NudgePilot Data Processing Agreement
Last updated: September 29, 2026
This Data Processing Agreement ("Agreement") is between:
- Strenvo Trading (owner: Hamed Valigholizadeh), Burgemeester Hogguerstraat 309, Amsterdam, the Netherlands, registered with the Dutch Chamber of Commerce (KvK) under number 96110910, operator of NudgePilot, the Shopify app and the plugin NudgePilot for WooCommerce ("NudgePilot", "we"); and
- the merchant who installs NudgePilot on a Shopify store, or connects the plugin on a WooCommerce store ("Merchant", "you").
It applies whenever NudgePilot processes personal data on your behalf while you use the app, and it forms part of NudgePilot's Terms of Service (the "Terms"). You accept it by installing, connecting or continuing to use NudgePilot. If this Agreement and the Terms conflict on data protection, this Agreement wins.
1. Definitions
Terms such as personal data, processing, controller, processor, data subject, personal data breach and supervisory authority have the meanings in the EU General Data Protection Regulation 2016/679 ("GDPR"). "Data Protection Law" means the GDPR, the UK GDPR, and any other data protection law that applies to the processing. "Sub-processor" means a third party we engage to process Merchant personal data.
2. Roles and scope
2.1 You are the controller of the personal data of visitors to your store. We are your processor.
2.2 We process personal data only to provide NudgePilot as described in the Terms, the app listing and Annex 1: deciding when to show a visitor one message with your shipping, returns or product comparison information, and measuring whether those messages help your sales.
2.3 NudgePilot is designed to avoid identifying anyone. It does not collect names, email addresses, phone numbers, postal addresses, IP addresses, customer IDs, order IDs or payment details. On a WooCommerce store, the plugin keeps the random visit ID on the order the visit led to, on your own site, until the paid order is reported to us and at most 48 hours; it sends us only the visit ID, the order's items subtotal and its currency. Some of the data it does process, such as a random visit ID linked to browsing counts, may still be personal data under the GDPR. This Agreement treats it as personal data.
3. Your instructions
3.1 We process personal data only on your documented instructions. The Terms, this Agreement and the settings you choose in the app are your complete instructions, unless the law requires otherwise. If it does, we will tell you before processing unless the law forbids it.
3.2 If we believe an instruction breaks Data Protection Law, we will tell you promptly and may pause that processing until it is resolved.
4. Your responsibilities
4.1 You are responsible for having a lawful basis for the processing, and for telling your visitors about it. The app's Settings › Privacy page offers suggested wording for your privacy policy.
4.2 On Shopify, NudgePilot runs only for visitors who allow analytics and preferences processing through Shopify's customer privacy settings. You are responsible for configuring your store's cookie banner (Shopify Settings › Customer privacy) as your local law requires.
4.3 On WooCommerce, NudgePilot runs by default only for visitors who allow statistics cookies in a cookie banner that uses the WP Consent API. If you choose My store doesn't ask for consent under Settings › Privacy, NudgePilot runs for every visitor unless a banner records a refusal; you are responsible for that choice being lawful for your store.
4.4 You will not use NudgePilot's settings to make it process special categories of personal data, or data about children, or any data beyond what the app is built to process.
5. Confidentiality
Everyone we authorize to process personal data is bound by confidentiality, by contract or by law. Access is limited to people who need it to run, secure or support NudgePilot.
6. Security
We maintain the technical and organizational measures described in Annex 2. We may update them, provided the overall level of protection does not decrease.
7. Sub-processors
7.1 You give us general authorization to use the Sub-processors listed in Annex 3.
7.2 We will give you at least 30 days' notice before adding or replacing a Sub-processor, by email to your store's contact email address and by updating Annex 3 on this page. You may object on reasonable data protection grounds within that period. If we cannot address the objection, you may stop using NudgePilot by uninstalling it; we will not charge you for the rest of that billing period.
7.3 We impose on each Sub-processor data protection obligations at least as protective as this Agreement, and we remain responsible to you for their performance.
