Version 1.0 — last updated 3 July 2026
Data Processing Agreement — SMSPorta for Shopify
This Data Processing Agreement ("DPA") is incorporated into the agreement between SMSPorta ("Processor") and the merchant installing the SMSPorta app on their Shopify store ("Controller"). By checking the compliance acknowledgement inside the app's settings, you accept the terms below.
1. Roles
The merchant is the data Controller for their customers' personal data. SMSPorta is a data Processor, acting only on the merchant's instructions — configured through the app's settings — to send order-notification SMS.
2. Data processed
| Data | Source | Purpose |
|---|---|---|
| Customer phone number | Order / fulfillment webhook (customer.phone, shipping_address.phone, or destination.phone) | Deliver the SMS |
| Customer first name | Order / fulfillment webhook (customer.first_name / destination.first_name) | Personalize the SMS template |
No other customer field — email, full address, payment data, order line items — is received or stored by SMSPorta.
3. Processing instructions
SMSPorta processes this data only to (1) render the merchant's configured SMS template for an enabled event (order placed / cancelled / shipped / delivered), and (2) transmit the rendered message through the merchant's own registered Android device. SMSPorta does not use this data for any other purpose — no marketing, no analytics on customer identity, no resale, no AI training.
4. Subprocessors
- Shopify — source of the order/customer data, via webhooks the merchant authorizes at install.
- Fly.io — infrastructure hosting (EU regions).
No other third party receives this data.
5. Security measures
- Access tokens and message bodies encrypted at rest; all traffic encrypted in transit (TLS 1.2+).
- Phone numbers and message bodies are never written to application logs.
- Staff access to personal data is role-restricted and access-logged.
See our Privacy Policy for full detail.
6. Retention and deletion
- Webhook records: retained 90 days, then permanently deleted.
- On merchant uninstall: all shop data, including the encrypted access token, is permanently deleted 30 days after uninstall.
- On Shopify's
customers/redactwebhook: that customer's message records are redacted immediately. - On Shopify's
shop/redactwebhook: all of the shop's data is deleted immediately.
7. Data subject rights
Because SMSPorta is a processor, requests from a merchant's customers to access, correct, or delete their data should go to the merchant (the controller). SMSPorta fulfills its part automatically via Shopify's mandatory compliance webhooks (Section 6).
8. Merchant obligations
The merchant is responsible for having a lawful basis to share customer phone numbers/names with SMSPorta for this purpose, complying with SMS-specific consent rules in their jurisdiction (e.g. TCPA, GDPR) for the notifications they configure, and for the Android device and SIM used as the sending gateway and its compliance with local telecom regulations.
9. International transfers
Data is processed and stored exclusively within the EU (Frankfurt/Amsterdam). No transfer outside the EU occurs.
10. Contact
Questions about this agreement: info@triforge.net.