Data Processing Agreement
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the merchant using Rinteo (the controller) and Rinteo, operated by Arsen Tomyn, Warsaw, Poland (“Rinteo”, the processor). It meets the requirements of Article 28 of the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the UK GDPR, and applies whenever Rinteo processes personal data on the merchant’s behalf.
1. Details of the processing
| Subject matter | Providing Rinteo’s email marketing service to the merchant’s Shopify store. |
|---|---|
| Duration | While Rinteo is installed, until the store’s data is deleted after an uninstall (Shopify shop/redact), plus any period the law requires. |
| Nature and purpose | Syncing store data from Shopify; storing, segmenting and personalizing; sending email on the merchant’s instructions; processing unsubscribes, bounces and complaints; measuring opens, clicks and attributed orders; support. |
| Data subjects | The merchant’s customers and subscribers. |
| Personal data | Name, email address, address (country), email marketing consent, customer tags, order and checkout data (items, totals, dates), and email activity (deliveries, bounces, complaints, unsubscribes, opens and clicks with time and user agent). |
| Special categories | None. The merchant must not send them to Rinteo. |
2. Rinteo’s obligations
Rinteo will:
- process personal data only on the merchant’s documented instructions — the Terms, this DPA and the merchant’s use of the app — unless the law requires otherwise, in which case Rinteo will tell the merchant first where the law allows;
- ensure that people authorised to process the data are bound by confidentiality;
- implement the technical and organisational measures in section 6;
- engage subprocessors only under section 3;
- help the merchant, taking into account the nature of the processing, to respond to data subject requests — including the Shopify customers/data_request and customers/redact requests, which Rinteo handles automatically;
- help the merchant with security, breach notification, data protection impact assessments and prior consultation, as far as they concern Rinteo’s processing;
- at the end of the service, delete the personal data (on Shopify’s shop/redact request after an uninstall), except a suppression entry (email address, reason, date) kept to honour unsubscribes and complaints, and data the law requires Rinteo to keep;
- make available the information needed to demonstrate compliance with Article 28 and allow for audits, including inspections, by the merchant or an auditor it mandates, on reasonable notice, at most once a year unless a breach or an authority requires otherwise.
Rinteo will tell the merchant if, in its opinion, an instruction infringes data protection law.
3. Subprocessors
The merchant gives general authorisation for Rinteo to use the subprocessors below. Rinteo imposes data protection obligations on each subprocessor equivalent to this DPA and remains responsible for them. Rinteo will announce a new or replaced subprocessor on this page and in the app at least 30 days in advance; the merchant may object on reasonable data protection grounds, and if no solution is found, may stop using Rinteo.
| Subprocessor | Purpose |
|---|---|
| Supabase | Database, authentication, file storage and server functions |
| Vercel | Application hosting |
| SendGrid (Twilio) | Email delivery and delivery events |
| Cloudflare | Network delivery and protection |
| Shopify | Platform the app runs in; source of store data; billing |
4. International transfers
Where personal data is transferred outside the European Economic Area or the UK to a country without an adequacy decision, Rinteo relies on the European Commission’s Standard Contractual Clauses (and the UK Addendum) or another lawful transfer mechanism.
5. Personal data breaches
Rinteo will notify Shopify within 24 hours and the affected merchant without undue delay after becoming aware of a personal data breach affecting the merchant’s data, with the information the merchant needs to meet its own obligations, and will take reasonable steps to contain it.
6. Security measures
- Encryption in transit (TLS) for all connections; Shopify access tokens encrypted at rest (AES-GCM).
- Each store’s data isolated at the database level by row-level security; server-only credentials never reach the browser.
- Access to production systems limited to the people who need it, with strong authentication.
- No IP addresses stored for opens and clicks; customers’ phone numbers are not read.
- Signed and verified webhooks and links (HMAC) for Shopify events, unsubscribes and tracking.
- Automatic deletion on Shopify’s privacy requests; abandoned checkouts deleted after 30 days.
- Monitoring of bounces and complaints, with automatic sending pauses.
7. The merchant’s obligations
The merchant is responsible for having a lawful basis for the processing (including consent for marketing email), for the accuracy of the data, and for the instructions it gives through the app.
8. Order of precedence
If this DPA conflicts with the Terms of Service on the processing of personal data, this DPA prevails. Questions: support@rinteo.com.