Merchant Data Protection Agreement
Summary (TL;DR)
- This agreement governs how Nimble handles your customers' personal data when our app processes it on your behalf — it sits alongside our Privacy Policy (which covers your account data) and our Terms of Use.
- You are the Controller; Nimble is the Processor. We process your customers' data only on your instructions, never for our own purposes.
- We do not sell, rent, or share your customers' data, use it for our own advertising or profiling, or use it to train or fine-tune AI models — and we never mix it with another merchant's data. Building segments and behavioral flows for you, inside your own store, on your instructions, is the service you turned on; we do none of it for ourselves or for anyone else.
- Your customers' data is hosted in the United States, encrypted in transit and at rest, isolated per-merchant, and stored only by named sub-processors.
- We honor data-subject rights (access, deletion, export) and Shopify's mandatory
customers/data_request,customers/redact, andshop/redactwebhooks. - For EU/EEA/UK/Swiss data subjects, international transfers rely on the EU Standard Contractual Clauses (and the UK Addendum / Swiss adaptations).
1. Parties, roles, and scope
1.1 Parties
This Data Protection Agreement ("DPA") is entered into between:
- Nimble — the operator of the Nimble Shopify application(s). Consistent with the Terms of Use, Nimble is operated by Nimble VC LLC, trading as "Nimble."
- Merchant — the Shopify store owner who installs and uses the Nimble app ("you," "Merchant").
This DPA supplements and forms part of the Nimble Terms of Use. In the event of a conflict between this DPA and the Terms of Use on the subject matter of personal-data processing, this DPA controls.
1.2 Roles
For all personal data of the Merchant's end customers that Nimble processes on the Merchant's behalf:
- The Merchant is the data Controller (and, where Shopify is itself a processor or controller of the same data, this DPA does not alter the Merchant's separate relationship with Shopify).
- Nimble is the data Processor, acting only on the Merchant's documented instructions.
For data about the Merchant's own account (shop domain, billing, usage metrics, the Merchant's contact details), Nimble acts as an independent Controller; that processing is governed by the Privacy Policy, not this DPA.
1.3 Scope
This DPA applies to Nimble's processing of Customer Personal Data (defined in §2) that Nimble obtains through the Shopify Admin API under the Merchant's authorization. It applies regardless of whether the Merchant or its end customers are located in a jurisdiction with an applicable data-protection law (GDPR, UK GDPR, CCPA/CPRA, etc.).
2. Categories of data and data subjects
2.1 Categories of Customer Personal Data processed
Where the Merchant authorizes scopes that expose end-customer data, the categories Nimble may process on the Merchant's behalf are:
| Category | Specific data | Source |
|---|---|---|
| Customer identifiers | Email address; first and last name; phone number (normalized to E.164); Shopify's own customer id | Shopify read_customers / read_orders |
| Marketing-consent state | Email and SMS marketing opt-in/opt-out status, its timestamp, and the recorded provenance of the consent | Shopify read_customers; Merchant-side sign-up surfaces |
| Coarse location | City, region/province, postal code, and country — taken from the customer's default address and from an order's shipping address. No street-address lines. | Shopify read_customers / read_orders |
| Order events | Order dates, order totals, line-item context, last-order recency/value (recent window only — no full order history) | Shopify read_orders |
| Checkout events | Abandoned-checkout/cart events tied to a customer email | Shopify abandoned-checkout resource |
| Storefront behavioral events | Page viewed, product viewed, checkout started, checkout completed — carrying a pseudonymous visitor id, a timestamp, and the page URL. No name, email, or phone. | Nimble's Shopify web pixel (write_pixels / read_customer_events) |
| Support-conversation content | The content of a customer's inbound support or buyer-chat message and Nimble's reply — where the Merchant enables those features. A customer may include personal data of their own choosing in that message. | Merchant's support inbox / storefront chat widget |
| Inventory/product context | Product titles, images, URLs, inventory level (back-in-stock triggers) — no customer personal data | Shopify read_products / read_inventory / read_locations |
Nimble does not process customer payment-card data or payment instruments — Shopify and the Merchant's payment processors handle those, and Nimble sees only whether a charge succeeded. Nimble does not store street-level address lines: the only address fields it retains are city, region, postal code, and country.
