Butter Commerce
Data Processing Addendum
Effective: 14 August 2026
Last updated: 14 August 2026
1. This applies automatically
This Data Processing Addendum ("DPA") forms part of the Terms of Use between you ("Customer," "Controller") and Butter Supply Inc. ("Butter," "Processor").
It applies whenever Butter processes personal data on your behalf. You do not need to sign it. It takes effect when you accept the Terms. If your organization requires a countersigned copy, request one at legal@buttercommerce.co.
Where this DPA conflicts with the Terms, this DPA governs — but only on data protection.
2. Definitions
"Data Protection Laws" means all laws applicable to the processing under this DPA, including the EU General Data Protection Regulation (2016/679) ("GDPR"), the UK GDPR and Data Protection Act 2018, Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA") and Quebec's Law 25, the California Consumer Privacy Act as amended ("CCPA"), and other US state privacy laws.
"Customer Personal Data" means personal data that Butter processes on your behalf under the Terms — principally data about Shoppers visiting your Storefront, and personal data contained in your Shopify store data.
"Controller," "Processor," "Data Subject," "Personal Data," "Processing," and "Personal Data Breach" have the meanings given in the GDPR. Under the CCPA, Butter is a "service provider" and you are a "business."
"Sub-processor" means a third party engaged by Butter to process Customer Personal Data.
"SCCs" means the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914.
"UK Addendum" means the International Data Transfer Addendum issued by the UK Information Commissioner under s.119A of the Data Protection Act 2018.
3. Roles
You are the Controller. Butter is the Processor.
You determine the purposes and means of processing Customer Personal Data. You are responsible for the lawfulness of that data — for having a legal basis, for giving Data Subjects notice, for obtaining consent where required (including cookie and tracking consent in the EU and UK), and for the accuracy of the instructions you give us.
Butter processes Customer Personal Data only on your documented instructions.
Butter is a Controller separately for the personal data of your own personnel — account, billing, support, and product usage data. That is governed by the Privacy Policy, not this DPA.
4. Scope of processing
Annex 1 sets out the subject matter, duration, nature, purpose, categories of Data Subject, and categories of Personal Data.
Your instructions are: the Terms, this DPA, the configuration choices you make in the Product, and any further written instruction you give that we accept. Enabling a feature is an instruction to process what that feature requires.
If we believe an instruction breaches Data Protection Laws, we will tell you and may suspend that processing until it is resolved. If we are required by law to process beyond your instructions, we will tell you first, unless the law forbids it.
5. What Butter commits to
Confidentiality. Everyone we authorize to process Customer Personal Data is bound by written confidentiality obligations and is trained appropriately. Access is limited to those who need it.
Security. We implement and maintain the technical and organizational measures in Annex 2, appropriate to the risk. We may update them, provided security is not materially reduced.
No unauthorized use. We will not:
sell Customer Personal Data, or share it for cross-context behavioural advertising;
retain, use, or disclose it outside the direct business relationship with you, or for any purpose other than the services — except as permitted in Section 8;
combine it with personal data from another source, except as permitted in Section 8 or where a Data Protection Law otherwise allows.
We certify that we understand these restrictions and will comply with them, as the CCPA requires of a service provider.
Assistance. Taking into account the nature of the processing and the information available to us, we will assist you with:
responding to Data Subject requests (Section 6);
your obligations on security, breach notification, data protection impact assessments, and prior consultation with a supervisory authority.
We provide reasonable assistance at no charge. Where assistance is materially burdensome or repeated, we may charge our reasonable costs, agreed in advance.
6. Data Subject requests
Butter has no direct relationship with your Shoppers, and we will not respond to their requests on our own initiative.
If we receive one, we will promptly redirect the Data Subject to you and notify you, unless we are legally prohibited from doing so.
We give you the tools to respond. Where a request cannot be fulfilled through the Product, we will assist on request within a reasonable time and in any case in time for you to meet your statutory deadline.
Shopify's mandatory privacy webhooks. The Butter Commerce Shopify app subscribes to Shopify's customers/data_request, customers/redact, and shop/redact webhooks. On a shop/redact we purge the Shopify-linked fields for that shop. On a customer redaction request we delete or de-identify the corresponding Customer Personal Data within the period Shopify requires.
7. Sub-processors
General authorization. You give us general written authorization to engage Sub-processors. Each is bound by a written contract imposing data protection obligations no less protective than this DPA, and we remain fully liable for their performance.
