Data Processing Agreement (DPA)
Last updated: 19th August 2026
This Data Processing Agreement (“Agreement”) forms part of the agreement between PreProduct Ltd (“Processor”, “we”, “us”) and the merchant using the PreProduct service (“Controller”, “you”). Its purpose is to ensure compliance with the UK GDPR, EU GDPR, and other applicable privacy laws when we process Personal Data on your behalf. By using PreProduct, you agree to the terms of this DPA.
1. Roles and Responsibilities
1.1 Controller
You are the Data Controller. You determine the purpose and means of processing your customers’ Personal Data.
1.2 Processor
PreProduct Ltd acts solely as a Data Processor when merchants use our application. We only process Personal Data on your instructions, as necessary to provide the PreProduct service.
Legal entity:
PreProduct Ltd
71–75 Shelton Street, Covent Garden, London WC2H 9JQ
Company Number: 14729070
United Kingdom
1.3 EU and UK representation
PreProduct Ltd is established in the United Kingdom and acts solely as a processor. Our service is offered to merchants rather than to consumers in the European Union, and we do not target or monitor data subjects on our own account. Our assessment is that Art. 3(2) EU GDPR is not engaged in respect of PreProduct, and we have accordingly not designated a representative under Art. 27.
Where a merchant is established in the EU, that merchant is the Controller under Art. 3(1) and PreProduct processes solely on their documented instructions under Art. 28. Controllers and data subjects may reach us at admin@preproduct.io.
2. Types of Personal Data We Process
We process only the minimum personal data required to deliver pre-order functionality. This includes:
- Customer name
- Customer email address
- For non-Shopify stores: shipping and billing address details
- Pre-order information (product, variant, quantity, timestamps)
PreProduct does not store or process payment card numbers or bank information.
For Shopify stores, all billing and payment data is processed by Shopify, Stripe or PayPal.
For non-Shopify stores, payment information is processed by Stripe.
3. How We Use Personal Data
We process Personal Data strictly to:
- record and manage pre-orders
- sync pre-order data with your ecommerce platform
- send system notifications (such as pre-order confirmation emails, if enabled)
- provide support, analytics, and security monitoring
- comply with legal obligations
We never sell or share Personal Data with third parties for marketing.
4. Data Storage Location and Transfers
Personal Data is processed in the following locations:
- Application servers and the primary database are hosted by Render.com in the United States (Oregon).
- File and image storage is hosted on Amazon Web Services in the United States (N. Virginia).
- Transactional email is processed by Mailgun on its European infrastructure.
- Product analytics are processed by PostHog on its European infrastructure.
- Content delivery and security filtering are handled by Cloudflare’s global network.
Transfers out of the UK and EEA are made under Standard Contractual Clauses together with the UK International Data Transfer Addendum, supported by the commitments of each sub-processor listed in section 7.
5. Data Security
We are committed to keeping data secure and preventing unauthorised access, use, or disclosure.
5.1 Security Measures
We use a combination of technical and organisational measures, including:
- HTTPS/TLS encryption for data in transit
- Encrypted database backups
- Managed hosting infrastructure with strict access controls
- Two-factor authentication for all systems with data access
- Firewall, CDN, and DDoS protections via Cloudflare
- Regular dependency and vulnerability scanning (via GitHub and hosting provider)
- Minimised logging of personal data within diagnostics and analytics tools
- Staff access limited strictly to those who need it
5.2 Encryption
Data is encrypted in transit via HTTPS.
Backups are encrypted.
Our production database relies on platform-level security from our hosting provider rather than full database-level encryption. Access is protected by long, randomly generated credentials and restricted network controls.
6. Access Controls and Logging
- Personal data is accessible only via authenticated HTTPS requests within the PreProduct application.
- For Shopify stores, customer identifiers are only visible to the authorised store owner through Shopify’s secure admin environment.
- Access to our server infrastructure requires two-factor authentication.
- Access logs are maintained by our hosting provider and can be provided upon request.
- Internal staff access is strictly limited to personnel who require access to perform support or maintenance tasks.
7. Subprocessors
Core infrastructure: Render.com (hosting and database, US), Amazon Web Services (file storage, US), Cloudflare (CDN, WAF and webhook processing).
Platform and payments: Shopify (platform API), Stripe (payment processing for non-Shopify checkouts), Paddle (merchant subscription billing).
Communications and analytics: Mailgun (transactional email, EU), PostHog (product analytics, EU, merchant-level data only), EmailOctopus (merchant mailing list, merchant contact details only), Tiny Funnel (merchant-level usage analytics).
Supporting services: Ipregistry (IP geolocation), Google reCAPTCHA (bot protection), Judoscale (infrastructure metrics, no Personal Data).
Optional integrations, engaged only where you connect them: Klaviyo (marketing automation), Gorgias (customer support), Loop Returns (returns management).
We will give notice of any new sub-processor before it begins processing Personal Data.
8. Retention and Deletion
Personal Data is retained for as long as your PreProduct account remains active, in order to support historical pre-order records.
On uninstall, erasure is automatic and requires no request from you. Shopify notifies us via the shop/redact webhook 48 hours after uninstall. This starts a 30 day grace period, which exists so that an accidental uninstall does not irreversibly destroy your pre-order history. We notify your registered contact address 14 days and 7 days before the deadline. At the end of the grace period all Personal Data associated with your store is permanently deleted, including customer names, email addresses, shipping addresses, pre-order records and payment references. Deletion is permanent removal from the database rather than a status flag.
You may request immediate erasure at any point, before or during the grace period. Individual data subjects are erased on receipt of Shopify’s customers/redact webhook, and we respond to customers/data_request by returning all Personal Data held for the identified data subject.
9. Data Subject Rights
We will assist you in responding to requests from your customers, including: access requests, rectification, erasure, data portability, objections or restrictions, complaints related to personal data processing. We will fulfil these requests only under your instruction as the Controller.
10. Incident Response
If we become aware of a personal data breach involving your data, we will: notify you within 36 hours, provide all available information, cooperate in investigations and regulatory notifications. We will document all incidents and actions taken.
11. Confidentiality
All staff and subcontractors with access to Personal Data are bound by confidentiality obligations. Access is limited to personnel who need it to provide the service.
12. Audits
You may request information necessary to demonstrate our compliance with this DPA. If additional audits are required, we will work with you on reasonable terms that do not disrupt service or compromise other customers’ data.
13. Suspension of Processing
If at any time you instruct us to cease processing Personal Data, we will do so promptly, except where continuation is required to comply with law.
14. Governing Law
This Agreement is governed by the laws of the United Kingdom. Any disputes arising from it are subject to the exclusive jurisdiction of UK courts.
15. Term and Termination
This DPA remains in effect for as long as we process Personal Data on your behalf.
16. Contact
If you have any questions about this DPA or our data-processing practices, contact: admin@preproduct.io