Nucleus by CROVION

Data Processing Addendum

Effective date: 20 August 2026

This Data Processing Addendum ("DPA") supplements the Merchant Terms of Service between Crovion ("Company," "Processor," "we") and the Merchant ("Controller," "you") and applies to Company's processing of personal data on Merchant's behalf through Nucleus by CROVION (the "App"). In the event of a conflict between this DPA and the Terms, this DPA controls with respect to the processing of personal data.

1. Roles of the parties

With respect to personal data of the Merchant's Customers processed through the App, the Merchant is the controller (data fiduciary) of that data, and the Company acts as a service provider/processor, processing that data only on the Merchant's documented instructions (as configured through the App's settings and ordinary use of its features).

2. Subject matter, duration, and purpose

Company processes personal data for the duration of the Merchant's use of the App, for the purposes described in the Privacy Policy: Cash on Delivery order verification, checkout funnel analytics, abandoned-checkout recovery messaging (where Shopify-recorded consent exists), shipment/delivery tracking, and related merchant-facing analytics.

3. Categories of data subjects

4. Categories of personal data

CategoryData elements
Order dataCustomer phone number, shipping pincode/city/state/country, and the full order webhook payload as received from Shopify (which may include additional fields such as name, email, and address).
Checkout dataEmail, phone number, and marketing/SMS-consent flags, where present on Shopify's checkout webhooks. Web Pixel–sourced checkout events carry no personal data.
OTP verification dataPhone number and a salted hash of the verification code (never the code itself in plain text).
Shipment/tracking dataCarrier name, tracking number, and delivery-event status. Contains no personal data — no customer name, address, or phone number is read from this data source.
Merchant/staff dataName, email, and locale of staff accounts, obtained via Shopify OAuth.

5. Sub-processors

Merchant authorizes Company to engage the following sub-processors, each limited to the purpose stated:

Sub-processorPurpose
ShopifyUnderlying commerce platform; source of order, checkout, and fulfillment data.
TwilioSMS delivery for OTP codes, order confirmations, and recovery messages.
Meta (WhatsApp Cloud API)WhatsApp delivery for OTP codes, order confirmations, and recovery messages.
NeonCloud PostgreSQL database hosting for all personal data described in this DPA.

Company will provide reasonable advance notice of any change to this sub-processor list, where practicable. No advertising or analytics platform (e.g. Meta Ads, Google Ads, TikTok Ads, GA4) currently receives personal data from the App and none is listed as a sub-processor.

6. Processor obligations

7. Retention and deletion

8. International transfers

Company is based in India. Sub-processors listed in Section 5 may process and store personal data outside India, in jurisdictions other than the Merchant's or Customer's own. Where such transfers occur, Company relies on the lawful basis available under applicable Indian data protection law for transferring personal data outside India, together with the international-transfer safeguards each sub-processor makes available under its own published terms:

These reflect each sub-processor's own published terms as of the effective date of this DPA and may change; Company does not control, and has not independently audited, its sub-processors' compliance with their own stated mechanisms.

9. Audit

On reasonable request, Company will first make available to the Merchant documentation and other evidence reasonably necessary to demonstrate compliance with this DPA. Where that documentation is insufficient, or where an audit is required by applicable law, Merchant may exercise reasonable audit rights, subject to reasonable advance notice and appropriate confidentiality and security restrictions (including restrictions necessary to protect the data of Company's other merchants).

10. Liability and governing law

Liability under this DPA is governed by the limitation of liability provisions in the Merchant Terms of Service. This DPA is governed by the laws of India, subject to the exclusive jurisdiction of the courts located in Firozabad, Uttar Pradesh, India.

11. Contact

Crovion
118 B-3, Shahpur Jat, New Delhi - 110049, India
Privacy contact: contact@crovion.com