RedeemWise

Data Processing Agreement

Last updated 27 July 2026

This agreement governs how MALVI ("we", the processor) handles personal data on behalf of a merchant ("you", the controller) when you install and use RedeemWise. It takes effect when you install the app and continues while it remains installed.

It supplements our Privacy Policy. Where the two differ on our obligations to you, this agreement governs.

1. Roles

You are the controller of your customers' personal data. You decide why it is processed and instruct us through your use of the app. We are your processor and act only on those instructions, plus what Shopify requires of apps on its platform.

2. Subject matter, duration and purpose

Subject matter: applying a customer's points balance as a discount at checkout, and reconciling that balance afterwards.

Duration: for as long as RedeemWise is installed on your store, plus the deletion windows in section 7.

Purpose: providing the app's functionality to you. Nothing else. We do not use your customers' data to train models, build profiles, produce analytics, or market to anyone.

3. Categories of data subject

Customers of your store who hold a RedeemWise points balance, and customers whose orders redeemed points.

4. Personal data processed

We deliberately do not request access to the protected customer fields — name, email address, phone number and postal address. Shopify redacts them from our API responses, so we could not read them even in error.

What we do process, transiently, to provide the functionality:

A customer ID and an order ID can be linked back to an individual by you within your own Shopify admin. We treat both as personal data, which is why they appear here.

5. What we store, and what we never store

Our database holds only:

No customer identifier is written to our database in any table. The audit record is keyed on the order, never on the customer. This is an architectural constraint of the app, not a policy we apply by hand, and it is what allows us to answer a customers/redact request honestly: there is nothing about that customer to erase.

Balances live on the customer record inside your Shopify store. They are your data, held by Shopify, and are never copied to our servers.

6. Operational logs

Our server logs record shop domains, order IDs, and — for the Credit, Debit and Set Balance Flow actions — customer IDs, so that a merchant support question about a specific balance can actually be answered. Logs contain no names, email addresses, phone numbers or addresses. They are held by Cloudflare under their retention period and are not exported, aggregated, or used for any purpose other than diagnosing faults.

7. Retention and deletion

You may ask us to delete your data sooner by emailing dev@mal-vi.com.

8. Sub-processors

Cloudflare, Inc. is our only sub-processor. It provides the compute (Workers) and the database (D1) the app runs on. We use no analytics provider, no error-tracking service, no advertising network, and no third-party scripts in the app or its storefront blocks.

We will give you notice before adding or replacing a sub-processor, and you may object.

9. Security

10. Assisting you

We will help you respond to data subject requests and to regulators. In practice this is usually quick, because we hold no customer identifiers — most requests are answerable from your Shopify admin alone.

11. Personal data breaches

If we become aware of a breach affecting your customers' personal data we will notify you without undue delay, and in any case within 72 hours, with what we know about the nature and likely consequences of the breach and the steps we are taking.

12. International transfers

The app runs on Cloudflare's global network, so processing may occur outside the country your store operates in. Cloudflare provides the transfer safeguards for its infrastructure.

13. Audits

On reasonable request we will provide the information needed to demonstrate compliance with this agreement.

14. Changes

Material changes will be reflected on this page with an updated date. Continuing to use the app after a change means accepting it.

Contact

dev@mal-vi.com — data protection questions, deletion requests, sub-processor objections.