Data Processing Addendum

Version 1.0, effective October 10, 2026. Sub-processors: honesttag.com/subprocessors.

Version: 1.0 Processor: HonestTag Inc, a Delaware corporation (Delaware file number 10752109) ("HonestTag," "Processor," "we," "us"). Address: 8 The Green, Ste B, Dover, DE 19901, USA. Privacy contact: support@honesttag.com


1. Preamble, Structure, and Acceptance

1.1 Relationship to the Terms of Service

This Data Processing Addendum, including its Annexes and Exhibits (collectively, the "DPA"), forms part of and is incorporated by reference into the HonestTag Terms of Service at https://honesttag.com/terms (the "Agreement") between HonestTag and the merchant that installs or uses the HonestTag Shopify app and the HonestTag edge measurement service (the "Service"). The merchant is referred to as "Merchant," "Controller," or "you."

This DPA governs the Processing by HonestTag of Personal Data relating to Merchant's website visitors, shoppers, and customers ("Shopper Data") that HonestTag Processes on behalf of and under the instructions of Merchant in providing the Service. For Shopper Data HonestTag acts as a Processor and, under U.S. state law, a service provider or processor.

This DPA does not cover Personal Data for which HonestTag is itself the controller (for example, the contact and account data of Merchant's staff who use HonestTag, visitors to honesttag.com, and prospects). That Processing is governed by the HonestTag Privacy Policy at https://honesttag.com/privacy.

1.2 Two-Document Architecture

1.3 Acceptance

By installing the HonestTag app from the Shopify App Store, or otherwise using the Service, after this DPA is published, Merchant accepts this DPA as part of the Agreement. No signature is required. If Merchant's counsel requires a countersigned copy, Merchant may request one at support@honesttag.com; it will contain the same terms as the published version in force. A Merchant that does not agree to this DPA must not install or use the Service.

1.4 Business Use

The Service is designed for businesses and is not offered for personal or household use. Nothing in this DPA creates obligations owed by HonestTag directly to any individual Shopper, except where Data Protection Law or the Standard Contractual Clauses give Data Subjects third-party-beneficiary rights.


2. Definitions

Capitalized terms not defined here have the meaning given in the Agreement or in applicable Data Protection Law.


3. Roles and Scope

3.1 Role Allocation

Data category Merchant HonestTag
Shopper Data (visitor, click, consent, order data) Controller Processor
Data of Merchant's staff who use HonestTag Controller (of its personnel) Controller (independent)
Aggregated, de-identified service telemetry (Section 6.3) n/a Controller (independent)
honesttag.com visitor and prospect data n/a Controller

3.2 Scope

This DPA applies to all Processing of Shopper Data by HonestTag under the Agreement. Each party is responsible for its own compliance with Data Protection Law: Merchant, as Controller, for the lawfulness of its instructions and of the data it makes available; HonestTag, as Processor, for following those instructions and for its Processor obligations.

3.3 Affiliates

Merchant enters into this DPA for itself and, where Data Protection Law requires, for its affiliates that use the Service under Merchant's account. Merchant represents that it is authorized to bind them, remains responsible for their acts and omissions under this DPA, and coordinates all communications with HonestTag for them.


4. Documented Instructions

4.1 Instructions Defined

HonestTag Processes Shopper Data only on Merchant's documented instructions, including with regard to transfers of Personal Data to a third country or an international organisation, unless required to do so by Union, Member State or UK law to which HonestTag is subject; in such a case HonestTag will inform Merchant of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest. Merchant's documented instructions ("Documented Instructions") are:

(a) this DPA and the Agreement; (b) Merchant's configuration of the Service through the HonestTag app and onboarding, including which Ad Platform Recipients are connected and which optional features are turned on (for example browse-event forwarding to an Ad Platform Recipient, and the Klaviyo profile match described in Annex I), and Merchant's Shopify Customer Privacy configuration as Shopify reports it to the Service; and (c) any further written instructions the parties agree.

Merchant acknowledges that its app configuration and its Shopify Customer Privacy settings are the operative instructions on when identifiers are collected and transmitted to Ad Platform Recipients.

4.2 Lawfulness of Instructions

HonestTag will immediately inform Merchant if, in its opinion, an instruction infringes Data Protection Law (without any obligation to review the lawfulness of Merchant's instructions generally), and may suspend the affected Processing until the instruction is confirmed, changed, or withdrawn.

4.3 Legally Required Processing

If Data Protection Law requires HonestTag to Process Shopper Data other than on Merchant's instructions, HonestTag will inform Merchant of that requirement before Processing, unless that law prohibits such notice on important grounds of public interest.


5. Merchant Obligations and How Consent Works in the Service

5.1 Lawful Basis, Notices, and Consent

Merchant, as Controller, represents, warrants, and undertakes that it will, and has all rights needed to:

(a) establish and maintain a valid lawful basis for the collection and Processing of Shopper Data through the Service, and for each transmission to an Ad Platform Recipient it connects; (b) give Shoppers all required privacy notices, including that HonestTag collects advertising click identifiers and order data for advertising measurement and transmits conversion data to the Ad Platform Recipients Merchant has connected; (c) obtain and keep all consents required by Data Protection Law and ePrivacy rules (including for storing or reading the ht_vid cookie on the Shopper's device) before any Processing that requires consent, through a consent mechanism that reports its result to Shopify's Customer Privacy API; and (d) describe the tracking performed through the Service in Merchant's own privacy policy.

