the Terms of Use and this DPA, this DPA shall prevail with respect to the processing of Merchant Customer Personal Data.
1. Purpose and Scope
This DPA sets forth the parties' obligations governing the processing of Merchant Customer Personal Data in connection with the Services. It applies to all Hoppy Apps applications that access, collect, store, or otherwise process Personal Data from or about your store or your customers. When you install a Hoppy Apps app from the Shopify App Store, Merchant Customer Personal Data is accessed through Shopify's APIs and is limited to the API access scopes (permissions) you approve at installation and the data each app requires to function.
Where the processing of Personal Data under this DPA is subject to data protection requirements in the European Economic Area (the "EEA"), the United Kingdom (the "UK"), Switzerland, or under U.S. state data protection laws, the relevant provisions of those laws apply to such processing and this DPA shall be interpreted accordingly.
2. Definitions
Capitalized terms used but not defined in this DPA have the meaning given to them in the Terms of Use:
- Applicable Data Protection Law(s): Any data protection or privacy laws applicable to the processing of Personal Data under the Terms of Use, including the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection, and U.S. state privacy laws such as the CCPA, each as amended or replaced from time to time.
- Customer: An individual who visits, engages with, and/or purchases a product, good, or service from your store(s).
- Data Controller or Business: The party that determines the purposes and means of the processing of Personal Data, or as otherwise defined under Applicable Data Protection Laws.
- Data Processor or Service Provider: The party that processes Personal Data on behalf of and at the direction of the Data Controller, or as otherwise defined under Applicable Data Protection Laws.
- Personal Data: Information defined as "personal data", "personal information", or "personally identifiable information" (or an analogous term) under Applicable Data Protection Laws.
- Personal Data Breach: A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Merchant Customer Personal Data, as interpreted in accordance with Applicable Data Protection Laws.
- Processing: Any operation performed on Personal Data, such as collection, recording, organization, storage, retrieval, use, disclosure, combination, restriction, erasure, or destruction.
- Subprocessor(s): Third-party Data Processors or Service Providers engaged by Hoppy Apps that may process Personal Data for the purpose of providing the Services.
- Merchant Customer Personal Data: Personal Data from or about your store and your Customers that is made available to Hoppy Apps through your use of the Services.
3. Nature of the Processing and Roles of the Parties
3.1 Hoppy Apps as a Data Processor
Hoppy Apps receives and processes Merchant Customer Personal Data solely to provide you with the Services you install and use. Hoppy Apps shall process Merchant Customer Personal Data as a Data Processor or Service Provider only:
- To provide, maintain, and improve the Services in accordance with the Terms of Use;
- In accordance with your documented instructions, which the Terms of Use together with this DPA constitute;
- As required to comply with applicable laws.
3.2 Merchant as a Data Controller
You act as the Data Controller of Merchant Customer Personal Data and are responsible for determining the purposes and means of its processing, including the legal basis for processing under Applicable Data Protection Laws.
3.3 No Sale or Sharing of Personal Data
Hoppy Apps does not "sell" or "share" Merchant Customer Personal Data, and does not engage in "targeted advertising" with Merchant Customer Personal Data, within the meaning of the CCPA or other Applicable Data Protection Laws. We do not retain, use, or disclose Merchant Customer Personal Data outside our direct business relationship with you or for any purpose other than providing the Services.
4. Hoppy Apps' Obligations
4.1 Data Security
Hoppy Apps will implement and maintain appropriate technical and organizational measures designed to protect Merchant Customer Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, theft, alteration, or disclosure, as set forth in Appendix B.
4.2 Confidentiality
Hoppy Apps will ensure that persons authorized to process Merchant Customer Personal Data are bound by written confidentiality agreements or statutory obligations of confidentiality.
4.3 Personal Data Breach Notification
- Hoppy Apps will notify you without undue delay upon confirming any Personal Data Breach.
- Such notice will include the information required under Applicable Data Protection Laws to the extent reasonably available to Hoppy Apps. Notification of a Personal Data Breach is not an acknowledgment of fault or liability.
- Hoppy Apps will investigate any Personal Data Breach and use commercially reasonable efforts to identify, prevent, mitigate, and remedy its effects.
4.4 Assistance to the Merchant
Taking into account the nature of the processing, Hoppy Apps will provide reasonable assistance as you may reasonably request to help you comply with your obligations under Applicable Data Protection Laws, including:
- Responding to Data Rights Requests from your Customers (access, rectification, erasure, portability, objection);
- Notifying relevant authorities and/or data subjects of a Personal Data Breach;
- Conducting data protection impact assessments and prior consultations.
4.5 Deletion and Return of Data
During your use of the Services, you may access, export, or delete Merchant Customer Personal Data through the app's features or by contacting us. Hoppy Apps also honors Shopify's mandatory privacy webhooks (customers/data_request, customers/redact, and shop/redact), so Data Rights Requests and redaction requests received through Shopify are processed as required by Shopify's API Terms. Following uninstallation of an app or termination of the Services, Hoppy Apps will, at your choice, delete or return Merchant Customer Personal Data, except where retention is required by law or permitted under our standard backup and record retention policies — in which case the data remains protected by this DPA and is not further processed.
