GrowMoe
How it worksPricing
Log inRequest early access

Data Processing Addendum

Last updated: 24 July 2026

This addendum sets out how GrowMoe, LLC processes your customers’ personal data on your instructions, and what we commit to when we do.

1. Scope and roles

This Data Processing Addendum (“DPA”) forms part of theTerms of Service between GrowMoe, LLC, a Delaware limited liability company (“GrowMoe”, “we”, “Processor”) and the merchant using GrowMoe (“Merchant”, “you”, “Controller”). It applies whenever we process personal data on your behalf.

  • You are the controller of the personal data in your Shopify store and in your GrowMoe account — your customers, their orders and carts, your company contacts, your support conversations. You decide why and how it is processed.
  • We are the processor of that data. We process it only to run the Service for you.
  • We are a controller for a narrow set of data we need to run our own business: your staff’s account records, billing and usage records, support correspondence with us, and security logs. Our Privacy Policy covers that, not this DPA.

Shopify is a separate controller and processor in its own right, under its own agreement with you. This DPA does not cover Shopify’s processing.

2. Definitions

“Personal data”, “processing”, “controller”, “processor”, “sub-processor”, “data subject” and “supervisory authority” have the meanings given in the GDPR. “Data Protection Laws” means the laws that apply to the processing under this DPA, including the EU GDPR, the UK GDPR and the UK Data Protection Act, the Swiss FADP, and US state privacy laws where they apply. “Merchant Personal Data” means personal data we process on your behalf under this DPA. “SCCs” means the Standard Contractual Clauses approved by the European Commission.

3. Details of processing

The subject matter, duration, nature, purpose, categories of data subjects and categories of personal data are set out in Annex 1.

4. Your instructions and your obligations

Your documented instructions to us are: this DPA, the Terms of Service, the Service documentation, and the configuration and actions you take in the app and API. We process Merchant Personal Data only on those instructions.

You confirm that:

  • you have a lawful basis for the processing you ask us to perform, and have given your data subjects the notices Data Protection Laws require;
  • you have collected and will honour the consents and preferences you rely on — including marketing consent, which the Service enforces at send time but cannot obtain for you;
  • your instructions will not put us in breach of Data Protection Laws;
  • you will not send us special-category data, payment card numbers, or government identifiers.

If we believe an instruction breaches Data Protection Laws, we will tell you and may pause that processing until it is resolved.

5. Our obligations as processor

We will:

  • process Merchant Personal Data only on your documented instructions (section 4);
  • not sell Merchant Personal Data, not share it for cross-context behavioural advertising, and not use it for our own purposes — including not using it to train models;
  • keep it confidential, and make sure the people who access it are bound by confidentiality obligations and access it only as needed to do their job (section 6);
  • apply the security measures in section 7 and Annex 2;
  • only use sub-processors on the terms in section 8, and stay responsible for what they do;
  • assist you with data subject requests as described in section 10;
  • notify you of a personal data breach affecting Merchant Personal Data as described in section 11;
  • assist you with data protection impact assessments and prior consultations as described in section 12;
  • make available the information you reasonably need to show compliance, as described in section 13;
  • delete or return Merchant Personal Data on termination, as described in section 14.

6. Confidentiality and personnel

Access to Merchant Personal Data is limited to personnel who need it to operate or support the Service. Those people are bound by written confidentiality obligations that survive the end of their engagement, and their access is logged (Annex 2). We remove access when it is no longer needed.

7. Security measures

We apply the technical and organisational measures described in Annex 2, taking into account the risk of the processing. The measures that matter most for this Service are: personal data encrypted at rest, access to customer personal data logged, strict tenant isolation (every record scoped by org_id, reachable only through a tenant-scoped database port), least-privilege Shopify access scopes, and personal-data minimisation before anything is sent to a telemetry sub-processor.

What we do not claim. GrowMoe is a small vendor. We hold no SOC 2 report, no ISO 27001 certificate, and we do not currently commission third-party penetration testing. We have not appointed a data protection officer, and we have not appointed an EU or UK representative. If your procurement process requires any of these, tell us before you rely on the Service — we would rather say so now than imply otherwise.

We may change the measures in Annex 2 as the Service evolves, but will not reduce their overall level of protection.

8. Sub-processors

You give us general authorisation to use sub-processors to provide the Service. Our current authorised sub-processors, what each one does, and where each is located, are listed at/legal/subprocessors. That list is part of this DPA.

For every sub-processor we use, we will:

  • carry out reasonable diligence on its security and privacy practices before engaging it;
  • put a written contract in place imposing data protection obligations no less protective than this DPA;
  • remain responsible to you for its performance, as if we had done the processing ourselves.

