Goalpost merchant data processing agreement

Version 2026-09-29

Parties and instructions

This agreement is between Klientship Technologies Pvt Ltd (Provider), operator of Goalpost: Free Shipping Bar, and the Shopify merchant identified by the authenticated store accepting this agreement (Merchant). For customer personal data processed through Goalpost, Merchant determines the purposes and means of processing and Provider processes it on Merchant's documented instructions. Instructions consist of this agreement, the configured app features, and lawful authenticated support requests. Provider will notify Merchant if an instruction appears to violate applicable data-protection law.

Scope and permitted use

Processing consists of receiving limited Shopify order and refund events, calculating reward and campaign attribution, storing related records, displaying reports to the Merchant, and deleting records. Data subjects are the Merchant's customers and store visitors. Data may include Shopify order identifiers, order number, totals, currency, refund amounts, dates, cancellation status, and campaign/reward attribution flags. Goalpost does not request customer names, addresses, telephone numbers, email addresses, or payment details for these functions.

Provider will use this data only to supply and support Goalpost under the Merchant's instructions. Provider will not sell it, use it for advertising, or combine it across merchants to build customer profiles. Store account and support-contact information used to administer the service is described separately in the privacy policy.

Security and confidentiality

Provider will restrict access to authorized people who need it to operate or support the service and are subject to confidentiality obligations. Provider will maintain HTTPS for external app/API traffic, encrypted production storage, authenticated merchant access, tenant-scoped data operations, and verification of Shopify webhook signatures. Credentials will be kept server-side. Provider will regularly review these controls and address identified security defects.

Service providers and processing location

The authorized hosting provider is Oracle Cloud Infrastructure, with Goalpost's current application and database hosted in Mumbai, India. Shopify remains the Merchant's commerce platform under the Merchant's separate Shopify agreements. Provider will impose appropriate data-protection obligations on its own subprocessors and remain responsible for their processing under this agreement. Before adding or replacing a subprocessor, Provider will notify Merchant and allow a reasonable opportunity to object on data-protection grounds.

Where applicable law requires safeguards for an international transfer, Provider and Merchant must establish those safeguards before the affected transfer occurs. This agreement alone is not a claim that standard contractual clauses or another transfer mechanism have already been executed.

Retention and deletion

Customer-linked order attribution and refund records will be retained for no more than 365 days after the underlying order date, for annual attribution reporting and refund reconciliation. A daily cleanup will remove older records. Customer redaction requests will delete the affected records sooner. Raw customer identifiers will not be copied into aggregate analytics.

Store configuration and anonymous aggregate reports may be retained while Goalpost remains installed to provide the configured service and historical reports. On uninstall, stored Shopify sessions and tokens will be deleted. Remaining store data will be deleted when Shopify's signed shop-redaction event is received. A failed deletion will be retried through the webhook delivery mechanism and monitored until resolved.

Provider currently has no scheduled Goalpost volume backups in Coolify. Before introducing backups, Provider will define and disclose their encryption and expiration controls and ensure restored data is subject to prior deletion requests. No promise of backup availability is made by this agreement.

Data-subject requests and merchant assistance

Merchant is the primary contact for its customers. Provider will help Merchant respond to access, correction, deletion, objection, and other applicable requests. Provider will authenticate the requesting Merchant, identify the relevant records, and provide a secure export or complete deletion as appropriate. Provider will not disclose one Merchant's data to another. Contact: contact@klientship.in.

Provider will supply information reasonably needed to demonstrate its obligations under this agreement and support proportionate compliance assessments, subject to safeguards for other merchants and security-sensitive information.

Incidents and legal requests

Provider will notify Merchant without undue delay after becoming aware of a personal-data breach affecting Merchant data, share available information needed for Merchant's response, provide updates, and take reasonable containment and remediation steps. Provider will notify Merchant of legally compelled disclosure unless prohibited by law and will disclose only what is required.

Term and acceptance

This agreement takes effect only when an authorized Merchant representative accepts the published version in the authenticated app. It remains effective for as long as Provider processes Merchant customer data. The acceptance record must identify the authenticated shop, agreement version, accepting Shopify staff identifier where available, and timestamp. This agreement creates no historical acceptance and does not replace the Merchant's separate Shopify agreements.