5.2 How the Service Uses Consent Signals

HonestTag does not collect consent itself and does not decide whether consent is legally required. The Service behaves as follows, and Merchant configures its consent mechanism with this behaviour in mind:

(a) Storefront pixel. The HonestTag Web Pixel reads the consent state that Shopify's Customer Privacy API reports and listens for consent changes. When the Shopper has refused marketing or analytics processing, the pixel sets no ht_vid cookie and sends nothing. Where Shopify reports no refusal (including where Merchant's Shopify settings do not require consent in the Shopper's region, where the Shopper has not yet answered, or where the store exposes no consent state), the pixel runs and records the consent state it observed. (b) Browser privacy signals. HonestTag's pixel event endpoints and its first-party proxy discard requests that carry a Global Privacy Control (Sec-GPC: 1) or Do Not Track (DNT: 1) signal. Orders that Shopify sends to HonestTag by webhook carry no such browser signal and are not filtered by it. (c) EEA, UK and Swiss orders. For an order whose shipping address, else billing address, else customer default address is in an EU or EEA member state, the United Kingdom or Switzerland, HonestTag transmits the conversion to Ad Platform Recipients only when the order links (by checkout token, order ID, a recorded click ID or, for a phone or draft order where the matching in Section 6.2(b) is on, the buyer's matched email address or phone number) to a visitor that the HonestTag pixel observed without a refusal. Otherwise it transmits nothing for that order and records the block in the order's evidence record. This gate checks for that linked visitor; it does not read the consent state recorded for the visitor, so a visitor recorded as default_allow or unknown passes it. (d) Signals passed on. For such orders, Google Ads receives Google Consent Mode v2 ad_user_data and ad_personalization values: granted where the Shopper's recorded state is an explicit grant, or where Merchant's Shopify settings require consent in the Shopper's region and Shopify reported it given, and unspecified otherwise. Meta receives Limited Data Use flags derived from buyer location (for these orders, and for buyers in 18 U.S. states: California, Virginia, Colorado, Connecticut, Utah, Oregon, Texas, Montana, New Jersey, Delaware, Iowa, Tennessee, Indiana, New Hampshire, Nebraska, Minnesota, Maryland and Kentucky). Other Ad Platform Recipients receive no consent field. Browse events (add to cart, checkout started, payment info added), which Merchant may choose to forward, come only from visitors the pixel observed without a refusal; they are not subject to the gate in (c) and carry no Consent Mode values. (e) Later refusals. The pixel receives a Shopper's consent answer only when Shopify reports it. A refusal given after an earlier grant stops the pixel from sending anything further, but HonestTag does not receive that refusal; an order later linked to that visitor is treated according to the state HonestTag last recorded (which expires 90 days after it was recorded). (f) Gate settings. The gate in (c) is on by default. It is controlled by two settings of the store's configuration (whether EEA, UK and Swiss orders require a consenting visitor, and how a visitor with no recorded consent answer is treated); either one turns the gate off. Neither setting can be changed from the app; HonestTag changes them for a store only on Merchant's written instruction. In that case Merchant warrants that a compliant consent mechanism exists elsewhere and is solely responsible for it. (g) Merchant's responsibility. Because the gate in (c) relies on the pixel having run without a refusal, it is only as strict as Merchant's consent configuration. Where Data Protection Law requires prior consent before the ht_vid cookie is set or a conversion is transmitted, Merchant must configure its consent mechanism and Shopify Customer Privacy so that Shopify reports a refusal until consent is given.

5.3 Indemnity

Merchant will defend and indemnify HonestTag against third-party claims, and against fines and penalties imposed by a Supervisory Authority, to the extent caused by Merchant's breach of Section 5.1 or 5.2, including a failure to establish a lawful basis, give a required notice, or configure consent. This indemnity is subject to Section 16.

5.4 Children's Data

The Service is not directed at children. Merchant will not deploy the Service on stores directed at children, and warrants that its use of the Service complies with all laws on minors' data.


6. Purpose Limitation and Use Restrictions

6.1 No Own Use

HonestTag will not Process Shopper Data for any purpose other than providing the Service under Merchant's Documented Instructions. In particular, HonestTag will not:

(a) sell, rent, or license Shopper Data, or disclose it to any third party except to Sub-processors under Section 8 and to Ad Platform Recipients at Merchant's instruction; (b) use Shopper Data for its own advertising, marketing, or profiling; (c) combine Shopper Data of one Merchant with that of another Merchant, or with data from other sources, except as strictly necessary to provide the Service and as Data Protection Law permits; (d) buy, enrich, or supplement Shopper Data with third-party identity data; (e) use device fingerprinting other than the short-lived lookup described in Annex I (a hash of the request's IP address, user agent, language header and TLS handshake length, kept 30 minutes and used only to re-find the same device's random visitor ID before its cookie is set); or (f) use Shopper Data to train artificial-intelligence or machine-learning models, or provide it to any third party for that purpose.

6.2 Raw Contact Data and Pseudonymization

HonestTag minimizes raw Shopper contact data:

(a) Shopify order webhooks can carry the buyer's name, email address, telephone number, postal addresses, browser IP address and user agent. HonestTag writes the original webhook payload to an access-controlled durable inbox before acknowledging it, and clears the payload when processing succeeds. A payload whose processing fails for good is kept up to 30 days for recovery and diagnosis, and is cleared sooner by customers/redact and shop/redact. (b) During processing, the email address and telephone number (and, for Meta, first name, last name, city, state or province, postal code and country) are hashed with SHA-256 in memory. The hashed values travel in HonestTag's delivery queue until delivery is made or abandoned (at most 4 days) and are not stored anywhere else, with one exception. Phone and draft order matching and offline order delivery (point-of-sale and subscription renewal orders) are off by default and are not settings in the app; HonestTag turns either on for a store only on Merchant's written instruction. While either is on, for an order linked to a tracked visit HonestTag keeps a store-keyed HMAC of the hashed email address and of the hashed telephone number, with that visit's visitor ID, for 365 days, so that a later phone, draft, point-of-sale or renewal order by the same buyer can be linked to the visit. The stored key is neither the address nor the hash any Ad Platform Recipient receives. (c) Data that HonestTag transmits unhashed, because the Ad Platform Recipient matches on it as given, is listed in Annex I, Part B.4. It includes the browser IP address and user agent (sent to Meta, TikTok, OpenAI Ads, Pinterest, Snapchat and Reddit) and, where Merchant uses the Klaviyo profile match, the order's email address sent once per visitor to Merchant's own Klaviyo account.

