Legal

Data Processing Agreement

Applies to Alcaris Inc., doing business as Propel Commerce, and all Propel apps

Last updated: 6 August 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Use or any other written agreement (the "Principal Agreement") between:

Alcaris Inc., an Ontario corporation doing business as Propel Commerce, developer of the Propel Commerce applications for Shopify, including Propel Replays, Propel Appointments, Propel Subscriptions, Propel Upsells, Propel Warranty, and Propel Low Stock Alerts, and any other Propel Commerce application the Controller installs (collectively, the "Apps") (the "Processor"); contact: support@propelcommerce.io; and

The Shopify Merchant using one or more of the Apps (the "Controller").

Together, the Processor and Controller are the "Parties". This DPA reflects the Parties' agreement regarding processing of personal data in connection with use of the Apps and is intended to comply with applicable data protection laws including the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act (the "CCPA"), as applicable.

If there is a conflict between this DPA and the Principal Agreement, or between this DPA and any privacy policy published by the Processor, this DPA prevails in respect of the processing of personal data.

§ 01

Subject Matter and Purpose

1.1 The Processor provides session recording, replay, heatmap, analytics, appointment booking, subscription management, upsell, warranty registration, and inventory monitoring and low-stock alerting services for Shopify stores, depending on which Apps the Controller installs.

1.2 The Processor processes personal data on behalf of the Controller solely for the purposes of delivering these services, including user-experience analysis, debugging, fraud prevention, customer-journey insights, appointment scheduling, recurring billing, post-purchase upsells, warranty registration and claim handling, and inventory threshold monitoring and alerting.

1.3 No processing shall occur for purposes other than those instructed by the Controller or otherwise required to provide the Apps.

§ 02

Duration

This DPA remains in force for as long as the Controller uses the Apps. Upon termination, data will be deleted or returned in accordance with Annex II (Data Retention & Deletion).

§ 03

Categories of Data Subjects

The Processor may process personal data relating to the following categories of data subjects:

— Visitors and customers of the Controller's Shopify store
— Users interacting with the Controller's storefront, checkout, customer portal, or booking pages
— Staff of the Controller who administer or use the Apps in the Shopify admin

§ 04

Types of Personal Data

The Processor processes only the following types of data, varying by App:

Common across the Apps:
— Metadata: IP address, user agent, device information, locale, referrer
— Approximate geolocation derived from IP address (country, region, city)
— Shopify customer identifiers (customer ID, order ID, cart token) where the merchant has installed and configured the App accordingly

Propel Replays specifically:
— Interaction data: clicks, taps, scrolls, page-navigation events, mouse/touch trails
— Page URLs, including query parameters
— DOM snapshots, with sensitive form fields masked by default and payment fields excluded entirely
— Survey responses where surveys are configured by the Controller

Propel Appointments specifically:
— Booking metadata: customer name, email, phone (where collected), appointment time, service selected

Propel Subscriptions specifically:
— Subscription metadata: customer ID, plan, frequency, status, billing history (no payment card data)

Propel Upsells specifically:
— Cart and conversion events: items added, offers shown, offers accepted, attributed revenue

Propel Warranty specifically:
— Registration data: customer-provided product registration form fields, serial numbers, claim attachments

Excluded data: the Apps do not collect passwords, payment card data (PAN, CVV, cardholder name), social security or national identification numbers, or other sensitive identifiers. Payment processing remains with Shopify and Shopify's payment processors.

§ 05

Obligations of the Controller

The Controller shall:

— Obtain a valid legal basis for processing and inform end users about the data practices of any installed App, consistent with the privacy policies for each App
— Configure and use the Apps responsibly, ensuring no unlawful collection of personal data
— Provide instructions to the Processor regarding data deletion, export, or suspension of processing
— Honor data-subject requests submitted directly to the Controller, with the Processor's cooperation as described in Section 6

§ 06

Obligations of the Processor

The Processor agrees to:

— Process data only on documented instructions from the Controller, including with regard to international transfers, unless required to do so by applicable law
— Maintain confidentiality of personal data and ensure that staff and sub-processors authorized to process personal data are bound by appropriate confidentiality obligations
— Implement the technical and organizational security measures described in Annex I
— Assist the Controller in fulfilling data-subject rights (access, rectification, erasure, portability, objection)
— Notify the Controller of any personal data breach without undue delay and in no event later than 36 hours after confirmation
— Make available relevant information for audits, as outlined in Section 11
— Delete or return all personal data upon termination of services, as outlined in Annex II
— Notify the Controller in writing without undue delay, and in any case within 5 business days, if the Processor determines that it can no longer meet its obligations under applicable data protection laws
— Assist the Controller in fulfilling its obligations under Articles 32–36 GDPR, including implementing and maintaining appropriate technical and organizational measures (TOMs), supporting data-breach notifications, providing information to data subjects where required, and supporting Data Protection Impact Assessments (DPIAs) and prior consultation with supervisory authorities as needed.

