Data Processing Addendum

Last updated: September 8, 2026

Draft: this Addendum has not undergone legal review.

1. Parties and scope

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Vasta, Inc., a California corporation with its principal office at 3313 Adriatic Ave, Long Beach, CA 90810, United States ("Proa", "we") and the merchant that installs the Proa Shopify app or places the Proa script on its store (the "Merchant"). It applies whenever Proa processes personal data of the Merchant's shoppers on the Merchant's behalf.

For that processing the Merchant is the controller and Proa is the processor (under the CCPA, the Merchant is the "business" and Proa the "service provider"; GDPR art. 4(7) and 4(8) and LGPD, Law no. 13,709/2018, art. 5, VI and VII, where they apply). Proa processes shopper data only on the Merchant's documented instructions, as set out in this DPA, and never sells or shares it. Installing the app, or placing the script, constitutes acceptance of this DPA.

2. What Proa processes

Proa processes the minimum needed to run and report A/B tests on the Merchant's storefront. The table separates what reaches Proa, what Proa reads from it, and what Proa keeps. Shopper name, email address, phone number, billing and shipping address, line item contents and payment data are never persisted or logged, and the order webhook subscription asks Shopify to send only the fields listed below.

SourceReceived and readKeptPurpose
Storefront scriptPage and experiment events (visit, variant shown, cart reached) with device class, traffic source and the country derived at the edge from the request. The IP address is not read by Proa's code and never stored. No cookies; the script keeps the test assignment in the browser's own storage and never transmits it.Daily counters per website, variant and coarse class. No visitor identifier, no session record.Count sessions and conversions per test variant.
Shopify order webhook (orders/paid)The subscription limits the payload to: order id, order number, currency, total and subtotal, order timestamps, cart attributes, line item properties and the checkout token. Cart attributes and line item properties are read to find the test variant; the raw checkout token is hashed on receipt and then discarded.Order id and number, currency, amounts, order date, the variant, and the SHA-256 hash of the checkout token. Line item properties and the raw token are not kept.Attribute revenue to the variant the shopper saw.
Shopify Web Pixel (checkout)Three checkout steps (started, payment submitted, completed) with the checkout token and the variant from the cart. Sent only when the shopper's analytics consent allows it.One row per checkout step keyed by the hashed checkout token, plus daily counters per variant. No order id, no customer id.Show where shoppers drop off between variants.
Shopify app installationShop domain, shop id, granted scopes and the access token Shopify issues to the app.The same, with the access token encrypted at rest and the pixel token stored only as a hash.Operate the app for that store.
Shopify compliance webhookscustomers/data_request, customers/redact and shop/redact requests, with the shop, customer id and order ids Shopify names in them.One audit row per request with those identifiers and counts of what was done, so the Merchant can show the request was honored.Fulfil and evidence privacy requests.

3. Proa's obligations

  • Instructions: process personal data only to provide the Service to the Merchant, as described in this DPA and the Merchant's configuration, and never for advertising, profiling, resale or any purpose of Proa's own.
  • Minimum data: collect only the fields listed in section 2 and keep the Web Pixel limited to the analytics purpose.
  • Consent: the checkout pixel honors the shopper consent state that Shopify exposes, stops emitting when analytics consent is denied or withdrawn, and never replays earlier events. The storefront script has no consent gate because it produces only aggregate counters with no identifier; the Merchant remains responsible for the notices its own jurisdiction requires.
  • Confidentiality: limit access to personnel bound by confidentiality obligations and with a need to operate the Service.
  • Security: encryption in transit on every endpoint; access tokens encrypted at rest; checkout and pixel tokens stored only as hashes; every webhook signature verified before processing; each Merchant's data kept separate in storage and reporting.
  • Assistance: support the Merchant in answering data subject requests and in demonstrating compliance, within the limits of what Proa holds.

4. Retention and deletion

Uninstalling the Shopify app is not the end of the Merchant's relationship with Proa: the Merchant may keep running tests with the Proa script and the manual order webhook. Each step below therefore does one specific thing.

  • Retention clock: order records, daily counters, checkout step rows and the compliance audit rows are kept for 400 days from their date and then purged automatically.
  • Uninstalling the app stops all collection through the app: the installation is marked uninstalled, the offline access token is deleted and events from its pixel stop being accepted. Records already ingested stay under the retention clock, because the Merchant may continue using Proa without the app.
  • shop/redact, which Shopify sends 48 hours after an uninstall, anonymizes every order record that came in through the app: shop, order and checkout identifiers are cleared and the orders are removed from the Merchant's reports. What remains is amount, date and variant, with no way back to the order, until the retention clock expires. The installation record loses its shop domain and every secret. Records that came in through the manual webhook or the script are not touched: they belong to the Merchant's Proa account and follow the last item of this section.
  • customers/redact does the same for the named orders only, whichever path they came in through.
  • Checkout step rows are not part of either redaction because they hold no order or customer identifier, only the hashed checkout token; they expire on the retention clock.
  • customers/data_request is answered with the data Proa holds for that shopper, which by design contains no identifier beyond the order ids the Merchant already has.
  • Ending the Proa relationship: on written request to the address in section 9, Proa deletes every record held for the Merchant's store, whatever path it came in through, within 30 days.

5. Sub-processors

The Merchant authorizes the sub-processors below (Shopify itself is the Merchant's own platform, under the Merchant's agreement with Shopify, and is not a sub-processor of Proa). Proa will publish changes on this page with at least 15 days' notice; the Merchant may object in writing to the address in section 9, and continued use of the Service after the notice period constitutes acceptance.

Sub-processorRoleLocation
Vercel, Inc.Hosting and file storageUnited States
Neon, Inc.DatabaseUnited States
Upstash, Inc.Queues and job schedulingUnited States

Proa stores and processes data in the United States. Where the GDPR applies, transfers out of the EEA rely on the European Commission's standard contractual clauses or an adequacy decision; where the LGPD applies, transfers follow LGPD art. 33.

6. Incidents

Proa will notify the Merchant without undue delay, and at most within 72 hours of becoming aware, of any personal data breach affecting the Merchant's data, with the information reasonably available to support the Merchant's own notifications.

7. Audit

On written request, no more than once a year unless an incident or a supervisory authority requires otherwise, Proa will provide the documentation reasonably needed to show compliance with this DPA.

8. Term and changes

This DPA applies while Proa processes personal data for the Merchant and, for the deletion obligations, until they are fulfilled. Changes will be published on this page with the last-updated date; material changes are notified through the account's contact channels.

9. Contact

Data protection questions and requests: info@vasta.me. Data Protection Officer (DPO): Bruno Cassimiro, bruno@vasta.me.