Data Processing Agreement
Effective date: 29 September 2026 Last updated: 29 September 2026
This Data Processing Agreement ("DPA") is between:
- the merchant that installs the Comeback app on its Shopify store ("you"), as controller; and
- Tan Oguz, trading as Tan Solutions, The Parkland Phetkasem 56, Building 12A F, 650/242, Bang Wa, Phasi Charoen, Bangkok 10160, Thailand, oguz@tansolutions.org ("we", "us"), as processor.
It forms part of our Terms of Service ("Terms"). You accept it when you accept the Terms by installing or using the app, and it binds both parties from then on without a signature. If you would like a signed copy, fill in the signature block at the end and send it to oguz@tansolutions.org; we will countersign and return it.
1. Definitions
- "Data Protection Law" means the laws on personal data that apply to the processing under this DPA, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection ("FADP"), and Thailand's Personal Data Protection Act B.E. 2562 (2019).
- "Customer Personal Data" means the personal data of your customers, and of anyone else who uses the app's customer-facing features on your store, that we process for you through the app, as described in Annex 1.
- "SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module Two (transfer controller to processor).
- "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A(1) of the Data Protection Act 2018, version B1.0, in force from 21 March 2022.
- "Controller", "processor", "data subject", "personal data breach", "processing" and "supervisory authority" have the meanings given in the GDPR.
If the SCCs or the UK Addendum conflict with this DPA, they prevail. If this DPA conflicts with the Terms, this DPA prevails.
2. Scope and roles
2.1 You are the controller of Customer Personal Data, and we process it as your processor. Annex 1 describes the processing: its subject matter, duration, nature and purpose, and the types of personal data and data subjects.
2.2 This DPA does not cover data about you and your business that we use to run our own relationship with you (for example your store details, settings and support emails). We are the controller of that data, and our Privacy Policy describes it.
3. Your instructions
3.1 We process Customer Personal Data only on your documented instructions, including with regard to transfers to other countries, unless the law we are subject to requires otherwise; in that case we will tell you before the processing, unless that law forbids it. Your instructions are:
- these Terms and this DPA;
- the settings you choose in the app (for example whether the EU withdrawal form is on, your region rules and your alert addresses); and
- any further written instructions you send us that are consistent with the Terms.
3.2 We will tell you immediately if, in our opinion, an instruction infringes Data Protection Law.
3.3 You are responsible for the lawfulness of your instructions, for having a legal basis for the processing, and for informing your customers about it.
4. Confidentiality
Everyone we authorise to process Customer Personal Data is bound by a duty of confidentiality, by contract or by law.
5. Security
5.1 We apply the technical and organisational measures in Annex 2 to protect Customer Personal Data, as required by Article 32 GDPR.
5.2 We may change these measures over time, as long as the overall level of protection does not go down.
6. Sub-processors
6.1 General authorisation. You authorise us to use sub-processors. Annex 3 lists the sub-processors we use today.
6.2 Notice of changes. We will tell you at least 14 days before we add or replace a sub-processor, by email to your Shopify account address and with a notice in the app, and we will update Annex 3 on this page.
6.3 Objections. You may object on reasonable data protection grounds within those 14 days by writing to oguz@tansolutions.org. We will discuss your concern in good faith. If we cannot resolve it, you may end the Terms by uninstalling the app, and we will refund any fees you prepaid for the period after it ends.
6.4 Flow-down. We bind every sub-processor by a written contract that imposes data protection obligations equivalent to this DPA. We remain fully liable to you for how our sub-processors perform those obligations.
7. Help with data subjects' requests
7.1 The app helps you answer requests from your customers: Shopify's customer data requests (customers/data_request) produce a download of the data we hold about that customer, and Shopify's customer deletion requests (customers/redact) delete it.
7.2 If a data subject contacts us directly about Customer Personal Data, we will pass the request to you without undue delay and will not answer it ourselves, except to say that we have passed it on.