2.2 Categories of data subjects
The Merchant's end customers and prospects — people who have purchased from, started a checkout with, or subscribed to marketing from the Merchant's Shopify store.
2.3 Nature and purpose of processing
Nimble processes Customer Personal Data solely to operate the marketing, commerce, and support programs the Merchant enables, on the Merchant's behalf:
- Building and maintaining the Merchant's email and SMS subscriber lists with per-channel consent state, and honoring opt-outs and suppressions.
- Triggering behavioral flows — abandoned checkout, abandoned cart, browse abandonment, post-purchase, back-in-stock, and win-back — keyed on a consenting customer's email address or phone number.
- Building the audience segments those flows send to, including segments derived from order history and coarse location.
- Operating the Merchant's loyalty program — membership, points accrual, and reward issuance.
- Measuring storefront traffic and funnel steps through Nimble's web pixel, using a pseudonymous visitor id.
- Where the Merchant enables AI-assisted customer support or buyer chat: answering a customer's own message, and — only after that customer's identity is verified against the order — looking up that customer's own order to answer it.
Nimble does not process Customer Personal Data for any purpose of its own, for another merchant, or for advertising audience-building.
2.4 Duration
Processing continues for the duration of the Merchant's installation of the app, subject to the deletion terms in §7.
3. Processor obligations
Nimble, as Processor, will:
- Process on documented instructions only. Process Customer Personal Data only on the Merchant's documented instructions (including the instructions embodied in this DPA, the app configuration, and the Merchant's flow/segment settings), and not for any purpose of its own. Nimble will not sell, rent, or share Customer Personal Data, will not use it for Nimble's own advertising or profiling, will not use it to train or fine-tune AI models, and will not merge it with another merchant's data. Segmentation, scoring, and behavioral targeting performed for the Merchant, on the Merchant's documented instructions and within the Merchant's own store, is processing for the Merchant and is the subject matter of this DPA — not processing for Nimble's own purposes.
- Confidentiality. Ensure that persons authorized to process Customer Personal Data are bound by confidentiality. Today Nimble VC LLC has a single principal — its Chief Executive Officer — who is the only person with potential access; any staff or contractor added in the future will be bound by equivalent confidentiality and data-protection terms before access is granted.
- Security. Implement the technical and organizational measures in §5 (GDPR Art. 32).
- Sub-processors. Engage sub-processors only under §4.
- Assist the Controller. Taking into account the nature of processing, assist the Merchant by appropriate measures in responding to data-subject-rights requests (§6) and in meeting the Merchant's own security, breach-notification, DPIA, and prior-consultation obligations (GDPR Arts. 32–36).
- Deletion / return. At the Merchant's choice, delete or return Customer Personal Data on termination, per §7.
- Demonstrate compliance. Make available information necessary to demonstrate compliance with Art. 28, and allow for and contribute to audits per §9.
- Notify of unlawful instructions. Promptly inform the Merchant if, in Nimble's opinion, an instruction infringes applicable data-protection law.
