This Data Processing Addendum (DPA) forms part of the ReguCart Terms of Service (Terms) between the merchant (you, the Merchant) and Shivam Bector, trading as Debug Ninja, a sole proprietorship based in Panchkula, Haryana, India (Debug Ninja, we, us). You accept it when you accept the Terms. No separate signature is needed.
It applies whenever we process Customer Personal Data (defined below) on your behalf. If this DPA and the Terms conflict on the processing of Customer Personal Data, this DPA prevails.
1. Definitions
1.1 Customer Personal Data means personal data that we process on your behalf in providing the Service, as described in Annex 1. It includes grievance desk submissions, seller details form submissions, personal data contained in your store content or in documents you upload, and signatory details on your certificate pages. It does not include data for which we are the Data Fiduciary under our Privacy Policy (for example, the details of your staff who accept our Terms).
1.2 Data Fiduciary, Data Processor, Data Principal, personal data, personal data breach and processing have the meanings given in the Digital Personal Data Protection Act 2023 (DPDP Act). Until the relevant DPDP provisions take effect on 13 May 2027, references to the DPDP Act should be read, where relevant, as references to section 43A of the Information Technology Act 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011 (SPDI Rules), and "Data Fiduciary" means the body corporate that collects the information.
1.3 Data Protection Law means the DPDP Act, the Digital Personal Data Protection Rules 2025 (DPDP Rules), the Information Technology Act 2000 and rules under it (including the SPDI Rules while they apply), and any other law of India on personal data that applies to the processing.
1.4 Subprocessor means a third party we engage to process Customer Personal Data.
1.5 Other capitalised words have the meanings given in the Terms.
2. Roles
2.1 For Customer Personal Data, you are the Data Fiduciary and we are your Data Processor.
2.2 This DPA is the contract under section 8(2) of the DPDP Act under which you engage us as your Data Processor.
2.3 Each party will comply with the Data Protection Law that applies to it in its role.
3. Your obligations
3.1 You are responsible for having a lawful basis for the Customer Personal Data you ask us to process, and for giving every notice the law requires. In particular, your store's privacy notice must explain that complaints submitted through your grievance form, and details submitted through your seller form, are processed by a service provider on your behalf.
3.2 Your instructions to us must comply with Data Protection Law.
3.3 You are responsible for responding to Data Principals who exercise their rights against you, and for deciding how complaints are handled.
3.4 You must not ask us to process more Customer Personal Data than the feature needs. Where you upload sample invoices or documents, you should remove personal data that the check does not need (for example, a buyer's name and address).
3.5 You are responsible for notifying the Data Protection Board of India and affected Data Principals of a personal data breach where the law requires it.
4. Our obligations
4.1 Instructions. We process Customer Personal Data only on your documented instructions. Your instructions are: the Terms, this DPA, and the settings and actions you take in the app (for example, turning on the grievance desk, replying to a complaint or changing a ticket's status). We may also process it where Indian law requires us to; if so, we will tell you first unless the law forbids it.
4.2 Unlawful instructions. We will tell you if we believe an instruction breaches Data Protection Law. We may decline to follow it.
4.3 Purpose. We will not process Customer Personal Data for our own purposes, sell it, use it for advertising, or use it to train AI models.
4.4 Confidentiality. Everyone we authorise to access Customer Personal Data is bound by a duty of confidentiality. At present, only our owner has such access.
4.5 Security. We will maintain the reasonable security safeguards described in Annex 2, appropriate to the nature of the data and the risks, to protect Customer Personal Data against personal data breach.
4.6 Logs. From 13 May 2027 we will keep logs of access to Customer Personal Data for the period the DPDP Rules require (at least one year), and make relevant extracts available to you on reasonable request.
5. Subprocessors
5.1 You give us general authorisation to engage Subprocessors. Our current Subprocessors are listed at regucart.com/subprocessors.
5.2 We will impose on each Subprocessor data protection terms that are no less protective than this DPA, to the extent applicable to the service it provides. We remain responsible to you for our Subprocessors' processing of Customer Personal Data.
5.3 We will give you at least 14 days' notice before adding or replacing a Subprocessor that will process Customer Personal Data, by updating the list and notifying you in the app or by email. If you object on reasonable data protection grounds, tell us within that period. We will try to address your objection. If we cannot, you may stop using the affected feature or end the Terms by uninstalling the app. If you end a prepaid annual plan for this reason, we will refund the unused part of the fee, through Shopify where possible.
5.4 In an emergency (for example, a provider failure), we may replace a Subprocessor immediately and will notify you as soon as practicable.
6. Transfers outside India
6.1 You authorise us to transfer Customer Personal Data to, and process it in, the countries where we and our Subprocessors operate, as listed at regucart.com/subprocessors. These include Singapore and the United States.
6.2 We will not transfer Customer Personal Data to a country or territory that the Central Government has restricted under section 16 of the DPDP Act.
7. Help with Data Principal requests
7.1 Taking into account the nature of the processing, we will help you respond to requests from Data Principals to access, correct, complete, update or erase their personal data, to withdraw consent, or to raise a grievance.
7.2 The app supports this as follows:
- you can view, update and close complaints in the Grievances screen;
- when Shopify sends us a "customers/redact" request, we delete grievance records linked to that person's email;
- when Shopify sends us a "customers/data_request", we send you the grievance records linked to that email;
- on written request to [email protected], we will locate, export, correct or delete specific Customer Personal Data within 7 days.
7.3 If a Data Principal contacts us directly about Customer Personal Data, we will pass the request to you within 7 days and will not respond to it ourselves except to tell them we have done so, unless you instruct us otherwise or the law requires it.
