ApproveLane

ApproveLane Data Processing Addendum

Last updated: 13 September 2026

This Data Processing Addendum (“DPA”) forms part of the agreement between REXCODE DIGITAL LTD (“RexCode”, “Processor”, “we”, or “us”) and the merchant or organisation using ApproveLane (“Merchant”, “Controller”, or “you”) where RexCode processes personal data on the Merchant’s behalf through the ApproveLane Shopify application. ApproveLane is a product provided by REXCODE DIGITAL LTD and is not a separate legal entity.

1. Scope and instructions

This DPA applies to personal data processed by RexCode on behalf of the Merchant in connection with ApproveLane. The Merchant determines the purposes of its customer-data processing. RexCode processes that data only to provide and secure ApproveLane, follow documented lawful Merchant instructions, comply with applicable law, or meet Shopify platform requirements.

2. Subject matter and purpose

The processing supports proof-management and approval for customised or made-to-order products. It includes retrieving relevant Shopify order information, associating orders and customers with proofs, storing proof versions, presenting secure approval pages, recording approval or revision decisions, maintaining audit history, supporting notifications, and maintaining service security and reliability.

3. Data, data subjects, and duration

Personal data may include customer name and email; Shopify order identifier, number, date, product title, variant title, and quantity; proof files and filenames; merchant messages; customer comments and optional reviewer name; approval status and timestamps; authorised-user session information; and limited security, request, and webhook metadata.

Data subjects may include Merchant customers, authorised customer representatives, Merchant staff, and other persons legitimately included in a proof workflow. Processing continues while the App is installed and for the limited retention or deletion period described in the Privacy Policy. ApproveLane is not intended for payment-card credentials or special-category personal data, and Merchants should not submit such data unless lawfully necessary and appropriately protected.

4. Processor obligations

RexCode will process personal data only for the purposes above; maintain appropriate confidentiality and access restrictions; apply reasonable technical and organisational measures; assist with valid data-subject requests where reasonably required; support Shopify’s mandatory privacy mechanisms; notify the Merchant where required of a confirmed breach affecting Merchant-controlled data; and delete, anonymise, restrict, or return data following termination where required, subject to lawful retention obligations.

5. Merchant obligations

The Merchant is responsible for lawful collection and use of submitted data, required privacy notices and lawful bases, authorised staff access, appropriate App configuration, responses to customer requests where the Merchant is controller, and avoiding unnecessary sensitive information in files or comments.

6. Security measures

Implemented application measures include encrypted HTTPS/TLS connections and managed encryption at rest; authenticated Shopify sessions; tenant-scoped database access; row-level security and restricted Data API roles; private object storage; server-only credentials; cryptographically random, hashed, expiring and version-bound approval tokens; short-lived signed file URLs; file type and size validation; database integrity constraints; immutable application audit records; request rate limits; secret-aware application logging; and authenticated, idempotent Shopify privacy and uninstall webhooks.

Operational access is limited to authorised accounts and providers. Source code is held in a private GitHub repository and production secrets are held in provider environment controls rather than committed to source. Protected-data reads are recorded in an append-only tenant-scoped access log without names, email addresses, proof contents, tokens, or credentials and retained for 24 months. On Supabase Free, a daily restricted workflow exports application records and proof objects, encrypts them with AES-256 before private artefact storage, retains encrypted backups for 30 days, and verifies restoration in an isolated temporary database. This DPA does not promise continuous point-in-time or zero-data-loss recovery.

7. Subprocessors

The Merchant authorises these current subprocessors where necessary: Shopify (commerce platform and authorised APIs), Supabase (managed PostgreSQL and private object storage), Vercel (application hosting, deployment, and platform logs), GitHub (private source-code hosting, deployment integration, and encrypted backup artefacts), and Resend (transactional proof-notification email delivery). Resend receives only the recipient address and the limited proof-notification content needed to deliver the merchant-initiated message. RexCode may replace or add subprocessors as the service evolves and will apply appropriate contractual and security safeguards.

8. International transfers

Providers may process data outside the United Kingdom or another jurisdiction requiring transfer safeguards. Where required, RexCode will rely on adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved Standard Contractual Clauses, Standard Contractual Clauses, or another lawful recognised transfer mechanism.

9. Data-subject requests

If RexCode receives a request concerning data controlled by the Merchant, RexCode may direct the individual to the Merchant unless required to respond directly. RexCode will provide reasonable assistance for valid access, correction, deletion, restriction, portability, objection, or other applicable requests and supports Shopify’s mandatory customer-data and shop-data webhooks.

10. Security incidents

RexCode will investigate suspected incidents affecting data processed through ApproveLane, contain and remediate confirmed issues, preserve appropriate evidence, and notify the Merchant where notification is legally required. Available information will be provided as reasonably necessary to support the Merchant’s own obligations.

11. Deletion and termination

Uninstall immediately disables the shop’s active application session and approval links. Shopify customer-redaction and shop-redaction requests remove affected proof objects and anonymise affected customer and order fields. Independently, proof-workflow personal data and proof files are automatically deleted or anonymised after 12 months without workflow activity. Only a non-personal workflow shell, integrity metadata, status/timestamps, immutable audit information, and the 24-month protected-data access log remain for security, accountability, and dispute evidence. Encrypted backups expire after 30 days, so deleted information may remain only until the relevant encrypted artefact expires.

12. Audit information and contact

On reasonable request, RexCode may provide information needed to demonstrate compliance, subject to confidentiality, proportionality, system security, and protection of other merchants. RexCode is not required to disclose credentials, raw security tokens, source code, or information that would materially weaken security.

Data-protection questions may be sent to support@rexcode.co.uk.

REXCODE DIGITAL LTD
Company Number: 17088152
Registered Office: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
ICO Registration Reference: ZC205511