Data Processing Agreement - Merchant
Last updated August 4, 2025
1. Introduction
This Data Processing Agreement ("DPA") forms part of and is incorporated into the applicable master subscription agreement, terms of service, order form, or other written or electronic agreement governing the provision of the Service (the "Agreement") between Customer and Veeper, Inc. ("Veeper").
For purposes of this DPA, Customer acts as the Controller and Veeper acts as the Processor with respect to Customer Personal Data processed by Veeper in connection with the Service.
2. Purpose and Scope
This DPA applies where Veeper processes personal data on behalf of Customer in connection with Veeper's SaaS discount, coupon protection, campaign, and ecommerce integration services for Shopify merchants.
The parties enter into this DPA to set out their respective obligations regarding the processing of Customer Personal Data under applicable data protection laws, including where applicable the GDPR, UK GDPR, and similar laws requiring processor terms.
3. Definitions & Processing Details
For purposes of this DPA:
"Controller" means the entity that determines the purposes and means of processing personal data.
"Processor" means the entity that processes personal data on behalf of the Controller.
"Customer Personal Data" means personal data processed by Veeper on behalf of Customer in connection with the Service.
"Applicable Data Protection Law" means all laws applicable to the processing of Customer Personal Data under the Agreement, including, where applicable, the GDPR and UK GDPR.
"Subprocessor" means any third party engaged by Veeper to process Customer Personal Data on behalf of Customer.
3.1 Subject Matter
The subject matter of the processing is Veeper's provision of SaaS services to help merchants manage offers, discount logic, coupon protection, store integrations, and related analytics and operational support.
3.2 Duration
Processing will continue for the duration of the Agreement and any limited post-termination period during which Veeper retains Customer Personal Data in accordance with the Agreement, this DPA, or applicable law.
3.3 Nature and Purpose
Veeper will process Customer Personal Data as necessary to provide, secure, maintain, support, and improve the Service; to sync relevant data with Shopify and other authorized systems; to detect coupon leakage and misuse; to administer campaigns and discounts; and to generate operational reports and logs.
3.4 Types of Personal Data
Depending on Customer's use of the Service, Customer Personal Data may include:
Merchant account and user information, such as names, business contact details, store identifiers, and account credentials or authentication metadata.
Store configuration and campaign data, including offers, rules, coupon settings, and usage records.
End-customer ecommerce data made available through authorized integrations, such as order identifiers, products, discounts used, customer names, email addresses, and shipping or billing details where provided through platform APIs.
Device, browser, IP address, request metadata, logs, telemetry, and support-related information generated through use of the Service.
3.5 Categories of Data Subjects
Categories of data subjects may include Customer's personnel, Customer's store administrators and staff, and Customer's end customers whose data is transmitted to Veeper through authorized integrations or use of the Service.
4. Controller Instructions
Veeper will process Customer Personal Data only on Customer's documented instructions, including as set out in the Agreement, this DPA, and Customer's use of the Service features and configuration settings.
If Veeper believes an instruction infringes applicable data protection law, Veeper may inform Customer and suspend the affected processing until the issue is resolved. If Veeper is required
by law to process Customer Personal Data other than on Customer's instructions, Veeper will notify Customer before such processing unless legally prohibited from doing so.
5. Security Measures
Veeper will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, implementation costs, nature of processing, and risk to individuals.
These measures may include, as appropriate:
Encryption of Customer Personal Data in transit.
Encryption of Customer Personal Data at rest where appropriate.
Role-based access controls and multi-factor authentication for privileged access. Logging and monitoring of relevant production access and security events. Vulnerability management, patching, and incident response procedures. Backup and recovery processes designed to support resilience and availability
Veeper may update its security measures from time to time, provided that such updates do not materially diminish the overall security of the Service
- Subprocessors
Customer authorizes Veeper to use Subprocessors to provide the Service, provided that Veeper remains responsible for the performance of its Subprocessors' data protection obligations to the extent required by applicable law.
Veeper will maintain an up-to-date list of Subprocessors or make such list available upon request. Where required by applicable law, Veeper will provide at least 30 days' prior notice of a new or replacement Subprocessor and allow Customer to raise reasonable objections on data protection grounds during that notice period.
Veeper will impose data protection obligations on each Subprocessor that are materially no less protective than those set out in this DPA, as applicable to the nature of the services provided by the Subprocessor.
7. Assistance with Data Subject Requests
Taking into account the nature of the processing, Veeper will provide reasonable assistance to Customer to enable Customer to respond to requests from data subjects exercising their rights under applicable data protection law, to the extent Customer cannot reasonably fulfill such requests independently through the Service.
