This DPA is between the Merchant (the Shopify store installing the App) and Woratas Nirasratom, sole proprietor (Samut Sakhon, Thailand) (“Provider”, “we”), operator of Upfront Invoice.
Installing the App constitutes acceptance of this DPA. It prevails over any other terms between the parties with respect to the processing of personal data.
We process personal data only on the Merchant’s documented instructions. Installing and configuring the App constitutes those instructions. We will tell the Merchant if we believe an instruction breaches applicable data-protection law.
Full details are in Annex A.
customers/data_request, customers/redact and shop/redact webhooks.For merchants in the EU/UK, rendering and storage take place in Frankfurt, Germany and invoice email is sent from Ireland. Our subprocessors are incorporated outside the EEA/UK, so their support and administrative access may constitute a transfer; each is engaged under Standard Contractual Clauses or another lawful mechanism through their own data processing agreements (Annex C).
This DPA applies for as long as the App is installed.
Governing law: the laws of the Kingdom of Thailand, with the courts of Thailand having jurisdiction — this does not deprive the Merchant or any data subject of the protection of mandatory provisions of the law that applies to them, including the GDPR and UK GDPR.
Our aggregate liability under this DPA is limited to the fees paid by the Merchant for the App in the twelve months preceding the claim, except where such a limitation is not permitted by applicable law.
| Item | Detail |
|---|---|
| Subject matter | Generating and delivering invoices, credit notes and packing slips |
| Duration | While the App is installed (+ up to 48h for deletion of stored records) |
| Nature & purpose | Automated retrieval of order data, rendering to PDF in memory, emailing to the buyer |
| Categories of data subjects | The Merchant’s customers (buyers); Merchant staff users |
| Categories of personal data | Name; billing and shipping address; email; order contents, amounts, tax lines, currency, dates |
| Stored by the Provider | Invoice number, sequence, Shopify order ID, issue date, template version, shop domain, the Merchant’s own template settings, and an access log of which order was rendered and when |
| Never stored by the Provider | Customer name, address, email; the generated PDF |
| Explicitly excluded | Customer phone number (not requested); payment card data; special-category data |
Encryption in transit (TLS) and at rest, including encrypted backups · least-privilege access with strong passwords and 2FA · access logging for every read of protected customer data · separation of test and production data · data-loss-prevention controls (no public database exposure, no bulk personal-data export endpoint) · documented incident response · data minimisation (phone field never requested; customer data never persisted).
| Subprocessor | Purpose | Customer data | Location | Their terms |
|---|---|---|---|---|
| Shopify Inc. (Canada) | App platform; source of order data | Controller-side platform | Global | shopify.com/legal/dpa |
| Fly.io, Inc. (USA) | Application hosting; PDF rendering | In memory only, during a render | Frankfurt, Germany | fly.io/legal/dpa |
| Neon, LLC (USA — a Databricks company) | Invoice record and settings storage | None | Frankfurt, Germany (AWS eu-central-1) | neon.com DPA · subprocessors |
| Resend, Inc. (USA) | Invoice email delivery | Recipient address and attached PDF, in transit | Ireland (AWS eu-west-1) | resend.com/legal/dpa |