Data Processing Agreement
When you send Crust your merchants' business contact details, you stay the controller and we act strictly as your processor. This DPA makes that contractual: what data is covered, what we may and may not do with it, and how deletion, breaches, subprocessors, and international transfers are handled. It applies automatically — and we'll countersign a copy if your process requires one.
1. Affiliate accounts, referrals and manual payments
Affiliate accounts store a verified email address, name, hashed password, session and one-use security-token hashes, notification preferences, program memberships and recorded terms acceptance. Program records include referral links and clicks, normalized Shopify app/shop/install identifiers, verification evidence, collected transactions, commissions and their adjustments.
Manual payment records include requests, encrypted recipient instructions and frozen payment details, private invoice or receipt files, external payment references, receipt confirmations and dispute decisions. HeyCrust records these facts; transfers take place outside the Service. Only the partner and workspace identities with current permission can access the relevant private payment records. Public listings and marketplace moderation do not expose bank details or invoice files.
Closing an affiliate account revokes sessions and security tokens, archives memberships, disables promotion and replaces the visible name and email. Financial and audit identifiers remain for outstanding obligations and disputes. An encrypted verified email and its lookup hash are retained for one-use recovery of that account's financial access. Recovered access permits statements, payment requests, recipient updates, receipt confirmation and disputes; it does not reactivate promotion.
The worker prunes removable click/export payloads and expired saved import responses after the configured period (90 days by default). Pending installation proofs and evidence held for an open claim or payment dispute are retained. Normalized transaction, commission, payment and audit history remains separate. Merchant contact redaction clears removable affiliate contact/evidence payloads while preserving accounting identifiers. Affiliate attribution does not store raw IP addresses.
Configured integrations may send listing-export queries to Google BigQuery, account and program email through Resend or the workspace's verified SMTP provider, and notifications to explicitly configured Slack/webhook destinations. Enabled partner Flow drafting uses Google Gemini with a limited partner/program context; recipient instructions and invoice bytes are excluded. Render hosts the application and database. A configured integration requires its credentials and access settings; configuration is not proof of a completed delivery.
2. Scope and roles
This Data Processing Agreement (“DPA”) forms part of the Terms of Use between you (the customer using Crust, the “Controller”) and:
NextGen Software LLC192 Bear Christiana Rd #2016
Bear, DE 19701
United States
hello@heycrust.com
(“Crust”, the “Processor”). It applies whenever you submit personal data about your merchants or affiliate program partners to the Service — via the tracking pixel, the identify API, a backfill route, or a CSV import. You are the controller of that data; Crust processes it only on your behalf and on your documented instructions.
3. Covered data and data subjects
Data subjects: the merchants who install your Shopify apps, their staff who open your apps, and affiliate partners whose program data you manage.
Categories of personal data:
- Merchant business contact details — shop domain, business email, owner name, country, Shopify plan, and phone only where you choose to send it;
- App user details — name, email, and account role of Shopify users who open your app;
- In-app usage data — page paths, session identifiers, timestamps.
Excluded data: the Service is not designed for, and you agree not to submit, your merchants' end-customer (buyer) data or any special categories of personal data.
Duration: for as long as you maintain a workspace, plus the deletion window in Section 8. Nature and purpose: revenue analytics, churn intelligence, and win-back tooling for your Shopify apps, affiliate referral and commission accounting, and configured program communications.
4. Processing on your instructions only
- Crust processes Covered Data solely to provide the Service to you, as configured by you in the product. Your instructions are these Terms, this DPA, and your in-product settings.
- Crust will never sell Covered Data, use it to enrich other customers' workspaces, aggregate it across customers, or contact your merchants except as you explicitly direct (for example, win-back emails you approve).
- If Crust believes an instruction violates applicable data-protection law, it will inform you before processing.
5. Confidentiality
Every person Crust authorizes to process Covered Data is bound by a contractual or statutory duty of confidentiality, and access is limited to what operating the Service requires.
6. Security measures
Crust implements the technical and organizational measures described on the Security & Data Handling page — including AES-256-GCM encryption of stored secrets, TLS on all traffic, per-workspace isolation, cryptographic verification before any contact record is written, and transient-only handling of merchant store access tokens (never persisted). That page is incorporated into this DPA; material weakening of those measures will be notified per Section 6's mechanism.
7. Subprocessors
You generally authorize Crust to engage subprocessors for hosting, storage, email delivery, and payments. The current list is maintained in our Privacy Policy (service providers section). Crust remains fully liable for its subprocessors, imposes data-protection terms no weaker than this DPA, and will give notice of additions or replacements (via email or the in-product changelog) at least 14 days before they process Covered Data. If you object on reasonable data-protection grounds, you may terminate the affected service and Section 8 applies.
8. Assistance with data subject rights and DPIAs
- Deletion: call
DELETE /api/identifyfor a merchant (the snippet and retention-policy guidance are on the Security page) — their contact record, app users, and usage events are erased immediately. - Access / portability: your dashboard's CSV exports return everything held about a merchant.
- Crust will provide reasonable further assistance with data-subject requests, DPIAs, and consultations with supervisory authorities, taking into account the nature of the processing.
9. Breach notification; deletion on termination
Crust will notify you without undue delay after becoming aware of a personal-data breach affecting Covered Data, with the information reasonably available to help you meet your own notification duties.
On termination of the Service (or on request at hello@heycrust.com), Crust deletes your workspace's Covered Data within 30 days, except where retention is required by law. Export your data first — the CSV exports exist for exactly this.
10. Audits and international transfers
Crust will make available the information reasonably necessary to demonstrate compliance with this DPA and will respond to reasonable written security questionnaires from customers.
Covered Data is processed in the United States. Where transfers of EEA, UK, or Swiss personal data apply, the parties incorporate by reference the EU Standard Contractual Clauses (Module Two: controller-to-processor), with you as data exporter and Crust as data importer, and the UK Addendum / Swiss adaptations as applicable.
11. How this DPA is executed
This DPA is automatically incorporated into your agreement with Crust and takes effect the moment you submit Covered Data to the Service — no signature required. If your compliance process needs a countersigned copy, email hello@heycrust.com and we'll return an executed PDF, normally within two business days.