Sushinet — Data Processing Agreement
Last updated: 2026-07-30 · Effective: 2026-07-30 · Version: 1.0
This Data Processing Agreement ("DPA") is entered into between:
- You, the merchant who has installed one of the Apps on your Shopify store (the "Merchant", "you"); and
- Edwin Guo (ABN 20 938 499 163), a sole trader in New South Wales, Australia, trading as Sushinet ("Sushinet", "we", "us").
It covers the Shopify apps we build and operate — currently Ruleproof, and any future app we publish that this DPA is offered with (together, the "Apps").
In short: where one of our Apps touches personal data belonging to your customers, you decide what happens to it and we act only on your instructions. This document is the contract that says so, in the form European law requires.
How this becomes binding
You do not need to sign anything. This DPA is incorporated by reference into the terms you accept when you install an App, and takes effect automatically at installation. Every merchant with an App installed has this agreement in force.
If your compliance process requires a countersigned copy, or your own DPA template, email support@sushinet.fyi and we will sign and return one. If you require the European Commission's Standard Contractual Clauses as a separate executed instrument, we will enter into them (see §11).
We publish the current version at https://sushinet.fyi/ruleproof/dpa, hosted separately from the Apps themselves — you should be able to read the terms governing your data even at a moment when an app is down.
1. Definitions
"Controller", "Processor", "Data Subject", "Personal Data", "Processing" and "Supervisory Authority" have the meanings given in the GDPR.
- "GDPR" means Regulation (EU) 2016/679, and where relevant the UK GDPR as incorporated by the Data Protection Act 2018.
- "Privacy Act" means the Australian Privacy Act 1988 (Cth), including the Australian Privacy Principles ("APPs") and the Notifiable Data Breaches scheme.
- "Data Protection Law" means the GDPR, the Privacy Act, and any other data protection or privacy law applicable to a party's processing under this DPA.
- "Merchant Personal Data" means Personal Data relating to your customers that an App Processes on your behalf, as described in Annex I.
- "Privacy Policy" means our privacy policy at https://sushinet.fyi/ruleproof/privacy, which describes in ordinary language what the Apps collect and why.
- "Sub-processor" means a third party engaged by us to Process Merchant Personal Data.
2. Roles of the parties
This is the split, and it is the same split set out in §2 of the Privacy Policy:
| Data | Controller | Processor |
|---|---|---|
| Your customers' data that an App touches — order and customer references in the monitor log, customer tags copied into an app-owned metafield | You | Us |
| Your own shop's data — OAuth session, shop settings, rule definitions, order-volume counters, support correspondence | Us | — |
This DPA governs only the first row. Where we act as Controller of your shop's own data, the Privacy Policy governs, not this DPA — we are not your Processor for that data and it would be misleading to write a Processor agreement covering it.
You confirm that, as Controller, you have a lawful basis for the Processing you instruct us to carry out, and that you have given your customers whatever notice Data Protection Law requires. We cannot establish a lawful basis on your behalf and do not purport to.
3. Processing only on your instructions
We Process Merchant Personal Data only:
- on your documented instructions, which comprise this DPA, the Privacy Policy, the settings and rules you configure in the App, and any further written instruction you give us; and
- where we are required to Process it by a law we are subject to — in which case we will tell you about that requirement before Processing, unless that law prohibits us from telling you.
We do not Process Merchant Personal Data for any purpose of our own. We do not sell it, share it for anyone else's purposes, use it to train models, or use it to build any product. There is no advertising network, data broker, marketing tool, ad pixel or third-party analytics SDK anywhere in the Apps.
We will tell you if, in our opinion, an instruction you give us infringes Data Protection Law. We may suspend Processing of the affected instruction until it is resolved.
4. Confidentiality
Access to Merchant Personal Data is limited to the operator of Sushinet, who is bound by an ongoing duty of confidentiality. We do not currently employ staff or engage contractors with access to Merchant Personal Data. If that changes, anyone granted access will be under a written confidentiality obligation before access is given, and we will update Annex II accordingly.
5. Security
We implement the technical and organisational measures set out in Annex II, which are designed to meet Article 32 of the GDPR and APP 11.
