Xeon AppsShopify apps

Chaperone

Data Processing Addendum

Effective date: August 24, 2026 · Incorporated into the Chaperone terms for all merchants

1. Roles

For personal data processed through Chaperone, the merchant is the controller and Chaperone is the processor. Chaperone processes personal data only on the merchant’s documented instructions: the permissions, connection rules, approvals, and connections the merchant configures in the app, and applicable law.

2. Scope of processing

  • Subject matter:governed relay of Shopify Admin API data between the merchant’s store and the AI assistants the merchant connects; rule enforcement; approval workflow; audit logging.
  • Duration: while the app is installed, plus the deletion window in §6.
  • Categories of data: store commerce data (products, inventory, orders where enabled), staff identifiers (approval attribution, notification email), and — only where the merchant enables customer domains after platform approval — customer contact and order details.
  • Data subjects:the merchant’s staff and, where enabled, the merchant’s customers.

3. Processor obligations

  • Process personal data only per merchant instructions; never for Chaperone’s own purposes, and never to train AI models.
  • Ensure persons authorized to process the data are bound by confidentiality.
  • Implement the technical and organizational measures in §7.
  • Assist the merchant with data-subject requests and with Shopify’s mandatory privacy webhooks (data request, customer redact, shop redact).
  • Notify the merchant without undue delay after becoming aware of a personal data breach affecting their data.
  • Make available information reasonably necessary to demonstrate compliance with this addendum.

4. Sub-processors

The merchant authorizes these sub-processors; Chaperone remains responsible for their performance:

  • MongoDB Atlas — database hosting.
  • Application hosting provider — server infrastructure.
  • Email delivery provider — merchant notifications.

AI providers the merchant connects (e.g. Anthropic, OpenAI) are notsub-processors of Chaperone. They are independent services the merchant chooses; Chaperone transmits data to them solely as directed by the merchant’s configuration, and the merchant’s agreement with those providers governs their processing. Chaperone will give notice (in-app or by email) before adding or replacing a sub-processor.

5. International transfers

Where processing involves transfers of personal data subject to GDPR or similar laws, the parties rely on the sub-processors’ standard contractual clauses and equivalent safeguards.

6. Deletion

On uninstall, Chaperone deletes all personal data it holds for the store following Shopify’s shop/redact notice (typically within 48 hours of that notice). Customer-level redaction requests are honored inside all records, including audit and approval entries, within the legally required timeframe.

7. Security measures

  • Shopify API credentials encrypted at rest; never exposed to AI assistants or third parties.
  • Per-store tenant isolation enforced at the credential and data layers; AI assistants hold only revocable, store-bound gateway credentials.
  • TLS for all data in transit.
  • Customer PII redaction toward AI assistants on by default; redacted inputs in the audit ledger.
  • Append-only, hash-chained audit ledger providing tamper-evident access logging.
  • Merchant-controlled kill switch and permission revocation with immediate effect.

8. Contact

Data protection contact: support@xeonapp.com.