This addendum forms part of the Terms of Service between you (the merchant) and Tripster Developers Limited, trading as Miko Apps ("we"), for every Miko app you install. It applies automatically from installation; you do not need to sign anything. If you need a countersigned copy for your records, email us and we will send one with these same terms.
1. Roles
- For personal data about your customers that our apps receive from your store, you are the controller and we are your processor.
- We process that data only to provide the app you installed, on your instructions as set by your app settings and use of the app, and as required by law.
- For your own account details as a merchant (store domain, owner name and email), we are the controller, as described in the Privacy Policy.
2. What we process
The categories of data, the people they relate to and how long we keep them are listed per app in section 4 of the Privacy Policy. We collect only what each app needs and do not sell personal data or use it to train AI models.
3. Our people
- Only the people who maintain the apps can access production systems, and they are bound by confidentiality.
- We do not look at your store's data except to run the app, to fix a problem you report, or when the law requires it.
4. Sub-processors
- The providers we use, what each one handles and where, are listed in section 5 of the Privacy Policy. You authorise us to use them.
- We will update that list before adding a new provider that handles shopper data. If you object to a new provider on reasonable data protection grounds, tell us and, if we cannot address it, you can uninstall and your data is deleted as described below.
- We use providers that commit to their own data processing terms covering the data they handle for us.
5. Hosting and where data is stored
- Our Shopify apps run on Railway, in the United States, with each app's database alongside it. Authentica runs in Railway's US West region (California) on a PostgreSQL database.
- The Odoo connector runs on Render and Supabase, as noted in the Privacy Policy.
- For transfers of EEA, UK or Swiss data to the United States we rely on the Standard Contractual Clauses or the EU-US Data Privacy Framework, as set out in section 9 of the Privacy Policy.
6. Security
- All connections to our apps, and between our apps and Shopify, use HTTPS (TLS).
- Each merchant's data is separated by store, and every request is checked against the signed-in store.
- Access tokens, API keys and credentials are stored server-side and never exposed to the storefront. Developer API keys are stored only as a one-way hash.
- Webhooks we receive from Shopify are checked against Shopify's signature before they are processed. Authentica's outgoing webhooks are signed once you create a signing secret, so you can check they came from us.
7. Security incidents
If we become aware of a breach affecting your store's personal data, we will tell you without undue delay, by email to your store's contact address, with what we know about what happened, the data involved and what we are doing about it. We will keep you updated and help you meet any notification duty you have.
8. Helping you with requests
- Shopify's customer data request and customer redaction webhooks reach us automatically. We send you what we hold about that customer, or delete or anonymise it, within 30 days.
- If a customer contacts us directly, we pass the request to you and help you respond.
- We will give you reasonable help with data protection impact assessments and questions from a regulator about our processing.
9. Export, deletion and backups
- Export at any time. Apps that store records you may want to keep let you export them from inside the app. In Authentica, every plan can export certificates, ownership history and the change log as CSV, and Pro adds a full JSON export and a ZIP of private photos.
- When you uninstall. Shopify sends us a shop redaction request 48 hours after you uninstall, and we then delete your store's app data within 30 days, as described in section 6 of the Privacy Policy. Reinstall within those 48 hours and your data is still there.
- Backups. Copies held in our hosting providers' backups roll off on their standard schedules and are not restored except to recover the service.
10. Information and audits
On reasonable written request, we will answer your questions about how we process your store's data and give you the information you need to show that this addendum is being followed.
11. Order of precedence
If this addendum and the Terms of Service conflict on data protection, this addendum wins. Where the Standard Contractual Clauses apply, they win over both.
12. Contact
Tripster Developers Limited (NZBN 9429051238919), trading as Tripster Developers and Miko Apps, Auckland, New Zealand. hello@tripsterdevelopers.com.