Effective 1 September 2026
Roles
The merchant is the controller of its customers' personal data, and Point Blank Engineering Limited acts as processor. We are controller only for merchant account data, such as the store owner's contact details. Our Data Processing Agreement sets out the processor terms; email support@subscriptions.super-simple.co for a copy.
Where data is hosted
| Component | Provider | Location |
|---|---|---|
| Web application servers | AWS Elastic Beanstalk | Ireland (eu-west-1) |
| Renewals, billing attempts and notifications | AWS Lambda, SQS and EventBridge | Ireland (eu-west-1) |
| Email delivery | AWS SES | Ireland (eu-west-1) |
| File storage and admin audit log | AWS S3 | Ireland (eu-west-1) |
| Database | MongoDB Atlas | France |
| Content delivery and firewall | Amazon CloudFront and AWS WAF | Global edge network; visitors in Europe are served from European locations |
Our team accesses production systems from Bulgaria, in the European Union.
Sub-processors
| Sub-processor | Purpose | Personal data | Location |
|---|---|---|---|
| Amazon Web Services | Hosting, processing, email delivery, storage, content delivery | All data the App holds | Ireland |
| MongoDB Atlas | Database | All data the App holds | France |
| PostHog | Admin analytics and session recordings; cookieless website analytics | Merchant staff usage; customer details shown on admin screens; anonymous website page views and clicks | Germany |
| Crisp | Support chat and support records | Merchant contact details and messages | France |
| Lumigo | Monitoring of background processing | Processing logs, which can include customer email addresses | Ireland |
Shopify is the platform the App runs on. If a merchant connects Klaviyo, the App sends notification events to the merchant's own Klaviyo account on the merchant's instruction. We give notice before adding or replacing a sub-processor, so merchants can object.
Personal data the App holds
- Merchants: store contact email addresses, the store owner's name, Shopify staff user IDs in the admin audit log, support chat messages, and admin usage analytics.
- Customers: Shopify customer, subscription and order IDs; subscription status and history; shipping addresses customers enter in the customer portal; the email addresses notifications were sent to; merchant notes; pause and cancellation reasons and comments; and details of subscriptions imported from another app.
- Not held: payment card details, which stay with Shopify. Other customer names, emails and addresses are read live from Shopify and not stored.
Security measures
- Encryption in transit: TLS for all connections to the App. The load balancer accepts HTTPS only, and only from the CDN.
- Encryption at rest: the database and file storage are encrypted by their providers. Integration API keys are also encrypted by the App.
- Store access: Shopify OAuth, limited to the permissions shown at install.
- Request authentication: admin requests are verified as signed Shopify sessions, Shopify webhooks by HMAC signature, and customer portal requests per customer.
- Tenant separation: every record is scoped to one store.
- Audit log: admin actions are recorded and kept for 13 months.
- Backups: the database is backed up automatically by MongoDB Atlas.
- Staff access: multi-factor authentication is required on AWS, MongoDB Atlas, Shopify Partners, PostHog and Crisp.
Deletion and redaction
| Event | What happens |
|---|---|
| Merchant uninstalls | The App stops billing: active and paused subscriptions are marked as failed, and can be reinstated on reinstall. |
| 48 hours after uninstall (Shopify shop/redact) | Access tokens and integration credentials are deleted. The store email, sender email and review text are removed or redacted, and every customer's personal data in subscription history, analytics and imported records is redacted. Subscription records and App configuration are kept. Skipped if the store has reinstalled. |
| Customer erasure request (Shopify customers/redact) | That customer's addresses, notification email addresses, notes, pause and cancellation comments, typed reasons and imported details are redacted, automatically when Shopify sends the request. |
| Merchant asks us directly | Handled within 30 days. |
Redacted values are overwritten with "[redacted]", so history still shows that an address changed or an email was sent. Other retention: admin audit log 13 months, settings snapshot taken at uninstall 12 months, anonymous storefront error reports 30 days.
Data subject requests
- Access requests (Shopify customers/data_request): we compile the data we hold about that customer and make it available to the merchant to download in the App, and email the merchant that it is waiting, within 30 days. The email holds no customer details.
- Requests sent to us directly: customers are directed to the merchant as controller, and we assist the merchant without undue delay.
Personal data breaches
We notify affected merchants without undue delay, and within 48 hours of becoming aware of a breach, with the information they need for their own notifications.
Contact
Stefan Gagov, Data Protection Officer, support@subscriptions.super-simple.co.
Point Blank Engineering LimitedKemp House, 152-160 City Road
London EC1V 2NX
United Kingdom