Data Processing Agreement

Last updated: September 20, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Customer," "Controller," "you") and Metrifact ("Metrifact," "Processor," "we," "us") wherever Metrifact processes personal data on your behalf as part of the Service — most relevantly, data read from a connected Google Ads, Meta Ads, GA4, Search Console, or Shopify account. If there is a conflict between this DPA and the Terms of Service on data protection matters, this DPA controls.

1. Roles of the parties

For personal data processed through your connected platform accounts (including Shopify customer and order data, and advertising audience data), you are the Controller and Metrifact is the Processor, within the meaning of the GDPR, UK GDPR, and equivalent applicable data protection laws. You determine what data to connect and what it is used for; Metrifact processes it solely to fulfill the requests you (or an AI assistant acting on your instructions) make through the Service.

2. Subject matter and duration

The subject matter is Metrifact's provision of the Service as described in the Terms of Service. Processing continues for as long as your account remains active and a given platform connection stays enabled, and ends on deletion of your account or disconnection of that platform, per Section 7 below.

3. Nature, purpose, and categories of data

Nature and purpose. Personal data is retrieved live from the platform you connect, in direct response to a query or action you make through an AI assistant, and returned to that assistant. Metrifact does not independently analyze, profile, or repurpose this data beyond fulfilling the specific request made.

Categories of data subjects:

  • Your own store's customers and order recipients (for Shopify connections)
  • Your advertising audiences and website visitors, to the extent reflected in Google Ads, Meta Ads, GA4, or Search Console reporting data

Categories of personal data:

  • Contact information (name, email, phone) where a connected Shopify store has granted customer-data access
  • Order and transaction data (order value, line items, fulfillment/financial status)
  • Marketing attribution data (referrer, landing page, UTM parameters, device/location signals)
  • Advertising performance data tied to campaigns/audiences on connected ad platforms

4. Processor obligations

  • Process personal data only on your documented instructions — as expressed through the queries you make and the scopes you authorize — unless required to do otherwise by law.
  • Ensure personnel authorized to process the data are subject to confidentiality obligations.
  • Implement appropriate technical and organizational security measures (see the Privacy Policy and the Security section of our homepage), including OAuth-based authentication, encrypted storage of connection credentials, CSRF protection, and rate limiting.
  • Assist you, to the extent reasonably possible, in responding to data subject requests (access, correction, deletion, portability) concerning data processed through the Service.
  • Notify you without undue delay after becoming aware of a personal data breach affecting your data, and provide reasonably available information to help you meet your own breach-notification obligations.
  • Not engage a new sub-processor without giving you the opportunity to object, per Section 5.

5. Sub-processors

You authorize Metrifact to engage the following sub-processors, each bound by written data protection terms at least as protective as this DPA:

  • Google Cloud Platform — hosts the Service's compute infrastructure. Personal data passes through this infrastructure in memory to serve your requests; it is not the retrievable data store described below.
  • Supabase — stores your account information, OAuth connection tokens, and connected-account identifiers/names. Live platform data itself is not written to this store.
  • Cloudflare — network, security, and hosting layer for the Service's website and app. Traffic to and from the Service, which can include personal data in transit, passes through Cloudflare.

Metrifact also uses Dodo Payments (billing), Resend (email), PostHog (product analytics), and Sentry (error monitoring). These process your account information as described in the Privacy Policy, and we do not send them your connected-platform data by design.

We will give you at least 30 days' notice before adding or replacing a sub-processor that will process your personal data, by updating this page and its "Last updated" date. You may object on reasonable data-protection grounds by contacting legal@metrifact.com within that period; if we cannot resolve your objection, either party may terminate the affected connection.

6. International data transfers

Our sub-processors may process data outside your own country or region. Where applicable law requires a specific transfer mechanism (such as Standard Contractual Clauses), we rely on our sub-processors' own certified transfer mechanisms for their respective services.

7. Deletion and return of data

Because Metrifact does not retain a persistent copy of the personal data it retrieves from your connected platforms — it is fetched live for each request and returned, not stored separately — disconnecting a platform account or deleting your Metrifact account removes Metrifact's access to that data immediately and there is no further copy to return or delete on our end. Account and connection metadata is deleted per the Privacy Policy's retention terms.

8. Audits

On reasonable written request, no more than once per year, Metrifact will provide information reasonably necessary to demonstrate compliance with this DPA, such as a summary of the security measures in place. This DPA does not require on-site audits of Metrifact's infrastructure.

9. Liability

Each party's liability under this DPA is subject to the limitations of liability set out in the Terms of Service.

Metrifact remains liable for the actions of the sub-processors listed in Section 5 to the extent they process personal data on Metrifact's documented instructions under this DPA. This does not extend to independent business decisions, policy changes, or enforcement actions — including account restriction, suspension, or loss of access — taken by a connected platform (Google, Meta, or Shopify) in its own capacity as the operator of that platform, including actions taken by that platform's own automated security or fraud-detection systems in response to API access patterns. Those platforms act as independent controllers of their own services, not as Metrifact's sub-processors, and Metrifact has no ability to direct, predict, or prevent their enforcement decisions.

10. Term and termination

This DPA takes effect when you first connect a platform account that involves personal data and remains in effect for as long as the Terms of Service remain in effect between us.

11. Governing law

This DPA is governed by the laws of India, without regard to conflict-of-law principles, consistent with the Terms of Service.

12. Contact

Questions about this DPA: legal@metrifact.com