Data Processing Addendum
Version 1.0, effective October 10, 2026. Sub-processors: honesttag.com/subprocessors.
Version: 1.0 Processor: HonestTag Inc, a Delaware corporation (Delaware file number 10752109) ("HonestTag," "Processor," "we," "us"). Address: 8 The Green, Ste B, Dover, DE 19901, USA. Privacy contact: support@honesttag.com
1. Preamble, Structure, and Acceptance
1.1 Relationship to the Terms of Service
This Data Processing Addendum, including its Annexes and Exhibits (collectively, the "DPA"), forms part of and is incorporated by reference into the HonestTag Terms of Service at https://honesttag.com/terms (the "Agreement") between HonestTag and the merchant that installs or uses the HonestTag Shopify app and the HonestTag edge measurement service (the "Service"). The merchant is referred to as "Merchant," "Controller," or "you."
This DPA governs the Processing by HonestTag of Personal Data relating to Merchant's website visitors, shoppers, and customers ("Shopper Data") that HonestTag Processes on behalf of and under the instructions of Merchant in providing the Service. For Shopper Data HonestTag acts as a Processor and, under U.S. state law, a service provider or processor.
This DPA does not cover Personal Data for which HonestTag is itself the controller (for example, the contact and account data of Merchant's staff who use HonestTag, visitors to honesttag.com, and prospects). That Processing is governed by the HonestTag Privacy Policy at https://honesttag.com/privacy.
1.2 Two-Document Architecture
- HonestTag Privacy Policy: HonestTag as controller of its own website, prospect, and merchant-account data; and
- This DPA: HonestTag as processor of Shopper Data on Merchant's behalf.
1.3 Acceptance
By installing the HonestTag app from the Shopify App Store, or otherwise using the Service, after this DPA is published, Merchant accepts this DPA as part of the Agreement. No signature is required. If Merchant's counsel requires a countersigned copy, Merchant may request one at support@honesttag.com; it will contain the same terms as the published version in force. A Merchant that does not agree to this DPA must not install or use the Service.
1.4 Business Use
The Service is designed for businesses and is not offered for personal or household use. Nothing in this DPA creates obligations owed by HonestTag directly to any individual Shopper, except where Data Protection Law or the Standard Contractual Clauses give Data Subjects third-party-beneficiary rights.
2. Definitions
Capitalized terms not defined here have the meaning given in the Agreement or in applicable Data Protection Law.
- "Data Protection Law" means all laws and regulations applicable to the Processing of Personal Data under the Agreement, including: (a) Regulation (EU) 2016/679 ("EU GDPR"); (b) the EU GDPR as it forms part of the law of England and Wales, Scotland, and Northern Ireland ("UK GDPR"), together with the Data Protection Act 2018; (c) the Swiss Federal Act on Data Protection of 25 September 2020 ("FADP"); (d) the ePrivacy Directive 2002/58/EC as transposed nationally, and the UK Privacy and Electronic Communications Regulations 2003; (e) the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"); and (f) the other U.S. state comprehensive consumer privacy laws listed in Exhibit B, each as amended or replaced from time to time.
- "Personal Data," "Controller," "Processor," "Data Subject," "Processing," "Personal Data Breach," and "Supervisory Authority" have the meanings given in the EU GDPR; equivalent terms under other Data Protection Law (for example "personal information," "business," "service provider," "consumer") are read accordingly.
- "Shopper Data" means Personal Data relating to Merchant's website visitors, shoppers, and customers that HonestTag Processes on Merchant's behalf, as described in Annex I.
- "Documented Instructions" has the meaning in Section 4.1.
- "Sub-processor" means any third party engaged by HonestTag that Processes Shopper Data on HonestTag's behalf.
- "Ad Platform Recipient" means an advertising, analytics, or marketing destination that Merchant connects to the Service and to which HonestTag transmits data at Merchant's configured instruction (at the date of this version: Google Ads, Meta, Klaviyo, Microsoft Advertising, TikTok, Google Analytics 4, Pinterest, Snapchat, Reddit and OpenAI Ads). Ad Platform Recipients are not Sub-processors (Section 8.6).
- "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
- "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, template Addendum B.1.0, issued by the UK Information Commissioner and laid before Parliament under section 119A of the Data Protection Act 2018, or any version that replaces it.
- "TOMs" means the technical and organizational measures in Annex II.
3. Roles and Scope
3.1 Role Allocation
| Data category | Merchant | HonestTag |
|---|---|---|
| Shopper Data (visitor, click, consent, order data) | Controller | Processor |
| Data of Merchant's staff who use HonestTag | Controller (of its personnel) | Controller (independent) |
| Aggregated, de-identified service telemetry (Section 6.3) | n/a | Controller (independent) |
| honesttag.com visitor and prospect data | n/a | Controller |
3.2 Scope
This DPA applies to all Processing of Shopper Data by HonestTag under the Agreement. Each party is responsible for its own compliance with Data Protection Law: Merchant, as Controller, for the lawfulness of its instructions and of the data it makes available; HonestTag, as Processor, for following those instructions and for its Processor obligations.
3.3 Affiliates
Merchant enters into this DPA for itself and, where Data Protection Law requires, for its affiliates that use the Service under Merchant's account. Merchant represents that it is authorized to bind them, remains responsible for their acts and omissions under this DPA, and coordinates all communications with HonestTag for them.
4. Documented Instructions
4.1 Instructions Defined
HonestTag Processes Shopper Data only on Merchant's documented instructions, including with regard to transfers of Personal Data to a third country or an international organisation, unless required to do so by Union, Member State or UK law to which HonestTag is subject; in such a case HonestTag will inform Merchant of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest. Merchant's documented instructions ("Documented Instructions") are:
(a) this DPA and the Agreement; (b) Merchant's configuration of the Service through the HonestTag app and onboarding, including which Ad Platform Recipients are connected and which optional features are turned on (for example browse-event forwarding to an Ad Platform Recipient, and the Klaviyo profile match described in Annex I), and Merchant's Shopify Customer Privacy configuration as Shopify reports it to the Service; and (c) any further written instructions the parties agree.
Merchant acknowledges that its app configuration and its Shopify Customer Privacy settings are the operative instructions on when identifiers are collected and transmitted to Ad Platform Recipients.
4.2 Lawfulness of Instructions
HonestTag will immediately inform Merchant if, in its opinion, an instruction infringes Data Protection Law (without any obligation to review the lawfulness of Merchant's instructions generally), and may suspend the affected Processing until the instruction is confirmed, changed, or withdrawn.
4.3 Legally Required Processing
If Data Protection Law requires HonestTag to Process Shopper Data other than on Merchant's instructions, HonestTag will inform Merchant of that requirement before Processing, unless that law prohibits such notice on important grounds of public interest.