Current list. The Sub-processors we use are listed in Section 12 below and maintained at buttercommerce.co/legal/sub-processors.
Changes. We will give at least 30 days' notice before adding or replacing a Sub-processor, by email to your account address and by updating the published list. Subscribe to change notifications at privacy@buttercommerce.co.
Objection. You may object on reasonable data-protection grounds within 30 days of notice. We will work in good faith to offer an alternative. If we cannot within a reasonable time, you may terminate the affected part of the Services without penalty, and we will refund prepaid fees for the unused period.
8. De-identified and aggregate data
Butter may de-identify and aggregate Customer Personal Data, and use the result to operate, secure, analyse, and improve the Services, and to produce and publish aggregate benchmarks and industry research.
This right is limited by the following, which are conditions, not aspirations:
a. De-identification standard. Data is treated as de-identified only when all of the following are true:
direct identifiers are removed or replaced with irreversible one-way hashes, salted with a secret Butter does not disclose;
store identifiers and domains are removed or replaced with values that cannot be mapped back without information we hold separately and under access control;
free-text fields that may contain personal data are removed, not merely redacted;
the result cannot reasonably be used, alone or with other information we hold or can access, to identify a Data Subject, a Store, or an order.
b. No re-identification. We will not attempt to re-identify de-identified data, and we will not permit anyone else to. We will contractually bind any recipient to the same restriction.
c. Minimum aggregation for anything published. Published benchmarks and research must be aggregated across no fewer than 30 Stores, and must not include any figure derived from fewer than that. No published output will name, describe, or be capable of identifying a Store, a Customer, a Shopper, or an order.
d. No re-supply. We will not disclose de-identified data derived from your Customer Personal Data to a third party in a form that permits that party to re-identify it, and we will not sell it.
e. Survival. This right survives termination for data already de-identified. De-identified data is not subject to the deletion obligations in Section 10, because by definition it is no longer personal data.
f. Opt out. You may opt out of having your data included in published benchmarks by writing to privacy@buttercommerce.co. Opting out does not affect our use of de-identified data to operate and improve the Services.
Where a Data Protection Law treats de-identified data as still personal data, we continue to treat it as Customer Personal Data and this Section does not apply to it.
9. Personal Data Breach
We will notify you without undue delay, and in any case within 48 hours, of becoming aware of a Personal Data Breach affecting Customer Personal Data.
The notice will describe, so far as we know at the time: the nature of the breach and the categories and approximate number of Data Subjects and records affected; the likely consequences; the measures taken or proposed; and a contact point for more information. We will supply further detail as it becomes available.
We will assist you with your own notification obligations to supervisory authorities and Data Subjects. Notification is not an admission of fault or liability.
10. Retention, return, and deletion
We retain Customer Personal Data only as long as needed to provide the Services, or as required by law. Retention periods are in Section 9 of the Privacy Policy.
On termination, or on your written request, we will delete or return Customer Personal Data within 90 days, and delete existing copies — except where we must retain it under law, in which case we will retain only what is required, keep it protected, and process it only for that purpose.
Data in backups is deleted as backups cycle, in the normal course of operation. Until then it remains protected by the measures in Annex 2.
11. International transfers
We may transfer Customer Personal Data outside its country of origin, including to Canada, the United States, and the European Union.
Canada has an adequacy decision from the European Commission for data transferred to organizations subject to PIPEDA.
Where a transfer requires additional safeguards, the following apply and are incorporated by reference:
EEA transfers — the SCCs, Module Two (Controller to Processor). You are the data exporter; Butter is the data importer. Docking clause: applicable. Clause 9: Option 2 (general written authorization), with the 30-day notice period in Section 7. Clause 11: the optional redress body is not used. Clause 17: governed by the law of Ireland. Clause 18: the courts of Ireland. Annexes I, II, and III of the SCCs are populated by Annex 1, Annex 2, and Section 12 of this DPA.
UK transfers — the SCCs as above, as amended by the UK Addendum. Table 4: neither party may end the Addendum under Section 19.
Swiss transfers — the SCCs, with references to the GDPR read as references to the Swiss FADP, the competent authority as the Swiss FDPIC, and "member state" read to include Switzerland.
Government access. If we receive a legally binding request from a public authority for Customer Personal Data, we will notify you unless legally prohibited, challenge requests we consider unlawful or overbroad, and disclose only the minimum required. We will publish aggregate transparency information where lawful. As of the effective date, we have received no such request.