Notice of changes. Before we add or replace a sub-processor, we will update the list at /legal/subprocessors and give notice. You may object on reasonable data protection grounds within the notice period; we will work with you to find a solution, and if we cannot, you may stop using the affected capability or terminate by uninstalling the app under the Terms, with no further payment obligation for the unused period.

9. International transfers

GrowMoe is established in the United States and processes Merchant Personal Data in the United States and in the locations its sub-processors operate from. If you are in the EEA, the UK or Switzerland, that means personal data is transferred outside your jurisdiction.

Where such a transfer takes place and no adequacy decision covers it, the transfer is made under the Standard Contractual Clauses, which are incorporated into this DPA by reference. For UK transfers, the SCCs apply as amended by the UK International Data Transfer Addendum. For Swiss transfers, the SCCs apply with references read as referring to the Swiss FADP and the Federal Data Protection and Information Commissioner.

For the purposes of the SCCs: Annex 1 of this DPA supplies the description of the transfer and the parties; Annex 2 supplies the technical and organisational measures; the sub-processor list supplies the authorised sub-processors; the governing law and forum are as stated in the SCCs themselves rather than the Terms of Service.

10. Assisting with data subject rights

You are responsible for responding to your data subjects. We will help, and the Service implements the Shopify data-subject webhooks so that most requests are handled automatically:

RequestMechanismWhat happens
Access / portabilitycustomers/data_requestWe assemble the personal data we hold for that customer and make it available for you to give to the data subject.
Erasurecustomers/redactWe scrub that customer’s personal data across the records we own and the records we mirror from Shopify, and propagate the erasure to the sub-processors that hold data for that person. Non-personal aggregates may be retained.
Store-wide purgeshop/redactOn uninstall, we purge the store’s data within 48 hours. See section 14.

For rectification, restriction, objection and portability requests that the webhooks do not cover, you can act directly in the app, or email[email protected] and we will assist within a reasonable time. If a data subject contacts us directly, we will not respond on your behalf — we will refer them to you and tell you about it.

11. Personal data breach

If we become aware of a personal data breach affecting Merchant Personal Data, we will notify you without undue delay and give you the information you reasonably need to meet your own notification obligations — what we know about the nature of the breach, the categories and approximate volume of data and data subjects affected, the likely consequences, and the steps we are taking to address it and limit the damage. We will send follow-up information as the investigation progresses.

We will not notify a supervisory authority or a data subject about a breach of Merchant Personal Data on your behalf unless the law requires us to, or you ask us to in writing.

Our notification is not an admission of fault.

12. Data protection impact assessments

If you need to carry out a data protection impact assessment or a prior consultation with a supervisory authority about processing performed by the Service, we will give you the information we reasonably hold about how the Service processes personal data — the details in Annex 1, the measures in Annex 2, the sub-processor list, and answers to written questions about data flows. We may charge for assistance that goes materially beyond responding to reasonable written questions, and we will tell you before we do.

13. Audit and information rights

On written request, and no more than once a year unless a supervisory authority or a breach requires otherwise, we will:

  • provide the documentation we hold about our security and privacy practices, including Annex 2 and the sub-processor list;
  • answer a reasonable written security questionnaire about the processing under this DPA;
  • confirm in writing the measures we have in place and any material change to them.

We do not offer on-site audits or direct access to our systems or production data. Granting third-party auditors access to a multi-tenant system would put other merchants’ data at risk, and we are a small team. Written responses and documentation are the audit mechanism we can genuinely support. If your obligations require more than this, raise it before you rely on the Service.

14. Retention, deletion and return

  • While you are a customer, we keep Merchant Personal Data for as long as the Service needs it to work for you.
  • Raw high-volume events — storefront and cart events, custom events, usage events and automation run records — are retained for a bounded window, currently a default of400 days, after which they are rolled up into non-personal aggregates or deleted. The window is configurable per organisation, subject to a floor enforced by your plan.
  • On a customer erasure request, that person’s personal data is scrubbed as described in section 10.
  • On uninstall or account closure, we purge the store’s datawithin 48 hours, triggered by Shopify’s shop/redactwebhook, and propagate the deletion to sub-processors holding that data. Export anything you want to keep before you uninstall.
  • Return instead of deletion. If you ask before you uninstall, we will provide a machine-readable export of Merchant Personal Data rather than only deleting it.
  • Exceptions. We may keep data we are required by law to keep, and de-identified aggregates that cannot be linked back to a data subject. Anything retained stays protected by this DPA. Backups age out on their own cycle and are not selectively edited.

15. Liability

Each party’s liability under this DPA is subject to the limitation of liability in theTerms of Service, except where Data Protection Laws or the SCCs do not permit that limit.

