Data Processing Agreement · Updated July 22, 2026
Data Processing Agreement
This Data Processing Agreement (DPA) forms part of the agreement between the merchant who installs VIP Alert (the Controller) and Taylor Sicard Consulting, operator of VIP Alert (the Processor, we). It governs the Processor's processing of personal data on the Controller's behalf and reflects the requirements of Article 28 of the EU and UK General Data Protection Regulation (GDPR). By installing and using VIP Alert, the Controller agrees to this DPA. To execute a countersigned copy, contact us at the address below.
1. Roles and scope
The merchant is the Controller of their customers' personal data. VIP Alert acts as a Processor, processing that data only to provide the service. Where we engage third parties who process the data on our behalf, they act as sub-processors. Shopify is an independent controller or processor for the merchant under its own terms and is not a sub-processor under this DPA.
2. Subject matter, nature, and purpose
We process personal data to identify and classify the Controller's customers (VIP, business, and public-figure detection), score and grade them, and return results to the Controller. Processing lasts for as long as the Controller uses the app, plus the limited retention described below.
3. Categories of data and data subjects
- Data subjects: the Controller's customers who place orders.
- Personal data: customer name, email address, shipping locality (city, region, postal code, country), order values and traffic source, and the enrichment and public-profile data we derive (for example job title, employer, and public social or encyclopedic profiles).
- We do not intentionally process special-category data, and the app is not intended for that purpose.
4. Processor obligations
- Process personal data only on the Controller's documented instructions, including the configuration choices made in the app.
- Ensure personnel authorized to process the data are bound by confidentiality.
- Implement appropriate technical and organizational security measures (Section 6).
- Assist the Controller in responding to data subject requests and in meeting its breach-notification and impact-assessment obligations.
- Delete or return personal data at the end of the service, as described in Section 7.
- Make available information necessary to demonstrate compliance with this DPA and allow for reasonable audits.
- We never sell personal data and never use it to build products other than providing this service.
5. Sub-processors
The Controller provides general authorization for us to engage the sub-processors below. We remain responsible for their compliance and will give notice of any intended additions or replacements so the Controller may object on reasonable data-protection grounds.
- People Data Labs and Apollo: professional-profile enrichment (receive customer email and/or name).
- Serper (Google Search): public-web corroboration and social-profile discovery (receive customer name and locality).
- Netlify: application hosting and serverless compute (United States).
- Neon: managed Postgres database storing app records (United States).
- Resend: transactional email delivery for alerts (recipient addresses and detection details).
Wikipedia and Wikidata are queried as public sources using only a customer's name and locality; they do not act as sub-processors holding data on our behalf.
6. Security measures
- Encryption of data in transit (TLS) and at rest.
- Access restricted to authorized personnel and to the minimum data needed for each lookup.
- Secrets and API keys stored in a managed secret store.
- Verification of inbound webhooks (HMAC) and use of Shopify session tokens for authentication.
7. Retention and deletion
- Customer records are retained while the Controller uses the app.
- We honor Shopify's GDPR webhooks automatically: a customer redaction request deletes that customer's records and shared cache entry, and a shop redaction request (48 hours after uninstall) deletes all personal data for that store, including customer records, order-level records, alerts, queued orders, and settings.
- After a shop redaction we retain one row of aggregate business metrics about the store itself: average monthly orders and revenue, average order value, how many VIPs were found, and the plan used. This contains no personal data of any kind, no customer records, and no order-level records. We keep it so that a later conversation about the product can reference the store's own numbers. Write to hello@taylorsicard.com to have it removed.
- Shared enrichment-cache entries expire automatically after 180 days.
8. International transfers
Sub-processors are located in the United States. Where personal data is transferred out of the EU, UK, or other regulated regions, the transfer relies on an appropriate safeguard such as the Standard Contractual Clauses, incorporated by reference into this DPA.
9. Data breach
We will notify the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller's data, with the information the Controller reasonably needs to meet its own obligations.
10. Term and changes
This DPA remains in effect while VIP Alert is installed. We may update it to reflect changes in law or our sub-processors, and will post the updated version here with a revised date.
Contact
Data-protection questions, audit requests, or to request a countersigned copy: VIPalert@taylorsicard.com. See also our privacy policy and support page.