Altimeter Data Processing Agreement
This Data Processing Agreement ("DPA") is between the merchant ("Controller") and Vx Digital, LLC (doing business as Altimeter), 1699 E Olive Ave, Gilbert, AZ 85234, United States ("Altimeter" or "Processor"). It applies whenever Altimeter processes personal data on the merchant's behalf, and forms part of the Terms of Service.
It is meant to meet Article 28 of the GDPR and UK GDPR, and the service provider requirements of the CCPA/CPRA. If this DPA and the Terms conflict, this DPA wins on data protection.
1. Subject matter and duration
| Item | Detail |
|---|---|
| Subject | Providing Altimeter, a read-only profit-analytics dashboard, to the Controller |
| Nature | Copying (read-only sync), storing, organising, analysing and displaying data from the Controller's tools |
| Purpose | Showing the Controller its own analytics: sales, margins, new vs returning customers, cohorts, a customer list and profile |
| Duration | While the Controller's account is active, plus the deletion periods in section 9 |
2. Personal data and data subjects
| Data subjects | Personal data |
|---|---|
| The Controller's customers (people who ordered) | Name, email, Shopify customer ID; order history (items, dates, amounts); first-visit source, campaign and landing-page path |
| The Controller's team members using Altimeter | Name, email, role, sign-in records |
No special categories of data (Article 9 GDPR) are processed. No street addresses, phone numbers or payment details are collected.
Data from ShipHero, Klaviyo and Meta is read only in aggregate or at shipment or ad level, and contains no customer personal data.
3. Controller's instructions
The Processor processes personal data only on the Controller's documented instructions. These Terms, this DPA and the Controller's use of Altimeter's settings are those instructions. The Processor will tell the Controller if it believes an instruction breaks data protection law.
The Processor will not:
- sell or share the personal data (as the CCPA defines those words);
- use it for its own purposes, for advertising, or for profiling;
- combine it with data from other merchants or other sources;
- make automated decisions about individuals with legal or similarly significant effects.
4. Processor obligations
The Processor will:
- make sure everyone who can access the data is bound by confidentiality;
- apply the security measures in section 6;
- help the Controller respond to data subjects' requests (section 7);
- help the Controller with data protection impact assessments and consultations with authorities, where these concern Altimeter;
- notify the Controller of personal data breaches (section 8);
- delete or return data at the end of the service (section 9);
- make available the information needed to show compliance (section 10).
5. Subprocessors
The Controller gives general authorisation for the Processor to use the subprocessors below.
| Subprocessor | Purpose | Location | Personal data |
|---|---|---|---|
| Cloudflare, Inc. | Hosting (Workers), databases (D1, Durable Objects), sign-in (Access), logs | United States (D1 in Western North America; brand databases in the US) | All data in the service |
| Clerk, Inc. (planned) | Sign-in for team members, once introduced | United States | Team members' names, emails, sign-ins |
| GitHub, Inc. | Source code hosting and CI | United States | None. No merchant or customer data. |
| Anthropic, PBC | None today. Altimeter has no AI feature that processes merchant data. | n/a | None |
- The Processor will give the Controller at least 30 days' notice before adding or replacing a subprocessor that handles personal data, by email and on this page. The Controller may object on reasonable data protection grounds. If we cannot resolve the objection, the Controller may end the service.
- The Processor will impose data protection terms on each subprocessor at least as protective as this DPA, and remains responsible for them.
6. Technical and organisational measures
What is in place today is marked (in place). What is planned is marked (planned) and will be marked in place once shipped.
