Holdfast — Data Processing Agreement

Last updated 6 August 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Fineprint Labs ("Processor", "we") and the Shopify merchant who installs the Holdfast app ("Controller", "you"). It takes effect when you install Holdfast and remains in force while the app is installed.

1. Roles

You are the data controller for your customers' personal data. We act solely as a data processor, processing that data only on your documented instructions — which, for this app, are the destinations and identifiers you configure inside it.

2. Subject matter and duration

Subject matter: forwarding completed-checkout purchase events to the analytics and advertising destinations you configure. Duration: for as long as Holdfast is installed on your store, plus the deletion window in section 7.

3. Nature and purpose of processing

We receive a purchase event when a checkout completes and relay it to your own Google Analytics 4, Meta, and TikTok accounts, replacing tracking scripts that Shopify disables on 26 August 2026. We do not use the data for our own purposes, and we never sell it, share it for cross-context behavioural advertising, build cross-merchant profiles, or use it to train models.

4. Categories of data

Order-level commerce data only:

We do not request customer names, email addresses, phone numbers, or postal addresses. Holdfast makes no field-level protected customer data selections, so Shopify withholds those fields from us.

5. Categories of data subjects

Customers who complete a checkout on your store.

6. Security

All transmission occurs over HTTPS/TLS. Data at rest is stored on encrypted hosting volumes. Credentials you supply are held server-side only and are never exposed in storefront or checkout code. Access is limited to the sole operator of Fineprint Labs; there are no other staff.

7. Retention and deletion

Purchase events are forwarded in real time. We keep a short activity log of order identifiers, values, and delivery status so you can confirm tracking is working; entries older than 30 days are deleted automatically. On Shopify's shop redaction request we delete your configuration, activity log, and sessions in full. You may also request deletion at any time using the contact below.

8. Sub-processors

We use Fly.io for application hosting. The analytics and advertising platforms you configure (for example Google, Meta, TikTok) receive data at your direction and act under their own terms with you; they are your processors, not our sub-processors. We will give notice before adding a hosting sub-processor.

9. Assistance to the controller

We support Shopify's mandatory privacy webhooks. On a customer data request or customer redaction request we confirm that no customer personal data is held. On a shop redaction request we delete all data held for your shop. We will assist you with data subject requests and with any required impact assessment.

10. International transfers

Data may be processed in the region where our hosting infrastructure runs. Where a transfer requires a lawful mechanism, the parties rely on the applicable standard contractual clauses.

11. Breach notification

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need to meet your own notification obligations.

12. Audit

On reasonable written request we will provide the information necessary to demonstrate compliance with this DPA.

Contact

Questions, deletion requests, or audit requests: saviswarup@gmail.com

Privacy Policy