6.3 Aggregated Telemetry

HonestTag may create and use aggregated, de-identified telemetry about the operation of the Service (for example request volumes, error rates, latency and feature-usage counts) solely to operate, secure, debug, and improve the Service. For that telemetry HonestTag acts as an independent controller. It (a) contains nothing that identifies any Shopper, and HonestTag will not attempt to re-identify it; and (b) is kept and used only in aggregated or de-identified form. HonestTag will contractually bind any recipient to the same restrictions, consistent with Cal. Civ. Code §1798.140(m).

6.4 Sensitive Data

The Service is not designed to Process special categories of Personal Data under Article 9 EU GDPR and UK GDPR, data relating to criminal convictions, government identifiers, financial-account credentials, or health information (collectively, "Sensitive Data"). Merchant will not configure or use the Service to send Sensitive Data to HonestTag. Product names in order line items are transmitted as described in Annex I; Merchant is responsible for assessing whether its product catalog could reveal Sensitive Data about a Shopper and, if so, for not connecting the Ad Platform Recipients that receive product names.


7. Confidentiality of Personnel

HonestTag will ensure that every person it authorizes to Process Shopper Data (a) is bound by a contractual or statutory duty of confidentiality; (b) Processes Shopper Data only on Documented Instructions; and (c) is instructed in data protection and security. Access is limited to personnel who need it to provide or support the Service.


8. Security and Sub-processors

8.1 Technical and Organizational Measures

HonestTag will implement and maintain the TOMs in Annex II, designed to ensure a level of security appropriate to the risk, taking into account Article 32 EU GDPR and UK GDPR.

8.2 Updates

HonestTag may update the TOMs from time to time provided that updates do not reduce the overall level of protection of Shopper Data.

8.3 General Authorization

Merchant gives HonestTag general written authorization to engage Sub-processors. The current Sub-processors are listed in Annex III and at https://honesttag.com/subprocessors.

8.4 Notice and Objection

HonestTag will notify Merchant at least thirty (30) days before adding or replacing a Sub-processor, by email to the email address associated with Merchant's Shopify installation and by updating https://honesttag.com/subprocessors. Merchant may object on reasonable data-protection grounds within that period, before the new Sub-processor is engaged, by writing to support@honesttag.com. The parties will try in good faith to resolve the objection. If they cannot, Merchant may terminate the Agreement before the change takes effect by uninstalling the app, which ends billing under the Agreement. If Merchant does not terminate, the change takes effect for Merchant's Shopper Data on the date given in the notice. This does not limit Merchant's rights under Clauses 12 and 16 of the SCCs.

8.5 Flow-Down and Liability

HonestTag will impose on each Sub-processor, by written contract, data-protection obligations that offer at least the same level of protection as this DPA, to the extent applicable to the services the Sub-processor provides. HonestTag remains fully liable to Merchant for each Sub-processor's performance of those obligations. One exception is stated in Annex III: Discord, HonestTag's internal notification channel, is listed because a support-request notice can carry Shopper Data that Merchant writes into a support request, and Discord offers no data processing agreement for these messages. HonestTag does not use Discord for any other Shopper Data, masks Shopper identifiers in its operations alerts as Annex III describes, and remains fully liable to Merchant for this Processing as if Discord were bound by such a contract. Merchant can avoid it by leaving Shopper Data out of support requests.

8.6 Ad Platform Recipients

Ad Platform Recipients receive data because Merchant connects them and instructs HonestTag to deliver to them. Each acts under Merchant's own agreement with it, as an independent controller or as Merchant's processor according to that agreement. They are not HonestTag's Sub-processors, Section 8.5 does not apply to them, and Merchant is responsible for its relationship and terms with each. Criteo, where connected, is read-only: HonestTag reads reporting from it and sends it nothing.


9. Data Subject Requests

9.1 Forwarding and Assistance

Taking into account the nature of the Processing, HonestTag will (a) promptly notify Merchant if HonestTag receives a request from a Shopper to exercise rights under Data Protection Law about Shopper Data, and not respond to it except on Merchant's instructions or as legally required; and (b) give Merchant reasonable technical and organizational assistance, insofar as possible, to respond to such requests.

9.2 Automated Handling

Shopify's mandatory privacy webhooks give effect to access and deletion requests that Merchant receives through Shopify, as described in Section 10.


10. Shopify Mandatory Privacy Webhooks

HonestTag acts automatically on Shopify's mandatory privacy webhooks. Each arrives at HonestTag's endpoint and is authenticated by HMAC with the app secret; a webhook that fails verification is rejected with HTTP 401 and not processed.