6.9 GDPR Art. 32–36 Assistance

In relation to personal data the Processor processes for the Controller, the Processor shall, on a commercially reasonable efforts basis:

(a) TOMs. Implement and maintain the technical and organizational measures set out in Annex I and, on request not more than once per calendar year, provide a TOMs summary (architecture/data-flow overview, encryption statement, access-control matrix, vulnerability-scan executive summary).

(b) Incidents. Without undue delay and in any case within 36 hours after confirmation, notify the Controller and provide an incident report covering: nature of the incident, systems affected, categories/volume of data, timelines, likely consequences, and containment and remediation steps. The Processor shall preserve relevant security logs and evidence for not less than 90 days and reasonably cooperate with the Controller's notifications under GDPR Articles 33–34.

(c) Data-Subject Requests (DSAR). Within 5 business days of written instruction from the Controller, use reasonable efforts to locate, export (CSV/JSON with field glossary), rectify, restrict, or delete personal data within the Processor's systems, and provide written confirmation upon completion.

(d) DPIA Support (Art. 35). Within 10 business days of request, provide a DPIA Input Pack covering: purposes, data categories, sources, retention, recipients/sub-processors, transfer mechanisms, TOMs, and material risks/mitigations; and notify the Controller of material changes that impact the DPIA.

(e) Prior Consultation (Art. 36). Provide reasonable cooperation for supervisory-authority consultations initiated by the Controller, including technical Q&A and documentation. Target response time is 5 business days unless urgent.

(f) Point of Contact. All requests under this Clause 6.9 shall be sent to support@propelcommerce.io. The Processor shall maintain an audit trail of assistance actions under this Clause for not less than 2 years.

(g) Scope & Limits. Assistance is limited to personal data processed by the Processor and does not constitute legal advice. The Processor shall flow down equivalent assistance obligations to its approved sub-processors.

§ 07

Sub-processors

7.1 The Processor may engage sub-processors to provide infrastructure or supporting services necessary to deliver the Apps.

7.2 Current sub-processors are listed in Annex III (Sub-processors).

7.3 The Processor shall ensure sub-processors are bound by written agreements providing the same level of protection as this DPA, including the CCPA/CPRA restrictions set out in Section 16.

7.4 The Processor shall notify the Controller of any intended changes to sub-processors at least one (1) month prior to their engagement. The Controller may object to the proposed sub-processor within 14 days of receiving the notice. If no objection is raised within this period, the sub-processor may be engaged. In the event of a justified objection, the Processor shall not engage the sub-processor, or the Controller shall have the right to terminate the relevant part of the agreement with reasonable notice.

§ 08

International Data Transfers

8.1 Data is primarily processed and stored on infrastructure operated by the sub-processors listed in Annex III.

8.2 Where data is transferred outside the EU/EEA, such transfers will be protected by Standard Contractual Clauses (SCCs), the UK International Data Transfer Agreement (where applicable), or other legally valid transfer mechanisms.

§ 09

Security Measures

The Processor implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk of processing. These measures are detailed in Annex I (Technical & Organizational Security Measures).

§ 10

Data Subject Rights

The Processor shall assist the Controller, to the extent reasonably possible, in fulfilling obligations to respond to data-subject requests under applicable data protection laws, in line with the timelines set out in Section 6.9.

§ 11

Audit & Reporting

— The Controller may request the Processor to complete a security questionnaire or provide documentation necessary to demonstrate compliance with this DPA.
— On-site or remote audits may be requested with reasonable prior notice of at least 14 calendar days. Audits are conducted no more than once per calendar year, or more frequently if required by a supervisory authority or following a personal data breach.

§ 12

Data Breach Notification

In the event of a personal data breach, the Processor shall:

— Detect and assess incidents promptly upon initial detection
— Notify the affected Controller without undue delay and in any case within 36 hours of confirmation
— Provide details of the nature of the breach, scope of data affected, likely consequences, and remediation steps taken or proposed

§ 13

Liability

Liability under this DPA is governed by the Principal Agreement. Each Party is liable for damages arising from its own breach of data-protection obligations, subject to any limitations of liability set out in the Principal Agreement.