5. Merchant Obligations and How Consent Works in the Service
5.1 Lawful Basis, Notices, and Consent
Merchant, as Controller, represents, warrants, and undertakes that it will, and has all rights needed to:
(a) establish and maintain a valid lawful basis for the collection and Processing of Shopper Data through the Service, and for each transmission to an Ad Platform Recipient it connects;
(b) give Shoppers all required privacy notices, including that HonestTag collects advertising click identifiers and order data for advertising measurement and transmits conversion data to the Ad Platform Recipients Merchant has connected;
(c) obtain and keep all consents required by Data Protection Law and ePrivacy rules (including for storing or reading the ht_vid cookie on the Shopper's device) before any Processing that requires consent, through a consent mechanism that reports its result to Shopify's Customer Privacy API; and
(d) describe the tracking performed through the Service in Merchant's own privacy policy.
5.2 How the Service Uses Consent Signals
HonestTag does not collect consent itself and does not decide whether consent is legally required. The Service behaves as follows, and Merchant configures its consent mechanism with this behaviour in mind:
(a) Storefront pixel. The HonestTag Web Pixel reads the consent state that Shopify's Customer Privacy API reports and listens for consent changes. When the Shopper has refused marketing or analytics processing, the pixel sets no ht_vid cookie and sends nothing. Where Shopify reports no refusal (including where Merchant's Shopify settings do not require consent in the Shopper's region, where the Shopper has not yet answered, or where the store exposes no consent state), the pixel runs and records the consent state it observed.
(b) Browser privacy signals. HonestTag's pixel event endpoints and its first-party proxy discard requests that carry a Global Privacy Control (Sec-GPC: 1) or Do Not Track (DNT: 1) signal. Orders that Shopify sends to HonestTag by webhook carry no such browser signal and are not filtered by it.
(c) EEA, UK and Swiss orders. For an order whose shipping address, else billing address, else customer default address is in an EU or EEA member state, the United Kingdom or Switzerland, HonestTag transmits the conversion to Ad Platform Recipients only when the order links (by checkout token, order ID, a recorded click ID or, for a phone or draft order where the matching in Section 6.2(b) is on, the buyer's matched email address or phone number) to a visitor that the HonestTag pixel observed without a refusal. Otherwise it transmits nothing for that order and records the block in the order's evidence record. This gate checks for that linked visitor; it does not read the consent state recorded for the visitor, so a visitor recorded as default_allow or unknown passes it.
(d) Signals passed on. For such orders, Google Ads receives Google Consent Mode v2 ad_user_data and ad_personalization values: granted where the Shopper's recorded state is an explicit grant, or where Merchant's Shopify settings require consent in the Shopper's region and Shopify reported it given, and unspecified otherwise. Meta receives Limited Data Use flags derived from buyer location (for these orders, and for buyers in 18 U.S. states: California, Virginia, Colorado, Connecticut, Utah, Oregon, Texas, Montana, New Jersey, Delaware, Iowa, Tennessee, Indiana, New Hampshire, Nebraska, Minnesota, Maryland and Kentucky). Other Ad Platform Recipients receive no consent field. Browse events (add to cart, checkout started, payment info added), which Merchant may choose to forward, come only from visitors the pixel observed without a refusal; they are not subject to the gate in (c) and carry no Consent Mode values.
(e) Later refusals. The pixel receives a Shopper's consent answer only when Shopify reports it. A refusal given after an earlier grant stops the pixel from sending anything further, but HonestTag does not receive that refusal; an order later linked to that visitor is treated according to the state HonestTag last recorded (which expires 90 days after it was recorded).
(f) Gate settings. The gate in (c) is on by default. It is controlled by two settings of the store's configuration (whether EEA, UK and Swiss orders require a consenting visitor, and how a visitor with no recorded consent answer is treated); either one turns the gate off. Neither setting can be changed from the app; HonestTag changes them for a store only on Merchant's written instruction. In that case Merchant warrants that a compliant consent mechanism exists elsewhere and is solely responsible for it.
(g) Merchant's responsibility. Because the gate in (c) relies on the pixel having run without a refusal, it is only as strict as Merchant's consent configuration. Where Data Protection Law requires prior consent before the ht_vid cookie is set or a conversion is transmitted, Merchant must configure its consent mechanism and Shopify Customer Privacy so that Shopify reports a refusal until consent is given.
5.3 Indemnity
Merchant will defend and indemnify HonestTag against third-party claims, and against fines and penalties imposed by a Supervisory Authority, to the extent caused by Merchant's breach of Section 5.1 or 5.2, including a failure to establish a lawful basis, give a required notice, or configure consent. This indemnity is subject to Section 16.
5.4 Children's Data
The Service is not directed at children. Merchant will not deploy the Service on stores directed at children, and warrants that its use of the Service complies with all laws on minors' data.
6. Purpose Limitation and Use Restrictions
6.1 No Own Use
HonestTag will not Process Shopper Data for any purpose other than providing the Service under Merchant's Documented Instructions. In particular, HonestTag will not:
(a) sell, rent, or license Shopper Data, or disclose it to any third party except to Sub-processors under Section 8 and to Ad Platform Recipients at Merchant's instruction; (b) use Shopper Data for its own advertising, marketing, or profiling; (c) combine Shopper Data of one Merchant with that of another Merchant, or with data from other sources, except as strictly necessary to provide the Service and as Data Protection Law permits; (d) buy, enrich, or supplement Shopper Data with third-party identity data; (e) use device fingerprinting other than the short-lived lookup described in Annex I (a hash of the request's IP address, user agent, language header and TLS handshake length, kept 30 minutes and used only to re-find the same device's random visitor ID before its cookie is set); or (f) use Shopper Data to train artificial-intelligence or machine-learning models, or provide it to any third party for that purpose.
6.2 Raw Contact Data and Pseudonymization
HonestTag minimizes raw Shopper contact data:
(a) Shopify order webhooks can carry the buyer's name, email address, telephone number, postal addresses, browser IP address and user agent. HonestTag writes the original webhook payload to an access-controlled durable inbox before acknowledging it, and clears the payload when processing succeeds. A payload whose processing fails for good is kept up to 30 days for recovery and diagnosis, and is cleared sooner by customers/redact and shop/redact.
