Data Processing Agreement (DPA)
Last updated: 21 September 2026
1. Subject matter and duration
LeadArcade processes data on the merchant's behalf for one purpose only: providing the gamified popup service. Processing lasts as long as the app is installed and ends 48 hours after it is removed.
2. Categories of data processed
- Random visitor identifier generated in the browser
- Salted one-way hash of the IP address (the raw IP is never stored)
- Game outcome and the discount code issued
- Consent timestamp and the consent text shown
- Shop domain, Shopify access token, and the admin user's name and email
Visitor contact details are not stored by LeadArcade. The first name, last name, email and phone the merchant chooses to collect are processed for transfer only: within the request they arrive in, they are written to the merchant's own Shopify customer list through the Admin API and dropped from memory. They are never written to a table, a backup or a log.
3. Processing on instructions
LeadArcade processes personal data only on the merchant's instructions and for the purpose set out here. It does not use the data for its own commercial purposes, does not sell it, does not share it for advertising, and never blends data across merchants.
4. Security measures
- TLS 1.2+ required in transit
- Production database on a LUKS2-encrypted volume (AES-XTS, 512-bit)
- Daily backups encrypted with AES-256; keys readable only by the system owner; 30-day retention
- The Shopify access token lives only in the Shopify session store; the app keeps no second copy
- Data minimisation: neither raw IPs nor visitor contact details are ever written
- No personal data in application logs
- Server access restricted to SSH keys; password login disabled
- Database connections logged; test and production data kept in separate databases
- App Proxy requests verified by HMAC signature
5. Sub-processors
- Shopify Inc. — app platform and authentication
- Hetzner Online GmbH (Germany) — server and database hosting
This page is updated before any new sub-processor is added.
6. Data subject requests
Shopify's customers/data_request, customers/redact and shop/redact webhooks are answered within 30 days. Because LeadArcade stores no customer personal data, data requests are answered with "no records held" and an audit trail is kept.
7. Breach notification
If a personal data breach is detected, the merchant is notified without undue delay and within 72 hours at the latest, together with the scope of the breach and the measures taken.
8. Deletion and return
On uninstall the access token is deleted immediately and all shop records are deleted within 48 hours. Subscribers in the Shopify "Customers" list are the merchant's own data and stay with the merchant.
9. International transfers
Data is processed inside the European Union (Germany). No transfers outside the EU take place.