12. Sub-processors
Infrastructure and operations
Sub-processor | Entity and location | What it processes | Purpose |
|---|---|---|---|
Supabase | Supabase, Inc. — United States | Store configuration, account records, storefront event and attribution data, Recipes | Primary application database |
Google Cloud / Firebase | Google LLC — United States | Authentication credentials, legacy store and configuration data | Authentication and legacy data store, being migrated to Supabase |
Vercel | Vercel, Inc. — United States | All data in transit to the web app and API; request logs | Application hosting and edge network |
Shopify | Shopify Inc. — Canada | Store data, product and order data, app billing records | Commerce platform and app distribution and billing |
Framer | Framer B.V. — Netherlands | Plugin installation context and canvas data; visitor analytics on our marketing site | Plugin distribution, marketing site hosting, and site analytics |
Google Analytics | Google LLC — United States | Visitor analytics on buttercommerce.co and app.buttercommerce.co | Marketing site analytics. Consent-gated through Framer's banner. |
Billing and communications
Sub-processor | Entity and location | What it processes | Purpose |
|---|---|---|---|
Stripe | Stripe, Inc. — United States / Stripe Payments Europe — Ireland | Customer billing contact, subscription and payment records | Subscription billing |
Loops | Astrodon Corporation — Delaware, United States | Customer email address, and where relevant store name, plan name, inviter name, and invitation link | Transactional and lifecycle email only. No shopper data, no marketing list sync. |
Intercom | Intercom, Inc. — United States / Ireland | Support conversations and the contact details in them | Customer support and help centre |
Google Workspace | Google LLC — United States | Support and business email, and anything a customer sends us | Business email and support correspondence |
Slack | Slack Technologies (Salesforce, Inc.) — United States | Customer names, email addresses, and store details where a support issue is discussed internally | Internal communication. Listed because support discussion places personal data there, not because it is a customer-facing tool. |
Authentication
Sub-processor | Entity and location | What it processes | Purpose |
|---|---|---|---|
Google LLC — United States | Name, email address, profile information | Optional "Continue with Google" sign-in for Customer personnel | |
X (Twitter) | X Corp. — United States | Name, email address, profile information | Optional "Continue with X" sign-in for Customer personnel |
Loaded in the shopper's browser
These receive a Shopper's IP address, user agent, and referring page by virtue of the browser making the request, even though we send them no data ourselves.
Sub-processor | Entity and location | What it processes | Purpose |
|---|---|---|---|
esm.sh | Operated by the | Shopper IP address, user agent, referring page | Runtime module CDN. Butter's storefront components import their JavaScript dependencies from esm.sh at page load. See the note below. |
Iconify | Iconify OÜ (reg. 14973677) — Estonia | Shopper IP address, user agent, referring page | Serves the country flag icons used by Markets components |
Framer | Framer B.V. — Netherlands | Shopper IP address; and, for reviews integrations, the Customer's Yotpo or Judge.me API token | Framer's CORS proxy relays reviews API calls. Where you have connected Yotpo or Judge.me, your API token for that service passes through the proxy. We are moving these calls server-side to remove that exposure. |
FreeIPAPI | FreeIPAPI, Altdorferstr 6, 40237 Düsseldorf — Germany | Shopper IP address | Fallback country lookup for Markets and currency, when Butter's own geolocation endpoint is unavailable. Its published policy retains API request logs for monitoring and debugging without stating a retention period. We are replacing this fallback with edge-provided geolocation. |
On esm.sh. This service is an open-source project with no incorporated legal entity behind it, and therefore no contract and no data processing agreement is available. Section 7 of this DPA requires every Sub-processor to be bound by written data-protection terms, and esm.sh cannot be. We are removing this dependency by bundling these libraries into our component build. Until that ships, it is disclosed here rather than omitted.
Not sub-processors — integrations you enable
These receive data because you configure them. They act as your providers, under your agreement with them, not ours. We pass data to them on your instruction and are not responsible for what they do with it.