Annex II describes the measures actually in place, not an aspirational list. Where a control is partial, or provided by a platform rather than by us, it says so. A security annex that overstates what exists is worse than a short one, because it is the document a regulator reads after an incident.
6. Sub-processors
You give general authorisation for us to engage Sub-processors, subject to this section.
Our current Sub-processors are listed in Annex III and in §5 of the Privacy Policy. Each is bound by terms imposing data protection obligations no less protective than those in this DPA, and each Processes Merchant Personal Data only on our instructions.
Before adding or replacing a Sub-processor that would hold Merchant Personal Data, we will update Annex III and notify you by email at least 30 days in advance. If you reasonably object on data protection grounds within that period, we will work with you in good faith to find an alternative. If we cannot, you may terminate by uninstalling the App, and we will delete your data under §9. That is your remedy — we will not proceed with a Sub-processor you have reasonably objected to while continuing to Process your data through it.
We remain fully liable to you for a Sub-processor's performance of its data protection obligations.
7. Assisting you with data subject requests
The Apps implement Shopify's three mandatory compliance webhooks, and these are the primary mechanism by which we assist you:
customers/data_request— we identify what the App holds relating to that person, including entries linked by customer id and entries linked to the orders named in the request, and report the result so you can answer within the 30 days Shopify requires.customers/redact— we delete every monitor-log entry relating to that person for your shop, matched both by customer id and by the orders listed inorders_to_redact. Both are necessary: a guest order carries no customer id, so matching on the customer alone would silently leave those entries in place.shop/redact— we delete the shop's data as described in §9.
All three verify the webhook's HMAC signature before acting; an invalid signature is rejected and no data is touched.
Where a Data Subject contacts us directly about data we hold as your Processor, we will not respond substantively — we will refer them to you and tell you promptly, because the request is yours to answer as Controller.
Taking into account the nature of the Processing and the limited information available to us, we will also assist you with obligations under GDPR Articles 32–36 (security, breach notification, data protection impact assessments, prior consultation), by providing the information we hold.
8. Personal data breaches
If a breach affects Merchant Personal Data, we will notify you without undue delay, and in any event within 72 hours of becoming aware of it.
That notification will describe, to the extent known: the nature of the breach, the categories and approximate volume of data and Data Subjects affected, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the full picture is not available within 72 hours, we will tell you what we know and follow up as it develops rather than delaying the initial notice.
Where the Notifiable Data Breaches scheme or GDPR Article 33 requires it, we will also notify the relevant Supervisory Authority within the time that law allows.
We will not notify your customers directly unless you instruct us to or the law requires it — communicating with your customers is yours to control.
Note on the clock: 72 hours matches GDPR Article 33 and §9 of our Privacy Policy. Some competitors promise 48. We have deliberately stated the same number in both of our documents rather than advertising a shorter one in one place and a longer one in the other, because a breach is precisely the moment an inconsistency between two published commitments becomes a problem.
9. Deletion and return
On uninstall, Shopify sends shop/redact approximately 48 hours later. On receiving it we delete
the shop's rules, its monitor log in full, its settings, and its order-volume and auto-pause records.
The OAuth session is cleared immediately and separately by the app/uninstalled webhook, which
fires the moment the App is removed, rather than waiting for that delay.
Before uninstall, Merchant Personal Data is subject to the retention limits in §7 of the Privacy Policy — notably, monitor-log entries are pruned after 60 days and capped at 5,000 entries per shop, so an order or customer reference is not retained indefinitely even while the App remains installed.
You may request earlier deletion, or a copy of Merchant Personal Data in a commonly used format, by emailing support@sushinet.fyi at any time.
Backups. Deletion from the live database is immediate. Encrypted backups are retained on a rolling 30-day cycle and expire automatically; we do not restore a backup in order to resurrect deleted data. If a backup were ever restored for disaster recovery, we would re-apply any outstanding deletion requests to the restored data. We state this rather than claiming instant erasure everywhere, because a backup regime and an instant-erasure claim cannot both be true.
We retain no copy after deletion except where a law we are subject to requires it, in which case we will tell you what and why.