Access control
- The whole app sits behind sign-in. Today this is Cloudflare Access: a one-time code sent to an allowlisted email address. (in place)
- The service checks the signed sign-in token on every API request, and refuses everything if sign-in is not configured. (in place)
- Role-based access per brand: owner, admin, viewer. Only owners and admins can change settings or connections. (in place)
- The app is served only on our own domains; default and preview addresses are switched off. (in place)
- Sign-in through Clerk with multi-factor authentication available. (planned)
- An explicit, time-limited support-access role visible to the merchant. (planned)
Separation of data
- Each brand's data lives in its own database (a SQLite Durable Object), which only the service can reach and which refuses requests for any other brand. (in place)
- Every query is also filtered by brand as a second safeguard. (in place)
- Tests prove two brands' data are isolated. (in place)
- Test environments hold no real customer personal data: outside production, customer names and emails are replaced with pseudonyms as they are written, and staging's earlier data was scrubbed on Oct 2, 2026. Local development copies replace them again. (in place)
Encryption
- Data at rest is encrypted by Cloudflare (AES-256) in D1 and Durable Objects. (in place)
- All traffic uses TLS (HTTPS only). (in place)
- Third-party access keys are encrypted per brand and source with an envelope scheme (RSA-OAEP 3072-bit + AES-256-GCM). The private key exists only as a secret inside the running service, and is never written to disk or shown to anyone. (in place)
Data minimisation
- Only customer name and email are read from Shopify. No addresses, phone numbers or payment details. (in place)
- Landing pages are stored as a path only, without query strings. (in place)
- Emails are masked in customer lists. (in place)
- All connections to third-party tools are read-only. (in place)
Logging and monitoring
- Every sign-in is logged by Cloudflare Access. (in place)
- Changes to settings and connections record who and when. (in place)
- Application logs never contain access keys: they are blanked out of error messages. (in place) The service does not deliberately log customer names or emails. (in place) Unexpected server errors are logged by type and route only, never with their message. (in place)
- An audit log of who opened routes that show customer personal data (person, brand, route, time; no customer details), kept for 1 year. (in place)
Availability and recovery
- Cloudflare point-in-time recovery: up to 30 days for D1 and for each brand's Durable Object database. (in place)
- Because all connections are read-only, the merchant's tools stay the source of truth, and data can be re-synced from them. (in place)
Development and change control
- Code lives in a private GitHub repository. Changes go through pull requests with automated checks (format, lint, type-check, tests). (in place)
- Dependencies are updated automatically (Dependabot). (in place)
- Changes touching access, secrets or customer data need Jack's approval. (in place, by policy)
- Enforced branch protection on
main. (not yet: GitHub's free plan doesn't offer it for private repositories; needs GitHub Pro or Team)
Organisational
- Staff access is limited to people who need it. Today that is Jack Parcell (Vx Digital, LLC). (in place)
- Two-factor sign-in is on for every staff account used to run Altimeter: the email accounts that receive sign-in codes, Cloudflare, GitHub and the Shopify Partner account. (in place)
- A written Incident Response Plan.
7. Data subject requests
- If a data subject contacts the Processor directly, the Processor will pass the request to the Controller and not answer it itself, unless the Controller asks it to.
- Shopify privacy requests are handled automatically (in place):
customers/data_request: recorded and shown to the Controller's owners with what Altimeter holds, so the Controller can answer.customers/redact: the customer's name and email are erased within 10 days (Shopify allows 30). Order figures stay, anonymous.
8. Personal data breaches
- The Processor will notify the Controller without undue delay, and within 72 hours, after becoming aware of a personal data breach affecting the Controller's data.
- The notice will say, as far as known: what happened, the data and people affected, likely consequences, and what has been done and is planned. More information will follow as it becomes available.
- The Processor will help the Controller meet its own duties to notify authorities and people.
- See the Incident Response Plan.
9. Deletion and return
- When the Controller uninstalls the Altimeter Shopify app, Shopify sends a
shop/redactrequest 48 hours later. The Processor deletes all of that brand's store data, connections and settings, and its customers' personal data, within 48 hours of receiving it. (in place) The brand's account record, its team memberships and the access log are kept until the merchant's account is closed, and the access log for its 1-year period. - If the service ends another way, the Processor deletes the Controller's data within 30 days.
- Before deletion, the Controller may ask for a copy of its data in a common format.
- Deleted data remains in Cloudflare's point-in-time recovery for up to 30 days, then is gone. It is not restored except to recover from an incident.
- The Processor keeps a minimal deletion record (brand id, shop, date) as evidence, with no personal data.
10. Audits
- The Processor will answer reasonable written security questionnaires, and make available this DPA, its security overview and policies.
- Altimeter has no independent audit or certification of its own. Its infrastructure provider, Cloudflare, holds third-party certifications (including SOC 2 Type II and ISO/IEC 27001) covering Cloudflare's own systems; reports are available from Cloudflare under its terms.
- If the above is not enough, or a regulator requires it, the Controller may audit the Processor once a year, with 30 days' notice, at its own cost, under confidentiality, in a way that does not expose other merchants' data.
11. International transfers
Altimeter stores and processes personal data in the United States. Cloudflare's network may carry traffic through other countries in transit.
Altimeter does not currently offer its service to merchants in the EU or UK, and has not appointed an EU or UK representative. Before it does, the parties will add the transfer safeguards the law requires (such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum) to this DPA.
12. Liability and term
- Liability under this DPA is subject to the limits in the Terms of Service, except where the law does not allow it.
- This DPA lasts as long as the Processor processes personal data for the Controller.
13. Contact
Data protection contact: media@vxdigital.co Vx Digital, LLC (doing business as Altimeter), 1699 E Olive Ave, Gilbert, AZ 85234, United States