Merchant Data Processing Terms
Last updated: September 3, 2026
1. Roles
For protected customer data that a merchant makes available through Shopify, the merchant acts as the business/controller (or equivalent role under applicable law) and Hangzhou Yidao Chuhai Digital Technology Co., Ltd. acts as a service provider/processor to the extent required by applicable privacy law.
2. Processing instructions and purpose
We process authorized data only on documented merchant instructions arising from installation, configuration, and use of the app, for store management, app functionality, and analytics. We do not sell customer personal data or use it for unrelated advertising.
3. Data categories
V1 may process Shopify Level 1 protected customer data contained in order and related operational resources. V1 does not request the protected fields Name, Address, Email, or Phone.
4. Confidentiality and access
Access to production systems and merchant data is restricted to authorized personnel and service providers who need access to operate or secure the service and are subject to confidentiality obligations.
5. Security measures
Measures include HTTPS/TLS in transit, AES-256-GCM encryption of Shopify access/refresh tokens at rest, secret separation, least-privilege access, token/PCD-safe logging, and mandatory Shopify webhook HMAC verification. See the Security Overview.
6. Subprocessors
We may use infrastructure, hosting, database, security, and monitoring providers solely to operate the service. Before public production launch, the production subprocessor set will be maintained in current product documentation. We remain responsible for requiring appropriate data-protection obligations from subprocessors.
7. Data subject and Shopify privacy requests
We support Shopify's mandatory customers/data_request, customers/redact, and shop/redact workflows. Where we hold responsive data, we will complete the required action within the applicable Shopify/legal timeframe.
8. Retention and deletion
Raw protected customer/order data is not persisted in V1. Shopify session credentials are deleted on uninstall and shop redaction. See the Data Retention & Deletion Policy.
9. International transfers
Where cross-border processing occurs, the parties will use applicable contractual or other lawful transfer mechanisms as required by law.
10. Assistance and contact
Merchants can contact aiken@yeedoor.com for privacy, security, or data-processing questions.