10. Audits and information
On written request, and no more than once in any 12-month period (unless a Supervisory Authority requires otherwise or there has been a breach affecting your data), we will:
- make available the information reasonably necessary to demonstrate compliance with this DPA — in the first instance by answering a written security questionnaire; and
- permit and contribute to an audit conducted by you or an independent auditor you appoint, on at least 30 days' notice, during business hours, subject to confidentiality, and in a manner that does not compromise the security or privacy of other merchants.
You bear the cost of an audit you initiate, unless it reveals material non-compliance.
We would rather set a proportionate audit right we can actually honour than promise unlimited on-site access we could not deliver at our size.
11. International transfers
Merchant Personal Data is stored on a dedicated server in Sydney, Australia. The Sub-processors in Annex III mean it may also be disclosed to recipients in the United States and Canada.
Australia is not the subject of a European Commission adequacy decision. Where the GDPR or UK GDPR applies to a transfer to us, that transfer relies on the appropriate safeguards in Article 46 — in practice the European Commission's Standard Contractual Clauses (Module Two, Controller to Processor), which we will enter into with any merchant who asks — or, where genuinely applicable, the derogations in Article 49.
Where the SCCs are executed between us, they apply in addition to this DPA, and the SCCs prevail in the event of any conflict. For the purposes of Clause 17, the SCCs are governed by the law of Ireland unless the parties agree otherwise; for Clause 18, disputes are resolved before the courts of Ireland. The docking clause applies. Annex I and Annex II of this DPA serve as the corresponding annexes to the SCCs, and Annex III serves as the list of authorised Sub-processors under Clause 9(a) Option 2.
Under APP 8 we remain accountable for what an overseas recipient does with personal information we disclose to it.
12. Liability, term, and general
Term. This DPA takes effect when you install an App and continues for as long as we Process Merchant Personal Data on your behalf. §§4, 8, 9, 10 and 11 survive termination to the extent required.
Liability. Each party's liability under this DPA is subject to the limitations and exclusions in the terms governing your use of the Apps. Nothing in this DPA limits liability that cannot lawfully be limited, including a Data Subject's rights under Article 82 of the GDPR.
Order of precedence. If this DPA conflicts with the App terms, this DPA prevails on data protection matters. If executed SCCs conflict with this DPA, the SCCs prevail.
Governing law. This DPA is governed by the laws of New South Wales, Australia, and the parties submit to the non-exclusive jurisdiction of its courts — except where §11 provides otherwise for executed SCCs.
Changes. We may update this DPA to reflect a change in the Apps, our Sub-processors, or the law. Material changes are notified by email at least 30 days in advance, and the version number and date at the top of this document change with every revision. Continuing to use an App after a change takes effect constitutes acceptance; if you do not accept, you may uninstall and your data is deleted under §9.
Contact. support@sushinet.fyi
Annex I — Description of the Processing
This Annex also serves as Annex I to the Standard Contractual Clauses where those are executed.
Data exporter: the Merchant, acting as Controller. Data importer: Edwin Guo trading as Sushinet, acting as Processor. Contact: support@sushinet.fyi.
Subject matter. Provision of the Apps — checkout rules that a merchant configures, which Shopify's own checkout Functions then enforce, together with the monitor mode that records what a rule would have done.
Duration. For as long as the App is installed, subject to the retention limits in §9. On uninstall,
deletion follows Shopify's shop/redact (~48 hours) and, for the OAuth session, app/uninstalled
(immediate).
Nature and purpose. Storing rule configurations; evaluating rules against checkout and order data; recording what a rule did or would have done, so a merchant can verify a rule before it takes effect; copying customer tags into an app-owned metafield so a rule can act on them; detecting anomalous rule behaviour and automatically pausing a rule that misfires.
Categories of Data Subjects. The Merchant's customers who reach checkout or place an order on the Merchant's Shopify store.
Categories of Personal Data.
| Category | Detail |
|---|---|
| Order and customer references | Shopify order id and, where the order was not placed as a guest, customer id, recorded in the monitor log against the rule that matched |
| Customer tags | Shopify customer tags copied into an app-owned metafield, so that "block checkout unless tagged X" rules can be enforced |
| Checkout attributes evaluated by a rule | Postcode, province, country, whether an address appears to be a PO Box, whether billing and shipping countries differ, cart contents and totals, and — where a merchant configures such a rule — customer email address or phone number |
Special categories. None. The Apps do not collect or Process special-category data under Article 9, and no rule condition is designed to act on one.
