Skip to content
frontforge
  • Get support

Legal

Data processing agreement

Version 1.0 — 6 September 2026

These terms govern our handling of personal data when you install a frontforge app on your Shopify store. They apply automatically from installation; you do not need to sign anything for them to bind us. If your own compliance process needs a countersigned copy, ask through the support form.

What each app collects in practice, in plainer language, is on the app privacy page. Where that page and this one describe the same thing differently, this one governs.

1. Parties

  • Processor — frontforge Pty Ltd, ABN 80 600 354 283, of Narangba QLD, Australia ("we", "us").
  • Controller — the merchant operating the Shopify store on which the app is installed ("you").

2. Words we use

  • Personal data, controller, processor, data subject and processing carry the meanings given in the General Data Protection Regulation (EU) 2016/679, and the equivalent meanings under any other data protection law that applies to you.
  • Sub-processor — a third party we engage to process personal data on your behalf.
  • The app — the frontforge Shopify app you have installed. Today that is Picksheet.
  • Data protection law — whichever privacy and data protection laws apply to your processing, including the GDPR and the UK GDPR where relevant.

3. Roles

You are the controller of the personal data the app processes. You decide which orders are printed and for what purpose. We are your processor and act only on your behalf.

Shopify holds the underlying store data and is a separate party to this agreement. Nothing here changes your relationship with Shopify or theirs with you.

4. Our instructions

We process personal data only on your documented instructions, including in relation to transfers out of your region. Your instructions are: this agreement, the app privacy page, and your use of the app's features. Installing the app and selecting orders to print is an instruction to process the personal data those orders carry.

We do not process personal data for our own purposes. We do not sell it, use it for advertising, use it to train models, or use it to build profiles.

If we believe an instruction breaches data protection law, we will tell you and may pause that processing until it is resolved. If we are required by law to process beyond your instructions, we will tell you first unless that law forbids it.

5. What is processed

Subject matter and purpose

Printing pick lists and pack slips from the orders you select, so that goods can be picked and parcels addressed.

Duration

For as long as the app is installed on your store, plus the retention periods in section 10.

Categories of data subject

  • Your customers — specifically the recipients of the orders you print.
  • Your staff — the Shopify user account that opens the app.

Types of personal data

  • Read when you print, never stored — the order recipient's name; the shipping address, being address lines, city, province or state, postal code and country.
  • Read to list orders — the recipient's name only. The app requests no address fields for the order list.
  • Stored — your shop domain; Shopify order identifiers with a count and timestamp, recording what was printed and when; the Shopify session, including the staff account identifier, name and email that Shopify supplies with an online access token.

The app does not request customer email addresses or telephone numbers from Shopify, holds no read_customers scope, and never receives payment card data.

We do not knowingly process special categories of personal data. The app cannot select for them, and asks Shopify for no field that would carry them.

6. Security

We maintain technical and organisational measures appropriate to the risk, as required by Article 32. The measures in place are:

  • No customer personal data at rest. Names and addresses are read from Shopify's API when you print, rendered, and discarded. They are never written to our database, so no database compromise can disclose them.
  • Data minimisation in the queries themselves. The app asks Shopify only for fields it displays or prints.
  • Encryption in transit. All traffic is served over TLS, with plain HTTP redirected, and API calls to Shopify are over TLS. The app reaches its database over the hosting provider's private network, which is WireGuard encrypted and never crosses the public internet; the database has no public endpoint.
  • Encryption at rest. Database storage is encrypted at rest by our hosting provider.
  • Authenticated webhooks. Webhook deliveries are verified against their HMAC signature using a constant-time comparison and rejected with a 401 if the signature does not match.
  • Access control. Production access is limited to our maintaining personnel, with unique credentials per service and multi-factor authentication where the provider supports it. Secrets are held in the hosting platform's environment configuration and never in source control.
  • An access record. Every print is recorded — which shop, which order references, and when — giving an audit trail of each occasion order data was read.
  • Logging without personal data. Application logs record the shop and any error condition. They do not record customer names or addresses.
  • Separated environments. Production and test run as separate deployments with separate databases.
  • Encrypted backups. The app database is backed up daily with six-day retention and point-in-time recovery across the same window. Backups are taken, held and encrypted at rest by the hosting provider; we extract no copies, so no backup artifact leaves the platform boundary.