5. Merchant's Obligations
5.1 Privacy Notices and Transparency
You represent and warrant that you comply with all obligations under Applicable Data Protection Laws to provide notice and transparency concerning your processing of Merchant Customer Personal Data, including maintaining a privacy policy that discloses your use of third-party apps such as ours.
5.2 Lawful Basis and Permissions
You represent and warrant that you have all necessary rights, permissions, and consents to make Merchant Customer Personal Data available to Hoppy Apps, and for Hoppy Apps to process it to provide the Services, in accordance with the Terms of Use, this DPA, and Applicable Data Protection Laws.
5.3 Data Rights Requests
You represent and warrant that you provide your Customers with the ability to exercise their data rights as required under Applicable Data Protection Laws with respect to processing for which you are the Data Controller.
5.4 Regulatory Inquiries
Unless prohibited by applicable law, you will notify us promptly of any governmental, regulatory, or other third-party inquiry or complaint concerning your use of the Services.
6. Subprocessors
- You generally authorize Hoppy Apps to engage Subprocessors to process Merchant Customer Personal Data for the purpose of providing the Services. These include cloud hosting providers, analytics services, and customer support platforms.
- The Services run on the Shopify platform, and Merchant Customer Personal Data is made available to Hoppy Apps through Shopify's APIs. Shopify processes Merchant Customer Personal Data under your separate agreement with Shopify (including Shopify's own Data Processing Addendum) and not as a Subprocessor of Hoppy Apps.
- Where Hoppy Apps engages a Subprocessor, it will enter into a written agreement imposing contractual obligations substantially the same as those set out in this DPA, and Hoppy Apps remains responsible for the Subprocessor's compliance.
- If Applicable Data Protection Laws grant you such rights, you may object to Hoppy Apps' use of a new Subprocessor. If Hoppy Apps is unable or unwilling to accommodate your objection, you may stop using the impacted Services within 30 days of such notification.
7. International Data Transfers
You acknowledge that Merchant Customer Personal Data may be transferred to and processed in any country in which Hoppy Apps or its Subprocessors operate. Any such transfer will be made in compliance with Applicable Data Protection Laws. Where required for transfers of Personal Data subject to EEA, UK, or Swiss data protection laws to countries without an adequacy decision, Hoppy Apps will rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, as applicable.
8. Data Retention and Deletion
Hoppy Apps retains Merchant Customer Personal Data only for as long as necessary to provide the Services or as required by law. When you uninstall one of our apps, we initiate our data deletion process in accordance with our retention policies and Shopify's requirements, after which remaining data is deleted, returned, or de-identified.
9. Amendments to This DPA
Hoppy Apps may amend this DPA from time to time by posting the amended version on this page and updating the "Last updated" date. Amendments are effective as of the date of posting, and your continued use of the Services after posting constitutes your acceptance of the amended DPA. If you do not agree to any changes, discontinue use of the Services.
10. Contact Us
If you have any questions about this DPA or wish to exercise any rights under it, please contact us:
Hoppy Apps
Email: legal@hoppyapps.com
Support: https://help.hoppyapps.com
Appendix A: Categories of Personal Data
Depending on which of our apps you install and how you configure them, we may receive and process the following categories of Personal Data to provide the Services:
- Store information: your Shopify store URL, store name, and admin email address;
- Merchant contact and account information you provide to us;
- Store configuration and settings, and product information;
- Order and transaction data, only as needed for app functionality;
- Customer information (such as name, email, or booking/delivery details), only as needed to provide the Services;
- Usage data: features used, settings configured, and frequency of use;
- Device and log data: browser type, IP address, operating system, and error or performance logs;
- Any other Personal Data you or your Customers choose to make available to Hoppy Apps through the Services.
Appendix B: Security Measures
Hoppy Apps maintains an information security program that includes the following technical and organizational measures:
- Access Controls: Systems are accessible only to authorized personnel, on a least-privilege basis, protected by authentication controls including two-factor authentication where supported.
- Encryption: Data is encrypted in transit using industry-standard TLS; encryption at rest is applied where supported by our hosting providers.
- Vulnerability Management: We monitor, investigate, and remediate identified security issues affecting the Services.
- Change Management: Changes to the Services are reviewed, tested, and documented before deployment to production.
- Availability and Backups: We use reputable cloud hosting providers with redundancy and backup capabilities designed to keep the Services available and recoverable.
- Incident Response: We maintain incident response procedures designed to detect, investigate, mitigate, and respond to security incidents, and to notify affected Merchants as described in Section 4.3.
- Personnel: Team members authorized to access Merchant Customer Personal Data are bound by confidentiality obligations and receive security awareness guidance appropriate to their role.
We review our security measures from time to time and may update this Appendix; any updates will replace prior versions as of the date they are published.