§ 14

Termination

Upon termination of the Principal Agreement:

— The Controller may instruct the Processor to return or delete personal data
— Unless otherwise instructed, the Processor will delete personal data according to Annex II

§ 15

Governing Law

This DPA shall be governed by the laws of the Province of British Columbia and the federal laws of Canada applicable therein, unless otherwise required by applicable data-protection law (including, where relevant, the laws of the EU/EEA member state in which the data subject resides).

§ 16

CCPA/CPRA Service Provider Addendum

This Section 16 applies to personal information that the Processor processes on the Controller's behalf and that is subject to the CCPA. It is the written contract required by Cal. Civ. Code sections 1798.100(d) and 1798.140(ag). Where it conflicts with any other part of this DPA in respect of that personal information, this Section 16 controls.

16.1 Definitions and Roles

For personal information covered by this Section, the Controller is the "business" and the Processor is a "service provider", as those terms are defined in the CCPA. The terms "personal information", "consumer", "sell", "share", "business purpose", "commercial purpose", "process", "deidentified", and "contractor" have the meanings given to them in the CCPA. The Processor receives personal information from the Controller, or collects it on the Controller's behalf through the Apps, only for the limited and specified business purposes described in Section 1 of this DPA and in the privacy policy for the relevant App. The Processor does not receive that personal information as consideration for any service or other item of value.

16.2 Service Provider Restrictions

The Processor shall not:

(a) No sale or sharing. Sell or share the personal information, as "sell" and "share" are defined in the CCPA. The Processor does not use shopper personal information for cross-context behavioral advertising.

(b) Purpose limitation. Retain, use, or disclose the personal information for any purpose other than the business purposes specified in this DPA, including performing the services described in Section 1 and the internal uses permitted by Section 16.8, or as otherwise permitted by the CCPA. In particular, the Processor shall not retain, use, or disclose the personal information for any commercial purpose of its own.

(c) Outside the business relationship. Retain, use, or disclose the personal information outside the direct business relationship between the Processor and the Controller.

(d) No combining. Combine the personal information with personal information that the Processor receives from or on behalf of another person, or that it collects from its own interaction with the consumer, except to the extent the CCPA and its implementing regulations permit a service provider to do so (11 CCR section 7050), for example to perform a business purpose on behalf of another business where that business's contract permits it, or as necessary to detect data security incidents or protect against fraudulent or illegal activity.

16.3 Compliance and Level of Protection

The Processor shall comply with the obligations applicable to it as a service provider under the CCPA and shall provide the same level of privacy protection for the personal information as the CCPA requires of the Controller as a business.

16.4 Notification of Inability to Comply

The Processor shall notify the Controller in writing without undue delay, and in any case within 5 business days, if it determines that it can no longer meet its obligations under the CCPA or under this Section 16. This notification obligation is the same one stated in Section 6. Following such a notice, the Controller may exercise the rights in Section 16.5.

16.5 The Controller's Rights

(a) Ensuring consistent use. The Controller has the right to take reasonable and appropriate steps to ensure that the Processor uses the personal information in a manner consistent with the Controller's obligations under the CCPA. Those steps include the security questionnaires, documentation requests, and audits described in Section 11, and the TOMs summary described in Section 6.9(a).

(b) Stopping and remediating unauthorized use. Upon notice, including a notice given by the Processor under Section 16.4, the Controller has the right to take reasonable and appropriate steps to stop and remediate any unauthorized use of the personal information. Those steps include instructing the Processor to cease the processing at issue, to delete or return the affected personal information, or to provide a written remediation plan. The Processor shall cooperate with the Controller and shall confirm completion in writing.

16.6 Consumer Requests

The Processor shall assist the Controller in responding to verified consumer requests forwarded by the Controller, including requests to know, access, correct, delete, opt out of the sale or sharing of personal information, and limit the use of sensitive personal information, on the timelines set out in Section 6.9(c). Where the Controller instructs the Processor to give effect to an opt-out of sale or sharing, the Processor shall do so within its systems, noting that the Processor does not sell or share personal information as described in Section 16.2(a).

Opt-out preference signals, including Global Privacy Control, and consumer consent choices reach the Apps through the Controller's own Shopify privacy settings and Shopify's Customer Privacy API. Where the Controller enables consent enforcement, collection by Propel Replays is gated on the consent status Shopify reports for the visitor. The Controller selects the scope of that enforcement in the App's settings (off, EU/EEA/UK visitors only, or all visitors), and consent status gates collection only for visitors within the selected scope. The Controller remains responsible for surfacing the consent or preference interface on its storefront, whether through Shopify's cookie banner or a compatible privacy app, and for configuring its Shopify privacy settings so that those signals are passed to the Apps.

