Data Processing Addendum
Last updated: July 3, 2026
This Data Processing Addendum ("DPA") forms part of, and is incorporated by reference into, the Terms of Service between the merchant ("Controller," "you") and Edge Traversal LLC, a California limited liability company ("Doorman," "we," "us"). It governs our processing of personal data on your behalf when you use the Doorman app. Where the Terms and this DPA conflict on the subject of data protection, this DPA controls.
This DPA takes effect when you install or use Doorman. By doing so, you enter into it on behalf of the Controller and confirm you are authorized to do so. If you require a countersigned copy for your records, email hello@doormanapp.com.
1. Definitions
"Applicable Data Protection Law" means all privacy and data protection laws applicable to the processing under this DPA, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018 ("UK GDPR"), and the California Consumer Privacy Act as amended by the CPRA ("CCPA"). The terms controller, processor, data subject, personal data, processing, personal data breach, service provider, sell, and share have the meanings given in the Applicable Data Protection Law. "Standard Contractual Clauses" or "SCCs" means the clauses annexed to EU Commission Implementing Decision (EU) 2021/914.
2. Roles of the parties
For personal data relating to your storefront visitors and customers, you are the Controller and Doorman is the Processor (a "service provider" under the CCPA), processing that data only on your behalf and under your documented instructions. For personal data relating to you as a merchant (your account, billing, and settings), Doorman acts as an independent controller as described in our Privacy Policy, and that processing is outside the scope of this DPA.
3. Scope and instructions
We will process personal data only: (a) to provide, secure, and support the Service; (b) as further described in Annex A; and (c) in accordance with your documented instructions, including through your configuration of the Service (for example, enabling the Klaviyo integration). Your use of the Service, together with the Terms and this DPA, constitutes your complete and documented instructions. We will inform you if, in our opinion, an instruction infringes Applicable Data Protection Law, and we may suspend processing that we reasonably believe is unlawful.
4. Our obligations as Processor
- Confidentiality — we ensure that personnel authorized to process the personal data are bound by an appropriate duty of confidentiality.
- Security — we implement and maintain the technical and organizational measures described in Annex B, appropriate to the risk under Article 32 GDPR.
- Data subject requests — taking into account the nature of the processing, we assist you by appropriate technical and organizational measures, insofar as possible, to respond to requests to exercise data subject rights. Because Doorman stores no name-, email-, or customer-ID-keyed records for storefront visitors, most such requests are fulfilled by you as Controller; we will support you as reasonably needed.
- Assistance — we assist you, taking into account the nature of processing and the information available to us, with your obligations regarding security (Art. 32), breach notification (Arts. 33–34), and data protection impact assessments and prior consultation (Arts. 35–36).
- Records & audits — we make available information reasonably necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, which may be satisfied by our providing our then-current security documentation, subprocessor list, and responses to a reasonable security questionnaire no more than once per year (or following a personal data breach).
5. Subprocessors
You grant a general authorization for us to engage the subprocessors listed in our Privacy Policy (currently Fly.io, our managed Postgres provider, managed Redis, MaxMind, Cloudflare, and — only if you enable it — Klaviyo). We impose data protection obligations on each subprocessor no less protective than those in this DPA and remain responsible for their performance. We will give you at least 30 days' notice of any intended addition or replacement of a subprocessor (by updating the Privacy Policy and, for installed merchants, by email). If you reasonably object on data protection grounds, you may raise the objection with us within that window and, if we cannot resolve it, terminate the Service by uninstalling.
6. International transfers
Where we transfer personal data originating in the EEA, UK, or Switzerland to a country without an adequacy decision, the transfer is governed by the SCCs (Module Two: controller to processor), which are hereby incorporated by reference and completed as follows: the docking clause (Clause 7) applies; Option 2 of the general authorization applies under Clause 9(a) with the 30-day notice period in Section 5 above; Clause 11 (redress) — the optional independent dispute-resolution body — does not apply; the governing law under Clause 17 is the law of the Republic of Ireland; the supervisory forum under Clause 18 is Ireland; and Annexes I, II, and III are populated by Annexes A and B of this DPA and the subprocessor list referenced in Section 5. For UK transfers, the UK International Data Transfer Addendum to the SCCs applies and is likewise incorporated. If any incorporated transfer mechanism conflicts with this DPA, that mechanism prevails to the extent of the conflict.
7. CCPA — service provider terms
With respect to personal information governed by the CCPA that we process on your behalf, we act as a service provider. We: (a) will not sell or share that personal information; (b) will not retain, use, or disclose it for any purpose other than the business purposes specified in this DPA and the Terms, including not for any commercial purpose other than providing the Service; (c) will not retain, use, or disclose it outside the direct business relationship between you and us; and (d) will not combine it with personal information received from other sources, except as permitted by the CCPA. We certify that we understand and will comply with these restrictions.
8. Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting personal data we process on your behalf, and will provide information reasonably available to us to help you meet your notification obligations. Our notification is not an acknowledgment of fault or liability.
9. Return and deletion
On termination of the Service (including your uninstalling the app), we delete the personal data we process on your behalf within 48 hours, consistent with Shopify's shop/redact webhook and our Privacy Policy, unless retention is required by law. Detection events are in any case purged automatically within 90 days.
10. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Terms, and any reference in the Terms to a party's liability means the aggregate liability of that party under the Terms and this DPA together.
Annex A — Details of processing
- Subject matter — provision of bot-detection and mitigation for the Controller's Shopify storefront and checkout.
- Duration — the term of the Service, plus the retention periods stated in the Privacy Policy.
- Nature and purpose — collecting and scoring request signals to distinguish automated from human traffic, and acting on that score (rate limiting, suppression, tagging, or forwarding an attribute to an integrated email provider the Controller enables).
- Categories of data subjects — visitors to and customers of the Controller's storefront.
- Types of personal data — truncated/anonymized IP address (host portion removed before storage; full IP held transiently under 60 seconds for rate limiting), user-agent string, client-side behavioral signal scores and signal names, country code, Shopify cart/checkout tokens, and storefront page URL. If the Controller enables the Klaviyo integration: the buyer's email address, forwarded in transit to the Controller's own Klaviyo account and not stored by us.
- Special categories — none are intentionally processed. Doorman does not solicit or require sensitive personal data.
Annex B — Technical and organizational measures
- Encryption in transit — all traffic is served over HTTPS/TLS.
- Encryption at rest — merchant-supplied secrets (the Klaviyo API key) are envelope-encrypted with AES-256-GCM.
- Data minimization — IP addresses are truncated to a non-identifying network prefix (IPv4 /24, IPv6 /48) before persistence; no names, emails, addresses, payment data, or cross-site tracking are stored.
- Access control — database access is restricted to the application host; Shopify session tokens are retained only while the app is installed.
- Retention & deletion — detection events auto-purge within 90 days; all merchant-scoped personal data is deleted within 48 hours of uninstall via Shopify's
shop/redactwebhook. - Resilience & isolation — transient rate-limit counters live in a separate short-lived store keyed on IP and expire within 60 seconds; they hold no detection events or merchant data.
Contact
Questions about this DPA, or requests for a countersigned copy or our security documentation: hello@doormanapp.com, or by mail to:
Edge Traversal LLC, a California limited liability company
307 S. Pixley St, Orange, CA 92868, USA