SLATE
Merchant Data Processing Agreement
|
Draft for business and legal counsel review. Not approved for publication. |
Processing terms
Where applicable, the merchant is controller/business and Slate is processor/service provider. The merchant supplies lawful instructions, Shopify permissions, notices, and customer-facing responses. Slate processes merchant data only for configured ingestion, normalization, reporting, joins, rules, exports, support, security, privacy requests, deletion, and legal duties.
Slate restricts access by need to know and confidentiality obligation and uses organization isolation, server authorization, encryption, value-free logging, safe immutable audits, incident handling, and credential controls. Slate assists with exact-customer export/redaction and exact-shop deletion; detailed assistance scope, fees, and channels require approval.
Verified uninstall or administrator disconnect clears credentials, stops sync, and deletes exact-shop data after 48 hours unless reconnected. Verified customer or shop redaction is immediate. Non-Shopify termination treatment requires final business terms. Legal/accounting exceptions require an approved legal basis, minimum necessary preferably deidentified/segregated records, and a deletion date; they never permit Shopify credentials, raw customer records, customer IDs, shop domains, attribution URLs, or webhook payloads. There is no generic legal hold.
Slate will maintain approved subprocessors and appropriate contractual duties. Final notice/objection, audit/information, confidentiality, breach cooperation, international-transfer, termination, liability, and order-of-precedence terms require negotiation. Incident notice will occur without undue delay and within applicable legal or contractual deadlines when required; this draft invents no deadline or certification.
Draft subprocessor schedule
Service |
Repository-grounded status |
Function / required decision |
Clerk |
Required current authentication and membership architecture |
Confirm entity, production use, data, regions, and transfer terms |
Vercel |
Deployment and Workflow integrations present; production facts unproven |
Confirm hosting/Workflow use, entity, regions, and terms |
Neon |
Candidate only; repository proves PostgreSQL, not vendor |
Include only after production database vendor/region verification |
Sentry |
Optional; blank configuration disables ingestion |
Include only if enabled; verify entity, region, and terms |
Heap |
Optional; blank public environment ID disables it |
Include only if enabled; verify entity, region, and terms |
Stripe |
Billing integration exists; production enablement unproven |
Confirm actual use and data flow |
Google analytics tooling |
GTM/analytics code exists; external enablement/publication unproven |
Separate and verify every enabled vendor |
Shopify |
Merchant platform/data source, not Slate's subprocessor for Slate processing |
Describe as the merchant platform relationship |
Google Sheets |
Merchant-directed export destination |
State merchant responsibility; assess separate Slate-controlled processing if any |
Required publication inputs
- Party identities, addresses, signatures, dates, governing law, venue, and liability.
- Final roles, subject matter, duration, purposes, data/data-subject categories.
- Verified subprocessors, regions, transfer mechanisms, notice/objection process.
- Security exhibit, audit evidence, breach contact/terms, and assistance terms.
- Non-Shopify return/deletion schedule and termination treatment.