(b) During processing, the email address and telephone number (and, for Meta, first name, last name, city, state or province, postal code and country) are hashed with SHA-256 in memory. The hashed values travel in HonestTag's delivery queue until delivery is made or abandoned (at most 4 days) and are not stored anywhere else, with one exception. Phone and draft order matching and offline order delivery (point-of-sale and subscription renewal orders) are off by default and are not settings in the app; HonestTag turns either on for a store only on Merchant's written instruction. While either is on, for an order linked to a tracked visit HonestTag keeps a store-keyed HMAC of the hashed email address and of the hashed telephone number, with that visit's visitor ID, for 365 days, so that a later phone, draft, point-of-sale or renewal order by the same buyer can be linked to the visit. The stored key is neither the address nor the hash any Ad Platform Recipient receives.
(c) Data that HonestTag transmits unhashed, because the Ad Platform Recipient matches on it as given, is listed in Annex I, Part B.4. It includes the browser IP address and user agent (sent to Meta, TikTok, OpenAI Ads, Pinterest, Snapchat and Reddit) and, where Merchant uses the Klaviyo profile match, the order's email address sent once per visitor to Merchant's own Klaviyo account.
6.3 Aggregated Telemetry
HonestTag may create and use aggregated, de-identified telemetry about the operation of the Service (for example request volumes, error rates, latency and feature-usage counts) solely to operate, secure, debug, and improve the Service. For that telemetry HonestTag acts as an independent controller. It (a) contains nothing that identifies any Shopper, and HonestTag will not attempt to re-identify it; and (b) is kept and used only in aggregated or de-identified form. HonestTag will contractually bind any recipient to the same restrictions, consistent with Cal. Civ. Code §1798.140(m).
6.4 Sensitive Data
The Service is not designed to Process special categories of Personal Data under Article 9 EU GDPR and UK GDPR, data relating to criminal convictions, government identifiers, financial-account credentials, or health information (collectively, "Sensitive Data"). Merchant will not configure or use the Service to send Sensitive Data to HonestTag. Product names in order line items are transmitted as described in Annex I; Merchant is responsible for assessing whether its product catalog could reveal Sensitive Data about a Shopper and, if so, for not connecting the Ad Platform Recipients that receive product names.
7. Confidentiality of Personnel
HonestTag will ensure that every person it authorizes to Process Shopper Data (a) is bound by a contractual or statutory duty of confidentiality; (b) Processes Shopper Data only on Documented Instructions; and (c) is instructed in data protection and security. Access is limited to personnel who need it to provide or support the Service.
8. Security and Sub-processors
8.1 Technical and Organizational Measures
HonestTag will implement and maintain the TOMs in Annex II, designed to ensure a level of security appropriate to the risk, taking into account Article 32 EU GDPR and UK GDPR.
8.2 Updates
HonestTag may update the TOMs from time to time provided that updates do not reduce the overall level of protection of Shopper Data.
8.3 General Authorization
Merchant gives HonestTag general written authorization to engage Sub-processors. The current Sub-processors are listed in Annex III and at https://honesttag.com/subprocessors.
8.4 Notice and Objection
HonestTag will notify Merchant at least thirty (30) days before adding or replacing a Sub-processor, by email to the email address associated with Merchant's Shopify installation and by updating https://honesttag.com/subprocessors. Merchant may object on reasonable data-protection grounds within that period, before the new Sub-processor is engaged, by writing to support@honesttag.com. The parties will try in good faith to resolve the objection. If they cannot, Merchant may terminate the Agreement before the change takes effect by uninstalling the app, which ends billing under the Agreement. If Merchant does not terminate, the change takes effect for Merchant's Shopper Data on the date given in the notice. This does not limit Merchant's rights under Clauses 12 and 16 of the SCCs.
8.5 Flow-Down and Liability
HonestTag will impose on each Sub-processor, by written contract, data-protection obligations that offer at least the same level of protection as this DPA, to the extent applicable to the services the Sub-processor provides. HonestTag remains fully liable to Merchant for each Sub-processor's performance of those obligations. One exception is stated in Annex III: Discord, HonestTag's internal notification channel, is listed because a support-request notice can carry Shopper Data that Merchant writes into a support request, and Discord offers no data processing agreement for these messages. HonestTag does not use Discord for any other Shopper Data, masks Shopper identifiers in its operations alerts as Annex III describes, and remains fully liable to Merchant for this Processing as if Discord were bound by such a contract. Merchant can avoid it by leaving Shopper Data out of support requests.
8.6 Ad Platform Recipients
Ad Platform Recipients receive data because Merchant connects them and instructs HonestTag to deliver to them. Each acts under Merchant's own agreement with it, as an independent controller or as Merchant's processor according to that agreement. They are not HonestTag's Sub-processors, Section 8.5 does not apply to them, and Merchant is responsible for its relationship and terms with each. Criteo, where connected, is read-only: HonestTag reads reporting from it and sends it nothing.
9. Data Subject Requests
9.1 Forwarding and Assistance
Taking into account the nature of the Processing, HonestTag will (a) promptly notify Merchant if HonestTag receives a request from a Shopper to exercise rights under Data Protection Law about Shopper Data, and not respond to it except on Merchant's instructions or as legally required; and (b) give Merchant reasonable technical and organizational assistance, insofar as possible, to respond to such requests.
9.2 Automated Handling
Shopify's mandatory privacy webhooks give effect to access and deletion requests that Merchant receives through Shopify, as described in Section 10.
10. Shopify Mandatory Privacy Webhooks
HonestTag acts automatically on Shopify's mandatory privacy webhooks. Each arrives at HonestTag's endpoint and is authenticated by HMAC with the app secret; a webhook that fails verification is rejected with HTTP 401 and not processed.
