Merchant data
Data Processing Addendum
Effective 26 August 2026 · Version 2026-08-26
This Data Processing Addendum (DPA) forms part of the Merge Me Terms of Service between the Merchant as controller or business (Controller) and Marvello Pty Ltd as processor or service provider (Processor). It applies only to Personal Data that Marvello processes on the Merchant’s behalf to provide Merge Me.
1. Definitions and priority
Data Protection Law means privacy and data-protection law applicable to the processing, including the Australian Privacy Act 1988 (Cth), the GDPR, UK GDPR and applicable United States state privacy laws. Personal Data, process, controller, processor, data subject and personal data breach have the meanings given by applicable Data Protection Law. Customer Data means Personal Data contained in the Merchant Data processed on behalf of the Merchant.
If this DPA conflicts with the Terms on processing Customer Data, this DPA prevails. Mandatory Data Protection Law prevails over both. This DPA does not make Marvello a processor for information it independently controls as described in the Privacy Policy.
2. Processing instructions
The Merchant instructs Marvello to process Customer Data only to provide, secure, maintain and support the Service; perform the Merchant’s documented settings and authorised app actions; respond to data-subject and Shopify privacy requests; prevent abuse and unsafe duplicate actions; delete or return data; and comply with law. The Terms, Merchant’s in-app configuration, authenticated actions and written support instructions are documented instructions.
Marvello will process Customer Data only on documented instructions unless law requires otherwise. If legally permitted, Marvello will notify the Merchant before processing required by law. Marvello will promptly inform the Merchant if, in its reasonable opinion, an instruction infringes Data Protection Law and may suspend that instruction while the parties address it.
3. Merchant obligations
The Merchant determines the purposes and essential means of processing and is responsible for: the lawfulness, fairness and transparency of its instructions; required notices and lawful bases; responding to data subjects; the accuracy and minimisation of submitted data; configuring appropriate access and retention; assessing whether the Service is suitable for its processing; and obtaining any required consent or authorisation. The Merchant must not instruct Marvello to process sensitive or special-category data unless the parties first agree written safeguards.
4. Confidentiality and personnel
Marvello will ensure that people authorised to process Customer Data are bound by confidentiality obligations, receive appropriate privacy and security instructions, and access Customer Data only where needed for their role.
5. Security
Taking account of the state of the art, implementation cost, nature, scope, context and purposes of processing and risks to individuals, Marvello will maintain appropriate technical and organisational measures. Current measures include, as applicable:
- encryption in transit and at rest through configured platform controls;
- logical tenant separation and tenant-bound database controls;
- least-privilege identities, restricted secrets and separation of web, worker, writer, privacy and support roles;
- Shopify HMAC and session authentication, bounded request handling and protection against replay and duplicate actions;
- pseudonymous match and operational identifiers, minimal logs and prohibition on placing identifying data in immutable audit records;
- change review, dependency and vulnerability management, automated tests, monitoring and incident-response procedures;
- retention and privacy-erasure workflows, protected backups and recovery planning; and
- regular review of access, safety gates and material service-provider controls.
No security measure eliminates all risk. The Merchant is responsible for its Shopify account, staff permissions, devices, downstream providers, and secure use of outputs.
6. Subprocessors
The Merchant gives Marvello general written authorisation to use the providers on the Subprocessors page. Marvello will impose written data-protection obligations that are no less protective in substance for the relevant processing and remains responsible for a subprocessor’s performance of those obligations to the extent required by law.
Marvello will give reasonable advance notice, normally at least 15 days, before a new subprocessor begins processing Customer Data where practicable. The Merchant may object during that period on reasonable data-protection grounds. The parties will work in good faith on a commercially reasonable alternative. If none is available, either party may terminate the affected Service; Marvello will refund prepaid fees for the unused terminated period where applicable.
7. Data-subject and privacy requests
Taking account of the nature of processing, Marvello will provide reasonable technical and organisational assistance for the Merchant to respond to requests for access, correction, deletion, restriction, objection, portability or other applicable rights. If Marvello receives a request concerning Customer Data directly, it will refer the person to the relevant Merchant where reasonably identifiable and will not independently fulfil the request unless authorised or legally required.
Merge Me processes authenticated Shopify privacy webhooks for customer data requests, customer redaction and shop redaction. The Merchant remains responsible for its communication with the requesting person.
8. Personal data breaches
Marvello will notify the Merchant without undue delay after confirming a personal data breach affecting Customer Data and will provide available information reasonably needed for the Merchant’s assessment and notification duties, including the nature of the incident, affected data and people where known, likely consequences, measures taken or proposed, and a contact point. Information may be supplied in phases as it becomes available.
