Data Processing Addendum

Last updated: 2026-07-17

This addendum describes how DiscloseMate Product Guard processes data on behalf of the merchant (the data controller). The app operator acts as a data processor for the limited operational data described below.

Scope of processing

Processing is limited to shop identity, Shopify session records, merchant-defined rules, catalog audit summaries, temporary product title snapshots, disclosure references and merchant-confirmed disclosure snapshots, job and row-level evidence, durable mutation attempts, the billing entitlement result, and operational usage aggregates. The app requests only the write_products andwrite_metaobjects scopes.

No protected customer data

The app does not access or process protected customer data, orders, checkout, payment, shipping, theme, or file data. It does not transfer data to external analytics providers.

Sub-processors

Hosting is provided by Vercel. The database is a dedicated Neon PostgreSQL project. Entitlement verification uses the Shopify Partner API. Data is stored in a single configured region.

Retention and deletion

Retention follows the Privacy Policy. On uninstall or a shop redaction request, app-owned data and sessions are deleted through database cascades, even when no session exists. Native Shopify disclosure entries and product assignments remain in the merchant's store.

Contact

Support email: cadosy@gmail.com