Shopify topic What HonestTag does Timing
customers/data_request Compiles the data linkable to the listed orders (order-to-visitor links, reported conversion values, held-order records, post-purchase survey answers, click, consent, browser-ID (Meta _fbp, Google Analytics client ID), Klaviyo profile-ID, email-engagement and browsing-context stores, the order's evidence record including the order name, the customer's cohort record and, where the matching in Section 6.2(b) is on, the number of match keys kept for the visitor) into a report stored in Cloudflare R2. Emails Merchant that the request arrived, naming the Shopify request, customer and order IDs. HonestTag support then sends the report file to Merchant's installation email address. Neither the email nor the report contains the customer's email address or phone number. Recorded in an audit log. Report available within Shopify's 30-day response period
customers/redact Deletes, for each listed order and its linked visitor: the order-to-visitor link, reported conversion value, evidence record and its indexes, survey answers, held-order records, per-order delivery-deduplication state, and the visitor's click, first-click, consent, browser-ID, Klaviyo profile-ID, email-engagement and browsing-context stores; the match keys in Section 6.2(b) for those visitors and for the customer's email address and phone number, and any staff-browser marker on those visitors; the customer's cohort record; any data-request report naming those orders or that customer; any failed webhook payload naming them; and queues removal of the customer's rows from the store's raw event archive. Not reached by this deletion, and expiring on their own schedule (Annex I, Part B.6): the device lookup (30 minutes), delivery queue messages (at most 4 days), the click-ID reverse lookup and checkout link (90 and 30 days), key-value delivery-deduplication markers (30 days), the order money record kept for refund netting (order total, tax, customer type and order date, keyed by order ID, without the visitor ID; 180 days), the live event log (72 hours), Analytics Engine rows (three months), and backups (30 days). Recorded in an audit log with counts. On receipt; archive removal at the next archive pass
shop/redact Full store purge: first an isolated safety snapshot of the store's database rows (if the snapshot fails, the purge stops and is retried); then the store's Durable Object state that the purge can name (the live event log, and the per-order delivery records of orders whose reported conversion value is still kept; Section 15.3 names the rest), every store-prefixed key-value entry and the global entries that name the store, the store's R2 objects (including the raw event archive and data-request reports), the store's database rows (including credentials and installations), and the store's processed webhook payloads; then caches are cleared. Records kept afterwards are listed in Annex I, Part B.6. Not performed if the store has reinstalled the app since uninstalling. Recorded in an audit log. Shopify sends it about 48 hours after uninstall; performed on receipt
app/uninstalled Marks the installation revoked and the account cancelled, deletes the stored Shopify access credentials, revokes HonestTag's access grants at connected Ad Platform Recipients where they allow it, and ends billing. Other data is kept until shop/redact so the purge can find it. On receipt

This automation supplements, and does not limit, Merchant's rights under Sections 9 and 15.


11. Personal Data Breach

11.1 Notification

HonestTag will notify Merchant of a Personal Data Breach affecting Merchant's Shopper Data without undue delay, and in any event within forty-eight (48) hours after HonestTag becomes aware of it, by email to the email address associated with Merchant's Shopify installation.

11.2 Content and Assistance

The notification will include, to the extent known (and may be given in phases): (a) the nature of the breach, including where possible the categories and approximate number of Data Subjects and records concerned; (b) its likely consequences; (c) the measures taken or proposed to address it and mitigate its effects; and (d) a contact point for more information.

HonestTag will assist Merchant, taking into account the nature of the Processing and the information available to HonestTag, in meeting Merchant's obligations under Articles 32 to 36 EU GDPR and UK GDPR, including Merchant's notification of the breach to the Supervisory Authority (Article 33) and communication to Data Subjects (Article 34). Section 11.5 does not delay that assistance.

11.3 Exclusions

Unsuccessful attempts that do not compromise the security of Shopper Data, such as failed log-in attempts, pings and port scans, are not Personal Data Breaches.

11.4 No Admission

Notifying or responding to a Personal Data Breach is not an admission of fault or liability.

11.5 Communications

The parties will cooperate in good faith on external communications about a breach. Neither will make a public statement naming the other in connection with it without prior consultation, except where law requires.


12. DPIAs and Prior Consultation

Taking into account the nature of the Processing and the information available to it, HonestTag will give Merchant reasonable assistance with data protection impact assessments (Article 35 EU GDPR and UK GDPR) and prior consultations with a Supervisory Authority (Article 36), including by providing the information in this DPA and its Annexes.


13. Audits and Compliance Information

13.1 Information

HonestTag will make available to Merchant all information necessary to demonstrate compliance with Article 28 EU GDPR and UK GDPR and this DPA.

13.2 Audits

HonestTag will allow for and contribute to audits, including inspections, at reasonable intervals or if there are indications of non-compliance, conducted by Merchant or by an independent auditor Merchant mandates. To make them efficient: (a) Merchant gives reasonable prior written notice (normally thirty (30) days, shorter where a Supervisory Authority requires it or a Personal Data Breach has occurred); (b) audits take place during normal business hours, without unreasonable disruption and under confidentiality; (c) HonestTag may offer documentation (this DPA, its Annexes, written answers, and any third-party reports it holds), which Merchant may accept in place of, or before, an inspection; and (d) HonestTag charges no fee as a condition of an audit. The results of any audit will be made available to the competent Supervisory Authority on request. Nothing in this Section limits Clause 8.9 of the SCCs.

13.3 Records and Regulators

HonestTag will keep a record of its Processing activities as Article 30(2) EU GDPR and UK GDPR require, and will tell Merchant, where lawful, of any Supervisory Authority inquiry relating to Merchant's Shopper Data.

13.4 Legal Demands

If HonestTag receives a legally binding demand for Shopper Data, it will, unless legally prohibited, notify Merchant before disclosure, disclose only the minimum required, and where lawful seek to challenge or redirect the demand to Merchant.


14. International Data Transfers

14.1 Where Processing Takes Place

HonestTag is established in the United States and runs the Service on Cloudflare's global network; Shopper Data may be processed in any location where Cloudflare or another Sub-processor in Annex III operates. HonestTag does not offer EU-only or country-specific data residency.

14.2 EU Standard Contractual Clauses

Where Processing under this DPA involves a transfer of Personal Data from Merchant to HonestTag that requires appropriate safeguards under Chapter V of the EU GDPR, the SCCs are incorporated into this DPA by reference and apply as follows:

If the SCCs conflict with this DPA, the SCCs prevail for the transfers they govern. Where Merchant is not established in the EEA and HonestTag's Processing of the Shopper Data is itself subject to the EU GDPR under its Article 3(2), HonestTag complies with the EU GDPR directly as a processor; the European Commission has stated that the 2021 SCCs are not designed for an importer already subject to the GDPR, and the parties will enter any transfer instrument the Commission adopts for that case. Until then, the obligations of Module Two or Module Three that are not already obligations under the EU GDPR apply between the parties as contractual terms for that Processing.

14.3 Onward Transfers to Sub-processors

HonestTag engages Sub-processors only on terms meeting Clause 9(b) of the SCCs, except Discord as Section 8.5 states, for which HonestTag remains fully liable as Clause 9(c) of the SCCs provides, and makes onward transfers only as Clause 8.8 of Module Two or of Module Three permits.

