Data Processing Agreement

Last updated: September 2026

This Data Processing Agreement (“DPA”) forms part of the WineFollow Terms of Service. It applies automatically to every merchant (“Merchant”) who installs the WineFollow application (“WineFollow”) on their Shopify store.

It governs the processing of the personal data of the Merchant’s customers, in accordance with Article 28 of the General Data Protection Regulation (GDPR) and other applicable data protection laws.


1. Roles

  • The Merchant is the controller of their customers’ personal data.
  • WineFollow acts as a processor and processes this data only on the Merchant’s behalf.

2. Description of the Processing

  • Purpose: let the Merchant’s customers follow wines, producers, appellations and vintages; show these follows to the Merchant; apply tags to the Shopify customer record so the Merchant can inform their customers with their own tools.
  • Data subjects: logged-in customers of the Merchant’s store who use the follow feature.
  • Personal data: Shopify customer ID, first name, last name, email address, list of follows and the date of each follow.
  • Data not processed: postal address, phone number, payment data, order history. No special categories of data within the meaning of Article 9 GDPR.
  • Duration: for as long as the application is installed, then until deletion as described in section 8.

3. Merchant’s Instructions

WineFollow processes the data only to provide the application, on the Merchant’s documented instructions. Installing and configuring the application constitute these instructions. WineFollow:

  • does not use the data for its own purposes;
  • does not sell or rent the data;
  • does not use the data for advertising profiling;
  • makes no automated decisions producing legal or similarly significant effects.

If WineFollow considers that an instruction infringes applicable law, it informs the Merchant.


4. Confidentiality

Persons authorised to access the data are bound by confidentiality. Access to production data is limited to those who need it to operate and maintain the service.


5. Security

WineFollow implements appropriate technical and organisational measures, including:

  • encryption of data in transit (HTTPS/TLS) and at rest;
  • encrypted database backups;
  • two-factor authentication on administrative accounts;
  • access secrets stored outside the source code;
  • separation of development and production environments;
  • no personal data in application logs;
  • a security incident response policy.

6. Sub-processors

The Merchant authorises WineFollow to use the following sub-processors:

  • Fly.io, Inc. — application hosting — European Union (Paris)
  • Supabase, Inc. — database hosting — European Union (Ireland)

WineFollow imposes data protection obligations on these sub-processors that are equivalent to those in this DPA. Where a sub-processor may access data from outside the European Economic Area, the transfer is covered by a mechanism recognised under the GDPR: the European Commission’s Standard Contractual Clauses or the EU–US Data Privacy Framework.

WineFollow informs the Merchant of any addition or replacement of a sub-processor by updating this DPA at least 30 days in advance. The Merchant may object by uninstalling the application.


7. Data Subject Rights

WineFollow helps the Merchant respond to their customers’ requests:

  • Access: the Merchant can see each customer’s follows in the application.
  • Objection and withdrawal: customers can remove their follows at any time, from a product page or from their customer account.
  • Erasure: requests sent by Shopify (customers/redact webhook) automatically delete all of the customer’s data.

For any other request: support@winefollow.app.


8. End of Processing and Deletion

When the Merchant uninstalls the application, Shopify sends a deletion request (shop/redact webhook) about 48 hours later. WineFollow then deletes all of the store’s data: follows, settings and sessions. Backups are overwritten at the end of their normal retention period.


9. Personal Data Breach

WineFollow notifies the Merchant of any personal data breach affecting them without undue delay, and no later than 72 hours after becoming aware of it. The notification describes:

  • the nature of the breach;
  • the data and approximate number of people concerned;
  • the likely consequences;
  • the measures taken.

WineFollow assists the Merchant with their own notification obligations to the supervisory authority and the data subjects.


10. Audit

Upon reasonable written request, WineFollow provides the Merchant with the information necessary to demonstrate compliance with this DPA.


11. Contact

support@winefollow.app