Legal
Data Processing Agreement
Version 1.0 · Last updated: September 3, 2026
This Data Processing Agreement ("DPA") applies where a merchant ("Controller") installs Sprout Affiliate and, in doing so, has us process personal data on their behalf. It forms part of the Terms of Service between the Controller and O10 Media LLC, a California limited liability company trading as Sprout Affiliate ("Processor," "we," "us").
1. Roles
For personal data about shoppers and affiliates in a merchant's program, the merchant is the Controller and Sprout Affiliate is the Processor. The merchant decides who joins their program, what commission is owed and when payouts happen. We act only on the merchant's instructions.
Where we process data about the merchant's own account (billing, support, security logs) we act as a Controller, and our Privacy Policy governs that.
2. Subject matter, duration, nature and purpose
- Subject matter: providing the Sprout Affiliate service.
- Duration: for as long as the app is installed, plus the deletion window in section 10.
- Nature and purpose: recording referrals, calculating commission, running an affiliate portal, sending transactional email and notifications, and making payouts.
Categories of data subjects
- The merchant's affiliates, and people who apply to become one.
- Shoppers whose orders are attributed to an affiliate.
- The merchant's own staff who use the app.
Types of personal data
- Affiliates: name, email address, optional company name and postal address, payout method and payout details (a PayPal email or bank details), tax form information where the merchant collects it, and the commission ledger.
- Shoppers: order number, date, total, discount code used, and, where the merchant enables it, the customer name shown on a referral row.
- Usage: referral click records, which may include an IP address and user agent.
- Merchant staff: name and email address.
We do not process payment card data. We do not ask for and do not want special category data under Article 9.
3. Our obligations
We will:
- Process personal data only on the Controller's documented instructions, which include this DPA, the Terms and the merchant's use of the app's settings. If we are required by law to process it otherwise, we will tell the Controller first unless the law forbids that.
- Tell the Controller if, in our opinion, an instruction infringes the GDPR or other data protection law.
- Ensure that anyone authorised to process the data is bound by confidentiality.
- Take the security measures described in Annex II.
- Respect the conditions in section 4 for engaging sub-processors.
- Assist the Controller, by appropriate technical and organisational measures, in responding to data subject requests under Articles 12 to 23.
- Assist the Controller with Articles 32 to 36, including security, breach notification and data protection impact assessments.
- Delete or return the data at the end, as set out in section 10.
- Make available the information needed to demonstrate compliance with Article 28, and allow for and contribute to audits as set out in section 9.
4. Sub-processors
The Controller gives general authorisation for the sub-processors listed at sproutaffiliate.com/subprocessors.html. We will post any intended addition or replacement there at least 30 days in advance. A Controller who objects on reasonable data protection grounds within those 30 days may tell us, and if we cannot offer a reasonable alternative the Controller may terminate the affected part of the service without penalty.
Each sub-processor is engaged under a written contract imposing data protection obligations no less protective than this DPA. We remain fully liable to the Controller for a sub-processor's performance.
5. International transfers
Sprout Affiliate is operated from the United States, and the application and database run in Ashburn, Virginia. Personal data from the European Economic Area, the United Kingdom or Switzerland is therefore transferred to the United States.
For those transfers the parties adopt, and this DPA incorporates by reference:
- The Standard Contractual Clauses in European Commission Implementing Decision (EU) 2021/914, Module Two (Controller to Processor), completed as in Annex I, Annex II and Annex III below. Clause 7 (docking) applies. Under Clause 9 the parties select Option 2, general written authorisation, with the 30-day notice period in section 4. Under Clause 17 the clauses are governed by the law of Ireland. Under Clause 18(b) disputes are heard in the courts of Ireland.
- For UK transfers, the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner (version B1.0), with the SCCs above as the Approved EU SCCs. Tables 1 to 4 are completed by the corresponding parts of this DPA; in Table 4 neither party may end the Addendum when the Approved Addendum changes.
- For Swiss transfers, the SCCs above apply with the amendments in the Swiss Federal Data Protection and Information Commissioner's guidance: references to the GDPR are read as the Swiss FADP, the competent authority is the FDPIC, and "member state" is read so as not to deprive data subjects in Switzerland of the right to sue where they are resident.
Where the SCCs conflict with the rest of this DPA, the SCCs prevail.
6. Government access requests
We have received no national security orders or government requests for the personal data we process for merchants. If we receive one we will, unless legally prohibited, notify the affected Controller, challenge requests that appear unlawful or overbroad, and disclose only the minimum required. We will publish any change to the first sentence of this paragraph on this page.
