Skip to content

Data Processing Agreement

This agreement applies when you use AppFly to build an app that processes personal data — order data, customer records, anything from your store. It sits under the [Privacy Policy](/legal/privacy) and overrides it where the two differ.

Last updated October 2, 2026hello@appfly.si

Please read this firstAppFly is a developer tool. These documents describe what the software does and what it does not do with data, and they are written to match the code in this repository. They are not a substitute for review by a qualified lawyer in your jurisdiction before you rely on them in a commercial agreement.

Roles

You are the controller of the personal data your apps process. AppFly is the processor, acting only on your documented instructions — which, in normal use of the product, means: store the schema, run the database you asked for, and delete both when you delete the app.

Scope of processing

Subject matter: the Shopify apps you build with AppFly.

Duration: for as long as the app exists, or the account does, whichever ends first.

Categories of data: whatever your apps collect, which is whatever you decide they collect. AppFly itself has no access to your store's customers and does not collect their data.

Purpose: to build, run, preview and deploy the app, and to keep the platform secure.

Security measures

Each app is issued its own database and its own Postgres login role, and that role cannot connect to any other app's database — isolation enforced in the database itself, not in application code. Secrets are encrypted at rest with AES-256-GCM, and a credential-shaped column is masked before any data table is shown to a page. The full list is on the security page.

Sub-processors

AppFly's sub-processors are the categories listed in the Privacy Policy under “Who else sees it”: the payment processor, Shopify, the host and container runtime, and the AI provider you connected. We will give you notice before adding a new category, and you may object in writing within 30 days.

Data-subject requests

Assist us in responding to requests from the people whose data your apps hold. Where a request reaches Shopify and is forwarded to AppFly, we will tell you: we hold nothing of your customers', so the request is yours to answer in your own app.

Breach notification

Notify you without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting data processed under this agreement, with what we know and what we are still finding out. Security disclosures to the public are coordinated with you unless doing so would delay the notice.

Deletion and return

On your request or on the end of the app, delete the app's database, files, containers, deployments and DNS records. Deletion is queued and retried until it succeeds rather than being abandoned halfway. We keep nothing after that except where the law requires a record, and we will confirm deletion to you in writing.

International transfers

Our infrastructure is hosted outside the EEA. Where that means personal data leaves the EEA, transfers are made under the European Commission's Standard Contractual Clauses, with the UK Addendum where the data is UK personal data.

Contact

Data protection questions, access requests and breach reports go to hello@appfly.si. Signed terms for an enterprise agreement replace this document.