7.3 Where the app's tools are not enough, we will give you reasonable further help, taking into account the nature of the processing.
8. Personal data breaches
8.1 We will notify you without undue delay, and no later than 48 hours after becoming aware of a personal data breach affecting Customer Personal Data, by email to your Shopify account address.
8.2 Our notice will describe, as far as we know them, the nature of the breach, the categories and approximate number of data subjects and records concerned, its likely consequences, and the measures taken or proposed. Where we don't have all of this at once, we will send it in stages without further undue delay.
8.3 We will take reasonable steps to contain the breach and reduce its effects, and will help you meet your own notification duties under Articles 33 and 34 GDPR.
9. Impact assessments and consultations
We will give you reasonable help with data protection impact assessments and prior consultations with supervisory authorities, by providing the information about the app that you need.
10. Deletion and return at the end
10.1 Return. While the app is installed, you can export your withdrawal log as a CSV file on every plan, and your request history on the Growth and Pro plans. Please export what you need before uninstalling.
10.2 Deletion. When you uninstall the app, Shopify sends us its shop deletion request (shop/redact) 48 hours later, and we delete all Customer Personal Data of your store when it arrives. If you ask, we will delete it earlier. Deleted data leaves our nightly backups within 14 days.
10.3 We keep Customer Personal Data after that only where a law we are subject to requires us to.
11. Information and audits
11.1 We will make available to you the information you need to show that we meet our obligations under Article 28 GDPR and this DPA, and will answer your reasonable written questions about our processing.
11.2 We will allow and contribute to audits, including inspections, by you or by an independent auditor you appoint who is bound by confidentiality, at reasonable intervals or where there are indications that we are not meeting our obligations. To keep audits proportionate:
- you give us at least 30 days' written notice, except after a personal data breach or where a supervisory authority requires a shorter period;
- audits take place during our business hours and without access to other customers' data;
- routine audits happen no more than once in any 12 months; and
- each party bears its own costs.
11.3 Nothing in this section limits your rights under clause 8.9 of the SCCs.
12. International transfers
12.1 Where we process data. We process Customer Personal Data on our own server in Thailand, and our sub-processors process it as described in Annex 3. Thailand has no adequacy decision from the European Commission or the UK.
12.2 EEA: the SCCs. Where the GDPR applies to your processing and our processing involves a transfer of Customer Personal Data to a third country, the SCCs, Module Two, are incorporated into this DPA by reference, with you as data exporter and us as data importer, and with these choices:
- Clause 7 (docking clause) applies.
- Clause 9(a): option 2, general written authorisation; the notice period is 14 days, as in section 6.
- Clause 11(a): the optional independent dispute resolution wording does not apply.
- Clause 13(a): the competent supervisory authority is the one set out in Annex 1, Part C.
- Clause 17: option 1; the SCCs are governed by the law of Ireland.
- Clause 18(b): disputes are resolved by the courts of Ireland.
- Annexes I, II and III of the SCCs are Annexes 1, 2 and 3 of this DPA.
12.3 UK: the UK Addendum. Where the UK GDPR applies, the UK Addendum is incorporated into this DPA by reference, and completed as follows:
- Table 1 (parties): as in Annex 1, Part A. The start date is the date you accept this DPA.
- Table 2 (selected SCCs): the Approved EU SCCs as incorporated in section 12.2, Module Two, with the choices made there.
- Table 3 (appendix information): Annex 1 (list of parties and description of the transfer), Annex 2 (technical and organisational measures) and Annex 3 (sub-processors) of this DPA.
- Table 4 (ending the Addendum when the Approved Addendum changes): neither party.
12.4 Switzerland. Where the FADP applies, the SCCs as set out in section 12.2 also apply, with these changes: the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority for transfers governed by the FADP; references to the GDPR include the FADP; and the term "Member State" in clause 18(c) does not prevent data subjects in Switzerland from bringing claims where they habitually reside.
