Skip to content
Rinteo
PricingSupportGet early access

Data Processing Agreement

Effective October 10, 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the merchant using Rinteo (the controller) and Rinteo, operated by Arsen Tomyn, Warsaw, Poland (“Rinteo”, the processor). It meets the requirements of Article 28 of the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the UK GDPR, and applies whenever Rinteo processes personal data on the merchant’s behalf.

1. Details of the processing

Subject matterProviding Rinteo’s email marketing service to the merchant’s Shopify store.
DurationWhile Rinteo is installed, until the store’s data is deleted after an uninstall (Shopify shop/redact), plus any period the law requires.
Nature and purposeSyncing store data from Shopify; storing, segmenting and personalizing; sending email on the merchant’s instructions; processing unsubscribes, bounces and complaints; measuring opens, clicks and attributed orders; support.
Data subjectsThe merchant’s customers and subscribers.
Personal dataName, email address, address (country), email marketing consent, customer tags, order and checkout data (items, totals, dates), and email activity (deliveries, bounces, complaints, unsubscribes, opens and clicks with time and user agent).
Special categoriesNone. The merchant must not send them to Rinteo.

2. Rinteo’s obligations

Rinteo will:

  1. process personal data only on the merchant’s documented instructions — the Terms, this DPA and the merchant’s use of the app — unless the law requires otherwise, in which case Rinteo will tell the merchant first where the law allows;
  2. ensure that people authorised to process the data are bound by confidentiality;
  3. implement the technical and organisational measures in section 6;
  4. engage subprocessors only under section 3;
  5. help the merchant, taking into account the nature of the processing, to respond to data subject requests — including the Shopify customers/data_request and customers/redact requests, which Rinteo handles automatically;
  6. help the merchant with security, breach notification, data protection impact assessments and prior consultation, as far as they concern Rinteo’s processing;
  7. at the end of the service, delete the personal data (on Shopify’s shop/redact request after an uninstall), except a suppression entry (email address, reason, date) kept to honour unsubscribes and complaints, and data the law requires Rinteo to keep;
  8. make available the information needed to demonstrate compliance with Article 28 and allow for audits, including inspections, by the merchant or an auditor it mandates, on reasonable notice, at most once a year unless a breach or an authority requires otherwise.

Rinteo will tell the merchant if, in its opinion, an instruction infringes data protection law.

3. Subprocessors

The merchant gives general authorisation for Rinteo to use the subprocessors below. Rinteo imposes data protection obligations on each subprocessor equivalent to this DPA and remains responsible for them. Rinteo will announce a new or replaced subprocessor on this page and in the app at least 30 days in advance; the merchant may object on reasonable data protection grounds, and if no solution is found, may stop using Rinteo.

SubprocessorPurpose
SupabaseDatabase, authentication, file storage and server functions
VercelApplication hosting
SendGrid (Twilio)Email delivery and delivery events
CloudflareNetwork delivery and protection
ShopifyPlatform the app runs in; source of store data; billing

4. International transfers

Where personal data is transferred outside the European Economic Area or the UK to a country without an adequacy decision, Rinteo relies on the European Commission’s Standard Contractual Clauses (and the UK Addendum) or another lawful transfer mechanism.

5. Personal data breaches

Rinteo will notify Shopify within 24 hours and the affected merchant without undue delay after becoming aware of a personal data breach affecting the merchant’s data, with the information the merchant needs to meet its own obligations, and will take reasonable steps to contain it.

6. Security measures

  • Encryption in transit (TLS) for all connections; Shopify access tokens encrypted at rest (AES-GCM).
  • Each store’s data isolated at the database level by row-level security; server-only credentials never reach the browser.
  • Access to production systems limited to the people who need it, with strong authentication.
  • No IP addresses stored for opens and clicks; customers’ phone numbers are not read.
  • Signed and verified webhooks and links (HMAC) for Shopify events, unsubscribes and tracking.
  • Automatic deletion on Shopify’s privacy requests; abandoned checkouts deleted after 30 days.
  • Monitoring of bounces and complaints, with automatic sending pauses.

7. The merchant’s obligations

The merchant is responsible for having a lawful basis for the processing (including consent for marketing email), for the accuracy of the data, and for the instructions it gives through the app.

8. Order of precedence

If this DPA conflicts with the Terms of Service on the processing of personal data, this DPA prevails. Questions: support@rinteo.com.

PrivacyTermsDPASupportsupport@rinteo.com

© 2026 Rinteo, operated by Arsen Tomyn