8. International transfers
8.1 We host NudgePilot's server and database in the European Economic Area (Amsterdam, the Netherlands).
8.2 If personal data is transferred outside the EEA, the UK or Switzerland, including to a Sub-processor, we ensure an appropriate safeguard under Chapter V of the GDPR. Examples are an adequacy decision, the EU–US Data Privacy Framework where the recipient is certified, or the European Commission's Standard Contractual Clauses.
9. Helping you with visitors' rights
9.1 NudgePilot cannot link the data it holds to a named person, so in most cases it cannot find one visitor's data. Visitors can remove the data in their own browser by closing the tab or withdrawing consent in your cookie banner. Data on our server is deleted within 48 hours.
9.2 Within these limits, we will help you respond to data subject requests. This includes answering Shopify's customer data request and customer erasure webhooks, which we do automatically. On WooCommerce, WordPress's personal data export and erasure tools (Tools › Export Personal Data and Erase Personal Data) include the visit ID the plugin keeps on a customer's orders. We will forward to you any request we receive directly from one of your visitors.
10. Personal data breaches
10.1 We will notify you without undue delay, and within 48 hours, after becoming aware of a personal data breach affecting your data. We will notify you at your store's contact email address.
10.2 Our notice will describe, as far as we know them: the nature of the breach, the categories and approximate volume of data affected, the likely consequences, and the measures taken or proposed. We will add information as it becomes available, and we will help you meet your own notification duties.
11. Impact assessments and consultation
We will give you reasonable information and help for any data protection impact assessment or prior consultation with a supervisory authority that relates to NudgePilot, taking into account what we know and the data we hold.
12. Deletion at the end
12.1 When you uninstall NudgePilot from a Shopify store, its code stops running on your storefront, and we delete your store's data on our server as soon as Shopify notifies us. We delete it again in response to Shopify's shop erasure webhook, about 48 hours after uninstall.
12.2 When you delete the plugin from a WooCommerce store, it stops running at once, asks us to delete your store's data (which we do immediately), and removes its settings and the visit IDs on orders from your site. If you disconnect instead, we delete visit records at once and your store's results and usage 30 days later, unless you connect again. If we don't hear from your store for 90 days, we delete its data too, unless it has a paid plan.
12.3 Copies in server backups expire within 14 days.
12.4 For Shopify stores, your settings and results are stored in your own Shopify store, not on our server; after uninstall NudgePilot can no longer read them. For WooCommerce stores, your settings are stored on your own site, and your store-wide results are stored on our server until your store's data is deleted as above.
12.5 Because the data is deleted automatically and is of no use outside the app, we do not return it. The Results page shows your totals while the app is installed.
13. Demonstrating compliance and audits
13.1 On written request, and no more than once a year unless a supervisory authority requires more, we will give you the information reasonably needed to show that we meet this Agreement. This includes this Agreement, our data inventory and our security measures.
13.2 If that information is not enough, you may have an independent auditor, bound by confidentiality, inspect our compliance. You must give us 30 days' notice, the audit must happen during business hours without disrupting our service, and you bear the cost.
14. Liability
Each party's liability under this Agreement is subject to the limitations in the Terms, except where Data Protection Law does not allow liability to be limited.
15. Term, changes and law
15.1 This Agreement lasts as long as we process personal data for you. Sections 10 and 12 continue until your data has been deleted.
15.2 We may update this Agreement to reflect changes in the law or in NudgePilot. We will give you 30 days' notice of material changes, and we will not reduce the protection of your data.
15.3 This Agreement is governed by the laws of the Netherlands. The courts of Amsterdam have exclusive jurisdiction, unless Data Protection Law requires otherwise.
