Data Processing Agreement (DPA) — RestockIQ

Effective date: 2026-07-23 Last updated: 2026-07-23

This Data Processing Agreement ("DPA") forms part of the agreement between Aerel Systems ("RestockIQ", "Processor") and the Shopify merchant that installs and uses the RestockIQ app ("Merchant", "Controller"), governing the processing of Personal Data on the Merchant's behalf. Where terms are not defined here, they have the meaning given in applicable data protection law (GDPR, UK GDPR, CCPA/CPRA, and similar).

By installing or using RestockIQ, the Merchant accepts this DPA.


1. Roles

The Merchant is the Controller of its customers' Personal Data. RestockIQ is a Processor acting on the Merchant's documented instructions. For RestockIQ's own account/authentication and diagnostic data, RestockIQ acts as an independent controller as described in the Privacy Policy.

2. Subject matter and scope of processing

Item Detail
Subject matter Providing inventory forecasting and reorder planning to the Merchant
Duration For the term the app is installed, plus the retention period in §7
Nature & purpose Reading and aggregating Shopify order line items to compute per-SKU demand forecasts ("Store management")
Types of Personal Data Order line items only: variant, quantity, order date, cancellation status, POS location, discounted unit price. No customer name, email, phone, or address.
Categories of data subjects The Merchant's customers (as reflected in order line items only)

RestockIQ does not access Shopify protected customer fields (name, email, phone, address) and does not process Personal Data for any purpose other than providing the service.

3. Merchant (Controller) obligations

The Merchant warrants that it has a lawful basis to have RestockIQ process the order data, and that its own privacy notices to its customers cover this processing.

4. RestockIQ (Processor) obligations

RestockIQ shall:

  1. Process Personal Data only on the Merchant's documented instructions (installing and using the app being the primary instruction), unless required by law.
  2. Ensure persons authorized to process Personal Data are bound by confidentiality.
  3. Implement the technical and organizational security measures in Annex A.
  4. Respect the conditions for engaging sub-processors in §5.
  5. Assist the Merchant, taking into account the nature of processing, in responding to data-subject requests (see §6) and in meeting its security, breach-notification, and impact-assessment obligations.
  6. At the Merchant's choice, delete or return Personal Data at the end of the service, and delete existing copies per §7.
  7. Make available information necessary to demonstrate compliance.
  8. Notify the Merchant without undue delay after becoming aware of a Personal Data breach.

5. Sub-processors

The Merchant provides general authorization for RestockIQ to engage the sub-processors listed in the Privacy Policy §5 (infrastructure hosting, database, cache/queue, transactional email, and diagnostics). RestockIQ imposes data-protection obligations on each sub-processor substantially equivalent to those in this DPA and remains responsible for their performance. RestockIQ will inform the Merchant of intended changes to sub-processors and give the Merchant an opportunity to object.

6. Data-subject requests

Because RestockIQ stores no customer-identifying data, it can typically satisfy data-subject requests structurally:

  • Access / portability: RestockIQ holds no customer identity data to return.
  • Erasure: handled via Shopify's customers/redact webhook — a no-op because no customer-identifying data is stored — and shop/redact, which deletes all Merchant data.
  • RestockIQ will assist the Merchant with any request that requires RestockIQ's cooperation.

7. Retention and deletion

Aggregated data is retained while the app is installed. On uninstall, RestockIQ flags the shop and deletes all associated data within 30 days, or sooner on Merchant request. This is automated via the app's scheduled worker.

8. International transfers

Where Personal Data is transferred across borders via sub-processors, such transfers are covered by appropriate safeguards (e.g. Standard Contractual Clauses).

9. Audit

RestockIQ will make available documentation reasonably necessary to demonstrate compliance and will contribute to audits as required by applicable law, subject to reasonable confidentiality and security constraints.

10. Liability and precedence

Liability is subject to the limitations in the main Terms of Service. In the event of a conflict between this DPA and other agreement terms regarding the processing of Personal Data, this DPA prevails.


Annex A — Technical and organizational security measures

  • Encryption in transit: TLS/HTTPS for all data transmission (Shopify Admin API, database, and app UI).
  • Encryption at rest — tokens: Shopify access tokens are encrypted with AES-256-GCM at the application layer (unique IV + authentication tag per token) before storage.
  • Encryption at rest — database: all stored data resides in a managed PostgreSQL database with at-rest encryption (AES-256) provided by the hosting provider.
  • Data minimization: order line items only are imported and are aggregated immediately into per-day/per-SKU/per-location totals; no customer-identifying data is collected or stored.
  • Access control: production secrets and the encryption key are stored as managed secrets; production data access is restricted to personnel who require it to operate the service.
  • Integrity & idempotency: inventory writes and webhook processing are idempotent to prevent duplication and corruption.
  • Deletion: automated purge of all shop data within 30 days of uninstall.
  • Breach response: breaches are triaged and the affected Merchant is notified without undue delay.

Annex B — Details of processing

  • Categories of data subjects: the Merchant's customers (reflected only in order line items).
  • Categories of Personal Data: order line items (variant, quantity, date, cancellation status, POS location, discounted unit price). No special-category data. No customer contact or identity fields.
  • Processing operations: collection via Shopify Admin API, aggregation, storage of aggregates, computation of forecasts, deletion.
RestockIQ·Privacy·Terms·DPA