Data Processing Addendum
Effective date: 20 August 2026
This Data Processing Addendum ("DPA") supplements the Merchant Terms of Service between Crovion ("Company," "Processor," "we") and the Merchant ("Controller," "you") and applies to Company's processing of personal data on Merchant's behalf through Nucleus by CROVION (the "App"). In the event of a conflict between this DPA and the Terms, this DPA controls with respect to the processing of personal data.
1. Roles of the parties
With respect to personal data of the Merchant's Customers processed through the App, the Merchant is the controller (data fiduciary) of that data, and the Company acts as a service provider/processor, processing that data only on the Merchant's documented instructions (as configured through the App's settings and ordinary use of its features).
2. Subject matter, duration, and purpose
Company processes personal data for the duration of the Merchant's use of the App, for the purposes described in the Privacy Policy: Cash on Delivery order verification, checkout funnel analytics, abandoned-checkout recovery messaging (where Shopify-recorded consent exists), shipment/delivery tracking, and related merchant-facing analytics.
3. Categories of data subjects
- The Merchant's Customers (end buyers placing orders through the Merchant's store).
- The Merchant's own staff/account users who access the App.
4. Categories of personal data
| Category | Data elements |
|---|---|
| Order data | Customer phone number, shipping pincode/city/state/country, and the full order webhook payload as received from Shopify (which may include additional fields such as name, email, and address). |
| Checkout data | Email, phone number, and marketing/SMS-consent flags, where present on Shopify's checkout webhooks. Web Pixel–sourced checkout events carry no personal data. |
| OTP verification data | Phone number and a salted hash of the verification code (never the code itself in plain text). |
| Shipment/tracking data | Carrier name, tracking number, and delivery-event status. Contains no personal data — no customer name, address, or phone number is read from this data source. |
| Merchant/staff data | Name, email, and locale of staff accounts, obtained via Shopify OAuth. |
5. Sub-processors
Merchant authorizes Company to engage the following sub-processors, each limited to the purpose stated:
| Sub-processor | Purpose |
|---|---|
| Shopify | Underlying commerce platform; source of order, checkout, and fulfillment data. |
| Twilio | SMS delivery for OTP codes, order confirmations, and recovery messages. |
| Meta (WhatsApp Cloud API) | WhatsApp delivery for OTP codes, order confirmations, and recovery messages. |
| Neon | Cloud PostgreSQL database hosting for all personal data described in this DPA. |
Company will provide reasonable advance notice of any change to this sub-processor list, where practicable. No advertising or analytics platform (e.g. Meta Ads, Google Ads, TikTok Ads, GA4) currently receives personal data from the App and none is listed as a sub-processor.
6. Processor obligations
- Process personal data only on the Merchant's documented instructions, as reflected in the App's own configuration and features.
- Ensure personnel authorized to process personal data are subject to confidentiality obligations.
- Implement reasonable technical and organizational safeguards appropriate to the personal data processed, including (among others): never storing OTP verification codes in plain text (only a salted cryptographic hash); verifying inbound provider webhook signatures (Twilio, Meta) before trusting a delivery-status callback; and storing Shopify access tokens via Shopify's own official session-storage mechanism. The Company does not hold any third-party security certification (e.g. SOC 2, ISO 27001) at this time.
- Assist the Merchant in responding to data subject requests. Company automatically processes Shopify's
customers/data_request,customers/redact, andshop/redactwebhooks; because the App identifies Customers primarily by phone number, requests that do not include a phone number may not be actionable. - Notify the Merchant without undue delay after becoming aware of a confirmed personal data breach affecting the Merchant's data processed through the App.
- Delete personal data following the end of the provision of services, per the automated retention and deletion process described in Section 7. The App does not currently offer a separate merchant-facing data export/return mechanism beyond that process and the Shopify
customers/data_requesthandling described above.
7. Retention and deletion
- Most operational records are retained for 90 days by default, then automatically purged.
- OTP-related transient data (e.g. a code awaiting delivery-status confirmation) is redacted immediately once that notification reaches a final state.
- Upon uninstallation, Merchant data is retained for a 30-day grace period, then automatically and permanently deleted.
- Shipment/tracking and aggregate campaign records, which contain no personal data, are retained indefinitely for historical reporting and are not subject to this section.
8. International transfers
Company is based in India. Sub-processors listed in Section 5 may process and store personal data outside India, in jurisdictions other than the Merchant's or Customer's own. Where such transfers occur, Company relies on the lawful basis available under applicable Indian data protection law for transferring personal data outside India, together with the international-transfer safeguards each sub-processor makes available under its own published terms:
- Shopify — Standard Contractual Clauses (European Commission-approved modules) and Shopify's own Binding Corporate Rules, under Shopify's Data Processing Addendum.
- Twilio — Standard Contractual Clauses (all three EU modules), together with Twilio's EU–US Data Privacy Framework self-certification and Binding Corporate Rules, under Twilio's Data Protection Addendum.
- Meta (WhatsApp Cloud API) — Standard Contractual Clauses and Meta's own Global Data Transfer Addendum, under Meta's Platform Terms.
- Neon — Standard Contractual Clauses (European Commission-approved), under the Data Processing Addendum of Databricks (Neon's parent company since its acquisition by Databricks).
These reflect each sub-processor's own published terms as of the effective date of this DPA and may change; Company does not control, and has not independently audited, its sub-processors' compliance with their own stated mechanisms.
9. Audit
On reasonable request, Company will first make available to the Merchant documentation and other evidence reasonably necessary to demonstrate compliance with this DPA. Where that documentation is insufficient, or where an audit is required by applicable law, Merchant may exercise reasonable audit rights, subject to reasonable advance notice and appropriate confidentiality and security restrictions (including restrictions necessary to protect the data of Company's other merchants).
10. Liability and governing law
Liability under this DPA is governed by the limitation of liability provisions in the Merchant Terms of Service. This DPA is governed by the laws of India, subject to the exclusive jurisdiction of the courts located in Firozabad, Uttar Pradesh, India.
11. Contact
Crovion
118 B-3, Shahpur Jat, New Delhi - 110049, India
Privacy contact: contact@crovion.com