12.5 Onward transfers. Our sub-processors receive Customer Personal Data under their own data processing terms, which include the SCCs or another transfer mechanism recognised by Data Protection Law.
12.6 Requests from public authorities. Clauses 14 and 15 of the SCCs apply. On request, we will give you the information you reasonably need for your own transfer impact assessment. As of the effective date, we have received no request from a public authority for Customer Personal Data.
12.7 Thai law. We are established in Thailand, so Thailand's Personal Data Protection Act also applies to our processing as a processor.
13. Liability
Each party's liability under this DPA is subject to the limits in section 9 of the Terms, except where the SCCs or Data Protection Law do not allow liability to be limited, including our liability towards data subjects under clause 12 of the SCCs.
14. Term and changes
14.1 This DPA applies for as long as we process Customer Personal Data for you, and its obligations continue until that data is deleted.
14.2 We may update this DPA with the notice in section 13 of the Terms (at least 14 days for material changes), but never so as to lower the protection of Customer Personal Data. Changes that the law or new standard clauses require may take effect sooner.
15. Governing law
This DPA is governed by the law and courts named in section 12 of the Terms (Thailand; the courts of Bangkok), except that the SCCs are governed by the law and courts named in section 12.2, and the UK Addendum by the law of England and Wales.
Annex 1 — Details of the processing
Part A. The parties
Data exporter (controller): the merchant that installs the Comeback app. Contact: the email address of the merchant's Shopify account. Activities: running an online store on Shopify and using the app for returns, exchanges and EU withdrawals. Signature and date: acceptance of the Terms, or the signature block below.
Data importer (processor): Tan Oguz, trading as Tan Solutions, The Parkland Phetkasem 56, Building 12A F, 650/242, Bang Wa, Phasi Charoen, Bangkok 10160, Thailand. Contact: oguz@tansolutions.org. Activities: providing the Comeback app. Signature and date: acceptance of the Terms by the data exporter, or the signature block below.
Part B. Description of the processing
Data subjects:
- the merchant's customers who ask for a return or exchange while signed in to their Shopify customer account;
- anyone who submits the EU withdrawal form on the merchant's store, including people whose declaration matches no order.
Personal data:
- Returns and exchanges: the Shopify customer ID; order number, items, variants, quantities, prices paid, product images and fulfilment status; shipping and billing country; return reasons and notes typed by the customer; a decline note written by the merchant; a review flag; and, read from Shopify when needed but not stored, the customer's name, email address and language.
- EU withdrawal form: the full name and email address as typed; order number as typed; the items selected; the matched order ID; date and time of receipt; a reference number; the page language; fingerprints (hashes) of the declaration and of the acknowledgement sent; email sending records (message ID and status). The IP address is used for abuse limits and not stored; only a keyed one-way value derived from it is kept, for about 48 hours.
Sensitive data: none is requested. Customers are asked not to include sensitive data in free-text notes; notes are stored encrypted.
Frequency: continuous, whenever a customer uses the app on the merchant's store.
Nature of the processing: collection through the app's forms; reading order and customer data from Shopify; matching declarations to orders; storage; display to the merchant; sending acknowledgement, confirmation and decline emails to customers and alerts to the merchant; creating return records in Shopify; export; deletion.
Purpose: providing the app's return, exchange and EU withdrawal features to the merchant.
Retention: while the app is installed on the merchant's store; deletion as set out in section 10, and for single customers on Shopify's customer deletion requests. Backups keep deleted data for up to 14 days.
Transfers to sub-processors: as described in Annex 3, for the duration of the processing.
Part C. Competent supervisory authority
- If the data exporter is established in an EU Member State: the supervisory authority of that Member State.
- If the data exporter is not established in the EU but the GDPR applies to it under Article 3(2) and it has appointed a representative under Article 27(1): the supervisory authority of the Member State where the representative is established.
