Data Processing Agreement (DPA)

Effective: July 15, 2026

EU Merchants: This DPA is automatically incorporated into your use of Parcelglance. No separate signature is required — installing the App constitutes acceptance. To receive a signed copy, email privacy@parcelglance.com (Partner-registered fallback: haimozhouqiu@outlook.com) with "DPA Request" in the subject line.

Between:

  • Merchant (the "Data Controller"): The Shopify store owner who has installed Parcelglance
  • Haimo Tech (the "Data Processor"): The developer and operator of Parcelglance

1. Scope and Purpose

This DPA applies to the processing of personal data by Haimo Tech on behalf of the Merchant in connection with the Parcelglance Shopify App ("the Service"). The subject matter, duration, nature, and purpose of the processing, the types of personal data processed, and the categories of data subjects are described in Annex A.

2. Roles and Responsibilities

2.1 Data Controller

The Merchant is the Data Controller of end-customer personal data processed through the Parcelglance chat widget on their Shopify store.

2.2 Data Processor

Haimo Tech acts as a Data Processor on behalf of the Merchant, processing personal data only to provide the Service as described in the Terms of Service and Privacy Policy.

2.3 Sub-processors

ProviderPurposeLocationTransfer Basis
Supabase Inc.Database hostingTokyo, JapanEU adequacy decision
DeepSeek (High-Flyer AI)AI response generation (non-tracking queries only)ChinaSCCs Module 3 + supplementary measures
Vercel Inc.Application hostingUSAEU-US DPF
Shopify Inc.OAuth, API, billingUSA/CanadaDPF certification
Resend Inc.Transactional email for GDPR data-subject-request delivery (Art. 15 packages). No marketing email.USASCCs (2021 EU) + EU-US DPF
OpenAI / Anthropic (LLM fallback)Chat reply generation for merchants who opt into non-DeepSeek LLM. Zero-retention headers where supported; no PII embedded in prompts.USASCCs (2021 EU) + EU-US DPF (OpenAI)

Haimo Tech will notify the Merchant of any changes to sub-processors at least 30 days in advance, providing the Merchant the opportunity to object.

3. Processor Obligations

Haimo Tech shall:

  1. Process personal data only on documented instructions from the Merchant (as set out in the Service configuration and this DPA)
  2. Ensure that persons authorised to process the personal data have committed themselves to confidentiality
  3. Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk (see Annex B)
  4. Not engage another processor without prior specific or general written authorisation (sub-processor list above constitutes general authorisation)
  5. Assist the Merchant in responding to data subject requests for exercising their rights
  6. Assist the Merchant in ensuring compliance with GDPR Articles 32-36
  7. Delete or return all personal data upon termination of the Service
  8. Make available to the Merchant all information necessary to demonstrate compliance

4. Security Measures (Annex B)

  1. Encryption in Transit: All data transmitted uses TLS 1.2+
  2. Encryption at Rest: Database storage uses AES-256 encryption
  3. Access Control: Service role keys stored as environment variables, never exposed in client-side code
  4. Data Minimisation: Order tracking queries process zero AI calls; only non-tracking chat messages are sent to DeepSeek AI; order data is fetched in real-time and not stored
  5. Pseudonymisation: Customer identifiers are pseudonymised where feasible
  6. Data Retention: Conversations retained for 90 days, PII anonymised after 90 days, automated daily cleanup
  7. Incident Response: Data breaches notified without undue delay and no later than 72 hours
  8. Secure Development: XSS prevention, input validation, CORS controls, rate limiting, HMAC-verified webhooks
  9. Geographic Controls: CN IP blocking via Vercel Geo-Location (HTTP 451)
  10. HSTS: Strict-Transport-Security enabled (max-age=31536000; includeSubDomains)

5. Data Subject Rights

Haimo Tech will assist the Merchant in fulfilling data subject requests by:

  • Providing data export functionality via GDPR webhooks (customers/data_request)
  • Deleting PII upon request (customers/redact)
  • Deleting all shop data upon uninstallation (shop/redact)

6. International Data Transfers

6.1 DeepSeek (China)

Transfers governed by Standard Contractual Clauses (Module 3: Processor to Processor), Commission Implementing Decision (EU) 2021/914, supplemented by encryption in transit and at rest, data minimisation, pseudonymisation, and real-time processing without retention. A Transfer Impact Assessment has been conducted considering China's legal framework.

6.2 Vercel and Shopify (USA)

Covered by the EU-US Data Privacy Framework certification.

6.3 Supabase (Japan)

Benefits from the EU adequacy decision for Japan (Commission Implementing Decision 2019/1919).

7. Data Breach Notification

Haimo Tech will notify the Merchant without undue delay and no later than 72 hours after becoming aware of a personal data breach, providing the nature of the breach, likely consequences, and measures taken.

8. Audit Rights

The Merchant has the right to audit Haimo Tech's compliance with this DPA, subject to reasonable notice (at least 14 days) and during normal business hours.

9. Term and Termination

This DPA remains in effect for the duration of the Merchant's use of the Service. Upon termination, all personal data will be deleted within 30 days. Written confirmation of deletion will be provided upon request.

10. Governing Law

This DPA shall be governed by the laws of Singapore. For EU Merchants, the mandatory provisions of GDPR and applicable EU member state law shall prevail where they provide greater protection.

Annex A: Processing Details

ItemDescription
Subject matterAI-powered order tracking chatbot for Shopify stores
DurationFor the duration of the Merchant's subscription
Nature of processingCollection, storage, query, and automated response generation
PurposeOrder tracking, customer service automation, analytics
Personal data typesCustomer email, customer name, chat messages, order numbers, locale/language
Categories of data subjectsEnd customers of the Merchant's Shopify store

Last updated: July 15, 2026