| Shopify topic | What HonestTag does | Timing |
|---|---|---|
customers/data_request |
Compiles the data linkable to the listed orders (order-to-visitor links, reported conversion values, held-order records, post-purchase survey answers, click, consent, browser-ID (Meta _fbp, Google Analytics client ID), Klaviyo profile-ID, email-engagement and browsing-context stores, the order's evidence record including the order name, the customer's cohort record and, where the matching in Section 6.2(b) is on, the number of match keys kept for the visitor) into a report stored in Cloudflare R2. Emails Merchant that the request arrived, naming the Shopify request, customer and order IDs. HonestTag support then sends the report file to Merchant's installation email address. Neither the email nor the report contains the customer's email address or phone number. Recorded in an audit log. |
Report available within Shopify's 30-day response period |
customers/redact |
Deletes, for each listed order and its linked visitor: the order-to-visitor link, reported conversion value, evidence record and its indexes, survey answers, held-order records, per-order delivery-deduplication state, and the visitor's click, first-click, consent, browser-ID, Klaviyo profile-ID, email-engagement and browsing-context stores; the match keys in Section 6.2(b) for those visitors and for the customer's email address and phone number, and any staff-browser marker on those visitors; the customer's cohort record; any data-request report naming those orders or that customer; any failed webhook payload naming them; and queues removal of the customer's rows from the store's raw event archive. Not reached by this deletion, and expiring on their own schedule (Annex I, Part B.6): the device lookup (30 minutes), delivery queue messages (at most 4 days), the click-ID reverse lookup and checkout link (90 and 30 days), key-value delivery-deduplication markers (30 days), the order money record kept for refund netting (order total, tax, customer type and order date, keyed by order ID, without the visitor ID; 180 days), the live event log (72 hours), Analytics Engine rows (three months), and backups (30 days). Recorded in an audit log with counts. | On receipt; archive removal at the next archive pass |
shop/redact |
Full store purge: first an isolated safety snapshot of the store's database rows (if the snapshot fails, the purge stops and is retried); then the store's Durable Object state that the purge can name (the live event log, and the per-order delivery records of orders whose reported conversion value is still kept; Section 15.3 names the rest), every store-prefixed key-value entry and the global entries that name the store, the store's R2 objects (including the raw event archive and data-request reports), the store's database rows (including credentials and installations), and the store's processed webhook payloads; then caches are cleared. Records kept afterwards are listed in Annex I, Part B.6. Not performed if the store has reinstalled the app since uninstalling. Recorded in an audit log. | Shopify sends it about 48 hours after uninstall; performed on receipt |
app/uninstalled |
Marks the installation revoked and the account cancelled, deletes the stored Shopify access credentials, revokes HonestTag's access grants at connected Ad Platform Recipients where they allow it, and ends billing. Other data is kept until shop/redact so the purge can find it. |
On receipt |
This automation supplements, and does not limit, Merchant's rights under Sections 9 and 15.
11. Personal Data Breach
11.1 Notification
HonestTag will notify Merchant of a Personal Data Breach affecting Merchant's Shopper Data without undue delay, and in any event within forty-eight (48) hours after HonestTag becomes aware of it, by email to the email address associated with Merchant's Shopify installation.
11.2 Content and Assistance
The notification will include, to the extent known (and may be given in phases): (a) the nature of the breach, including where possible the categories and approximate number of Data Subjects and records concerned; (b) its likely consequences; (c) the measures taken or proposed to address it and mitigate its effects; and (d) a contact point for more information.
HonestTag will assist Merchant, taking into account the nature of the Processing and the information available to HonestTag, in meeting Merchant's obligations under Articles 32 to 36 EU GDPR and UK GDPR, including Merchant's notification of the breach to the Supervisory Authority (Article 33) and communication to Data Subjects (Article 34). Section 11.5 does not delay that assistance.
11.3 Exclusions
Unsuccessful attempts that do not compromise the security of Shopper Data, such as failed log-in attempts, pings and port scans, are not Personal Data Breaches.
11.4 No Admission
Notifying or responding to a Personal Data Breach is not an admission of fault or liability.
11.5 Communications
The parties will cooperate in good faith on external communications about a breach. Neither will make a public statement naming the other in connection with it without prior consultation, except where law requires.
12. DPIAs and Prior Consultation
Taking into account the nature of the Processing and the information available to it, HonestTag will give Merchant reasonable assistance with data protection impact assessments (Article 35 EU GDPR and UK GDPR) and prior consultations with a Supervisory Authority (Article 36), including by providing the information in this DPA and its Annexes.
13. Audits and Compliance Information
13.1 Information
HonestTag will make available to Merchant all information necessary to demonstrate compliance with Article 28 EU GDPR and UK GDPR and this DPA.
13.2 Audits
HonestTag will allow for and contribute to audits, including inspections, at reasonable intervals or if there are indications of non-compliance, conducted by Merchant or by an independent auditor Merchant mandates. To make them efficient: (a) Merchant gives reasonable prior written notice (normally thirty (30) days, shorter where a Supervisory Authority requires it or a Personal Data Breach has occurred); (b) audits take place during normal business hours, without unreasonable disruption and under confidentiality; (c) HonestTag may offer documentation (this DPA, its Annexes, written answers, and any third-party reports it holds), which Merchant may accept in place of, or before, an inspection; and (d) HonestTag charges no fee as a condition of an audit. The results of any audit will be made available to the competent Supervisory Authority on request. Nothing in this Section limits Clause 8.9 of the SCCs.
13.3 Records and Regulators
HonestTag will keep a record of its Processing activities as Article 30(2) EU GDPR and UK GDPR require, and will tell Merchant, where lawful, of any Supervisory Authority inquiry relating to Merchant's Shopper Data.
13.4 Legal Demands
If HonestTag receives a legally binding demand for Shopper Data, it will, unless legally prohibited, notify Merchant before disclosure, disclose only the minimum required, and where lawful seek to challenge or redirect the demand to Merchant.
14. International Data Transfers
14.1 Where Processing Takes Place
HonestTag is established in the United States and runs the Service on Cloudflare's global network; Shopper Data may be processed in any location where Cloudflare or another Sub-processor in Annex III operates. HonestTag does not offer EU-only or country-specific data residency.
14.2 EU Standard Contractual Clauses
Where Processing under this DPA involves a transfer of Personal Data from Merchant to HonestTag that requires appropriate safeguards under Chapter V of the EU GDPR, the SCCs are incorporated into this DPA by reference and apply as follows:
- Module Two (controller to processor) applies where Merchant is a Controller. Module Three (processor to processor) applies where Merchant is itself a processor acting for a third-party controller (for example an agency running a client's store).
- Merchant is the data exporter and HonestTag the data importer.
- Where Module Three applies, Merchant warrants that its controller has authorised these terms and the Sub-processors in Annex III, will pass that controller's instructions to HonestTag before Processing, and will identify that controller to HonestTag before Processing; that controller is then recorded with Merchant's details for Annex I, Part A.
- Clause 7 (docking clause): included.
- Clause 9(a): Option 2 (general written authorization); the time period is thirty (30) days, as in Section 8.4.
- Clause 11(a): the optional language is not used.
- Clause 13(a) and Annex I, Part C: the competent Supervisory Authority is the one that applies under Clause 13(a) to Merchant as data exporter: the authority responsible for Merchant if Merchant is established in an EU Member State; otherwise the authority of the Member State in which Merchant's Article 27 representative is established, or, if Merchant need not appoint one, the authority of a Member State in which the Data Subjects concerned are located.
- Clause 17: Option 1; the SCCs are governed by the law of Ireland.
- Clause 18(b): the courts of Ireland.
- Annexes I, II and III of the SCCs are completed with Annex I (Part A parties, Part B description, Part C competent Supervisory Authority), Annex II (technical and organisational measures) and Annex III (Sub-processors) of this DPA.
