Data Processing Agreement (DPA)
Effective: July 15, 2026
EU Merchants: This DPA is automatically incorporated into your use of Parcelglance. No separate signature is required — installing the App constitutes acceptance. To receive a signed copy, email privacy@parcelglance.com (Partner-registered fallback: haimozhouqiu@outlook.com) with "DPA Request" in the subject line.
Between:
- Merchant (the "Data Controller"): The Shopify store owner who has installed Parcelglance
- Haimo Tech (the "Data Processor"): The developer and operator of Parcelglance
1. Scope and Purpose
This DPA applies to the processing of personal data by Haimo Tech on behalf of the Merchant in connection with the Parcelglance Shopify App ("the Service"). The subject matter, duration, nature, and purpose of the processing, the types of personal data processed, and the categories of data subjects are described in Annex A.
2. Roles and Responsibilities
2.1 Data Controller
The Merchant is the Data Controller of end-customer personal data processed through the Parcelglance chat widget on their Shopify store.
2.2 Data Processor
Haimo Tech acts as a Data Processor on behalf of the Merchant, processing personal data only to provide the Service as described in the Terms of Service and Privacy Policy.
2.3 Sub-processors
| Provider | Purpose | Location | Transfer Basis |
|---|---|---|---|
| Supabase Inc. | Database hosting | Tokyo, Japan | EU adequacy decision |
| DeepSeek (High-Flyer AI) | AI response generation (non-tracking queries only) | China | SCCs Module 3 + supplementary measures |
| Vercel Inc. | Application hosting | USA | EU-US DPF |
| Shopify Inc. | OAuth, API, billing | USA/Canada | DPF certification |
| Resend Inc. | Transactional email for GDPR data-subject-request delivery (Art. 15 packages). No marketing email. | USA | SCCs (2021 EU) + EU-US DPF |
| OpenAI / Anthropic (LLM fallback) | Chat reply generation for merchants who opt into non-DeepSeek LLM. Zero-retention headers where supported; no PII embedded in prompts. | USA | SCCs (2021 EU) + EU-US DPF (OpenAI) |
Haimo Tech will notify the Merchant of any changes to sub-processors at least 30 days in advance, providing the Merchant the opportunity to object.
3. Processor Obligations
Haimo Tech shall:
- Process personal data only on documented instructions from the Merchant (as set out in the Service configuration and this DPA)
- Ensure that persons authorised to process the personal data have committed themselves to confidentiality
- Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk (see Annex B)
- Not engage another processor without prior specific or general written authorisation (sub-processor list above constitutes general authorisation)
- Assist the Merchant in responding to data subject requests for exercising their rights
- Assist the Merchant in ensuring compliance with GDPR Articles 32-36
- Delete or return all personal data upon termination of the Service
- Make available to the Merchant all information necessary to demonstrate compliance
4. Security Measures (Annex B)
- Encryption in Transit: All data transmitted uses TLS 1.2+
- Encryption at Rest: Database storage uses AES-256 encryption
- Access Control: Service role keys stored as environment variables, never exposed in client-side code
- Data Minimisation: Order tracking queries process zero AI calls; only non-tracking chat messages are sent to DeepSeek AI; order data is fetched in real-time and not stored
- Pseudonymisation: Customer identifiers are pseudonymised where feasible
- Data Retention: Conversations retained for 90 days, PII anonymised after 90 days, automated daily cleanup
- Incident Response: Data breaches notified without undue delay and no later than 72 hours
- Secure Development: XSS prevention, input validation, CORS controls, rate limiting, HMAC-verified webhooks
- Geographic Controls: CN IP blocking via Vercel Geo-Location (HTTP 451)
- HSTS: Strict-Transport-Security enabled (max-age=31536000; includeSubDomains)
5. Data Subject Rights
Haimo Tech will assist the Merchant in fulfilling data subject requests by:
- Providing data export functionality via GDPR webhooks (customers/data_request)
- Deleting PII upon request (customers/redact)
- Deleting all shop data upon uninstallation (shop/redact)
6. International Data Transfers
6.1 DeepSeek (China)
Transfers governed by Standard Contractual Clauses (Module 3: Processor to Processor), Commission Implementing Decision (EU) 2021/914, supplemented by encryption in transit and at rest, data minimisation, pseudonymisation, and real-time processing without retention. A Transfer Impact Assessment has been conducted considering China's legal framework.
6.2 Vercel and Shopify (USA)
Covered by the EU-US Data Privacy Framework certification.
6.3 Supabase (Japan)
Benefits from the EU adequacy decision for Japan (Commission Implementing Decision 2019/1919).
7. Data Breach Notification
Haimo Tech will notify the Merchant without undue delay and no later than 72 hours after becoming aware of a personal data breach, providing the nature of the breach, likely consequences, and measures taken.
8. Audit Rights
The Merchant has the right to audit Haimo Tech's compliance with this DPA, subject to reasonable notice (at least 14 days) and during normal business hours.
9. Term and Termination
This DPA remains in effect for the duration of the Merchant's use of the Service. Upon termination, all personal data will be deleted within 30 days. Written confirmation of deletion will be provided upon request.
10. Governing Law
This DPA shall be governed by the laws of Singapore. For EU Merchants, the mandatory provisions of GDPR and applicable EU member state law shall prevail where they provide greater protection.
Annex A: Processing Details
| Item | Description |
|---|---|
| Subject matter | AI-powered order tracking chatbot for Shopify stores |
| Duration | For the duration of the Merchant's subscription |
| Nature of processing | Collection, storage, query, and automated response generation |
| Purpose | Order tracking, customer service automation, analytics |
| Personal data types | Customer email, customer name, chat messages, order numbers, locale/language |
| Categories of data subjects | End customers of the Merchant's Shopify store |
Last updated: July 15, 2026