8. Personal data breach
8.1 If we become aware of a personal data breach affecting Customer Personal Data, we will notify you without undue delay, and where feasible within 24 hours, and in any event within 48 hours, by email to your store's contact email and the alert recipients in your Settings.
8.2 Our notice will describe, as far as then known: the nature and extent of the breach, the categories and approximate number of Data Principals and records concerned, the likely consequences, the measures taken or proposed, and a contact person. We will send further details as they become available.
8.3 We will take reasonable steps to contain and remedy the breach, and give you the information and help you reasonably need to notify the Data Protection Board of India and affected Data Principals, and to meet the 72-hour detailed reporting duty under the DPDP Rules. Our notice is not an admission of fault.
9. Help with your other obligations
9.1 We will give you information reasonably needed to show that this DPA is being met, and reasonable help with any data protection impact assessment or audit that the law requires of you.
9.2 We will answer one written security questionnaire from you per year at no charge. Further requests, or an audit by you or an independent auditor bound by confidentiality, will be on at least 30 days' notice, at your cost, during business hours, limited to what is needed, and without access to other merchants' data. We will always cooperate with an audit required by a regulator.
10. Retention and deletion
10.1 We keep Customer Personal Data only as long as needed to provide the feature, as follows:
- grievance desk records: until 3 years after the complaint is closed, or a shorter period you ask for in writing, then deleted;
- seller details form data: while the app is installed;
- crawl evidence: 90 days on Pro; on Free, until the next scan replaces it;
- uploaded documents: while the app is installed, unless you delete them sooner.
10.2 On uninstall: Shopify sends us a "shop/redact" request 48 hours after you uninstall the app. When we receive it, we delete all Customer Personal Data for your store, including stored files.
10.3 On request: you can delete all data for your store at any time from Settings ("Delete my data"). Before deleting, you can export your data, and you can ask us for a copy of grievance records.
10.4 Deleted data in encrypted backups is overwritten within 14 days. We may keep Customer Personal Data longer only where Indian law requires it, and then only for that purpose.
11. Liability
Each party's liability under this DPA is subject to the limits and exclusions in the Terms (clause 15), to the extent the law allows.
12. Term
This DPA lasts as long as we process Customer Personal Data for you. Clauses that by their nature should continue (including 4.3, 4.4, 8 and 10) survive the end of the Terms.
13. Changes
We may update this DPA as described in clause 19 of the Terms. We will not reduce the protection given to Customer Personal Data without your acceptance, unless the law requires the change.
Annex 1: Details of the processing
| Item | Details |
|---|---|
| Subject matter | Providing the Service to the Merchant under the Terms |
| Duration | While the app is installed, then until deletion under clause 10 |
| Nature of processing | Collection through store forms, storage, encryption, display to the Merchant, sending acknowledgement and reply emails, SLA tracking, deletion; capture of storefront content; AI-assisted review of store content and uploaded documents; generation of pages from Merchant inputs |
| Purpose | To let the Merchant receive and handle consumer grievances, collect and display vendor information, run Checks on its store and documents, and publish its own pages |
| Data Principals | The Merchant's customers and other complainants; the Merchant's vendors and their contacts (marketplaces); people whose data appears in the Merchant's store content or uploads (for example reviewers, buyers named on sample invoices); signatories of the Merchant's certificate pages |
| Categories of personal data | Grievance desk: name, email, phone (optional), order reference (optional), complaint category and text, photos (optional), replies and status history. Seller form: business and contact names, addresses, emails, phone numbers, GSTIN, PAN (stored masked except last 4 characters), Udyam number, grievance officer details. Store content and uploads: whatever personal data the Merchant's content or documents contain. Certificate pages: signatory name, designation, date |
| Sensitive data | Not requested. Complaint text, photos and uploads may contain it (for example health information). It receives the same encryption and access controls as other grievance data |
| Frequency | Continuous while the feature is in use |
| Locations | See regucart.com/subprocessors |
Annex 2: Security safeguards
- Encryption in transit: TLS for all connections between the app, Shopify, our services and our Subprocessors.
- Encryption at rest: grievance name, email, phone and complaint text are encrypted with AES-256-GCM before storage, with keys held as hosting secrets separate from the database. Shopify access tokens are encrypted the same way. Files are stored in Cloudflare R2, which encrypts all stored objects at rest.
- Pseudonymised lookup: complainant emails are also stored as an HMAC-SHA256 keyed hash, used to find records for deletion and data requests.
- Minimum access: the app requests only the Shopify permissions it needs and does not request access to order or customer records. Only our owner can access production systems and provider accounts. The internal operations console is limited to an allowlist of accounts through Google single sign-on.
- Request integrity: all Shopify webhooks and storefront form submissions are verified by HMAC signature. The grievance form has rate limits and anti-spam checks that do not use third-party cookies.
- Data minimisation: crawl captures are limited to what evidence needs; AI tasks receive only the content needed; logs are structured and designed to exclude tokens and personal data.
- Separation: each merchant's data is keyed to its store and stored files are kept under a per-store prefix, so deletion removes them together.
- Resilience: daily database backups by our hosting provider; jobs are retried safely.
- Deletion: automatic deletion on Shopify "shop/redact" and "customers/redact" requests, scheduled deletion of grievance records after the retention period, and on-demand deletion from Settings.
- Incident response: structured logs of errors and job failures (error monitoring through Sentry is planned), and the breach process in clause 8.
Annex 3: Subprocessors
See regucart.com/subprocessors (version 2026-10-08).