Parties and roles
The merchant is the controller of personal data processed through the app. FrictionIQ acts as the processor for the merchant when handling synced Shopify data, classifications, and generated reports.
Subject matter and duration
The processing covers Shopify-connected feedback analysis, classification, reporting, billing operations, and technical support for the duration of the merchant’s use of the app and any configured retention period that applies after use ends.
Nature and purpose of processing
- Syncing selected order, refund, and return-related data from Shopify.
- Extracting feedback-bearing notes and return reasons.
- Classifying issue themes using merchant-configured categories.
- Generating merchant-facing summaries and scheduled reports.
- Maintaining secure sessions, scheduling, and technical operations.
Categories of personal data
Depending on what exists in Shopify, processed data may include order-linked records, refund notes, return notes, return reasons, and free-text entries that may contain customer or merchant-provided personal information.
Processor obligations
- Process personal data only to provide and secure the app.
- Apply appropriate technical and organizational security measures.
- Ensure personnel and subprocessors are bound by confidentiality obligations.
- Assist the merchant with deletion, export, and correction requests where reasonably required.
- Delete or return data in accordance with retention settings and termination instructions.
Subprocessors
The following subprocessors may be used to provide the service:
- Shopify: App platform, merchant installation, and synced commerce data source.
- Supabase Postgres: Managed application database hosting and storage.
- OpenRouter: AI classification and structured report generation.
- Resend: Email delivery for merchant reports and notifications.
- Hetzner: Application and reverse-proxy hosting infrastructure.
International transfers
Personal data may be processed in infrastructure operated by the listed subprocessors. Merchants should review the subprocessor services they enable as part of their own compliance review.
Security and incident handling
FrictionIQ uses HTTPS for public app traffic, encrypted Shopify session-token persistence, production database TLS, and access-controlled hosted infrastructure. If we become aware of a personal data incident affecting app data, we will notify affected merchants without undue delay.
Contact
For data protection requests regarding this DPA, contact contact@frictioniq.net.