Frequency. Continuous, at checkout and on order creation, for as long as the App is installed.
What is NOT Processed. No payment card or bank details (these never reach us — Shopify handles payment), no passwords or credentials belonging to a customer, no browsing or behavioural tracking, no IP addresses, no device or session identifiers. Shopify Functions do not receive IP or device data at all, so this is a property of the platform, not only of our policy.
Annex II — Technical and organisational measures
This Annex also serves as Annex II to the Standard Contractual Clauses where those are executed.
These are the measures in place as at the "Last updated" date. Where a measure is partial or is provided by a platform rather than by us, it says so.
| Area | Measure |
|---|---|
| Encryption in transit | HTTPS between Shopify, the App and a merchant's browser. |
| Encryption at rest | The server's storage volume is encrypted at rest with a provider-managed key (verified 2026-07-30). Backups are stored in object storage that applies AES-256 encryption at rest by default, which cannot be disabled. |
| Access control | Administrative access is key-based only; password authentication is disabled. Access is limited to the operator. The database file is readable only by the account the App runs as. |
| Isolation | The App runs on a server dedicated to the Apps, in a separate cloud compartment and network from any other system we operate. No other workload shares it. |
| Process confinement | The App runs as an unprivileged, dedicated system account under systemd confinement — no privilege escalation, read-only system paths, and write access restricted to its own data directory. |
| Minimisation | We request the minimum Shopify access scopes each feature needs. Merchant access tokens are kept out of logs. The monitor log stores order and customer references, not copies of customer records. |
| Retention limits | Monitor-log entries are pruned after 60 days and capped at 5,000 per shop, so retention is bounded even while the App is installed. |
| Integrity of backups | Backups are taken as consistent database snapshots (VACUUM INTO, not file copies), and every snapshot is verified before it is stored — structural integrity check plus a row-count reconciliation against the source. A snapshot that does not match is treated as a failure, not a warning. |
| Availability | Daily off-server backups to encrypted object storage, retained 30 days. Restores are tested. |
| Monitoring | Scheduled health checks covering process liveness, memory, error rates and database health. Anomaly detection automatically pauses a rule behaving abnormally, limiting the blast radius of a misconfiguration. |
| Patching | The server is kept patched on a routine basis. |
| Deletion | Automated deletion via Shopify's compliance webhooks, HMAC-verified before acting. |
| Secure development | Changes go through automated type checking and an automated test suite before deployment. Rule evaluation logic is covered by an exhaustive unit test suite so that a rule behaves identically in preview, in monitor mode, and at checkout. |
Known limitations, stated deliberately. We are a single-operator studio. There is no 24/7 staffed security operations centre, no formal ISO 27001 or SOC 2 certification, and no dedicated security team. Access control is therefore simple by design — one operator, key-based access, minimal scopes — rather than layered. We would rather a merchant's compliance team read an accurate description and decide, than discover the gap after signing.
Annex III — Authorised Sub-processors
This Annex also serves as the list of authorised Sub-processors under Clause 9(a) of the Standard Contractual Clauses where those are executed.
| Sub-processor | Role | Location | Merchant Personal Data it may hold |
|---|---|---|---|
| Shopify Inc. | The platform the Apps run on. Rules are stored in Shopify metafields and enforced by Shopify's own checkout Functions. | Canada, United States | All categories in Annex I — Shopify is the source of the data and where rules actually execute. |
| Oracle Cloud Infrastructure | The virtual server running the App's admin interface and database, and the object storage holding backups. | Sydney, Australia | The monitor log, customer tags in the app-owned metafield, rules, shop settings and the OAuth session. |
| Vercel Inc. | Hosts our public website sushinet.fyi only. |
United States | None. The Apps do not run on Vercel and no store, merchant or customer data reaches it. Listed for completeness because our privacy policy is served from there. |
We will update this Annex and give 30 days' notice before adding a Sub-processor that would hold Merchant Personal Data, per §6.