Merchant Data Processing Information
The processing terms that apply when a merchant connects a store to VIP Club. Intended to be read together with the Privacy Policy.
1. Roles
The merchant is the controller of shopper personal data. VIP Club is the processor and processes that data only on the merchant's documented instructions, which are given by connecting the store and configuring the loyalty programme. This page describes our processing; it does not replace a signed agreement where one is required — . To request a counter-signed DPA, contact .
2. Subject matter, duration, nature and purpose
- Subject matter: operation of the merchant's loyalty and rewards programme.
- Duration: for as long as the store is connected, plus the retention periods below.
- Nature: collection via Shopify webhooks and API, storage, calculation, display to authorised merchant staff, anonymisation and deletion.
- Categories of data subject: the merchant's customers who place orders, and the merchant's own staff users.
- Categories of personal data: email, first and last name, phone (optional), date of birth (optional), Shopify customer and order identifiers, order total/currency/status/date, marketing consent state, and loyalty records generated by the platform. No addresses, geolocation, IP addresses or payment data.
- Special category data: none is requested or intentionally processed.
3. Shopify scopes requested
read_orders and read_customers only. No write scopes and no additional protected scopes are requested. We use an offline, expiring access token with automatic refresh; tokens are encrypted at rest.
4. Security measures
- TLS/HTTPS for all data in transit.
- AES-256-GCM encryption of Shopify access and refresh tokens at rest.
- Row-level security on every table, scoped to the owning business, enforcing complete tenant isolation.
- Privileged (service-role) credentials are server-side only and never reach browser code.
- HMAC-SHA256 verification of every Shopify webhook against the raw request body.
- Single-use, hashed, expiring OAuth state to prevent replay.
- Idempotent order, refund and compliance processing.
- An immutable points ledger; corrections are additive entries, never edits.
- Personal data and secrets are stripped from application logs.
5. Subprocessors
Lovable Cloud (application hosting and managed Postgres, built on Supabase infrastructure). Shopify is the source system, not a subprocessor of ours. No email, SMS, analytics or support subprocessor is engaged today. We will list any addition here before it is used: .
6. Assistance with data subject requests
Shopify's mandatory privacy webhooks are implemented. A customers/data_request opens an auditable request in the merchant's Privacy requests screen, from which the merchant can export exactly the data we hold for that shopper. customers/redact irreversibly anonymises the shopper's identifying fields. shop/redact anonymises all of that store's shopper data, destroys the stored Shopify credentials and disconnects the integration. All three are idempotent and logged without personal data.
7. Return and deletion of data
Merchants can export their loyalty data from the dashboard at any time. On uninstall we delete the Shopify credentials immediately; on a shop redaction request we anonymise the shopper personal data while retaining non-identifying financial records for audit integrity.
8. International transfers
Transfer mechanism and hosting region depend on the project's infrastructure region: . Where personal data leaves the EEA or UK, the applicable transfer mechanism (for example EU Standard Contractual Clauses) is set out in the signed merchant agreement.
9. Audit and incident notification
We will notify the merchant without undue delay after becoming aware of a personal data breach affecting their data, using the account contact on file. Formal audit rights, notification deadlines and liability terms: to be set out in the signed merchant agreement.