4. Sub-processors
4.1 Authorized sub-processors
The Merchant provides general written authorization for Nimble to engage the following sub-processors. Each is engaged under terms that impose data-protection obligations no less protective than this DPA (GDPR Art. 28(4)):
| Sub-processor | Role / what they process | Hosting region |
|---|---|---|
| Supabase (PostgreSQL + Vault) | System of record — stores subscriber data, consent state, and event data; Vault stores per-merchant Shopify OAuth tokens | United States (AWS) |
| Google Cloud (Cloud Run / Cloud Run Jobs) | Compute — runs the app and the email-send/flow jobs; processes data transiently, no persistent storage on the compute layer | United States (us-central1) |
| Resend | Email delivery — receives recipient email + name + rendered content at send time | United States |
| Twilio | SMS delivery — receives the recipient's phone number and the message body at send time, plus the delivery receipt Nimble bills from. Inbound replies (STOP/HELP and free-text) arrive back through Twilio. | United States |
| Anthropic (Claude API) | AI-assisted customer support and buyer chat only. Receives the content of a customer's own message and, once that customer's identity is verified, the order context needed to answer it. Receives no Customer Personal Data on the content-generation path — see the note below this table. | United States |
| Google (Gemini API) | Capacity fallback for the same support / buyer-chat path as Anthropic, used only when the Claude API is rate-limited. Receives the same message content on that path and nothing more. | United States |
| Stripe | Billing for custom plans that are not billed through Shopify. Receives the Merchant's billing contact and payment status; card details go to Stripe directly and never pass through Nimble. Stripe receives no end-customer personal data. | United States |
| Shopify | Source of the data + OAuth + billing. Shopify is the Merchant's platform; for protected customer data it is both the source and, under the Shopify Partner Program Agreement and API License, a party whose terms bind Nimble. | Per Shopify |
Anthropic (Claude API). For content generation, Anthropic receives the Merchant's brand context and product information only, and no Customer Personal Data; the per-recipient email and SMS send paths contain no model call. Where the Merchant enables AI-assisted customer support or buyer chat, the content of a customer's own message is sent to Anthropic to generate a reply, and may contain personal data the customer chooses to include. For those features Anthropic acts as a sub-processor of Customer Personal Data. Anthropic does not train on API inputs.
Providers that do not receive Customer Personal Data. Where the Merchant connects Meta (Facebook / Instagram ads), bundle.social (organic social publishing), Canva, or Intuit QuickBooks, those providers receive only campaign and creative material, post content, Nimble-generated images, or accounting entries respectively. Nimble does not upload the Merchant's customer list to any advertising platform and does not build advertising audiences out of Customer Personal Data. Those providers are therefore not sub-processors of Customer Personal Data under this DPA; the data Nimble stores for those connections is described in §3.7 of the Privacy Policy. If that ever changes, §4.2's 30-day notice applies.
Nimble's analytics providers (PostHog and Google Analytics 4) process only first-party, anonymized analytics for Nimble's own marketing website, with session replay disabled and no personal data in events. They do not receive Customer Personal Data and are not sub-processors under this DPA.
4.2 Changes to sub-processors
Nimble will give the Merchant at least 30 days' notice (via in-app notification and/or email to the Merchant's store contact) before adding or replacing a sub-processor that processes Customer Personal Data. If the Merchant reasonably objects on data-protection grounds within that period, the Merchant may terminate the affected processing by uninstalling the app.
5. Security measures (Art. 32)
Nimble implements the following technical and organizational measures:
- Encryption in transit: HTTPS/TLS 1.2 or higher across all connections (Cloud Run, Supabase, Shopify Admin API).
- Encryption at rest: AES-256 for all stored data (Supabase-managed PostgreSQL on AWS). Per-merchant Shopify OAuth tokens are stored in Supabase Vault with additional application-level encryption.
- Tenant isolation: PostgreSQL Row-Level Security with
FORCE ROW LEVEL SECURITYon customer-data tables; each merchant's rows are isolated bybrand_id. No merchant can read another merchant's data. - Access control: Application access via a scoped, audited service role; the credential-decryption routine is callable by the service role only. Production database access is limited to the operator.
- Audit logging: Vault credential reads are logged; job execution is logged.
- Backups: Supabase-managed encrypted backups on a 30-day rolling cycle.