14.4 United Kingdom

Where a transfer is a restricted transfer under the UK GDPR, the UK Addendum is incorporated into this DPA and completed as follows:

For UK transfers, Section 15 of the UK Addendum amends the SCCs, including Clauses 13, 17 and 18 (supervision by the Information Commissioner, the law of England and Wales, and the courts of England and Wales).

14.5 Switzerland

Where a transfer is subject to the FADP, the SCCs as completed in Section 14.2 apply with these adaptations: (a) references to the EU GDPR are to be understood as references to the FADP; (b) the competent Supervisory Authority in Annex I, Part C is the Federal Data Protection and Information Commissioner (FDPIC) insofar as the transfer is governed by the FADP, in parallel with the EU authority where the EU GDPR also applies; (c) the term "Member State" is not to be interpreted so as to exclude Data Subjects in Switzerland from suing for their rights in their place of habitual residence (Switzerland) under Clause 18(c); and (d) Clause 17's governing law, the law of Ireland, is a law that allows and grants third-party-beneficiary rights.

14.6 Transfer Assessments and Government Access

HonestTag will give Merchant the information reasonably needed for Merchant's transfer impact assessment. If HonestTag receives a request from a public authority for access to Shopper Data, it will act as Clause 15 of the SCCs requires, whether or not the SCCs apply: notify Merchant where permitted, review the legality of the request, challenge it where there are reasonable grounds, and disclose only the minimum necessary.

14.7 Article 27 Representatives

HonestTag has no establishment in the EU, the EEA, the United Kingdom or Switzerland. Where Article 27 EU GDPR or UK GDPR requires HonestTag to designate a representative, HonestTag will do so in writing and publish the representative's name and contact address at https://honesttag.com/dpa. Supervisory Authorities and Data Subjects may address the representative in addition to or instead of HonestTag.


15. Deletion and Return

15.1 At the End of the Service

At the end of the Service, at Merchant's choice, HonestTag will delete all Shopper Data or return it to Merchant and then delete existing copies, within thirty (30) days, save as Section 15.3 provides, and will certify the deletion to Merchant in writing. Merchant makes its choice by writing to support@honesttag.com; if Merchant makes no choice, HonestTag deletes. In the ordinary case the trigger is Shopify's shop/redact webhook, which Shopify sends about 48 hours after uninstall and which HonestTag performs on receipt (Section 10). A written deletion request is carried out even if the store later reinstalls the app. Before uninstalling, Merchant can export its reports from the app, and a return is provided as a machine-readable export.

15.2 Ongoing Expiry

Independently of termination, Shopper Data expires on the schedules in Annex I, Part B.6. Every key-value entry in HonestTag's measurement data store carries an automatic expiry. The per-order delivery records kept in Durable Objects have no expiry (Annex I, Part B.6).

15.3 What Remains After Deletion

Ordinary backups, the pre-purge safety snapshot and database point-in-time recovery history are isolated, access-restricted, not used for the Service, and deleted within 30 days; a restore skips every store deleted, and every customer erased, since the backup was taken. Pseudonymous rows in Cloudflare Analytics Engine cannot be deleted individually and expire on Cloudflare's schedule (three months); HonestTag restricts access to them and does not use them for the Service after deletion. Per-order delivery records that deletion does not reach remain stored: those of refunds, cancellations and order edits, and those of orders whose reported conversion value record has expired. Each holds an order or refund ID and the Ad Platform Recipients it was delivered to, and no visitor ID or contact data; HonestTag does not use them for the Service after deletion. Otherwise HonestTag keeps Shopper Data after deletion only where Union, Member State or UK law, or other law to which HonestTag is subject, requires storage, and then only for that purpose and under this DPA's confidentiality and security obligations.


16. Liability

16.1 Limitation

Except as Section 16.2 provides, each party's liability arising out of or relating to this DPA is subject to the exclusions and limitations of liability in the Agreement, and counts toward them.

16.2 What the Limitation Does Not Cover

The exclusions and limitations in the Agreement do not apply to, and nothing in this DPA or the Agreement limits: (a) either party's liability under Clause 12 of the SCCs (including liability between the parties and the right to claim back), or under the UK Addendum; (b) liability to Data Subjects under Article 82 EU GDPR or UK GDPR, and claims for contribution between the parties under Article 82(5) EU GDPR or UK GDPR; or (c) any liability that cannot be limited under Data Protection Law.


17. Changes, Precedence, Survival and Governing Law

17.1 Changes

HonestTag may update this DPA to reflect changes in the Service or in Data Protection Law. For a change that materially reduces Merchant's rights or the protection of Shopper Data, HonestTag will give Merchant at least thirty (30) days' notice by email and in the app before it takes effect; Merchant may stop using the Service before then if it does not agree. A change required by law may take effect sooner, with notice as soon as reasonably possible. Each version is published at https://honesttag.com/dpa with its version number and effective date, and earlier versions remain available there. HonestTag will not change the selected SCC modules, the options elected in Section 14.2, or the UK and Swiss completion in Sections 14.4 and 14.5, except to adopt a replacement instrument issued by the European Commission, the UK Information Commissioner or the FDPIC.

17.2 Precedence

In a conflict: (1) the SCCs and the UK Addendum, for the transfers they govern; then (2) this DPA, including its Annexes and Exhibits; then (3) the rest of the Agreement and the HonestTag Privacy Policy. This DPA controls over the Agreement on the Processing of Personal Data. In particular, the Agreement's no-third-party-beneficiaries clause does not apply to the rights Clause 3 of the SCCs or the UK Addendum give Data Subjects, and the Agreement's arbitration and forum clauses do not apply to a claim by a Data Subject, to a claim for contribution under Article 82(5) EU GDPR or UK GDPR, or to a dispute under the SCCs or the UK Addendum, which Clause 18 of the SCCs and Section 15 of the UK Addendum govern.

