Data Processing Addendum

Last updated: 2 August 2026

This Data Processing Addendum (“DPA”) forms part of the Custodian AI Terms of Service. By installing or using Custodian, the merchant accepts this DPA.

1. Roles and instructions

The merchant is the controller of personal data processed through its Shopify store. Custodian AI, operated by Adrien Belhomme, acts as the processor and processes that data only on the merchant’s documented instructions, to provide the Service, and as required by applicable law.

2. Processing covered by this DPA

Custodian generates and maintains landing pages and provides their performance analysis. For the Daily Brief’s paid-order attribution, Custodian receives only the order identifier, currency and the line-item price, quantity, discount and properties required to verify its signed attribution marker. It stores a cryptographic order reference, attributed revenue, currency, timestamps and experiment integrity counters. It does not intentionally store customer names, emails, telephone numbers, addresses, payment-card details, or a raw Shopify order payload for this feature.

3. Purpose, duration and deletion

The purpose is to calculate attributed orders, revenue, conversion rate and revenue per session in the Daily Brief. Detailed storefront telemetry, anonymous assignments, experiment events and paid-order facts are retained for no more than 24 months, then automatically deleted. Shopify customer-data webhooks create an AES-GCM encrypted report that only the authenticated merchant can view or download and include in its response to the customer. The report is deleted immediately after confirmed delivery or automatically after 30 days; only a non-personal audit may remain for up to 24 months. The webhook response and logs do not contain the report. Shopify privacy webhooks are also used to locate or delete order-linked A/B records for a data-subject request. After uninstall, Shopify sends a shop-redact request and Custodian deletes data associated with the shop, subject only to any mandatory legal retention obligation.

4. Confidentiality and security

Custodian limits access to personnel and service providers who need it to operate the Service and who are bound by confidentiality obligations. It uses appropriate technical and organisational measures, including TLS encryption in transit, provider-managed database encryption at rest, application-level AES-GCM encryption for privacy exports and shop-level access controls, and will notify the merchant without undue delay after becoming aware of a personal-data breach that affects the merchant’s data.

5. Subprocessors and assistance

Custodian uses Shopify to receive authorised Shopify data, Vercel to operate the application, and its database hosting provider to store Service data. Custodian remains responsible for its subprocessors’ processing and will provide reasonable information and assistance for data-subject requests, security enquiries and compliance obligations.

6. Contact

Questions or requests concerning this DPA can be sent to adrien@custodiancommerce.com.