Data processing agreement
These terms apply between Appease and every merchant who installs the app. They take effect on install — there is nothing to sign. Last updated 4 August 2026.
1. Roles
The merchant is the data controller. Appease is the data processor and acts only on the merchant's documented instructions, which are given by installing the app and configuring a refund policy in it.
This agreement takes effect when a merchant installs Appease and remains in force while the app is installed.
2. Scope of processing
Subject matter: checking refunds against the merchant's own written refund policy and reporting or resolving them accordingly.
Categories of data subject: the merchant's customers who requested or received a refund.
Categories of personal data: order identifiers, order and refund amounts, refund timestamps, and the email address on the order. Appease does not process names, postal addresses, phone numbers or payment details.
Purpose: the email address is used solely to match refunds belonging to the same customer, so refunds beyond the merchant's own per-customer limit can be detected.
3. Retention and deletion
Order-level data is read from the Shopify Admin API when an audit runs and is not retained afterwards. Only aggregate totals are stored — counts and sums, no shopper identifiers.
On uninstall, the store's access credentials are deleted immediately.
On a shop/redact request, or on written request to henrik@appease.tech, all data relating to the store is deleted within 48 hours.
Appease stores no shopper personal data, so there is nothing to return or erase in response to an individual customer request. Such requests are answered stating this.
4. Security
Data is encrypted in transit (TLS 1.2 or higher) and at rest. Database backups are encrypted.
Access to production data is limited to the two founders and requires multi-factor authentication.
Development and production data are kept separate: data originating from Shopify development stores is marked at write time and excluded from production reporting.
Appease holds read-only Shopify scopes (read_orders, read_customers). It cannot write to a store.
5. Sub-processors
Vercel Inc. — application hosting.
Supabase Inc. (eu-central-1) — database.
Anthropic PBC — classification of helpdesk ticket text, where the merchant supplies it. Data sent to Anthropic is not used to train models.
Merchants are notified by email at least 30 days before a new sub-processor is added, and may object in writing.
6. Personal data breaches
Appease notifies affected merchants without undue delay and within 72 hours of becoming aware of a personal data breach, with the facts known at that time, the likely consequences, and the measures taken.
Appease's incident response procedure is published at appease.tech/security.
7. International transfers and audits
Data is stored in the EU. Where a sub-processor operates outside the EEA, transfers rely on the European Commission's Standard Contractual Clauses.
On reasonable written request, Appease will provide the information necessary to demonstrate compliance with this agreement.
Questions or a signed copy: henrik@appease.tech