17.3 Survival

This DPA's obligations survive termination of the Agreement for as long as HonestTag Processes Shopper Data for Merchant.

17.4 Governing Law

Except where the SCCs, the UK Addendum, or Data Protection Law require otherwise, this DPA is governed by the law that governs the Agreement.


Annex I: Description of the Processing

A. Parties

B. Description of the Processing and Transfer

B.1 Nature and Subject Matter

First-party advertising measurement: recording advertising click identifiers through the HonestTag Shopify Web Pixel, Merchant's first-party tracking domain or HonestTag's headless tag; linking them to Merchant's orders received through Shopify webhooks; classifying orders (including first-click and new-customer attribution); reporting conversions server-side to the Ad Platform Recipients Merchant connects, with the fields in Part B.4; correcting or recording refunds and cancellations where the recipient supports it; and producing reports and per-order evidence for Merchant.

B.2 Purpose

To provide the Service to Merchant under its Documented Instructions.

B.3 Categories of Data Subjects

Visitors to Merchant's online store, and Merchant's shoppers and customers.

B.4 Categories of Personal Data and Where They Go

Data Nature Sent to
Random visitor ID (ht_vid cookie; random, not derived from the Shopper) Pseudonymous Meta (external_id, unhashed) and Klaviyo (external_id, unhashed); TikTok, OpenAI Ads, Pinterest, Snapchat and Reddit (SHA-256)
Shopify customer ID, hashed (SHA-256; never sent raw), or the hashed email address, as Meta's external_id where an order has no visitor ID Pseudonymized identifier Meta
Advertising click IDs (gclid, gbraid, wbraid, fbclid, ttclid, msclkid, epik, ScCid, rdt_cid, OpenAI and Klaviyo click IDs) with timestamps, landing page path and UTM parameters Pseudonymous Each click ID to the platform that issued it, as recorded
Browser IDs set by other tags on Merchant's store: Meta _fbp, Google Analytics client ID Pseudonymous Meta (fbp), Google Analytics 4 (client_id)
Email and telephone number Hashed (SHA-256) in memory; raw only in the webhook inbox (Section 6.2) Hashed: Google Ads, Meta, Microsoft Advertising (goals with enhanced conversions only), TikTok, OpenAI Ads, Pinterest, Snapchat, Reddit
Email address, unhashed Personal Merchant's own Klaviyo account, once per visitor, where Merchant's plan includes and Merchant has connected Klaviyo (profile match); HonestTag keeps only the Klaviyo profile ID
First name, last name, city, state or province, postal code, country Hashed (SHA-256) Meta
Browser IP address and user agent (as recorded by Shopify on the order; for browse events the Shopper's request) Personal Meta, TikTok, OpenAI Ads, Pinterest, Snapchat, Reddit; not Google Ads, Microsoft Advertising, Google Analytics 4 or Klaviyo
Device lookup hash: SHA-256 of IP address, user agent, language header and TLS handshake length Pseudonymous, 30 minutes Not sent
Match keys: a store-keyed HMAC of the hashed email address and of the hashed telephone number, with the visitor ID (only while phone and draft order matching or offline order delivery is on, Section 6.2(b)) Pseudonymized identifier Not sent
Consent state observed by the pixel; GPC/DNT handling; Consent Mode and Limited Data Use values Consent signal Google Ads (Consent Mode), Meta (Limited Data Use)
Order and checkout identifiers, order name (the store's order number, such as #1001) Pseudonymous link Order ID to the platforms receiving purchases; order name to Klaviyo
Order value (or, where Merchant has it turned on for Meta or Snapchat, gross profit computed from Merchant's own product-cost upload), currency, shipping, new or returning customer classification Commercial Ad Platform Recipients receiving the conversion
Order line items: product IDs, quantities, prices; product names; discount code and amount Commercial Product IDs to Meta, TikTok, Pinterest, Snapchat, Reddit, OpenAI Ads, Google Analytics 4; product names to Google Analytics 4, Reddit, OpenAI Ads; discount code and amount to Meta
Buyer country and region (from shipping, else billing, else default address) Derived location Used for the consent gate (Section 5.2) and Meta Limited Data Use
Page-view and click event rows: visitor ID, order ID, click ID values, page path and referring URL, country, region and city as Cloudflare derives them, IP address truncated to its network prefix (/24 or /48), network operator, device and browser type Pseudonymous Not sent
Email and SMS engagement events read from Merchant's Klaviyo account (message, flow and campaign IDs, timestamps); the profile email is never requested Pseudonymous Not sent
Post-purchase survey answers (free text is stripped of email addresses and phone numbers) Pseudonymous Not sent
Original Shopify webhook payload (may include name, email, phone, addresses, IP address, user agent) Personal Not sent; held only as in Section 6.2(a)

No special-category data is intentionally Processed (Section 6.4).

B.6 Retention

Every key-value entry expires automatically; the periods below run from the entry's last write unless stated.

