Data processing agreement
Workbench for Shopify · Last updated 14 August 2026
The short version. You are the controller of your customers' data; we are a processor acting on your instructions. We process email addresses and order identifiers, and nothing else — no names, phone numbers or addresses.
There are two sub-processors, Fly.io for hosting and Resend for email. No analytics, no advertising, no tracking. We will never sell your customers' data.
The parties
This agreement is between you, the merchant who installs Workbench, and Mick O'Callaghan, trading as Workbench — a sole trader, referred to below as "we".
Anything in this agreement can be raised with us at support@workbenchorders.com.
You are the controller of your customers' personal data. You decide why it is processed and what happens to it.
We are a processor. We act only on your instructions, which are given by the way you configure and use the app.
What we process, and why
Subject matter: recording the stage of an order and, if you enable it, telling that order's customer about it.
Duration: for as long as the app is installed, plus up to 48 hours afterwards while Shopify's deletion request reaches us.
Categories of data subject: your customers, including people who placed draft orders.
Types of personal data:
- Email addresses, read from an order at the moment they are needed
- Order identifiers and order numbers, which can be linked back to a person
- Any note you type against an order, whose content you control
We do not process names, phone numbers or addresses. The app does not request those fields from Shopify.
Our obligations
- Instructions. We process personal data only to provide the app, and only as your use of it directs. We will not use it for our own purposes, and we will never sell it.
- Confidentiality. Everyone with access is bound to keep it confidential.
- Security. We keep appropriate technical and organisational measures, described below.
- Sub-processors. We use those listed below. We will give notice before adding another, and you may object.
- Your customers' rights. We will help you respond to access, correction, erasure and objection requests. Shopify's built-in requests reach us automatically.
- Breaches. We will tell you without undue delay, and within 72 hours of becoming aware, with what we know at the time.
- Deletion. On uninstall we erase your shop's data, as described in the privacy policy.
- Audit. We will provide the information needed to demonstrate compliance with this agreement.
Sub-processors
- Fly.io, Inc. — application hosting and database storage. United States.
- Resend (Plus Five Five, Inc.) — email delivery. United States. Receives data only when you enable customer emails.
There are no others. The app includes no analytics, advertising or tracking services.
International transfers
Our infrastructure is in the United States. Where personal data originates in the UK or European Economic Area, transfers rely on the appropriate safeguards, including Standard Contractual Clauses with our sub-processors.
Security measures
- Read-only access to your shop. The app cannot modify orders, fulfilment or any other shop data.
- Minimal collection: customer details are read live and not stored. No customer name, email, address or phone is written to our database against an order.
- Encryption of data at rest and in transit, including backups.
- Separation of test and production data.
- Access to production limited to the app's developer, protected by multi-factor authentication.
- Application logging of requests, retained for troubleshooting.
- A documented security incident response procedure.
Liability and term
This agreement takes effect when you install the app and ends when you uninstall it and your data is erased. Terms in your agreement with us about liability apply here too.
Questions, objections to a sub-processor, or requests for further information: support@workbenchorders.com.