If the SCCs conflict with this DPA, the SCCs prevail for the transfers they govern. Where Merchant is not established in the EEA and HonestTag's Processing of the Shopper Data is itself subject to the EU GDPR under its Article 3(2), HonestTag complies with the EU GDPR directly as a processor; the European Commission has stated that the 2021 SCCs are not designed for an importer already subject to the GDPR, and the parties will enter any transfer instrument the Commission adopts for that case. Until then, the obligations of Module Two or Module Three that are not already obligations under the EU GDPR apply between the parties as contractual terms for that Processing.
14.3 Onward Transfers to Sub-processors
HonestTag engages Sub-processors only on terms meeting Clause 9(b) of the SCCs, except Discord as Section 8.5 states, for which HonestTag remains fully liable as Clause 9(c) of the SCCs provides, and makes onward transfers only as Clause 8.8 of Module Two or of Module Three permits.
14.4 United Kingdom
Where a transfer is a restricted transfer under the UK GDPR, the UK Addendum is incorporated into this DPA and completed as follows:
- Table 1 (Parties): the parties, their details and contacts are those in Annex I, Part A, with Merchant as exporter (its legal name, address and contact email being those recorded in Merchant's Shopify account, and its official registration number, if any, the one Merchant gives HonestTag in writing) and HonestTag as importer; the start date is the date Merchant accepts this DPA under Section 1.3.
- Table 2 (Selected SCCs): the Approved EU SCCs, including the Appendix Information, are the SCCs as incorporated and completed in Section 14.2.
- Table 3 (Appendix Information): Annexes I, II and III of this DPA.
- Table 4 (Ending the Addendum): both the Importer and the Exporter may end the UK Addendum as provided in its Section 19.
- Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.
For UK transfers, Section 15 of the UK Addendum amends the SCCs, including Clauses 13, 17 and 18 (supervision by the Information Commissioner, the law of England and Wales, and the courts of England and Wales).
14.5 Switzerland
Where a transfer is subject to the FADP, the SCCs as completed in Section 14.2 apply with these adaptations: (a) references to the EU GDPR are to be understood as references to the FADP; (b) the competent Supervisory Authority in Annex I, Part C is the Federal Data Protection and Information Commissioner (FDPIC) insofar as the transfer is governed by the FADP, in parallel with the EU authority where the EU GDPR also applies; (c) the term "Member State" is not to be interpreted so as to exclude Data Subjects in Switzerland from suing for their rights in their place of habitual residence (Switzerland) under Clause 18(c); and (d) Clause 17's governing law, the law of Ireland, is a law that allows and grants third-party-beneficiary rights.
14.6 Transfer Assessments and Government Access
HonestTag will give Merchant the information reasonably needed for Merchant's transfer impact assessment. If HonestTag receives a request from a public authority for access to Shopper Data, it will act as Clause 15 of the SCCs requires, whether or not the SCCs apply: notify Merchant where permitted, review the legality of the request, challenge it where there are reasonable grounds, and disclose only the minimum necessary.
14.7 Article 27 Representatives
HonestTag has no establishment in the EU, the EEA, the United Kingdom or Switzerland. Where Article 27 EU GDPR or UK GDPR requires HonestTag to designate a representative, HonestTag will do so in writing and publish the representative's name and contact address at https://honesttag.com/dpa. Supervisory Authorities and Data Subjects may address the representative in addition to or instead of HonestTag.
15. Deletion and Return
15.1 At the End of the Service
At the end of the Service, at Merchant's choice, HonestTag will delete all Shopper Data or return it to Merchant and then delete existing copies, within thirty (30) days, save as Section 15.3 provides, and will certify the deletion to Merchant in writing. Merchant makes its choice by writing to support@honesttag.com; if Merchant makes no choice, HonestTag deletes. In the ordinary case the trigger is Shopify's shop/redact webhook, which Shopify sends about 48 hours after uninstall and which HonestTag performs on receipt (Section 10). A written deletion request is carried out even if the store later reinstalls the app. Before uninstalling, Merchant can export its reports from the app, and a return is provided as a machine-readable export.
15.2 Ongoing Expiry
Independently of termination, Shopper Data expires on the schedules in Annex I, Part B.6. Every key-value entry in HonestTag's measurement data store carries an automatic expiry. The per-order delivery records kept in Durable Objects have no expiry (Annex I, Part B.6).
15.3 What Remains After Deletion
Ordinary backups, the pre-purge safety snapshot and database point-in-time recovery history are isolated, access-restricted, not used for the Service, and deleted within 30 days; a restore skips every store deleted, and every customer erased, since the backup was taken. Pseudonymous rows in Cloudflare Analytics Engine cannot be deleted individually and expire on Cloudflare's schedule (three months); HonestTag restricts access to them and does not use them for the Service after deletion. Per-order delivery records that deletion does not reach remain stored: those of refunds, cancellations and order edits, and those of orders whose reported conversion value record has expired. Each holds an order or refund ID and the Ad Platform Recipients it was delivered to, and no visitor ID or contact data; HonestTag does not use them for the Service after deletion. Otherwise HonestTag keeps Shopper Data after deletion only where Union, Member State or UK law, or other law to which HonestTag is subject, requires storage, and then only for that purpose and under this DPA's confidentiality and security obligations.
16. Liability
16.1 Limitation
Except as Section 16.2 provides, each party's liability arising out of or relating to this DPA is subject to the exclusions and limitations of liability in the Agreement, and counts toward them.
16.2 What the Limitation Does Not Cover
The exclusions and limitations in the Agreement do not apply to, and nothing in this DPA or the Agreement limits: (a) either party's liability under Clause 12 of the SCCs (including liability between the parties and the right to claim back), or under the UK Addendum; (b) liability to Data Subjects under Article 82 EU GDPR or UK GDPR, and claims for contribution between the parties under Article 82(5) EU GDPR or UK GDPR; or (c) any liability that cannot be limited under Data Protection Law.
17. Changes, Precedence, Survival and Governing Law
17.1 Changes
HonestTag may update this DPA to reflect changes in the Service or in Data Protection Law. For a change that materially reduces Merchant's rights or the protection of Shopper Data, HonestTag will give Merchant at least thirty (30) days' notice by email and in the app before it takes effect; Merchant may stop using the Service before then if it does not agree. A change required by law may take effect sooner, with notice as soon as reasonably possible. Each version is published at https://honesttag.com/dpa with its version number and effective date, and earlier versions remain available there. HonestTag will not change the selected SCC modules, the options elected in Section 14.2, or the UK and Swiss completion in Sections 14.4 and 14.5, except to adopt a replacement instrument issued by the European Commission, the UK Information Commissioner or the FDPIC.