Annex 1: Details of the processing
| Subject matter | Showing one message to store visitors who seem unsure, and measuring its effect with a built-in test. |
| Duration | While NudgePilot is installed or connected, plus the deletion periods in section 12. |
| Nature and purpose | Collecting counts of on-page actions (with consent) to decide whether to show a message; assigning each visit at random to one of three test groups; recording whether checkout started and a purchase was completed, with its subtotal; adding these into store-wide totals for the Results page. |
| Data subjects | Visitors to the Merchant's online store who allow the processing (section 4). |
| Personal data | A random visit ID made in the visitor's browser (lasts at most 30 minutes, not linked to any customer record); counts of actions such as product views, cart views, cart changes, returns from checkout, visits to shipping or returns information, seconds in cart and seconds inactive; the page type; the test group; timestamps of checkout started, message shown and purchase; the purchase subtotal and currency; the type of message shown; and, if product comparison is on, the public details of products viewed, kept only in the visitor's browser tab. On WooCommerce, the visit ID is also kept in a first-party cookie (for the visit, or for 24 hours once checkout starts) and, on the Merchant's own site, on the order it led to until the paid order is reported and at most 48 hours. |
| Special categories | None. |
| Retention | Visit records are summarized into store-wide totals and deleted within 48 hours, and never kept longer than 7 days. Backups expire within 14 days. Totals are stored in the Merchant's Shopify store, or, for WooCommerce stores, on our server until the store's data is deleted (section 12). A dismissed message's hide-until time stays in the visitor's browser for 7 days. |
| Merchant account data | To run the app we also store the store's domain and Shopify access tokens, or, for WooCommerce stores, the site's address, its site ID, the plugin version, the settings our server needs (on or off, currency, returns terms, whether comparison is on) and, for paid plans, the plan, its status and dates and Paddle's customer and subscription IDs. No staff names or emails are stored. |
Annex 2: Security measures
- Data minimization and pseudonymization: no names, contact details, IP addresses, customer or order IDs are collected; a visit is identified only by a random ID created in the browser.
- Consent enforcement: the storefront code collects nothing until the visitor allows analytics and preferences processing, and it deletes its browser data when consent is withdrawn.
- Encryption in transit: all traffic to NudgePilot's server uses HTTPS (TLS); plain HTTP is redirected.
- Encryption at rest: the server's database is stored on an encrypted volume.
- Authentication: admin requests use Shopify session tokens. Webhooks are verified with HMAC signatures and rejected if invalid. Storefront requests arrive through Shopify's signed app proxy. The WooCommerce plugin signs every call from the merchant's site with a per-site secret (HMAC-SHA256, time-limited, replay-resistant), kept encrypted on the site; storefront requests from WooCommerce stores are accepted only from the store's own web address.
- Least privilege: the app requests only the Shopify permissions it needs, and access to the server and hosting accounts is limited to the operator.
- Logging: server logs never contain query strings or visitor data beyond request paths, status codes and store domains.
- Retention limits: automatic hourly summarizing and deletion as in Annex 1.
- Resilience: daily volume snapshots, kept 14 days; health checks on the running server.
- Change control: every change passes the automated test suite before it is deployed, and deployments are made from version control.
Annex 3: Sub-processors
| Sub-processor | Purpose | Data | Location | Transfer safeguard |
|---|---|---|---|---|
| Fly.io, Inc. | Hosting of NudgePilot's server, database and backups | All server-side data in Annex 1 | Amsterdam, the Netherlands (company based in the United States) | Fly.io's Data Processing Agreement, including the EU Standard Contractual Clauses (signed 25 September 2026) |
| TypeSafe | Runs Jev, the AI model behind Smart timing, which estimates whether a visitor seems unsure | Action counts only; no visit ID, store domain, URLs or amounts | United States | TypeSafe's Data Processing Addendum, which forms part of its terms, with the EU Standard Contractual Clauses (Module 2; last updated 24 April 2026) |
Shopify is not a Sub-processor: it is the Merchant's own platform. It delivers storefront requests through the app proxy and stores the app's settings and results in the Merchant's store under the Merchant's agreement with Shopify. WordPress and WooCommerce run on the Merchant's own site.
Paddle.com Market Ltd is not a Sub-processor either: as our reseller and merchant of record for WooCommerce paid plans, it processes the Merchant's own billing details (not visitors' data) as an independent controller under its own terms and privacy policy.