Early AccessShopify App Store rollout in progress -

Data Processing Addendum

Lokally - Regional Engine, operated by Nocodelane

Last updated: 1 October 2026

This addendum sets out how we process your shoppers' and customers' personal data on your behalf. It is part of our Terms of Service and applies automatically; you don't need to sign anything.

1. Scope and roles

This Data Processing Addendum ("DPA") forms part of the Terms of Service between you, the merchant ("you"), and Nocodelane ("we"). It applies to personal data about your shoppers and customers that we process on your behalf to provide the App ("Customer Personal Data").

For Customer Personal Data you are the controller (or "data fiduciary" under India's Digital Personal Data Protection Act, 2023, or "business" under the CCPA) and we are your processor (or "data processor" or "service provider"). Words such as "controller", "processor", "personal data breach" and "data subject" have the meanings given in the applicable data protection law ("Data Protection Law").

This DPA takes effect when you accept the Terms, and lasts as long as we process Customer Personal Data.

2. Processing on your instructions

We process Customer Personal Data only on your documented instructions, which are: the Terms, this DPA, and the settings you choose in the App (for example the regions, rewards and reward emails you turn on). We will tell you if we believe an instruction breaks Data Protection Law, and may decline to follow it.

We may also process Customer Personal Data where the law requires it; if so, we will tell you first unless the law forbids that.

3. Your obligations

  • You have a lawful basis, and any consent needed, for us to process Customer Personal Data as the App requires.
  • You give your shoppers and customers the notices the law requires, including about the App's cookie and browser storage and reward emails.
  • Your instructions comply with Data Protection Law.
  • You do not use the App to send us special categories of personal data (such as health or financial data) or data about children beyond what the App's features need.
  • You answer requests from your shoppers and customers about their data; we help as described below.

4. Our obligations

  • Anyone we allow to process Customer Personal Data is bound by confidentiality.
  • We keep appropriate technical and organisational security measures in place (Annex 2).
  • We help you answer data subject requests. The App answers Shopify's customer data request and erasure requests automatically, as described in our Privacy Policy.
  • We give you reasonable help with data protection impact assessments and with consulting regulators, where the request relates to our processing, taking into account the information available to us.
  • We do not sell or share Customer Personal Data, or retain, use or disclose it for any purpose other than providing the App, and we do not combine it with personal data from other sources except as the App needs to work.

5. Sub-processors

You authorise us to use the sub-processors listed in section 7 of our Privacy Policy. We bind each one to data protection terms that protect Customer Personal Data to the standard this DPA requires, and we remain responsible for their performance.

We will update that list and tell you by email or in the App at least 14 days before a new sub-processor starts processing Customer Personal Data. If you object on reasonable data protection grounds, tell us within that time and we will try to find a solution. If we can't, you may end the Terms by uninstalling the App; this is your only remedy for the objection.

6. Personal data breaches

If we become aware of a personal data breach affecting Customer Personal Data, we will tell you without undue delay, give you the information you reasonably need to meet your own obligations to notify regulators and individuals, and take reasonable steps to contain it. Telling you about a breach is not an admission of fault.

7. International transfers

We store Customer Personal Data in Singapore, and our sub-processors may process it in other countries. Where Data Protection Law requires safeguards for a transfer (for example from the EEA, the UK or Switzerland to a country without an adequacy decision), the European Commission's Standard Contractual Clauses (Module 2, controller to processor), with the UK Addendum or Swiss changes where relevant, apply between us and form part of this DPA. For those clauses: the optional docking clause does not apply; sub-processors are authorised generally, with notice as in section 5; the optional redress wording does not apply; and they are governed by, and disputes under them go to the courts of, Ireland. If there is a conflict, the Standard Contractual Clauses prevail.

8. Deletion and return

You can export your data from Shopify at any time. When you uninstall the App, we delete Customer Personal Data after Shopify's store erasure request, as described in our Privacy Policy, unless the law requires us to keep it.

9. Information and audits

We will make available the information reasonably needed to show we meet this DPA, and answer your reasonable written questions about our processing. If Data Protection Law requires an audit that this information cannot satisfy, you may carry one out, at your cost, no more than once a year, on at least 30 days' written notice, during business hours, in a way that does not disrupt our service or breach our confidentiality obligations to others, and subject to reasonable confidentiality terms.

10. Liability and precedence

Each party's liability under this DPA is subject to the limitation of liability in the Terms, to the extent Data Protection Law allows. If this DPA conflicts with the Terms, this DPA prevails for the processing of Customer Personal Data.

11. Annex 1: Details of the processing

Subject matter and durationProviding the App to you, for as long as it is installed, and until deletion as in section 8
Nature and purposeApplying your regional prices, payment rules and content; showing you region analytics; issuing rewards and sending the reward emails you turn on; answering privacy requests
Data subjectsYour storefront visitors, shoppers and customers
Personal dataPIN code or region entered on your storefront; location coordinates, only if a shopper uses the location button (sent from their browser to OpenStreetMap, not to us); order number and order details Shopify sends for reward purposes; customer email address and first name for rewards; reward and email delivery records
Special categoriesNone
Sub-processorsAs listed in section 7 of the Privacy Policy

12. Annex 2: Security measures

We apply the following measures

  • Encryption in transit (HTTPS/TLS) for all connections to the App, Shopify and our providers.
  • Encryption at rest of our database and its backups by our hosting provider.
  • Access to production systems and data limited to the people who run the App.
  • Data separated by store; each request is limited to the store it is authenticated for.
  • Rate limiting and request signature checks on public endpoints.
  • Short retention of order notifications (section 9 of the Privacy Policy) and automatic deletion of region analytics after 90 days.
  • Regular dependency updates and review of security issues.

13. Contact

Questions about this DPA or requests under it: support@getlokally.com.

Nocodelane
Kolkata, West Bengal, India
Email: support@getlokally.com

Related: Privacy Policy · Terms of Service · Data Processing Addendum