Google Analytics 4 · Meta Pixel · Klaviyo · Judge.me · Yotpo · Loox
Not sub-processors — development and internal tools
These do not touch Customer Personal Data in any runtime path. Listed for completeness because they appear in our repositories:
Anthropic (Claude, in CI for documentation pull requests — repository content only) · Notion (internal documentation sync) · GitHub (source control) · Linear (issue tracking)
No error-reporting, session-replay, or product-analytics vendor is integrated in the product — no Sentry, PostHog, Segment, Mixpanel, Amplitude, Datadog, or equivalent. Support tools that hold correspondence (Intercom, Google Workspace, Slack) are listed above as sub-processors, since they sit outside the codebase but do hold personal data.
13. Audits
On request, we will make available the information reasonably necessary to demonstrate compliance with this DPA, including current security documentation and any third-party certifications or reports we hold.
Where that is insufficient for your obligations under Article 28(3)(h) GDPR, you may audit — or appoint an independent auditor, not a Butter competitor, bound by confidentiality — subject to: 30 days' written notice; no more than once every 12 months, unless required by a supervisory authority or following a Personal Data Breach; during business hours, without unreasonable disruption; scoped to systems processing Customer Personal Data; and at your cost, other than our reasonable internal time.
14. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms. Nothing here limits liability that cannot lawfully be limited, or a Data Subject's rights under the SCCs.
15. Term, conflicts, and general
This DPA runs for as long as we process Customer Personal Data. Sections 8, 10, 11, and 14 survive termination.
Order of precedence: the SCCs, then this DPA, then the Terms.
If a provision is held invalid, the rest remains in force. This DPA is governed by the law stated in the Terms, except where the SCCs specify otherwise.
Data exporter: Customer, as identified in its Butter account.
Data importer: Butter Supply Inc., 2727 Steeles Ave West, Unit 103-180, Toronto, ON M3J 3G9, Canada. Contact: privacy@buttercommerce.co.
Subject matter. Provision of the Butter Commerce storefront layer connecting a Shopify store to a Framer site.
Duration. The term of the Terms, plus the retention periods in Section 10.
Nature and purpose. Collecting, recording, organizing, structuring, storing, retrieving, using, transmitting, and erasing personal data in order to: display store data on the Storefront; operate cart, checkout hand-off, and Recipes; record storefront analytics and attribution where enabled; route data to integrations the Customer has configured; provide support; and secure and maintain the Services.
Categories of Data Subject.
Shoppers who visit the Customer's Storefront
The Customer's own customers, to the extent their data appears in Shopify data Butter processes
The Customer's personnel and authorized users
Categories of Personal Data.
Online identifiers: hashed IP address, visitor identifier, session identifier, cart token, checkout token
Device and browser: user agent, device type
Approximate location: country derived from IP address
Behavioural: pages viewed, products viewed, searches, filters, cart events, checkout events
Marketing attribution: UTM parameters, affiliate codes, ad-platform click identifiers, referrer
Transactional: Shopify order identifier, order total, currency, hashed customer email
Account: name, email address, workspace and role, for the Customer's personnel
Special category data. None is intentionally processed. Do not configure the Product to collect it.
Children's data. None is intentionally processed.
Frequency. Continuous, for the duration of the Terms.
Retention. As set out in Section 10 and the Privacy Policy.
Sub-processor processing. As described in Section 12, for the term of each engagement.
Access control. Role-based access; least privilege; row-level security in the production database; multi-factor authentication on administrative accounts; access reviewed on personnel change; separated staging and production environments with separate credentials.
Encryption. TLS 1.2 or above for all data in transit. Encryption at rest for the production database, object storage, and backups, provided by our infrastructure providers. Shopify access tokens and third-party integration credentials are additionally encrypted at the application layer using AES-256-GCM under a versioned key scheme, and are never exposed to client-side code.
Pseudonymization. Shopper IP addresses hashed before storage. Customer email addresses hashed in order-attribution records. Full order payloads not retained.
Resilience. Managed database with automated backups and point-in-time recovery; infrastructure hosted with providers offering redundancy across availability zones.
Testing and review. Schema changes reviewed as version-controlled migrations; code review before merge; dependency vulnerability monitoring; production deployments gated on explicit confirmation.
Personnel. Written confidentiality obligations for employees and contractors; access granted on need; access revoked on departure.
Incident response. Documented process for detection, escalation, containment, and notification within the periods in Section 9.
Sub-processor management. Written data-protection terms with each Sub-processor; the published list in Section 12; 30 days' notice of change.
Deletion. Deletion applied to live systems on request and to backups as they cycle; Shopify redaction webhooks handled as described in Section 6.