7. Data subject requests
If a data subject contacts us directly about a merchant's program, we will not respond substantively ourselves. We will tell them to contact the merchant and, unless prohibited, tell the merchant promptly.
The app is built so a merchant can answer these requests without us: affiliate records can be viewed, corrected, exported and deleted from the admin, and every affiliate can export or delete their own data from their portal. Where a merchant still needs help, we will assist at no charge.
8. Personal data breaches
We will notify the Controller without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting their data. The notice will describe what happened, the categories and approximate number of data subjects and records involved, the likely consequences, and the measures taken or proposed. Where we cannot provide all of it at once, we will provide it in phases without undue further delay.
9. Audits
We will make available to the Controller the information reasonably necessary to demonstrate compliance with Article 28, including answering a written security questionnaire. Where that is not sufficient, the Controller may audit once in any twelve-month period on 30 days' written notice, during business hours, without unreasonably disrupting the service, and subject to confidentiality. A supervisory authority may audit at any time as the law allows.
10. Deletion and return
When the app is uninstalled or the agreement ends, we delete the merchant's personal data. Uninstalling triggers Shopify's shop/redact webhook, which purges the store's data across every table that holds it. Deletion completes within 30 days of that request. A merchant may ask for an export before deletion, and may ask for immediate deletion at support@sproutaffiliate.com or via sproutaffiliate.com/delete-data.html.
Database snapshots are retained for 5 days and then expire, so deleted data is gone from backups within that window as well.
11. Liability and governing law
Liability under this DPA is subject to the limitations in the Terms of Service, except that nothing limits liability that cannot be limited by law, and except that the SCCs govern liability for the transfers they cover.
Annexes
Annex I
A. List of parties
Data exporter (Controller): the merchant that installed Sprout Affiliate. Name, address and contact are those on the merchant's Shopify account and, where a countersigned copy is requested, those the merchant provides. Activities: operating an affiliate marketing program for its own store. Signature and date: given by installing the app, or by the countersigned copy.
Data importer (Processor): O10 Media LLC, trading as Sprout Affiliate, California, United States. Contact: support@sproutaffiliate.com. Activities: providing the Sprout Affiliate service. Role: Processor.
B. Description of transfer
- Categories of data subjects: as in section 2.
- Categories of personal data: as in section 2.
- Special category data: none.
- Frequency: continuous, for as long as the app is installed.
- Nature and purpose: as in section 2.
- Retention: for the duration of the installation, then deleted under section 10.
- Sub-processor transfers: subject matter, nature and duration as described at /subprocessors.html.
C. Competent supervisory authority
The supervisory authority of the EEA member state in which the Controller is established. Where the Controller is not established in the EEA but has an Article 27 representative, the authority of the representative's member state. For UK transfers, the Information Commissioner's Office. For Swiss transfers, the FDPIC.
Annex II · Technical and organisational measures
These are the measures actually in place, not aspirations.
Encryption
- All traffic is served over HTTPS, and plain HTTP is redirected to it.
- Payout credentials and tax identifiers are encrypted at rest with AES-256-GCM under a key held only as a deployment secret, separate from the database.
- The database storage volume is encrypted at rest.
Access control
- Merchant access is authenticated by Shopify's OAuth session for the installing store; a session can only ever reach its own store's data.
- Affiliate portal sessions use signed, HTTP-only, Secure, SameSite cookies scoped to a single host.
- Administrative access to production is limited to the operator of the service.
- Production credentials are held as deployment secrets, never in source control.
Separation and integrity
- Every table holding merchant data is keyed by store, and queries are scoped by that key in one shared code path rather than per page.
- An automated check runs on every build and fails the build if any store-keyed table is not covered by the deletion routine. It currently covers 47 tables.
- Further automated checks on every build verify that database migrations exist for every schema field, that payout arithmetic reconciles, and that a payout fee is never exposed on an affiliate's document.
Resilience and logging
- Deployments are blue-green with health checks, so a failed release does not replace a working one.
- The database volume is snapshotted daily and snapshots are retained for 5 days.
- Application and access logs are retained for troubleshooting and security review.
Data minimisation
- We request the narrowest Shopify scopes the app needs, and read only the order fields commission depends on.
- Payment card data is never received or stored.
- Fonts and all other assets are served from our own origin, so no visitor IP address is disclosed to a third-party CDN.
Annex III · List of sub-processors
The Controller has authorised the sub-processors listed at sproutaffiliate.com/subprocessors.html, which forms part of this Annex and states each one's name, purpose, the data it receives and its location.
Contact
Questions about this DPA, or a request for a countersigned copy: support@sproutaffiliate.com.