Marvello’s notification is not an admission of fault or liability. The Merchant is responsible for notices to individuals and regulators unless law assigns that duty directly to Marvello. The Merchant must promptly provide information and cooperation needed to investigate an incident arising from its account, systems, staff or provider.
9. Compliance assistance
Taking account of the nature of processing and information available, Marvello will provide reasonable assistance with security obligations, breach assessment, data-protection impact assessments and prior consultation with regulators. Assistance beyond standard documentation or caused by the Merchant’s instructions, systems or breach may be charged at an agreed reasonable rate, except where the need results from Marvello’s breach of this DPA.
10. Deletion and return
During the term, the Merchant may retrieve information available through authenticated Service features. On uninstall or termination, Marvello will delete Customer Data in accordance with its documented retention and Shopify privacy workflows, unless law requires retention. Closed order-linked operational records are ordinarily deleted 30 days after closure; shorter and de-identified records follow the schedule in the Privacy Policy. Data in protected backups is isolated from ordinary use and deleted through normal rotation.
Marvello may retain the minimum data necessary to resolve an open safety or billing event, comply with law, establish or defend claims, or safely deduplicate a repeated privacy request. Retained data remains protected and is not used for another purpose.
11. Audit and information rights
Marvello will make available information reasonably necessary to demonstrate compliance with this DPA. The Merchant must first use current documentation, certifications, summaries and written responses. If those are insufficient, the Merchant may request one audit in a 12-month period by an independent qualified auditor bound by confidentiality, on at least 30 days’ notice, during business hours, and without accessing another merchant’s data or compromising security. More frequent audits are permitted after a confirmed material breach or where a regulator requires them.
The Merchant bears reasonable audit costs unless the audit identifies Marvello’s material breach. Marvello may require scope and security controls and may provide equivalent third-party audit evidence instead of access to systems or facilities.
12. International transfers
The primary app infrastructure is configured in Australia, but global providers and Shopify may process information elsewhere as described in the Privacy Policy and Subprocessors page. Each party will comply with applicable cross-border transfer requirements.
If Customer Data protected by the GDPR is transferred to Marvello in a country without an applicable adequacy decision and no other lawful mechanism applies, the parties will enter into or be deemed to incorporate the then-current European Commission controller-to-processor standard contractual clauses appropriate to the transfer, with the Merchant as data exporter and Marvello as data importer. For UK-restricted transfers, the parties will use the then-current UK addendum or other lawful mechanism. The parties will complete additional transfer details reasonably required for validity. These mechanisms do not apply where the transfer is otherwise lawful without them.
13. Government requests
Unless prohibited by law, Marvello will notify the Merchant of a binding government demand for Customer Data. Marvello will assess the demand, seek clarification or challenge it where there are reasonable grounds, and disclose only the minimum legally required data. Marvello does not voluntarily provide bulk or indiscriminate access to Customer Data.
14. Liability
The liability provisions in the Terms apply to this DPA, but nothing limits either party’s liability to individuals or regulators where Data Protection Law does not permit that limitation. Any contractual allocation between the parties does not reduce a data subject’s statutory rights.
15. Processing details
| Subject matter | Providing Shopify order matching, combined-order creation and verification, merge history, configured fulfilment actions, privacy handling, billing/usage, security and support. |
|---|---|
| Duration | For the term of the Service plus the limited deletion, backup and legal-retention periods described above. |
| Nature and purpose | Collection from Shopify, organisation, comparison, pseudonymisation, storage, retrieval, consultation, transmission back to Shopify or an authorised provider, restriction and deletion to perform the Service under Merchant instructions. |
| Data subjects | Merchant owners and staff; customers, recipients and contacts associated with Shopify orders; and, only where supplied in order data, other individuals connected to fulfilment. |
| Personal Data | Store/staff identifiers and contact details; customer identity and tags; delivery name, address and phone; order, line-item, product, discount, tax, shipping and fulfilment details; tracking; app settings, usage and support information; technical, session and security data. |
| Sensitive data | Not intentionally required. The Merchant must not submit special-category or sensitive information unless separately agreed. |
| Frequency | Continuous or event-driven while the app is installed and relevant features are enabled. |
16. Contact
Data-processing questions, notices and subprocessor objections may be sent to help@mergeme.app with “DPA” in the subject. This online DPA becomes binding when the Merchant accepts the Terms and uses the Service; a countersigned copy may be requested for an enterprise review.