Skip to content

Data Processing Agreement

Last updated June 10, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Solcro ("Solcro," "we," "us") and the merchant who uses our Services ("Merchant," "you") and governs Solcro's processing of personal data relating to the Merchant's customers and storefront visitors ("Customer Data") that Solcro accesses when the Merchant connects a Shopify store or installs the Solcro tracking script.

For Customer Data, the Merchant is the data controller and Solcro is the data processor. Solcro processes Customer Data only on the Merchant's documented instructions and to provide the Services. This DPA supplements our Terms and Privacy Policy.

1. Scope and roles

This DPA applies whenever Solcro processes Customer Data on the Merchant's behalf. The Merchant is the controller and determines the purposes of processing; Solcro is the processor and acts only on the Merchant's instructions, which include this DPA, the Terms, and the Merchant's use of the Services.

2. Nature, purpose, and duration of processing

Solcro processes Customer Data solely to provide its store-intelligence and conversion-optimization Services — computing aggregate analytics, audits, and recommendations for the Merchant. Processing continues for as long as the Merchant's store is connected or the Merchant maintains an account, after which the deletion terms in Section 8 apply.

3. Categories of data and data subjects

Data subjects: the Merchant's customers and storefront visitors.

Personal data processed (data minimization):

  • Order metrics only — order total, order date, and financial status. Solcro reads orders with a restricted field set and does not request or store customer names, email addresses, phone numbers, or postal addresses. Only aggregated results (e.g., monthly revenue, average order value, order counts) are stored — never individual orders.
  • Store catalog data — products, variants, images, descriptions.
  • Anonymous storefront behavior (only if the Merchant installs the tracking script) — a per-session identifier, clicks, scroll depth, and device type. No form input values, no personally identifying information, and no fingerprinting; checkout, account, and admin pages are skipped and form fields masked.

Solcro does not process special categories of personal data and does not sell personal data.

4. Processor obligations

  • Process Customer Data only on the Merchant's documented instructions, including for international transfers, unless required by law.
  • Ensure personnel authorized to process Customer Data are bound by confidentiality.
  • Implement and maintain the technical and organizational security measures in Section 7.
  • Assist the Merchant, taking into account the nature of processing, in responding to data-subject requests and in meeting the Merchant's security, breach-notification, and data-protection-impact-assessment obligations.
  • Make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits on reasonable notice.

5. Sub-processors

The Merchant authorizes Solcro to engage the following sub-processors, each under written terms imposing data-protection obligations no less protective than this DPA:

  • InsForge — application hosting, database, and authentication.
  • Anthropic and OpenRouter — AI processing for audits and recommendations. No Customer Data (no order or customer personal data) is sent to these providers — only store catalog text and aggregated metrics.
  • Stripe — payment processing for the Merchant's own subscription (does not process the Merchant's customers' data).

Solcro will give notice of any intended change to its sub-processors and give the Merchant the opportunity to object on reasonable data-protection grounds.

6. International data transfers

Where processing involves a transfer of Customer Data across borders, Solcro will ensure an appropriate transfer mechanism is in place (for example, Standard Contractual Clauses) to the extent required by applicable data-protection law.

7. Security measures

Solcro maintains technical and organizational measures appropriate to the risk, including:

  • Encryption of data in transit (TLS) and at rest.
  • Access controls with per-merchant row-level data isolation; least-privilege access.
  • Storage of Shopify access tokens in an access-restricted secrets vault, never exposed to the browser.
  • Data minimization (Section 3) and separation of production and non-production environments.

8. Data-subject requests, deletion, and return

Solcro honors Shopify's mandatory compliance webhooks: customers/data_request, customers/redact, and shop/redact. Because Solcro stores no customer contact PII, customer-level requests are satisfied accordingly.

On app uninstall, Solcro deletes the store's access token and deactivates the store. On a shop data-erasure request (shop/redact), Solcro deletes all of the store's data within 48 hours. On termination, Solcro deletes or returns Customer Data except where retention is required by law.

9. Breach notification

Solcro will notify the Merchant without undue delay (and, where feasible, within 72 hours) after becoming aware of a personal-data breach affecting Customer Data, with information reasonably available to assist the Merchant's own notification obligations.

10. Liability, term, and contact

This DPA is effective for the duration of the Services and survives until all Customer Data is deleted or returned. Liability under this DPA is subject to the limitations in the Terms. This DPA is governed by the law stated in the Terms.

Questions about this DPA can be sent to support@solcro.com.

This document is a template provided for transparency and is not legal advice; Merchants and Solcro should have it reviewed by qualified counsel for their jurisdiction.