Controller, processor, and project duties
The Shopify merchant usually acts as controller for customer data. Hafsa Software may act as technical service provider or processor depending on the project scope.
Roles should be defined by clarifying data categories, purposes, access rights, and involved parties.
Data processing agreement, access closure, and deletion flow
If the project scope requires personal data processing, the parties should define data roles, subprocessors, security measures, retention periods, and deletion or return processes in writing.
After project completion, unnecessary store access is removed, API keys are rotated or transferred, test data is cleaned up, and support records are kept only for the period required.
- DPA need review
- Subprocessor and provider list
- Access closure plan
- Deletion or return record
How GDPR principles are applied
Data minimization, purpose limitation, storage limitation, security, transparency, and accountability are included in the development process.
The app should request only necessary Shopify permissions, avoid unnecessary personal data storage, and document data flows.
- Minimum required API permissions
- Clear data flow diagram
- Readiness for deletion and access requests
- Reduced personal data in logs and issue reports
Technical and organizational measures
Tokens, API keys, and secrets are not exposed in the frontend; secure environment variables and access separation are used.
Access is limited to project needs. Logs and monitoring for live systems are planned to avoid unnecessary exposure of personal data.
- Secret management
- Access limitation
- HTTPS and secure hosting
- Log minimization
- Access review after project completion
Access, deletion, and objection requests
Apps and integrations should be designed so data subject requests can be answered. Access, deletion, correction, and objection requests should be considered technically.
The merchant’s own privacy notice and customer support processes may be decisive for applying these rights.
Third-country transfers and providers
Where third-party APIs or cloud services are used, data transfer, storage location, contractual safeguards, and subprocessors should be reviewed in the project.
Where required, standard contractual clauses, data processing agreements, or provider privacy documents are considered.