Legal

Data Processing Agreement (DPA)

Effective date: October 7, 2026

This Data Processing Agreement (the "Agreement") is an annex to the SellRules Terms of Service. By installing and continuing to use the App, the merchant is deemed to have agreed to this Agreement.

If you need a separately signed copy, please contact [email protected]. We will provide a signed version with the same content.

Section 01

Parties and Roles

  1. 1.This Agreement governs the handling of personal data in connection with the provision of the Shopify app "SellRules" (the "App") between the merchant who installs the App (the "Merchant") and JizaiDev, the provider of the App ("we", "us").
  2. 2.The Merchant is the controller of buyers' personal data (the business handling personal information under Japan's Act on the Protection of Personal Information), and we are the processor that processes it on the Merchant's instructions.
  3. 3.Our contact: [email protected]
Section 02

Purposes of Processing

We process personal data only for the following purposes.

  1. 1.Applying per-product selling rules (pre-order, made-to-order, stock-out behavior, purchase limits, deposit/balance payments) to the storefront, checkout and order processing
  2. 2.Sending notification emails to buyers (pre-order confirmation, delay, shipping, back-in-stock, balance payment requests)
  3. 3.Managing the progress of pre-order and made-to-order orders, and printing packing slips
  4. 4.Evaluating purchase limits (per-order and per-customer limits, eligibility by customer tag)
  5. 5.Responding to Shopify customer data requests and deletion requests (customers/data_request, customers/redact, shop/redact)
  6. 6.Handling incidents with the App and preventing misuse
We do not sell personal data, do not use it for advertising, marketing or machine-learning training, and do not process it for any purpose other than those above.
Section 03

Types of Data Processed

CategoryDataMain purposeStorage
Buyer contact detailsEmail address, languageNotification emailsStored (retention per Section 6 of the Privacy Policy)
Buyer identifiersShopify customer ID, order ID, order numberPurchase limits, order progressStored
Purchase detailsProducts, variants, quantities, amounts, payment termsOrder progress, deposit/balance paymentsStored
Shipping and billing informationShipping address, billing address, phone number, namePrinting packing slipsNot stored (retrieved from Shopify and displayed only when viewed)
Back-in-stock sign-upsEmail address, product signed up forBack-in-stock notificationsStored (1 year from last update; deleted on deletion request or uninstall)
Merchant staffShopify staff IDActivity and access records, external AI integration permissionsStored
We do not handle credit card information or passwords. Retention periods are detailed in Section 6 "Data Storage and Retention" of the Privacy Policy.
Section 04

Sub-processors

The Merchant agrees that we use the following sub-processors.

Sub-processorPurposeData handledLocation
Fly.io, Inc.App hosting and database (encrypted volume), automatic snapshotsAll data stored by the AppTokyo region (nrt)
ResendSending notification emailsRecipient email address, subject, bodySending region ap-northeast-1 (Tokyo); company based in the US
ShopifySystem of record for orders and customers, webhooks, Shopify Functions, FlowThe Merchant's store dataAs set by Shopify
Cloudflare, Inc.DNS for the sending domain jizai.devNo personal data—

As an internal system operated by us, there is a feedback intake (desk-api.jizai.dev; attachments are stored on Cloudflare R2). It handles only feedback the Merchant sends voluntarily and receives no buyer personal data.

When we add or change a sub-processor, we will notify the Merchant at least 30 days in advance through an in-app notice or the Merchant's registered email address. If the Merchant objects, the Merchant may uninstall the App, in which case data will be deleted in accordance with Section 8.

Section 05

Security Measures

  1. 1.Encryption in transit: The App accepts HTTPS connections only. Communications with Shopify and Resend are also encrypted with TLS.
  2. 2.Encryption at rest: The database is kept on an encrypted Fly.io volume, and automatic snapshots are encrypted as well. Authorization data for external AI integrations is additionally encrypted with AES-GCM.
  3. 3.Minimal storage: Shipping addresses and phone numbers are not stored. Order webhooks are reduced to the fields used for processing, stored temporarily, and deleted after processing.
  4. 4.Access restriction: Administrative access to the production environment is limited to our operators. The admin screens are available only to staff authenticated by Shopify.
  5. 5.Access logging: Views of packing slips (showing addresses and phone numbers) and downloads of customer data exports are recorded with staff ID, count and time, and kept for 365 days (the personal data itself is not recorded).
  6. 6.Separation of production and test data: Testing is done in a separate hosting environment, a separate database, and a separate Shopify app with development stores; production data is not used for testing.
  7. 7.Authentication: Operator accounts use strong passwords and have two-step authentication enabled.
Section 06

Merchant Instructions and Cooperation

  1. 1.We treat the App's settings and the Merchant's actions through Shopify as instructions for processing.
  2. 2.When a buyer requests access, correction or deletion, we respond through Shopify's customers/data_request and customers/redact. Disclosed data can be downloaded for 7 days from "Customer data requests" in the admin screens.
Section 07

Notification of Personal Data Breaches

  1. 1.When we become aware of a personal data breach or a suspected breach, we will notify Shopify within 24 hours.
  2. 2.We will notify affected Merchants without undue delay and no later than 72 hours after becoming aware, with the following to the extent known: when and what happened, the data affected and the estimated number of records, the measures taken, actions the Merchant needs to take, and our contact. Follow-up information will be sent as it becomes available.
  3. 3.Notifications will be sent to the email address registered for the Merchant's Shopify store.
  4. 4.We contain, investigate, recover from and prevent recurrence of incidents according to our internal incident response procedure, and keep records of them.
Section 08

Deletion at Termination

  1. 1.When the Merchant uninstalls the App, we delete that store's data upon receipt of the event. The same applies when we receive shop/redact.
  2. 2.Copies remaining in automatic snapshots are removed within 5 days at most. In all cases, all copies are erased within 30 days of uninstallation.
  3. 3.We may retain anonymous aggregates that contain no personal data and do not identify the store.
Section 09

Audit Cooperation

  1. 1.At the Merchant's request, we will provide information demonstrating compliance with this Agreement (this Agreement, retention periods, a description of security measures, and the number of access records).
  2. 2.On-site audits are subject to prior written agreement, 30 days' notice, and a reasonable scope and frequency (at most once a year), at the Merchant's expense.
Section 10

International Transfers

Data is in principle processed in Japan (Fly.io Tokyo region, Resend Tokyo region). Some sub-processors are headquartered in the United States and may access data from abroad for maintenance and incident response. For buyer data from the EEA and the UK, transfers rely on standard contractual clauses (SCCs) with sub-processors or other lawful transfer mechanisms.

Section 11

Order of Precedence

If this Agreement and the Terms of Service conflict regarding the handling of personal data, this Agreement prevails.

End of document