Data processing addendum
Last updated
This page is provided for information and is not legal advice. If you need advice specific to your situation, consult a qualified professional in your jurisdiction.
This addendum supplements the Terms of service and applies where applicable data protection law requires a written agreement between a controller and its processor. Given how little personal data the app actually handles (see Annex 1), most merchants won't need to invoke this formally, but it's here for those who do, for example as part of their own vendor compliance records.
1. Roles
Where you (the merchant) determine the purposes and means of processing personal data through your use of the app, you act as the controller, and Marti Belegu acts as your processor, processing personal data only on your instructions as set out in this addendum, the Terms of service, and the Privacy policy.
2. Subject matter and duration
Processing covers the personal data described in Annex 1, for the duration the app remains installed on your store, plus the period until Shopify's mandatory automatic erasure completes following uninstallation. See Uninstalling and your data.
3. Our obligations
- Process personal data only on your documented instructions, as reflected in the app's ordinary operation.
- Ensure that anyone we authorise to process personal data is subject to confidentiality obligations.
- Implement appropriate technical and organisational security measures; see Annex 3.
- Assist you, to a reasonable extent, in responding to requests from individuals exercising their data protection rights.
- Notify you without undue delay if we become aware of a personal data breach affecting your data.
- Delete or return personal data at the end of the provision of services, subject to Shopify's own mandatory retention and erasure requirements.
- Make available the information reasonably necessary to demonstrate compliance with this addendum.
4. Sub-processors
You authorise the use of the sub-processors listed in Annex 2. We will update that list if it changes and, where required by applicable law, provide notice of new sub-processors.
5. International transfers
Marti Belegu operates from Republic of Albania. The infrastructure processing your data, meaning hosting and database, is located in the European Union (see Annex 2), independent of the operator's own location. Where a transfer of personal data outside the European Economic Area or United Kingdom is considered to occur as a result, we rely on appropriate safeguards recognised under applicable law, such as the European Commission's Standard Contractual Clauses, and will provide further detail on request.
6. Liability
Liability under this addendum is subject to the limitations set out in the Terms of service.
Annex 1: description of processing
| Category | Data subjects | Data |
|---|---|---|
| Staff account details | Merchant staff who install the app | Name, email address, locale (provided by Shopify on installation) |
| Storefront usage | Blog visitors | Anonymous, aggregate daily counts only, with no identifiers of any kind. See What we collect. |
Processing is carried out by automated means for the duration of the app's installation, for the purpose of providing the app's functionality as described in the documentation.
Annex 2: sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Shopify, Inc. | Platform, installation, and billing | Varies by Shopify infrastructure |
| Vercel Inc. | Application hosting | Frankfurt, Germany (EU) |
| Supabase, Inc. | Database hosting | EU (Zurich region) |
Annex 3: security measures
Summarised here; see the Security page for more.
- The app requests only the minimum Shopify access scope it needs (
read_content). - All requests between the storefront, the app, and Shopify are made over encrypted connections (HTTPS/TLS).
- Requests reaching the app from your storefront are cryptographically verified using Shopify's own app proxy signing, so their origin can be trusted before any data is read or written.
- Webhook deliveries are verified against Shopify's signature before being processed.
- Database access is restricted to the application itself; there is no public-facing database endpoint.