8. Assistance with Compliance
Taking into account the nature of processing and the information available to Veeper, Veeper will provide reasonable assistance to Customer with Customer's obligations relating to security of processing, breach notification, data protection impact assessments, and prior consultation with supervisory authorities where required by applicable law.
9. Personal Data Breach
Veeper will notify Customer without undue delay and, in any event, within 48 hours after becoming aware of a confirmed personal data breach affecting Customer Personal Data, and will provide information reasonably available to Veeper that Customer may need to meet its legal obligations regarding the breach.
Veeper's notification of or response to a personal data breach will not be construed as an admission of fault or liability.
10. Audit Rights
Upon Customer's written request and subject to reasonable confidentiality controls, Veeper will make available information reasonably necessary to demonstrate compliance with this DPA. Where such information is insufficient under applicable law, Customer may request an audit conducted by Customer or an independent auditor subject to reasonable notice, scope, frequency, and confidentiality restrictions, and in a manner that minimizes disruption to Veeper's business operations.
Unless otherwise required by applicable law or where a material non-compliance is identified, Customer will bear its own audit costs
11. International Transfers
Where Veeper processes Customer Personal Data subject to GDPR or UK GDPR and such data is transferred to a country not recognized as providing an adequate level of protection, the parties will implement an approved transfer mechanism, such as the European Commission's Standard Contractual Clauses and, where relevant, the UK International Data Transfer Addendum.
The parties will cooperate in good faith to complete and maintain such transfer documentation and to implement supplementary measures where required.
12. Return and Deletion
Upon termination or expiration of the Agreement, Veeper will, at Customer's choice and subject to the Agreement and applicable law, delete or return Customer Personal Data within 30 days after the end of the provision of services, unless applicable law requires continued retention.
Veeper may retain Customer Personal Data in backup systems for a limited period consistent with its standard backup retention practices, provided such retained data remains protected under this DPA and is deleted in the ordinary course.
13. Liability
The liability of each party arising out of or relating to this DPA will be subject to the exclusions and limitations of liability set out in the Agreement, except to the extent such limitations are prohibited by applicable data protection law.
14. Governing Law
This DPA will be governed by the governing law and jurisdiction provisions of the Agreement, except to the extent required otherwise by mandatory provisions of applicable data protection law or any incorporated transfer mechanism.
15. Contact Information
Customer may send privacy or data protection inquiries under this DPA to the contact details designated by Veeper in the Agreement, privacy policy, security documentation, or customer support communications within the specified timeframe.
Schedule 1 – Details of Processing
A. Subject Matter
Processing of Customer Personal Data in connection with Veeper's SaaS services for discount control, coupon leak prevention, offer management, analytics, and ecommerce integrations.
B. Duration
For the term of the Agreement and any limited retention period thereafter as described in the Agreement, this DPA, or applicable law.
C. Nature and Purpose
Receiving, storing, organizing, analyzing, transmitting, and otherwise processing Customer Personal Data to provide, secure, support, and improve the Service.
D. Categories of Data Subjects
- Customer account owners and administrators
- Customer personnel and authorized users
- End customers interacting with Customer's ecommerce store
E. Categories of Personal Data
Names
Email addresses
Store identifiers
Order and discount information
Customer support communications
IP addresses and device/browser metadata
Log and telemetry data
Shipping and billing details where transmitted through integrations
F. Sensitive Data
Unless expressly agreed otherwise in writing, Customer will not provide Veeper with special categories of personal data or other sensitive regulated data not necessary for the Service. Customer remains responsible for determining whether the Service is appropriate for the data Customer chooses to submit.
Schedule 2 – Optional Commercial Positions
Subprocessor notice period: 30 days.
Breach notice commitment: without undue delay and no later than 48 hours after awareness of a confirmed personal data breach affecting Customer Personal Data.
Audit model: documentation-first, third-party reports first, then limited audit only if needed.
Return/deletion window: 30 days after termination, subject to backup retention. Liability: align fully with the MSA or carve out certain data protection breaches.
Transfer annexes: attach SCCs/UK addendum only when legally required rather than embedding all transfer text in the main body.
18. Contact Information
For questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:
Veeper
Email: jordan@veeper.com
Mailing Address: 15517 Outlook St, Overland Park, KS 66223, United States
Data Protection Officer: Dr. Wasim Irshad, wasim@veeper.com
We will respond to your inquiry within 30 days or as required by applicable law.
Effective Date: August 4, 2026
Last Updated: August 4, 2026
Thank you for trusting Veeper with your personal data. We are committed to protecting your privacy and transparency in our data practices.

