This Data Processing Agreement ("DPA") applies whenever a merchant ("you", the "Controller") installs the Rarity app and Rarity ("we", the "Processor"), operated by Callio LLC, processes personal data of your shoppers on your behalf. It is accepted by installing the app and takes precedence over the Terms of service where they conflict on data protection.
1. Parties and roles
You are the controller of the personal data of shoppers who bid, make offers or join a launch list on your store. We are your processor. We act only on your documented instructions, which are: the functions of the app as described in its listing and documentation, the settings you choose in the app, and any written instruction you send us.
2. What is processed
| Item | Detail |
|---|---|
| Data subjects | Shoppers on your store who bid, make an offer, or subscribe to a drop's launch list; your staff who use the app |
| Categories of data | Email address, name, hashed IP address, Shopify customer ID, bid and offer amounts and timestamps, email delivery status |
| Special categories | None. The app is not designed to receive them; do not submit them |
| Purpose | Running auctions, offers and drops; sending related emails; fraud prevention; showing you activity in your admin |
| Duration | While the app is installed, subject to the retention periods in the privacy policy |
3. Our obligations
We will:
- Process personal data only on your instructions, unless the law requires otherwise, in which case we will tell you first where we can.
- Make sure the people who can access personal data are bound by confidentiality.
- Apply the security measures in section 6.
- Help you respond to data subject requests (section 8) and meet your own security, breach-notification and impact-assessment duties, to the extent the information is in our hands.
- Delete or return personal data at the end of the relationship (section 11).
- Give you the information you need to show that we meet these obligations (section 10).
- Tell you promptly if we think an instruction breaks data protection law.
4. Your obligations
You are responsible for having a lawful basis for collecting shopper data through the app, for your own privacy notice to shoppers, for the accuracy of the data, and for the settings you choose (for example, connecting Klaviyo or a webhook, which sends data to a recipient of your choosing).
5. Sub-processors
You give us general permission to use the sub-processors below. We stay responsible for their work.
| Sub-processor | Purpose | Location |
|---|---|---|
| Our hosting provider (named here once the production host is confirmed) | Hosting the application and database | United States |
| Resend, Inc. | Email delivery | United States |
| Shopify Inc. | The platform the app runs on; draft orders, metafields and optional customer tags are stored in your store | Canada / global |
Klaviyo and any webhook endpoint you add are recipients you choose and control, not our sub-processors.
If we plan to add or replace a sub-processor, we will update this page and tell you in the app at least 30 days beforehand. If you object on reasonable data-protection grounds and we cannot resolve it, you may uninstall the app, and section 11 applies.
6. Security measures
- Encryption: all traffic uses HTTPS. The database and its backups are encrypted at rest. Integration credentials are additionally encrypted with a separate key inside the database.
- Data minimisation: IP addresses are stored only as a one-way hash. No payment details, addresses or phone numbers are collected.
- Access control: production access is limited to the people who operate Rarity and requires multi-factor authentication. Each store's data is isolated by store identifier on every query.
- Access logging: views of a collector's details in the app are recorded with who viewed them and when.
- Separation: development, staging and production are separate apps with separate databases. Production data is never copied to development.
- Backups and recovery: automatic encrypted backups with a tested restore procedure.
- Retention: automatic deletion as described in the privacy policy.
- Verification and abuse controls: email verification for bidders, rate limits per bidder and per IP hash, risk scoring.
7. Breach notification
If we become aware of a personal data breach affecting your data, we will notify you at your store's contact email without undue delay and in any case within 72 hours of becoming aware of it. The notice will describe what happened, the data and people affected as far as we know, the likely consequences, and what we are doing about it. We will keep you updated as we learn more. Our security and incident response policy has the detail.
8. Data subject requests
You can delete or anonymise any bidder from the Collectors page in the app. Launch-list subscribers can unsubscribe from any email. If a shopper contacts us directly, we will refer them to you where appropriate and otherwise assist within 30 days. We respond to Shopify's customer data request, customer redaction and shop redaction notices automatically.
9. International transfers
Data is hosted in the United States. Where personal data is transferred to a country without an adequacy decision (for example, to Resend in the United States), the transfer is covered by the sub-processor's Standard Contractual Clauses or an equivalent mechanism.
10. Audit and information
On written request, no more than once a year unless required by a regulator or following a breach, we will provide the information reasonably needed to show compliance with this DPA, including this policy set and a summary of our security measures. If that is not enough, you may carry out an audit at your cost, at a mutually agreed time, under confidentiality, and without disrupting other merchants' data.
11. Deletion on termination
When you uninstall the app, all of your store's data is deleted when Shopify sends us the uninstall notice, and again on Shopify's shop redaction notice 48 hours later. If you need an export first, request it from the app or email us before uninstalling. Encrypted backups rotate within 30 days.
12. General
Our liability under this DPA is subject to the limits in the Terms of service. This DPA is governed by the same law as the Terms. If any part is found unenforceable, the rest remains in force. We may update this DPA to reflect legal changes or new features; material changes are announced in the app and on this page with a new effective date.