Data Processing Addendum
This Data Processing Addendum (DPA) applies when 100 Rocks processes storefront visitor personal data for a merchant or other storefront operator. An authorized merchant accepts and enters into this DPA electronically when they select the DPA acceptance checkbox and create or connect a store.
1. Parties and roles
The merchant is the controller of storefront visitor personal data. 100 Rocks, operated by Karen Charykov, Entrepreneur individuel (EI), is the processor for storefront analytics and related adaptive interface testing. For merchant console account data, 100 Rocks acts as an independent controller under the Privacy Policy. This DPA covers storefront visitor data only.
2. Subject matter and duration
100 Rocks processes storefront visitor personal data to provide storefront analytics, consent-gated behavior measurement, commerce funnel reporting, approved PDP variant testing, and related support services. Processing lasts for the service term plus the time needed to return or delete data after termination, unless applicable law requires retention.
3. Nature and purpose of processing
Processing includes collecting and aggregating audience analytics; collecting consent-gated behavior analytics; providing reports, dashboards, approved test results, and verified subject-access packages; supporting merchant-initiated data subject requests; and applying retention and deletion schedules. 100 Rocks does not process storefront visitor personal data for its own advertising, cross-merchant shopper profiles, sale, or independent marketing.
4. Data subjects and personal data
Data subjects are storefront visitors and shoppers. Personal data may include page URLs and titles, navigation paths and events, referrer and campaign parameters, device, browser, and operating-system class, viewport, locale, coarse location signals, truncated IP-derived information, bot classification, opaque session and visitor identifiers, consent records, commerce funnel events and outcomes, consent-gated behavior metrics, and bounded normalized target tokens such as element IDs, classes, selected data attributes, roles, and hashes. Target tokens exclude visible text, input values, and raw full selectors. The custom-site consent UI stores its overall decision in localStorage.adaptive_analytics_consent and purpose choices in localStorage.adaptive_analytics_purpose_consent. On Shopify storefronts after analytics consent, a first-party rocks_session_key cookie may be used for up to 30 minutes to associate browser activity with Shopify Web Pixel commerce events and is deleted on denial, Global Privacy Control, or study opt-out. 100 Rocks does not intentionally collect names, email addresses, payment card data, or free-text form fields through the analytics tracker.
5. Merchant instructions and obligations
The merchant instructs 100 Rocks to process data as configured in the merchant console and installation settings. Limited audience measurement may run before consent only where the merchant determines that applicable law permits it and configures that path; behavior processing remains consent-gated. The merchant must maintain a lawful basis and valid consent mechanism where required, publish an accurate storefront privacy notice, configure Shopify Customer Privacy, a CMP, or the 100 Rocks consent banner before enabling behavior analytics where required, and not issue unlawful processing instructions.
6. Processor obligations
100 Rocks will process personal data only on documented merchant instructions unless law requires otherwise; ensure authorized personnel are bound by confidentiality; maintain appropriate security; impose protective terms on subprocessors; assist with data subject rights, security, breach, and impact-assessment obligations where reasonably possible; delete or return data at the end of the service; and provide information reasonably necessary to demonstrate compliance. 100 Rocks will notify the merchant if, in its opinion, an instruction infringes applicable data-protection law.
7. Subprocessors
For storefront visitor personal data, 100 Rocks uses Supabase for database services, Vercel for application hosting and content delivery, and Shopify for app installation and Web Pixel services where connected. Account billing, transactional email, abuse protection, and merchant-initiated design scans are outside this DPA unless they receive covered storefront visitor data. The merchant gives general authorization. 100 Rocks binds subprocessors as required by applicable law, publishes the current list, and emails account administrators at least 30 days before a material addition or replacement. The merchant may raise a reasonable data-protection objection during that period.
8. Security
100 Rocks maintains measures appropriate to the processing, including encrypted transport, access controls, tenant isolation, least-privilege access, and operational logging for security-relevant actions. The merchant remains responsible for storefront configuration, consent tooling, and access controls in its environment.
9. Personal data breach
100 Rocks will notify the merchant without undue delay after becoming aware of a personal data breach affecting merchant storefront visitor personal data and will provide information reasonably available to help the merchant meet its notification obligations.
10. Retention, return, and deletion
Default retention is 90 days for raw event-level analytics, 12 months for sessions and session metrics, 25 months for consent records, and 24 months for daily aggregate rollups and page layout references. Generated heatmap versions follow the merchant's plan quota (three ready versions per page/device by default), not a 24-month period. Production exposes no shopper session replay or general merchant raw-event/session-metrics export. On verified instruction, 100 Rocks can generate a subject-access package for one supplied session or visitor identifier. The package includes retained session quota/access-tier records. Erasure removes addressable events, sessions, metrics, and consent transitions and irreversibly tombstones the matching identifier in retained quota records while preserving quota totals. Request audits retain a legal reference, outcome, deleted/anonymized counts, package version/hash where applicable, and a tenant-scoped keyed identifier hash, not the new request's raw identifier or package contents. Remaining covered data is deleted under the stated periods unless law requires retention. Data in security backups is protected from ordinary use and expires through the normal backup-rotation process; it is restored only for recovery and deleted again when restored. Anonymous aggregates may remain after subject erasure, and tenant rollups are removed with project deletion.
11. International transfers
100 Rocks will not make a restricted transfer without a lawful mechanism. Where no adequacy decision applies, it will put in place the applicable European Commission Standard Contractual Clauses, including Module 2 where relevant, the UK International Data Transfer Addendum or IDTA where required, or another permitted mechanism. Onward transfers rely on the subprocessor's data-processing agreement and supplementary measures where required. Primary functions and database/authentication storage are configured in Paris/EU regions; other provider operations may occur elsewhere under those safeguards.
12. Audits and compliance information
On reasonable written request, 100 Rocks first provides information reasonably necessary to demonstrate compliance. Any further audit is remote-first, no more than once in twelve months unless required by a regulator or a confirmed incident creates a reasonable need, during normal business hours, and subject to confidentiality and protection of other merchants. The merchant bears its audit costs unless material non-compliance by 100 Rocks is identified.
13. US and Canadian privacy laws
Where applicable US state law treats 100 Rocks as a service provider, processor, or contractor, the specified purposes are analytics, reporting, approved testing, support, security, rights assistance, and deletion under this DPA. 100 Rocks will not sell or share covered data, use it outside those purposes and the direct business relationship, or combine it with unrelated data except as permitted by law. It will notify the merchant if it can no longer comply and support required monitoring and remediation. For Canadian personal information, 100 Rocks provides comparable protection and assists with applicable rights.
14. Order of precedence
If this DPA conflicts with the main service agreement, this DPA controls for the processing of storefront visitor personal data.
15. Governing law
Unless the parties agree otherwise or mandatory data-protection terms require another result, this DPA is governed by the same law and forum as the main service agreement.
16. Contact
Privacy and DPA requests: help@100.rocks.