CtrlOne · Shopify application
Data Processing Agreement
This DPA forms part of the Ctrl COD Terms of Service when CtrlOne processes personal data for a merchant.
Last updated: August 25, 2026
Roles and instructions
The merchant is the controller and CtrlOne is the processor for buyer personal data processed through Ctrl COD. CtrlOne will process that data only to provide the configured service, follow documented merchant instructions, comply with law and protect the service.
Processing details
- Subject: Shopify COD controls, OTP, order automation, confirmations and reporting.
- Duration: while the app is installed plus the limited retention and Shopify redaction periods described in the Privacy Policy.
- Data subjects: buyers, merchant staff and store contacts.
- Data: store identity/configuration, limited order/payment details, phone data for configured messaging, and operational/security logs.
Confidentiality and security
CtrlOne will limit access to personnel and providers who need it to operate the service and are subject to confidentiality obligations. Technical controls include authenticated Shopify sessions, signed webhook verification, data minimization, OTP hashing/fingerprinting, expiry and attempt limits, and authenticated retention/deletion workflows.
Subprocessors
The merchant authorizes subprocessors needed for hosting, databases, Shopify platform services, and messaging delivery selected by the merchant. CtrlOne remains responsible for imposing appropriate data-protection obligations on subprocessors and will provide notice of material changes where required.
Assistance and incidents
Taking into account the nature of processing, CtrlOne will reasonably assist with data-subject requests, security obligations and regulator inquiries. CtrlOne will notify affected merchants without undue delay after confirming a personal-data breach and will provide available information needed for the merchant’s response.
Deletion, return and audits
CtrlOne will delete personal data when required by Shopify’s mandatory redaction webhooks and its documented retention schedule, unless law requires continued storage. On reasonable written request, CtrlOne will provide information needed to demonstrate compliance; audits must protect other customers, security and confidential information.
International transfers
Where processing involves a restricted international transfer, the parties will use the legally required transfer mechanism and supplementary safeguards appropriate to the processing.
Contact
DPA and privacy requests may be sent to support@byctrlone.com.