Store Contents Retention
Device lookup (key-value and Durable Object) device hash to visitor ID 30 minutes
ht_vid cookie (Shopper's browser) random visitor ID 365 days
Click stores click IDs, timestamps, landing path, campaign 90 days; first click 365 days
Click-ID reverse lookup click ID to visitor ID 90 days
Consent state state observed by the pixel 90 days from last change
Browser IDs Meta _fbp, Google Analytics client ID 90 days
Browsing context collection and product pages viewed 30 days
Email engagement touches message and campaign IDs, timestamps 90 days; Klaviyo event IDs already read, 7 days
Klaviyo profile map visitor ID to Klaviyo profile ID 365 days
Checkout and order links checkout token or order ID to visitor ID 30 days / 90 days
Match keys (only while phone and draft order matching or offline order delivery is on) store-keyed HMAC of the hashed email address and telephone number, to visitor ID 365 days; deleted by customers/redact and shop/redact
Staff-browser markers (only while phone and draft order matching is on) visitor IDs of browsers Merchant's staff marked with a one-time link, so their visits are never attributed 400 days
Reported conversion values value, currency, classification, visitor ID, Microsoft click ID 180 days
Order money records (refund netting) order total, tax, customer type (new or returning), order date, keyed by order ID; no visitor ID 180 days; not reached by customers/redact (Section 10)
Order count order count and Shopify customer ID 7 days
Evidence records and indexes per-order attribution proof, order names 400 days on paid plans; none kept on the free Mirror
Survey answers answers to the post-purchase survey 400 days
Orders held while delivery is paused order ID, click IDs, value, currency, classification; no email, phone, IP address or user agent 100 days
Delivery deduplication markers (key-value) order and event IDs already delivered 30 days
Google pending-ingest markers order ID and Google click ID 7 days
Per-order delivery records (Durable Object) which platforms an order, refund, cancellation or order edit was delivered to, keyed by order or refund ID; no visitor ID or contact data No expiry. Deleted by customers/redact for the orders it names and by shop/redact for orders whose reported conversion value is still kept; records of refunds, cancellations and order edits, and of older orders, are reached by neither (Section 15.3)
Live event log (Durable Object) processing events, order names, visitor-ID prefixes 72 hours on paid plans; none kept on the free Mirror
Delivery queue messages conversion payloads including hashed identifiers, IP address and user agent Until delivered or abandoned; at most 4 days
Webhook inbox (database) original Shopify payload Payload cleared on successful processing; failed payloads up to 30 days
Customer cohort record (database) keyed hash of the customer, first order's country, region, product and discount code Until customers/redact or shop/redact
Order ID registers (database) order IDs counted for billing; orders erased by customers/redact Until shop/redact
Analytics Engine event rows (Cloudflare) Part B.4 event rows Three months (Cloudflare's retention; no per-row deletion)
Raw event archive (Cloudflare R2) copy of the store's event rows, referring URLs without query strings 25 months; a customer's rows removed on customers/redact; deleted on shop/redact
Archive copy (second Cloudflare R2 bucket) copy of the raw event archive and data-request reports Follows the archive at the next nightly copy
Data-request reports (Cloudflare R2) Section 10 reports Until customers/redact names them or shop/redact
Pre-purge safety snapshot (Cloudflare R2) the store's database rows at shop/redact 30 days, access-restricted, not used for the Service
Ordinary backups (Cloudflare R2) nightly backup of the measurement data store and of the database 30 days
Database point-in-time recovery (Cloudflare D1) database history 30 days
Records kept after shop/redact audit-log entries with the store identifier removed (entries naming a person are redacted and deleted after 30 days); partner commission records; error records with the store identifier removed Audit and commission records as law and accounting require; error records 90 days

B.5 Frequency

Continuous, for the duration of the Agreement.

B.7 Sub-processors

As listed in Annex III, for the purposes stated there.

C. Competent Supervisory Authority


Annex II: Technical and Organizational Measures

These describe the measures in place at the date of this version. HonestTag holds no security certification.

  1. Encryption in transit: TLS 1.2 or higher.
  2. Encryption at rest: data is stored encrypted at rest on Cloudflare's infrastructure.
  3. Credential protection: Merchant API and OAuth credentials are envelope-encrypted before storage in the database and are kept out of application logs.
  4. Minimization of contact data: raw email and phone are hashed in memory for delivery and are not stored in attribution stores or queues; the original webhook payload is held as described in Section 6.2(a).
  5. Pseudonymous identifiers: the visitor ID is random; the device lookup hash lives 30 minutes; IP addresses in event rows are truncated to the network prefix.
  6. Tenant isolation: each store's storage access goes through a tenant-scoped layer that prefixes every key-value entry, scopes every database query and stamps every queue message with the store's identifier; the few documented exceptions (request routing and the privacy purge) are listed in the code and reviewed.
  7. Automatic expiry: the tenant-scoped storage layer refuses any key-value write without an expiry.
  8. Webhook authentication: every Shopify webhook, including the mandatory privacy webhooks, is HMAC-verified and rejected with HTTP 401 on failure.
  9. Access control: production access is limited to HonestTag's authorized personnel on a need-to-know basis, and the administrative interface sits behind Cloudflare Access, which the Service verifies again on every request (people sign in with single sign-on; HonestTag's own scripts use an Access service token).
  10. Logging: privacy-webhook actions, purge counts and administrative actions are written to an audit log.
  11. Consent enforcement: a single consent gate in the pixel's send path; GPC and DNT handling at the event endpoints; one server-side gate, shared by every Ad Platform Recipient, for EEA, UK and Swiss orders (Section 5.2).
  12. Deletion safety: a store purge takes an isolated snapshot first and stops if the snapshot fails; restores skip deleted stores and erased customers.
  13. Secure development and change control: every change must pass an automated test suite (including privacy tests for the consent gate, webhook HMAC rejection, and the effects of customers/redact, customers/data_request and shop/redact) on the exact version deployed, before it reaches production.
  14. Backups and recovery: nightly backups kept 30 days in Cloudflare R2 (the database copy is restore-tested before it is stored; the key-value snapshot is checked against its manifest); a second copy of the raw event archive in a separate R2 bucket; database point-in-time recovery for 30 days.
  15. Incident response: HonestTag monitors the Service with automated alerts and follows a written security incident response policy (detection, containment including credential rotation and rollback, assessment of scope from audit records, notification, and a written post-mortem). Suspected Personal Data Breaches are handled and notified under Section 11.

Annex III: Sub-processors

Current list and change notices: https://honesttag.com/subprocessors.

