Version 1.0 — last updated 3 July 2026

Data Processing Agreement — SMSPorta for Shopify

This Data Processing Agreement ("DPA") is incorporated into the agreement between SMSPorta ("Processor") and the merchant installing the SMSPorta app on their Shopify store ("Controller"). By checking the compliance acknowledgement inside the app's settings, you accept the terms below.

1. Roles

The merchant is the data Controller for their customers' personal data. SMSPorta is a data Processor, acting only on the merchant's instructions — configured through the app's settings — to send order-notification SMS.

2. Data processed

DataSourcePurpose
Customer phone numberOrder / fulfillment webhook (customer.phone, shipping_address.phone, or destination.phone)Deliver the SMS
Customer first nameOrder / fulfillment webhook (customer.first_name / destination.first_name)Personalize the SMS template

No other customer field — email, full address, payment data, order line items — is received or stored by SMSPorta.

3. Processing instructions

SMSPorta processes this data only to (1) render the merchant's configured SMS template for an enabled event (order placed / cancelled / shipped / delivered), and (2) transmit the rendered message through the merchant's own registered Android device. SMSPorta does not use this data for any other purpose — no marketing, no analytics on customer identity, no resale, no AI training.

4. Subprocessors

  • Shopify — source of the order/customer data, via webhooks the merchant authorizes at install.
  • Fly.io — infrastructure hosting (EU regions).

No other third party receives this data.

5. Security measures

  • Access tokens and message bodies encrypted at rest; all traffic encrypted in transit (TLS 1.2+).
  • Phone numbers and message bodies are never written to application logs.
  • Staff access to personal data is role-restricted and access-logged.

See our Privacy Policy for full detail.

6. Retention and deletion

  • Webhook records: retained 90 days, then permanently deleted.
  • On merchant uninstall: all shop data, including the encrypted access token, is permanently deleted 30 days after uninstall.
  • On Shopify's customers/redact webhook: that customer's message records are redacted immediately.
  • On Shopify's shop/redact webhook: all of the shop's data is deleted immediately.

7. Data subject rights

Because SMSPorta is a processor, requests from a merchant's customers to access, correct, or delete their data should go to the merchant (the controller). SMSPorta fulfills its part automatically via Shopify's mandatory compliance webhooks (Section 6).

8. Merchant obligations

The merchant is responsible for having a lawful basis to share customer phone numbers/names with SMSPorta for this purpose, complying with SMS-specific consent rules in their jurisdiction (e.g. TCPA, GDPR) for the notifications they configure, and for the Android device and SIM used as the sending gateway and its compliance with local telecom regulations.

9. International transfers

Data is processed and stored exclusively within the EU (Frankfurt/Amsterdam). No transfer outside the EU occurs.

10. Contact

Questions about this agreement: info@triforge.net.