Data Processing Addendum
This Data Processing Addendum ("DPA") describes how PINUYA LLC processes personal data on behalf of a merchant using Order Vault. It is incorporated into and forms part of our Terms of Service.
Last updated September 10, 2026.
1. Parties and roles
The merchant who installs Order Vault ("Controller") determines why and how their customers' personal data is collected and used. PINUYA LLC ("Processor") processes that personal data only on the Controller's behalf, and only to provide Order Vault's features, as configured by the Controller through the app's settings and the Controller's own actions (e.g. approving or cancelling an order).
2. Scope and nature of processing
- Subject matter: Processing of order and customer data to identify orders flagged as risky by Shopify, verify them with the customer, let the merchant approve or cancel them, and produce chargeback evidence.
- Duration: For as long as Order Vault is installed on the Controller's store, plus the retention period described in Section 5.
- Nature and purpose: Fraud/chargeback risk review, customer order verification, fulfillment holding, and chargeback evidence assembly — see our Privacy Policy for the full description of how data is used.
- Categories of data: Customer name, email, phone, billing and shipping address, order details, payment result data (card last 4, AVS/CVV result codes — never full card numbers), Shopify's risk assessment for the order, the customer's verification record (confirmation time, IP address, browser user agent), and fulfillment/tracking information.
- Categories of data subjects: The Controller's customers who place orders on the Controller's store.
3. Processor obligations
- Instructions. We process personal data only on the Controller's documented instructions — expressed through the app's configuration and the Controller's own actions in Order Vault — unless required otherwise by law.
- Confidentiality. Access to personal data is limited to what Order Vault needs to operate; we do not provide a general-purpose data browser to third parties, and access is restricted to the owner's accounts.
- Security measures. We maintain the following technical and organizational measures:
- HTTPS/TLS encryption for all traffic to and from the app.
- Data encrypted at rest at the storage level by our hosting provider.
- Daily database backups, encrypted (age) before leaving the server, stored in Cloudflare R2, and kept for 30 days.
- Staff access limited to the owner's accounts, protected by strong passwords and two-factor authentication.
- An application log recording when merchant staff view or export customer personal data.
- Separate development and production environments and databases.
- Secrets and credentials kept out of source code.
- Subprocessors. We use the following subprocessors to provide Order Vault:
- Shopify — The e-commerce platform Order Vault runs on and reads order/customer data from.
- Resend (resend.com) — Delivers transactional emails: customer verification requests and merchant notifications.
- Railway (railway.com) — Hosts the Order Vault application and its database.
- Cloudflare (cloudflare.com) — DNS and encrypted database backup storage.
- Assistance with data subject requests. Shopify's mandatory GDPR webhooks (customer data request, customer redact, shop redact) notify us when a data subject exercises their rights, and Order Vault handles those automatically as described in our Privacy Policy. We will otherwise reasonably assist the Controller in responding to data subject requests they receive directly.
- Breach notification. We will notify the Controller without undue delay, and no later than 72 hours after becoming aware, of any breach affecting their personal data.
- Deletion or return at end of processing. When Order Vault is uninstalled, we delete the Controller's store data — order cases, evidence records, disputes, event history, settings, and the store's access token — after the uninstall notice period described in our Privacy Policy.
- Audits. We will provide the Controller with information reasonably necessary to demonstrate compliance with this DPA. We do not offer on-site audits beyond that.
4. International transfers
Our hosting provider (Railway (railway.com)) and other subprocessors may process or store data in regions outside the European Economic Area. Where such a transfer requires a safeguard under applicable law, we rely on Standard Contractual Clauses (or an equivalent recognized transfer mechanism) as the basis for that transfer.
5. Retention
Personal data covered by this DPA is retained for 18 months from creation, or longer while an order has an open verification case or an open/recent chargeback, as described in our Privacy Policy.
6. Incorporation into the Terms
This DPA is incorporated into and forms part of our Terms of Service. In the event of a conflict between this DPA and the Terms concerning the processing of personal data, this DPA controls.
7. Contact
Questions about this DPA can be sent to pinuya.llc@gmail.com.