17.2 Precedence
In a conflict: (1) the SCCs and the UK Addendum, for the transfers they govern; then (2) this DPA, including its Annexes and Exhibits; then (3) the rest of the Agreement and the HonestTag Privacy Policy. This DPA controls over the Agreement on the Processing of Personal Data. In particular, the Agreement's no-third-party-beneficiaries clause does not apply to the rights Clause 3 of the SCCs or the UK Addendum give Data Subjects, and the Agreement's arbitration and forum clauses do not apply to a claim by a Data Subject, to a claim for contribution under Article 82(5) EU GDPR or UK GDPR, or to a dispute under the SCCs or the UK Addendum, which Clause 18 of the SCCs and Section 15 of the UK Addendum govern.
17.3 Survival
This DPA's obligations survive termination of the Agreement for as long as HonestTag Processes Shopper Data for Merchant.
17.4 Governing Law
Except where the SCCs, the UK Addendum, or Data Protection Law require otherwise, this DPA is governed by the law that governs the Agreement.
Annex I: Description of the Processing
A. Parties
- Data exporter / Controller: Merchant, the Shopify store that installs the Service. Name, address and contact email: as recorded in Merchant's Shopify account; official registration number, if any: as Merchant gives it to HonestTag in writing. Activities: operating an online store and measuring its advertising. Role: controller (or processor, for Module Three). Signature and date: acceptance under Section 1.3.
- Data importer / Processor: HonestTag Inc, 8 The Green, Ste B, Dover, DE 19901, USA. Contact: support@honesttag.com. Activities: providing the Service. Role: processor. Signature and date: publication of this DPA and Merchant's acceptance under Section 1.3. Article 27 representatives, where designated: as published at https://honesttag.com/dpa.
B. Description of the Processing and Transfer
B.1 Nature and Subject Matter
First-party advertising measurement: recording advertising click identifiers through the HonestTag Shopify Web Pixel, Merchant's first-party tracking domain or HonestTag's headless tag; linking them to Merchant's orders received through Shopify webhooks; classifying orders (including first-click and new-customer attribution); reporting conversions server-side to the Ad Platform Recipients Merchant connects, with the fields in Part B.4; correcting or recording refunds and cancellations where the recipient supports it; and producing reports and per-order evidence for Merchant.
B.2 Purpose
To provide the Service to Merchant under its Documented Instructions.
B.3 Categories of Data Subjects
Visitors to Merchant's online store, and Merchant's shoppers and customers.
B.4 Categories of Personal Data and Where They Go
| Data | Nature | Sent to |
|---|---|---|
Random visitor ID (ht_vid cookie; random, not derived from the Shopper) |
Pseudonymous | Meta (external_id, unhashed) and Klaviyo (external_id, unhashed); TikTok, OpenAI Ads, Pinterest, Snapchat and Reddit (SHA-256) |
Shopify customer ID, hashed (SHA-256; never sent raw), or the hashed email address, as Meta's external_id where an order has no visitor ID |
Pseudonymized identifier | Meta |
Advertising click IDs (gclid, gbraid, wbraid, fbclid, ttclid, msclkid, epik, ScCid, rdt_cid, OpenAI and Klaviyo click IDs) with timestamps, landing page path and UTM parameters |
Pseudonymous | Each click ID to the platform that issued it, as recorded |
Browser IDs set by other tags on Merchant's store: Meta _fbp, Google Analytics client ID |
Pseudonymous | Meta (fbp), Google Analytics 4 (client_id) |
| Email and telephone number | Hashed (SHA-256) in memory; raw only in the webhook inbox (Section 6.2) | Hashed: Google Ads, Meta, Microsoft Advertising (goals with enhanced conversions only), TikTok, OpenAI Ads, Pinterest, Snapchat, Reddit |
| Email address, unhashed | Personal | Merchant's own Klaviyo account, once per visitor, where Merchant's plan includes and Merchant has connected Klaviyo (profile match); HonestTag keeps only the Klaviyo profile ID |
| First name, last name, city, state or province, postal code, country | Hashed (SHA-256) | Meta |
| Browser IP address and user agent (as recorded by Shopify on the order; for browse events the Shopper's request) | Personal | Meta, TikTok, OpenAI Ads, Pinterest, Snapchat, Reddit; not Google Ads, Microsoft Advertising, Google Analytics 4 or Klaviyo |
| Device lookup hash: SHA-256 of IP address, user agent, language header and TLS handshake length | Pseudonymous, 30 minutes | Not sent |
| Match keys: a store-keyed HMAC of the hashed email address and of the hashed telephone number, with the visitor ID (only while phone and draft order matching or offline order delivery is on, Section 6.2(b)) | Pseudonymized identifier | Not sent |
| Consent state observed by the pixel; GPC/DNT handling; Consent Mode and Limited Data Use values | Consent signal | Google Ads (Consent Mode), Meta (Limited Data Use) |
| Order and checkout identifiers, order name (the store's order number, such as #1001) | Pseudonymous link | Order ID to the platforms receiving purchases; order name to Klaviyo |
| Order value (or, where Merchant has it turned on for Meta or Snapchat, gross profit computed from Merchant's own product-cost upload), currency, shipping, new or returning customer classification | Commercial | Ad Platform Recipients receiving the conversion |
| Order line items: product IDs, quantities, prices; product names; discount code and amount | Commercial | Product IDs to Meta, TikTok, Pinterest, Snapchat, Reddit, OpenAI Ads, Google Analytics 4; product names to Google Analytics 4, Reddit, OpenAI Ads; discount code and amount to Meta |
| Buyer country and region (from shipping, else billing, else default address) | Derived location | Used for the consent gate (Section 5.2) and Meta Limited Data Use |
| Page-view and click event rows: visitor ID, order ID, click ID values, page path and referring URL, country, region and city as Cloudflare derives them, IP address truncated to its network prefix (/24 or /48), network operator, device and browser type | Pseudonymous | Not sent |
| Email and SMS engagement events read from Merchant's Klaviyo account (message, flow and campaign IDs, timestamps); the profile email is never requested | Pseudonymous | Not sent |
| Post-purchase survey answers (free text is stripped of email addresses and phone numbers) | Pseudonymous | Not sent |
| Original Shopify webhook payload (may include name, email, phone, addresses, IP address, user agent) | Personal | Not sent; held only as in Section 6.2(a) |
No special-category data is intentionally Processed (Section 6.4).