Sub-processor (address; data-protection contact) What it does for the Service Shopper Data it receives Location / transfer basis
Cloudflare, Inc. (101 Townsend Street, San Francisco, CA 94107, USA; Data Protection Officer, dpo@cloudflare.com) Runs the entire Service: compute (Workers), storage (KV, D1, R2, Durable Objects, Queues, Analytics Engine) and network All Shopper Data in Annex I Global network, United States; EU-U.S. Data Privacy Framework (including its UK Extension and the Swiss-U.S. framework) and SCCs per Cloudflare's data processing terms
Plus Five Five, Inc., trading as Resend (2261 Market Street #5039, San Francisco, CA 94114, USA; privacy@resend.com) Sends HonestTag's email to Merchant, including the data-request notice Shopify customer ID and order IDs named in a data-request notice United States; SCCs and the EU-U.S. Data Privacy Framework (including its UK Extension), per Resend's data processing addendum
Google LLC (Google Workspace) (address: the notices address in Google's Workspace agreement; Google Workspace data protection team, https://support.google.com/a/contact/googlecloud_dpr) Hosts HonestTag's support mailbox, from which data-request reports are sent to Merchant Data-request reports (Section 10) and anything Merchant includes in support correspondence United States; under Google's Cloud Data Processing Addendum, which Google incorporates into its Google Workspace agreement (https://cloud.google.com/terms/data-processing-addendum)
Discord Inc. (444 De Haro Street #200, San Francisco, CA 94107, USA; privacy@discord.com; Data Protection Officer, dpo@discord.com) HonestTag's internal notification channel: operations alerts about merchant stores, and notices of the support requests HonestTag receives by email or through its website support form None intentionally. An operations alert names the store and the problem, with Shopper identifiers masked as described below. A support notice states who wrote, their store and what they asked, so it carries any Shopper Data Merchant includes in a support request United States: Discord states that it processes and stores information on servers located in the United States and that it is the data controller of its users' personal information (Discord Netherlands BV for users in the EEA) (Discord Privacy Policy, effective September 29, 2025). No data processing agreement with Discord covers these messages

HonestTag offers no merchant support chat on Discord; Discord is used only as the internal notification channel described above. An operations alert names the store (its HonestTag tenant ID and shop domain) and the problem. Before sending it, HonestTag replaces Shopify order and customer IDs, visitor IDs, email addresses, every order name in Shopify's default format (#1001), any word after the word "order" that contains a digit, and every other word that contains a digit, which covers a store's own order-name format (Shopify's examples: EN1001, 1001-A). Kept are dates and times, HTTP status codes, durations, a bare number of one or two digits, and HonestTag's own support codes, record IDs and hashes. An order name left in an alert is therefore possible only where a store's order names are a bare one- or two-digit number, or a number followed only by a time unit, and the alert does not call it an order. Shopify is not a Sub-processor: it is the platform on which Merchant runs its store and from which the Service receives order data, under Merchant's own agreement with Shopify. Ad Platform Recipients are not Sub-processors (Section 8.6).


Exhibit A: CCPA Service-Provider Terms

This Exhibit applies where HonestTag Processes personal information subject to the CCPA on Merchant's behalf. HonestTag is a service provider and Merchant the business.

  1. Business purpose. HonestTag Processes personal information only to perform the Service, the business purpose described in Annex I, and for no other purpose.
  2. No selling or sharing by HonestTag. HonestTag will not sell or share personal information, as those terms are defined in the CCPA. Transmissions to Ad Platform Recipients are made at Merchant's direction as part of the Service; Merchant is responsible for any notice and opt-out the CCPA requires for them, including honoring opt-outs of sale or sharing.
  3. No use outside the relationship. HonestTag will not retain, use, or disclose personal information for any purpose other than the business purpose, or outside the direct business relationship between HonestTag and Merchant.
  4. No combining. HonestTag will not combine personal information received from or on behalf of Merchant with personal information from other sources, except as the CCPA permits for a business purpose.
  5. Compliance. HonestTag will comply with the CCPA's obligations applicable to service providers and provide the same level of privacy protection the CCPA requires of businesses.
  6. Notice. HonestTag will notify Merchant if it determines it can no longer meet its CCPA obligations; Merchant may then take reasonable and appropriate steps to stop and remediate unauthorized use.
  7. Merchant oversight. Merchant may take reasonable and appropriate steps to ensure HonestTag uses personal information consistently with the business's CCPA obligations, including through Section 13.
  8. De-identified data. HonestTag will not attempt to re-identify de-identified data and maintains it as Cal. Civ. Code §1798.140(m) requires.
  9. Assistance. HonestTag will reasonably assist Merchant in responding to verifiable consumer requests to know, delete, and correct.
  10. Sub-processors. HonestTag engages Sub-processors only under written contracts binding them to the same obligations, except Discord as Section 8.5 states, for which HonestTag remains fully liable.

Exhibit B: Other U.S. State Privacy Laws

This Exhibit applies where HonestTag Processes personal data subject to a U.S. state comprehensive consumer privacy law under which HonestTag is a processor and Merchant a controller, including the laws of Colorado, Connecticut, Utah, Virginia, Delaware, Indiana, Iowa, Montana, Oregon, Tennessee, Texas and New Jersey, and any other such law that takes effect and applies to the Processing.

Under each such law, HonestTag will:

  1. Process personal data only on Merchant's documented instructions and to provide the Service;
  2. ensure each person Processing the data is bound by a duty of confidentiality;
  3. implement the measures in Annex II;
  4. assist Merchant with consumer rights requests, data protection assessments, and security incident notification (Sections 9, 11 and 12);
  5. engage Sub-processors only under written contracts imposing the same obligations, except Discord as Section 8.5 states, for which HonestTag remains fully liable, after giving Merchant the opportunity to object (Section 8.4);
  6. make available the information reasonably needed to demonstrate compliance, and allow assessments as in Section 13; and
  7. at Merchant's direction, delete or return personal data at the end of the Service (Section 15), unless law requires retention.

Terms in this Exhibit have the meanings given in the applicable state law. Where a law requires additional terms, those terms are incorporated by reference and control for Processing subject to that law.


Article 27 representatives

HonestTag has not designated a representative under Article 27 of the EU GDPR or the UK GDPR. When it does, the name and contact address appear here.