6. Data-subject rights assistance
Where a data subject exercises a right (access, rectification, erasure, restriction, portability, objection) directly with the Merchant, Nimble will assist the Merchant by:
- Access / portability: providing, on the Merchant's request, the Customer Personal Data Nimble holds for the named data subject in a structured, machine-readable format. This is also wired through Shopify's mandatory
customers/data_requestwebhook. - Erasure: deleting the named data subject's records on the Merchant's request and on Shopify's mandatory
customers/redactwebhook, within 30 days of the request (Shopify's mandated window). §7 sets out which records the automated webhook path reaches today. - Rectification / restriction / objection: updating, suppressing, or ceasing processing of a data subject's records on instruction.
7. Retention, return, and deletion
| Trigger | Action | Timeline |
|---|---|---|
App uninstall (app/uninstalled) | OAuth tokens deleted from Vault; merchant marked inactive — processing stops | Immediate |
shop/redact webhook | Hard-delete all of the merchant's data, including any customer-data tables | Within 30 days of the webhook |
customers/redact webhook / data-subject erasure | Hard-delete the named customer's email, loyalty, and order-linked records. SMS records are covered by the note below this table. | Within 30 days |
| Merchant request | Return (machine-readable export) or delete, at the Merchant's choice | Without undue delay |
SMS records. The Merchant's SMS subscriber records — phone number, consent state, and message history — are hard-deleted in full on shop/redact. The automated customers/redact path does not yet reach them; Nimble erases a named individual's SMS records on the Merchant's request, within the same 30-day window.
On termination, Nimble deletes Customer Personal Data and existing copies unless retention is required by law; backups age out on the 30-day rolling cycle.
8. Personal-data breach notification
Nimble will notify the Merchant without undue delay after becoming aware of a personal-data breach affecting the Merchant's Customer Personal Data, and in any event consistent with Shopify's requirements and applicable law. The notification will describe, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. Nimble will reasonably assist the Merchant in meeting the Merchant's own breach-notification obligations (e.g., the GDPR Art. 33 72-hour authority-notification timeline that runs for the Merchant as Controller).
9. Audits
Nimble will make available to the Merchant the information necessary to demonstrate compliance with GDPR Art. 28 (e.g., this DPA, the security overview, and the sub-processor list). For a more detailed audit, the parties will agree on reasonable scope, timing, and confidentiality in advance; Nimble may satisfy an audit request by providing existing third-party reports or its security documentation where these reasonably address the Merchant's inquiry.
10. International transfers
Customer Personal Data is hosted in the United States (Supabase on AWS US; Google Cloud us-central1; Resend US; Twilio US; Anthropic US; Google Gemini API US). Where the Merchant or its data subjects are in the EU/EEA, UK, or Switzerland, transfers of Customer Personal Data to Nimble and its sub-processors in the US are made under an appropriate transfer mechanism:
- EU/EEA → US: the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Controller-to-Processor module, incorporated by reference, with the Merchant as data exporter and Nimble as data importer.
- UK → US: the EU SCCs as supplemented by the UK International Data Transfer Addendum issued by the ICO.
- Switzerland → US: the EU SCCs with the Swiss adaptations recognized by the FDPIC.
Nimble will assist the Merchant with any transfer-impact assessment by providing information about its US hosting and applicable government-access posture on request.
11. Liability, term, and miscellaneous
- Liability: the limitation-of-liability provisions in the Terms of Use apply to this DPA.
- Term: this DPA takes effect when the Merchant installs the app and remains in effect for as long as Nimble processes Customer Personal Data on the Merchant's behalf.
- Governing law: as set out in the Terms of Use, subject to the independent operation of the SCCs (§10), which are governed as the SCCs specify.
- Order of precedence: this DPA → SCCs (for transfer matters) → Terms of Use → Privacy Policy.
12. Contact
For data-protection questions or to exercise a data-subject right:
- Email: help@nimblevc.com (general / data requests)
- Security contact: security@nimblevc.com (security incidents)
Version 1 — published 2026-06-14; subject to legal review.