- If the data exporter is not established in the EU and has no representative: the supervisory authority of the Member State where most of the exporter's customers who use the app are located.
Annex 2 — Technical and organisational measures
Encryption
- All connections are encrypted with TLS: from customers' and merchants' browsers and from Shopify to our server (encryption ends on our server, not at the relay), from our server to Shopify, and from our server to Google's mail relay (TLS required).
- Customer names and email addresses from the withdrawal form, customers' notes, merchants' decline notes, merchants' alert addresses and Shopify access tokens are encrypted field by field with AES-256-GCM. Each value is bound to its field and store. The keys are kept outside the database.
- Lookups by email address use a keyed one-way index, not the plain address.
- Other database fields (order numbers and IDs, item titles, settings) are not field-encrypted. The server's disks are not fully encrypted today.
Access control
- We operate the server ourselves; no hosting company has access to it.
- The app and its database accept connections only from the server itself. Outside traffic reaches the app only through an encrypted relay that cannot read it.
- Server folders holding the app, its data and its secrets are restricted to administrators and the service accounts that need them. Secrets are generated on the server and kept in a folder that only administrators and the app's own service account can read.
- Merchants sign in through Shopify. Customer requests are checked against Shopify's signed customer session or Shopify's signed app proxy request, and Shopify webhooks are checked against their signature.
- Every record belongs to one store, and the database enforces that a record's related records belong to the same store.
- We do not enter Customer Personal Data into third-party tools that are not listed in Annex 3.
Integrity
- The withdrawal log is append-only: the database rejects changes, and allows deletion only through the redaction steps in section 10.
- Each declaration stores a fingerprint of its content, and each acknowledgement a fingerprint of what was sent, so later changes can be detected.
Availability and recovery
- The database is backed up every night to a second physical disk; the last 14 backups are kept, and each is checked after it is written.
- The app's services restart automatically after a failure.
Data minimisation and retention
- For signed-in customers, names and email addresses are read from Shopify when needed and not stored.
- IP addresses are not stored.
- Deletion runs automatically from Shopify's privacy webhooks (
customers/redact,shop/redact).
Separation and testing
- Tests run on separate, temporary databases with made-up data. Production data is never copied into test or development systems.
Logging
- Server logs record requests (method, web address, status and timing) and errors. They do not contain names, email addresses or free text; an address can contain a store's domain, an order number a merchant searched for, and the Shopify ID of an order, a customer or a staff account. The log files rotate by size, and older files are overwritten.
Incidents
- We follow a written incident-response procedure, and notify affected merchants within 48 hours of becoming aware of a personal data breach (section 8).
Annex 3 — Sub-processors
| Sub-processor | What it does | Customer Personal Data involved | Location | Transfer safeguard |
|---|---|---|---|---|
| Google (Google Workspace) | Sends the app's emails through Google's SMTP relay | Recipient name and email address and the email's content (acknowledgements, confirmations and decline emails to customers; alerts to the merchant, which include the customer's name and email address) | Google's data centres, including in the USA | Google's Cloud Data Processing Addendum, including the SCCs |
| Tailscale US Inc. (Tailscale Funnel) | Relays encrypted connections from the internet to our server | Connection details only (IP addresses, times, data volumes); the content is encrypted to our server and cannot be read by Tailscale | USA; traffic passes through Tailscale's relay servers | Tailscale's Terms and Data Processing Addendum, including the SCCs and the UK Addendum |
Shopify is not our sub-processor: it is the platform the app runs on, and you have your own agreement with Shopify.
Signatures (optional)
This DPA binds both parties when you accept the Terms. Sign below only if you want a signed copy.
For the merchant (controller) Store (myshopify domain): ______________________ Legal name of the business: ______________________ Name and role of signatory: ______________________ Signature: ______________________ Date: ____________
For the processor Tan Oguz, trading as Tan Solutions Signature: ______________________ Date: ____________