16.7 Sub-processors

Where the Processor engages another person to assist in processing the personal information for a business purpose, the Processor shall notify the Controller in accordance with Section 7.4 and shall enter into a written contract that binds that sub-processor to the same restrictions and obligations set out in this Section 16, as required by Cal. Civ. Code section 1798.140(ag)(2). Current sub-processors are listed in Annex III.

16.8 Permitted Internal Uses

Consistent with 11 CCR section 7050, the Processor may retain, use, and disclose the personal information only as follows:

— To perform the services specified in this DPA and the Principal Agreement
— To detect, investigate, and respond to data security incidents, and to protect against fraudulent or illegal activity
— To debug and repair errors that impair the intended functionality of the Apps
— To engage sub-processors in accordance with Sections 7 and 16.7, consistent with 11 CCR section 7050(a)(2)
— To comply with federal, state, or local law, or to respond to a lawful request from a governmental authority
— For internal use to build or improve the quality of the services the Processor provides, provided that the Processor does not use the personal information to perform services on behalf of another business, does not build or modify household or consumer profiles for use in providing services to another business, and does not correct or augment data acquired from another source

Any retention, use, or disclosure beyond the above, other than a disclosure to a sub-processor engaged under Section 16.7, requires the Controller's documented instruction or is prohibited.

16.9 Deidentified Data

Where the Processor uses deidentified data, it shall (i) take reasonable measures to ensure that the information cannot be associated with a consumer or household, (ii) publicly commit to maintain and use the information in deidentified form and not to attempt to reidentify it, except as reasonably necessary to test that the deidentification is effective, and (iii) contractually obligate any recipient of the information to comply with the same requirements. This commitment tracks the standard in Cal. Civ. Code section 1798.140(m).


Annex I — Technical & Organizational Security Measures

Encryption: data encrypted in transit (TLS 1.2+) and at rest
Authentication: Multi-Factor Authentication (MFA) required for all Processor administrative accounts
Access Control: least-privilege principle enforced; access reviewed regularly
Network Security: private network segmentation; web application firewall (WAF) and DDoS protection at the edge
Vulnerability Management: regular vulnerability scans; patches applied on a defined cadence
Masking & Redaction: automatic masking of password fields and payment fields in session recordings; PII redaction applied where the merchant configures it
Logging & Monitoring: security-relevant logs retained for not less than 90 days; alerting on anomalous access
Access Governance:

Engineering: read-only access to pseudonymized or deidentified data
Security: full access for incident response
Support: limited playback access with masked data

Annex II — Data Retention & Deletion

Propel Replays — session-replay and heatmap data: 30-day rolling window across every plan, free through Enterprise. Older sessions are automatically purged.
All other Apps, including Propel Appointments, Subscriptions, Upsells, Warranty, and Low Stock Alerts: retained for the duration of the Controller's active subscription, or as required to deliver the App's functionality (e.g., warranty registration records retained for the warranty period).
Logs: 90 days
Backups: retained on a rolling basis for the minimum period necessary for disaster recovery
Deletion Requests: the Controller may request deletion of specific records at any time by contacting support@propelcommerce.io; deletion is completed within 5 business days
Suspension: the Controller may suspend processing at any time by uninstalling or disabling the relevant App
Export: the Controller may export raw data (JSON or CSV) at any time on request

Annex III — Sub-processors

The Processor uses the following sub-processors:

Shopify Inc. — App platform, customer/order data, theme integration
Cloudflare, Inc. — CDN, WAF, DDoS protection, edge compute
Heroku (Salesforce) — Application hosting and runtime
Amazon Web Services (AWS) — Object storage (S3) and transactional email (SES)
Papertrail — Application log management
New Relic — Application performance monitoring
OpenAI, Inc. — AI-generated replay and heatmap summaries; data sent through the OpenAI API is not used to train OpenAI models
Rollbar, Inc. — Application error monitoring
Render Services, Inc. — Application hosting and database (Propel Low Stock Alerts)
Google LLC — Google Calendar integration (Propel Appointments, where the Controller connects it)
Zoom Communications, Inc. — Meeting creation for bookings (Propel Appointments, where the Controller connects it)

Where an App relies on an additional App-specific sub-processor, it is also identified in that App's privacy policy.


Questions about this DPA? Email us. For App-specific privacy practices, see the relevant privacy policy.