We may change these measures, provided the level of protection is not reduced.

7. Confidentiality

Everyone we authorise to process personal data under this agreement is bound by a duty of confidentiality, and is given access only to what their work requires.

8. Sub-processors

You give us general authorisation to engage the sub-processors below. Each is bound by written terms imposing data protection obligations no less protective than these, and we remain liable to you for their performance.

  • Railway — hosting for the app and its database.
  • Amazon Web Services — hosting for the support portal and ticket database.
  • Cloudflare — automated-submission checks on the public support form.
  • Microsoft — sign-in for the support portal, via Entra External ID.
  • SMTP2GO — delivery of support email.

We will give at least 30 days' notice before adding or replacing a sub-processor, by updating this page. If you reasonably object on data protection grounds within that period, we will work with you to find an alternative; if none is workable, you may uninstall the app and this agreement ends under section 10.

9. International transfers

Processing takes place outside the European Economic Area. Where personal data is transferred out of your region, the transfer is made under the relevant sub-processor's data processing terms, which incorporate the European Commission's standard contractual clauses, together with any supplementary measures those terms require. We will provide the current terms for any sub-processor on request.

10. Retention, return and deletion

  • Customer names and addresses — never stored, so nothing to retain or delete.
  • Print records — order identifiers, counts and timestamps, deleted 90 days after the print.
  • Application logs — deleted after 30 days.
  • Session records — deleted when you uninstall the app.
  • Your shop record — deleted when Shopify sends the shop redaction webhook, 48 hours after uninstall.

Deletion removes data from the live database at the times above. A copy may persist in an encrypted backup for up to six days until that backup ages out. If we restore from a backup, we re-apply any deletion made in the intervening period. No backup contains customer names or addresses, because those are never written to the database.

Uninstalling the app is your instruction to delete. Nothing needs to be returned to you, because everything we hold originates in your Shopify store and remains there.

11. Helping you meet your obligations

Taking into account the nature of the processing, we will help you with:

  • Requests from data subjects. Shopify's mandatory customer data request and redaction webhooks are implemented and actioned on receipt. A data request is answered with which print records referenced the orders in question; a redaction removes those order references, and deletes a print record left with none. If you receive a request directly, ask through the support form and we will help.
  • Security, breach notification and impact assessments. We will provide the information you reasonably need for your obligations under Articles 32 to 36.

12. Personal data breaches

We will notify you of a personal data breach affecting your data without undue delay after becoming aware of it, and in any event within 72 hours. The notification will describe what happened, the categories and approximate volume of data involved, the likely consequences, and the measures taken or proposed. Where we cannot provide all of it at once, we will provide it in stages without further undue delay.

13. Audits and information

We will make available the information reasonably necessary to demonstrate compliance with this agreement, and will answer your security and privacy questions in writing.

Where that is not sufficient for your obligations, you may audit us, or appoint an independent auditor who is not our competitor, on 30 days' written notice, no more than once in any 12 months, during business hours, and in a way that does not disrupt the service. You bear the cost of the audit. This limit does not apply where a supervisory authority requires otherwise, or following a personal data breach affecting your data.

14. Precedence and liability

Where this agreement conflicts with our other terms, this agreement governs the processing of personal data. Everything else is unchanged.

This agreement does not create liability separate from the terms for frontforge Shopify apps. Each party's liability arising out of or in connection with it is subject to the exclusions and the cap in section 10 of those terms.

Nothing here limits liability that cannot be limited by law. In particular, it does not affect a data subject's rights under Article 82 of the GDPR, or any liability we have directly to a data subject or to a supervisory authority.

15. Term and governing law

This agreement starts when you install the app and continues until the last of the retention periods in section 10 has run.

It is governed by the laws of Queensland, Australia, and disputes about it are resolved in the courts of Queensland, Australia — the same forum as the terms it sits under. That is without prejudice to any mandatory rights you have under data protection law in your own jurisdiction, or to your right to complain to your own supervisory authority.

16. Contact

Data protection questions, sub-processor objections, audit requests and breach correspondence all go to frontforge.com/support.

© 2026 frontforge. All rights reserved.

Support · Terms · Privacy · App privacy · DPA ·