B.6 Retention
Every key-value entry expires automatically; the periods below run from the entry's last write unless stated.
| Store | Contents | Retention |
|---|---|---|
| Device lookup (key-value and Durable Object) | device hash to visitor ID | 30 minutes |
ht_vid cookie (Shopper's browser) |
random visitor ID | 365 days |
| Click stores | click IDs, timestamps, landing path, campaign | 90 days; first click 365 days |
| Click-ID reverse lookup | click ID to visitor ID | 90 days |
| Consent state | state observed by the pixel | 90 days from last change |
| Browser IDs | Meta _fbp, Google Analytics client ID |
90 days |
| Browsing context | collection and product pages viewed | 30 days |
| Email engagement touches | message and campaign IDs, timestamps | 90 days; Klaviyo event IDs already read, 7 days |
| Klaviyo profile map | visitor ID to Klaviyo profile ID | 365 days |
| Checkout and order links | checkout token or order ID to visitor ID | 30 days / 90 days |
| Match keys (only while phone and draft order matching or offline order delivery is on) | store-keyed HMAC of the hashed email address and telephone number, to visitor ID | 365 days; deleted by customers/redact and shop/redact |
| Staff-browser markers (only while phone and draft order matching is on) | visitor IDs of browsers Merchant's staff marked with a one-time link, so their visits are never attributed | 400 days |
| Reported conversion values | value, currency, classification, visitor ID, Microsoft click ID | 180 days |
| Order money records (refund netting) | order total, tax, customer type (new or returning), order date, keyed by order ID; no visitor ID | 180 days; not reached by customers/redact (Section 10) |
| Order count | order count and Shopify customer ID | 7 days |
| Evidence records and indexes | per-order attribution proof, order names | 400 days on paid plans; none kept on the free Mirror |
| Survey answers | answers to the post-purchase survey | 400 days |
| Orders held while delivery is paused | order ID, click IDs, value, currency, classification; no email, phone, IP address or user agent | 100 days |
| Delivery deduplication markers (key-value) | order and event IDs already delivered | 30 days |
| Google pending-ingest markers | order ID and Google click ID | 7 days |
| Per-order delivery records (Durable Object) | which platforms an order, refund, cancellation or order edit was delivered to, keyed by order or refund ID; no visitor ID or contact data | No expiry. Deleted by customers/redact for the orders it names and by shop/redact for orders whose reported conversion value is still kept; records of refunds, cancellations and order edits, and of older orders, are reached by neither (Section 15.3) |
| Live event log (Durable Object) | processing events, order names, visitor-ID prefixes | 72 hours on paid plans; none kept on the free Mirror |
| Delivery queue messages | conversion payloads including hashed identifiers, IP address and user agent | Until delivered or abandoned; at most 4 days |
| Webhook inbox (database) | original Shopify payload | Payload cleared on successful processing; failed payloads up to 30 days |
| Customer cohort record (database) | keyed hash of the customer, first order's country, region, product and discount code | Until customers/redact or shop/redact |
| Order ID registers (database) | order IDs counted for billing; orders erased by customers/redact |
Until shop/redact |
| Analytics Engine event rows (Cloudflare) | Part B.4 event rows | Three months (Cloudflare's retention; no per-row deletion) |
| Raw event archive (Cloudflare R2) | copy of the store's event rows, referring URLs without query strings | 25 months; a customer's rows removed on customers/redact; deleted on shop/redact |
| Archive copy (second Cloudflare R2 bucket) | copy of the raw event archive and data-request reports | Follows the archive at the next nightly copy |
| Data-request reports (Cloudflare R2) | Section 10 reports | Until customers/redact names them or shop/redact |
| Pre-purge safety snapshot (Cloudflare R2) | the store's database rows at shop/redact |
30 days, access-restricted, not used for the Service |
| Ordinary backups (Cloudflare R2) | nightly backup of the measurement data store and of the database | 30 days |
| Database point-in-time recovery (Cloudflare D1) | database history | 30 days |
Records kept after shop/redact |
audit-log entries with the store identifier removed (entries naming a person are redacted and deleted after 30 days); partner commission records; error records with the store identifier removed | Audit and commission records as law and accounting require; error records 90 days |
B.5 Frequency
Continuous, for the duration of the Agreement.
B.7 Sub-processors
As listed in Annex III, for the purposes stated there.
C. Competent Supervisory Authority
- EU transfers: the Supervisory Authority determined under Clause 13(a) of the SCCs for Merchant as data exporter (Section 14.2).
- UK transfers: the UK Information Commissioner; Clause 13 of the SCCs is replaced as Section 15 of the UK Addendum provides.
- Swiss transfers: the FDPIC insofar as the transfer is governed by the FADP and, where the transfer is also governed by the EU GDPR, the authority under the first bullet insofar as the transfer is governed by the EU GDPR (parallel supervision).
Annex II: Technical and Organizational Measures
These describe the measures in place at the date of this version. HonestTag holds no security certification.
- Encryption in transit: TLS 1.2 or higher.
- Encryption at rest: data is stored encrypted at rest on Cloudflare's infrastructure.
- Credential protection: Merchant API and OAuth credentials are envelope-encrypted before storage in the database and are kept out of application logs.
- Minimization of contact data: raw email and phone are hashed in memory for delivery and are not stored in attribution stores or queues; the original webhook payload is held as described in Section 6.2(a).
- Pseudonymous identifiers: the visitor ID is random; the device lookup hash lives 30 minutes; IP addresses in event rows are truncated to the network prefix.
- Tenant isolation: each store's storage access goes through a tenant-scoped layer that prefixes every key-value entry, scopes every database query and stamps every queue message with the store's identifier; the few documented exceptions (request routing and the privacy purge) are listed in the code and reviewed.
- Automatic expiry: the tenant-scoped storage layer refuses any key-value write without an expiry.
- Webhook authentication: every Shopify webhook, including the mandatory privacy webhooks, is HMAC-verified and rejected with HTTP 401 on failure.
- Access control: production access is limited to HonestTag's authorized personnel on a need-to-know basis, and the administrative interface sits behind Cloudflare Access, which the Service verifies again on every request (people sign in with single sign-on; HonestTag's own scripts use an Access service token).
- Logging: privacy-webhook actions, purge counts and administrative actions are written to an audit log.
- Consent enforcement: a single consent gate in the pixel's send path; GPC and DNT handling at the event endpoints; one server-side gate, shared by every Ad Platform Recipient, for EEA, UK and Swiss orders (Section 5.2).
- Deletion safety: a store purge takes an isolated snapshot first and stops if the snapshot fails; restores skip deleted stores and erased customers.
- Secure development and change control: every change must pass an automated test suite (including privacy tests for the consent gate, webhook HMAC rejection, and the effects of
customers/redact,customers/data_requestandshop/redact) on the exact version deployed, before it reaches production. - Backups and recovery: nightly backups kept 30 days in Cloudflare R2 (the database copy is restore-tested before it is stored; the key-value snapshot is checked against its manifest); a second copy of the raw event archive in a separate R2 bucket; database point-in-time recovery for 30 days.
