Data processing agreement
How FairRev handles personal data about your shoppers on your instructions, our sub-processors, and the measures we keep.
Version 1.0. Effective date: 1 October 2026.
This agreement applies whenever we handle personal data about your shoppers. It forms part of the FairRev terms of service and takes effect when you install the app. It is entered into between:
You, the merchant, as controller, and
Doment Digital FZE LLC, Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates, licence 4431328.01, as processor.
Where you are yourself a processor for someone else, we are a sub-processor and this agreement is read accordingly.
1. What we process, and why
| Subject matter | Providing the FairRev app: showing offers, applying discounts through Shopify, and measuring which revenue the app produced |
|---|---|
| Duration | From installation until deletion under section 8 |
| Nature and purpose | Collecting, storing, analysing and aggregating storefront events and order data, and returning the results to you |
| Types of personal data | A rotating pseudonymous session identifier, cart token, order identifier, order line details, prices, currencies, payment method names, locale, coarse device type, and the time each event happened |
| Categories of data subject | Your shoppers and visitors to your store |
| Special category data | None. We do not process it and you must not send it to us |
| Direct identifiers | None requested. We do not ask Shopify for permission to read customer records, so we do not receive names, addresses, email addresses or phone numbers, and we discard any such field that arrives in an order payload |
2. We act only on your instructions
We process personal data only on your documented instructions. Installing the app, configuring your offers and using the admin are your instructions. We will not process it for any other purpose.
If we believe an instruction breaks data protection law, we will tell you and may pause that processing until it is resolved.
3. Confidentiality
Everyone who can access the data is under a duty of confidentiality, and access is limited to those who need it to do their job.
4. Security
We keep the measures set out in Annex 2. We may change them, and we will not make them weaker.
5. Sub-processors
You give general authorisation for us to appoint sub-processors. The current list is in Annex 1 and at https://fairrev.com/subprocessors.
We will give you at least thirty days' notice before adding or replacing one. You may object on reasonable data protection grounds, and if we cannot resolve it you may terminate the affected part of the service without penalty.
Every sub-processor is bound by terms no weaker than these, and we remain responsible to you for what they do.
6. Helping you meet your own obligations
We will help you, so far as we reasonably can and taking into account what we know:
- Respond to a shopper exercising their rights. In practice most requests are answered from your Shopify admin rather than from us, because we do not hold direct identifiers.
- Meet your security obligations.
- Notify a breach, and carry out an impact assessment or a prior consultation if you need one.
Breach notification. If we become aware of a personal data breach affecting your data, we will tell you without undue delay and in any case within seventy two hours, with what happened, which categories of data are affected, the likely consequences and what we are doing about it. We will keep telling you as we learn more.
7. Audit
We will make available the information you reasonably need to show we are meeting this agreement, and will allow an audit no more than once a year, on thirty days' notice, during business hours, and without disrupting other merchants. Anything learned during an audit is confidential.
You will bear the cost of an audit, unless it finds a material breach by us, in which case we will.
8. Return and deletion
When you uninstall, or when this agreement ends, we delete or anonymise the personal data we hold on your behalf when Shopify tells us to erase the shop, which it does 48 hours after you uninstall. We act on that request immediately rather than holding the data for a window of our own.
We keep what we are legally required to keep. In practice this is the billing ledger, which records what was charged and why. We remove or anonymise everything in it that is not needed for that.
9. International transfers
The data is stored in Frankfurt, Germany, inside the European Economic Area, and is not copied out of it in the ordinary running of the service.
Our company is in the United Arab Emirates, which is not covered by a UK or EU adequacy decision, so the people who operate and support the service reach that data from there. For that access the European Commission's standard contractual clauses apply, controller to processor, and are incorporated here. Where the data concerns people in the United Kingdom, the UK international data transfer addendum applies.
10. General
This agreement is governed by the same law as the terms of service. If it conflicts with the terms of service on the handling of personal data, this agreement wins.
Annex 1: sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Hostinger International Limited | Servers, database, background jobs | Frankfurt, Germany |
| Cloudflare, Inc. | Serving widget assets and offer configuration | Global edge |
Shopify is not listed as our sub-processor. Shopify is the platform you already have your own agreement with, and the data reaches us through it.
Annex 2: security measures
Access control. Production access is limited to people who need it and requires multi factor authentication. Access is reviewed when anyone's role changes.
Encryption. All traffic in transit uses HTTPS. Shopify access tokens are encrypted before storage using a key held outside the database.
Pseudonymisation. Shopper session identifiers are random and rotating. We request no permission to read customer records, so we hold no direct identifiers to pseudonymise in the first place.
Separation. Every record carries the shop it belongs to and every query is scoped to one shop.
Resilience. Daily backups, stored off the server, with restores tested rather than assumed.
Integrity. Records of attribution and of charges are append only. A correction is a new entry that reverses an old one, so history cannot be quietly rewritten.
Logging. An append only record of every change that affects what a merchant is charged or what their shoppers see, including changes we make ourselves.
Failure behaviour. If our backend is unreachable the storefront widget hides itself. It never blocks a cart or a checkout.
Vulnerability management. Dependencies are monitored continuously and a published fix for a high or critical severity issue is applied within seven days.