16. Term, precedence and changes

This DPA takes effect when you accept the Terms of Service and continues while we process Merchant Personal Data. If this DPA conflicts with the Terms of Service or the Privacy Policy on the processing of Merchant Personal Data, this DPA wins. If this DPA conflicts with the SCCs, the SCCs win.

We may update this DPA where a change in the Service or in Data Protection Laws requires it, so long as the change does not reduce the protection it gives you. Material changes are notified as described in the Terms of Service, and the “Last updated” date above is changed.

Annex 1 — Details of processing

Subject matterProvision of the GrowMoe Service to the Merchant: a B2B sales and customer platform that syncs data from the Merchant’s Shopify store and adds CRM, quoting, deals, support, marketing, subscriptions and analytics capabilities.
DurationFrom installation until the app is uninstalled or the account is closed, plus the deletion window in section 14 (purge within 48 hours of uninstall).
Nature of processingReceiving data from Shopify webhooks and the Shopify Admin API; storing it; indexing and linking records into customer and company profiles; generating derived records (segments, scores, timelines, rollups); presenting it in the app and API; sending messages the Merchant instructs; deleting and exporting on request.
Purpose of processingSolely to provide, secure and support the Service for the Merchant, and to follow the Merchant’s instructions. No independent use, no sale, no advertising, no profiling for our own purposes.
Categories of data subjectsThe Merchant’s customers and prospective customers; contacts at the Merchant’s business customers (B2B company contacts); visitors to the Merchant’s storefront who are tracked with consent; the Merchant’s own staff who use the Service.
Categories of personal dataIdentity and contact data (name, email, phone, addresses); company and role data; commerce data (orders, line items, carts, quotes, payment and fulfilment status — no card numbers); interaction data (support messages, notes, activity timeline, email engagement); consent and marketing-preference records; storefront behavioural events tied to a pseudonymous identifier; account data for the Merchant’s staff (name, email, role, audit trail).
Special categories of dataNone. The Service is not built for special-category data, and the Merchant must not upload it (see the acceptable-use and customer-data sections of theTerms of Service).
Frequency of processingContinuous, for as long as the app is installed: webhook-driven and near real-time, plus scheduled syncs and backfills.
RecipientsGrowMoe personnel on a need-to-know basis, and the sub-processors listed at/legal/subprocessors.

Roles: the Merchant is the controller (or, where the Merchant processes on behalf of another party, the processor) and GrowMoe, LLC is the processor. Contact for both parties on data protection matters: [email protected] for GrowMoe; the Merchant’s account contact for the Merchant.

Annex 2 — Technical and organisational measures

These are the measures actually in place. Nothing is listed here aspirationally.

EncryptionPersonal data is encrypted at rest. Data in transit between the Merchant, Shopify and the Service is encrypted with TLS.
Tenant isolationEvery record belonging to a Merchant carries an org_id, and application code can only reach data through a tenant-scoped database port that applies that scope. There is no code path that reads across organisations.
Access loggingAccess to customer personal data is logged. Writes are captured as field-level change records and entity snapshots, attributed to the acting user or system principal.
Access controlAccess inside the Service is role-based: each operation declares the roles that may run it, and the check runs centrally on every write. Internal administrative access is limited to the personnel who need it and is attributed to a named principal.
Data minimisation at the integration boundaryWe request the narrowest set of Shopify access scopes the enabled capabilities require, including for Protected Customer Data, and we do not request scopes for capabilities the Merchant has not switched on.
Minimisation in telemetryProduct-analytics and error-tracking sub-processors receive personal-data-minimised payloads only: pseudonymous identifiers, event names, non-personal properties, tags and opaque ids. Personal data is stripped before send, driven by the personal-data classification on each field rather than a hand-maintained list. Session replay is off by default and masks all text and inputs when enabled.
No card dataWe never receive or store payment card numbers or security codes. Billing runs through Shopify’s Billing API; card data is handled and tokenised by the billing rail, and we hold only references.
Erasure and retention controlsAutomated handling of Shopify’s data-subject webhooks (see section 10), a bounded retention window for raw high-volume events (see section 14), and propagation of erasure to sub-processors that hold the affected data.
Change controlAll changes to the Service are version-controlled and reviewed before release, with automated checks in continuous integration.

17. Contact

Data protection questions, data subject request assistance, sub-processor objections and DPA requests: [email protected].

GrowMoe, LLC — a Delaware limited liability company.

GrowMoeThe B2B sales & customer platform built on Shopify.
ProductHow it worksPricingRequest early access
LegalPrivacy PolicyTerms of ServiceCookie PolicyData Processing AddendumSub-processors
AccountLog inRequest early access
© 2026 GrowMoe. All rights reserved.

We use a privacy-friendly analytics cookie to understand what’s useful on this site. No ads, no selling data. See our Cookie Policy.