- Incident response: HonestTag monitors the Service with automated alerts and follows a written security incident response policy (detection, containment including credential rotation and rollback, assessment of scope from audit records, notification, and a written post-mortem). Suspected Personal Data Breaches are handled and notified under Section 11.
Annex III: Sub-processors
Current list and change notices: https://honesttag.com/subprocessors.
| Sub-processor (address; data-protection contact) | What it does for the Service | Shopper Data it receives | Location / transfer basis |
|---|---|---|---|
| Cloudflare, Inc. (101 Townsend Street, San Francisco, CA 94107, USA; Data Protection Officer, dpo@cloudflare.com) | Runs the entire Service: compute (Workers), storage (KV, D1, R2, Durable Objects, Queues, Analytics Engine) and network | All Shopper Data in Annex I | Global network, United States; EU-U.S. Data Privacy Framework (including its UK Extension and the Swiss-U.S. framework) and SCCs per Cloudflare's data processing terms |
| Plus Five Five, Inc., trading as Resend (2261 Market Street #5039, San Francisco, CA 94114, USA; privacy@resend.com) | Sends HonestTag's email to Merchant, including the data-request notice | Shopify customer ID and order IDs named in a data-request notice | United States; SCCs and the EU-U.S. Data Privacy Framework (including its UK Extension), per Resend's data processing addendum |
| Google LLC (Google Workspace) (address: the notices address in Google's Workspace agreement; Google Workspace data protection team, https://support.google.com/a/contact/googlecloud_dpr) | Hosts HonestTag's support mailbox, from which data-request reports are sent to Merchant | Data-request reports (Section 10) and anything Merchant includes in support correspondence | United States; under Google's Cloud Data Processing Addendum, which Google incorporates into its Google Workspace agreement (https://cloud.google.com/terms/data-processing-addendum) |
| Discord Inc. (444 De Haro Street #200, San Francisco, CA 94107, USA; privacy@discord.com; Data Protection Officer, dpo@discord.com) | HonestTag's internal notification channel: operations alerts about merchant stores, and notices of the support requests HonestTag receives by email or through its website support form | None intentionally. An operations alert names the store and the problem, with Shopper identifiers masked as described below. A support notice states who wrote, their store and what they asked, so it carries any Shopper Data Merchant includes in a support request | United States: Discord states that it processes and stores information on servers located in the United States and that it is the data controller of its users' personal information (Discord Netherlands BV for users in the EEA) (Discord Privacy Policy, effective September 29, 2025). No data processing agreement with Discord covers these messages |
HonestTag offers no merchant support chat on Discord; Discord is used only as the internal notification channel described above. An operations alert names the store (its HonestTag tenant ID and shop domain) and the problem. Before sending it, HonestTag replaces Shopify order and customer IDs, visitor IDs, email addresses, every order name in Shopify's default format (#1001), any word after the word "order" that contains a digit, and every other word that contains a digit, which covers a store's own order-name format (Shopify's examples: EN1001, 1001-A). Kept are dates and times, HTTP status codes, durations, a bare number of one or two digits, and HonestTag's own support codes, record IDs and hashes. An order name left in an alert is therefore possible only where a store's order names are a bare one- or two-digit number, or a number followed only by a time unit, and the alert does not call it an order. Shopify is not a Sub-processor: it is the platform on which Merchant runs its store and from which the Service receives order data, under Merchant's own agreement with Shopify. Ad Platform Recipients are not Sub-processors (Section 8.6).
Exhibit A: CCPA Service-Provider Terms
This Exhibit applies where HonestTag Processes personal information subject to the CCPA on Merchant's behalf. HonestTag is a service provider and Merchant the business.
- Business purpose. HonestTag Processes personal information only to perform the Service, the business purpose described in Annex I, and for no other purpose.
- No selling or sharing by HonestTag. HonestTag will not sell or share personal information, as those terms are defined in the CCPA. Transmissions to Ad Platform Recipients are made at Merchant's direction as part of the Service; Merchant is responsible for any notice and opt-out the CCPA requires for them, including honoring opt-outs of sale or sharing.
- No use outside the relationship. HonestTag will not retain, use, or disclose personal information for any purpose other than the business purpose, or outside the direct business relationship between HonestTag and Merchant.
- No combining. HonestTag will not combine personal information received from or on behalf of Merchant with personal information from other sources, except as the CCPA permits for a business purpose.
- Compliance. HonestTag will comply with the CCPA's obligations applicable to service providers and provide the same level of privacy protection the CCPA requires of businesses.
- Notice. HonestTag will notify Merchant if it determines it can no longer meet its CCPA obligations; Merchant may then take reasonable and appropriate steps to stop and remediate unauthorized use.
- Merchant oversight. Merchant may take reasonable and appropriate steps to ensure HonestTag uses personal information consistently with the business's CCPA obligations, including through Section 13.
- De-identified data. HonestTag will not attempt to re-identify de-identified data and maintains it as Cal. Civ. Code §1798.140(m) requires.
- Assistance. HonestTag will reasonably assist Merchant in responding to verifiable consumer requests to know, delete, and correct.
- Sub-processors. HonestTag engages Sub-processors only under written contracts binding them to the same obligations, except Discord as Section 8.5 states, for which HonestTag remains fully liable.
Exhibit B: Other U.S. State Privacy Laws
This Exhibit applies where HonestTag Processes personal data subject to a U.S. state comprehensive consumer privacy law under which HonestTag is a processor and Merchant a controller, including the laws of Colorado, Connecticut, Utah, Virginia, Delaware, Indiana, Iowa, Montana, Oregon, Tennessee, Texas and New Jersey, and any other such law that takes effect and applies to the Processing.
Under each such law, HonestTag will:
- Process personal data only on Merchant's documented instructions and to provide the Service;
- ensure each person Processing the data is bound by a duty of confidentiality;
- implement the measures in Annex II;
- assist Merchant with consumer rights requests, data protection assessments, and security incident notification (Sections 9, 11 and 12);
- engage Sub-processors only under written contracts imposing the same obligations, except Discord as Section 8.5 states, for which HonestTag remains fully liable, after giving Merchant the opportunity to object (Section 8.4);
- make available the information reasonably needed to demonstrate compliance, and allow assessments as in Section 13; and
- at Merchant's direction, delete or return personal data at the end of the Service (Section 15), unless law requires retention.
Terms in this Exhibit have the meanings given in the applicable state law. Where a law requires additional terms, those terms are incorporated by reference and control for Processing subject to that law.
Article 27 representatives
HonestTag has not designated a representative under Article 27 of the EU GDPR or the UK GDPR. When it does, the name and contact address appear here.