Data Processing Addendum
Last updated: July 17, 2026
This Data Processing Addendum ("DPA") forms part of our Terms of Service and applies whenever Preferd processes data from your store on your behalf. It reflects the requirements of Article 28 GDPR. Using the app is acceptance of this DPA — no signature needed. If you need a countersigned copy for your records, email us.
Roles
For store data processed through the app, you (the merchant) are the controller and Preferd (the operator of Preferd) is the processor. Shopify acts as a separate processor/controller under its own terms with you.
Subject matter, duration, nature and purpose
Processing covers the operation of Preferd: auditing and scoring your product catalog, generating and applying content optimizations you request, measuring AI visibility and AI-sourced traffic, and enforcing plan limits. It lasts while the app is installed on your store and ends with deletion on uninstall (see section 6).
Categories of data and data subjects
The app is deliberately scoped to catalog and store-operation data. We do not use Shopify's Customer or Orders APIs and do not store customer records, order records, customer IDs, order IDs, contact details or payment details. The storefront pixel receives de-identified visit and conversion events containing an opaque event ID, source, page path, timestamp and, for conversions, value and currency. Data processed:
- Your Shopify store domain and the app access token in server-side session storage. Access is restricted to the service and the token is never sent to the browser.
- Product data we read to score and optimize: titles, descriptions, tags, image alt text, SEO metadata, product type/category, vendor/brand, GTIN/barcodes and metafields.
- Computed GEO scores, the optimizations you generate and apply, and before/after snapshots used for the lift and one-click revert.
- Your subscription plan and usage counters (to enforce plan limits).
- AI-visibility check results and the competitors you choose to track.
- AI-traffic events: when a storefront visit or checkout conversion is attributed to an AI assistant (e.g. ChatGPT, Perplexity, Gemini), we record an opaque event ID, the AI source, event type, landing-page path, timestamp and, for conversions, value and currency. The application payload contains no customer identifier, order identifier, contact details or payment details. Raw events are pruned after 90 days; daily aggregate visits, conversions and revenue are retained to show your AI-traffic trend.
- For the optional monthly report email (paid plans): your store's contact email address as provided by Shopify, your email preference, and when the last report was sent. Deleted with the rest of your data when you uninstall.
Data subjects are limited to you and your staff (store domain, app session). Storefront visitors are not identified in the application payload; Shopify, hosting and network providers may process technical request data under their own terms when delivering pixel events.
Our obligations as processor
- Process store data only to provide the service and on your documented instructions (given through the app's controls), never for our own purposes. We do not sell data or use it to train AI models.
- Ensure persons authorized to process the data are bound by confidentiality.
- Apply appropriate technical and organizational measures: HTTPS in transit, managed PostgreSQL at rest, server-side secrets, OAuth with least-privilege scopes, server-side authorization checks on every action.
- Assist you with data-subject requests and with your GDPR obligations (Articles 32–36), including breach notification without undue delay after becoming aware of a personal data breach.
- Make available the information necessary to demonstrate compliance and allow audits, which for a service of this scale we satisfy through this documentation and written answers to reasonable security questionnaires.
Subprocessors
You authorize the following subprocessors. Each receives only the data needed for its function:
- Shopify
Hosts your store, authorizes the app (OAuth), provides the product data we read/write, and processes all billing.
Data shared: Store domain, app session, billing status.
- Railway
Application hosting and our PostgreSQL database (data at rest).
Data shared: All data the app stores about your store (see “What we store”).
- OpenAI
Generates AI content suggestions when you request an optimization (server-side only, on demand, via an OpenAI-compatible API).
Data shared: The catalog fields needed to generate the suggestion (including title, description, tags, image metadata, SEO metadata, vendor and relevant metafields).
- Perplexity
Powers AI-visibility checks — queries an AI assistant to see whether your store is recommended.
Data shared: Your store/brand name, product category and the buyer-style search queries used for the check.
- Resend
Delivers the optional monthly Impact-Report email (paid plans; you can opt out anytime in-app or via the unsubscribe link).
Data shared: Your store's contact email address and the aggregate report metrics in the email (scores, optimization counts, AI-traffic totals). Nothing is shared if the email is disabled.
We will update this list before adding or replacing a subprocessor. If you object to a change on reasonable data-protection grounds, your remedy is to uninstall the app, which deletes your data.
Deletion and return
Uninstalling the app permanently deletes all data tied to your store (cascade delete), and we honor Shopify's mandatory shop/redact webhook as a backstop. Because the app holds no customer personal data, customers/data_request and customers/redact return empty by design. You can export your product scores as CSV at any time before uninstalling.
International transfers
Subprocessors may process data outside the EU/EEA (e.g. in the United States). Where they do, transfers rely on appropriate safeguards — the providers' Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
Contact
Privacy questions and data-protection requests: [email protected]. See also the Privacy Policy.