HonestGate: Age Gate App
HomeGuideDocsChangelogPrivacySupport

RESOURCES

Shopify age gate guideMerchant documentationChangelogPrivacy noticeData Processing AddendumTermsSupport

Data Processing Addendum

EFFECTIVE AUGUST 29, 2026

This Data Processing Addendum ("DPA") forms part of the HonestGate: Age Gate App Terms. It applies when The Ad Genius LLC ("Provider") processes personal data for the Shopify merchant that installed HonestGate ("Merchant"). Merchant is the controller or business, and Provider is the processor or service provider, for that processing.

1. Scope and instructions

Provider processes personal data only to operate, secure, support, and improve the contracted HonestGate service; comply with law; and follow Merchant's documented instructions. Those instructions include the Terms, this DPA, Merchant's Shopify configuration, authenticated actions in the app, and lawful written directions consistent with the service. Provider will notify Merchant if an instruction appears to violate applicable data-protection law, unless law prohibits that notice.

2. Processing details

  • Subject matter: Shopify-only, post-purchase age review and related merchant support.
  • Duration: for Merchant's use of the service and the limited retention periods described below, unless law requires longer retention.
  • Data subjects: Merchant's buyers, prospective buyers, and authorized Shopify store staff.
  • Data: shop, order, checkout, customer, and fulfillment identifiers; the visible information contained in a buyer-selected ID image; review status, limited notes, timestamps, and audit events; saved approval status, approved minimum age, approval and expiry dates, last-use date, and revocation state; authenticated staff identifiers, names, and email addresses; text-only support-ticket content; and limited security and session metadata.
  • Operations: collection after Shopify confirms a paid order, normalization, private storage, shop-scoped display, human first review, eligible repeat-order approval reuse, status synchronization, optional app-owned fulfillment holds, support, retention, and deletion.

HonestGate does not use OCR, face matching, biometric scoring, AI approval, or automated document decisions. The first approval is made by Merchant staff. A later eligible order may reuse that saved result without collecting or inspecting another ID image. HonestGate does not use raw ID images for advertising, sell them, or use them to train models.

Launch reuse matches the same Shopify customer account within the same store. Checkout-email matching is disabled unless and until Shopify grants protected Email access. If Merchant later enables an approved email fallback, Provider reads the address only to create a keyed, shop-specific fingerprint and does not retain the plaintext checkout email for matching. A current guest is never approved by email alone; the fallback may allow a later authenticated Shopify account to claim its own prior guest approval, and different non-null Shopify customer IDs never match.

3. Confidentiality and security

Provider limits access to personnel and contractors who need it to provide the service and who are bound by confidentiality duties. Measures include TLS in transit, private app-managed object storage, authenticated and shop-scoped Shopify Admin access, short-lived image-view links, image normalization and metadata removal, access logging, rate limits, and separation of raw images from public Shopify Files and order metafields.

4. Retention, return, and deletion

Merchant chooses a raw-image retention period from 1–30 days; 14 days is the default. The app's scheduled worker is the primary deletion control, and a 30-day object-storage lifecycle is an additional backstop. Merchant can delete an image sooner from the review workflow. A saved approval is separate from the raw image. Merchant chooses a 30–3,650 day approval lifetime, with 365 days as the default, and can disable or revoke reuse. Order-linked decisions, limited notes, audit records, and support records may remain after raw-image deletion while needed to provide, secure, and support the service. Provider deletes remaining shop-scoped data when the applicable Shopify shop-redaction request is completed, except where law requires retention.

5. Data-subject and regulatory assistance

Taking into account the nature of the processing, Provider will reasonably assist Merchant with access, correction, deletion, objection, portability, security, breach, impact-assessment, and regulator-consultation obligations. Buyers should begin requests with the Merchant identified on their Shopify order. Provider processes Shopify's mandatory privacy webhooks and gives authenticated Merchants access to the app's privacy-request tools even when the paid workflow is inactive.

6. Security incidents

Provider will notify Merchant without undue delay after confirming a breach of Merchant personal data, provide available information reasonably needed for Merchant's response, take appropriate steps to contain and remediate it, and cooperate with Merchant's lawful notification obligations. Notification is not an admission of fault or liability.

7. Subprocessors

Merchant gives general authorization for Provider to use subprocessors that are bound by data-protection obligations appropriate to their services. Current subprocessors are Render for application hosting and managed PostgreSQL, Cloudflare for private R2 object storage, and Namecheap for support email. Shopify is Merchant's commerce platform under Merchant's own Shopify agreement, rather than a subprocessor appointed by Provider. Provider remains responsible for its subprocessors' performance of their data-processing duties and will make material changes available through the public Changelog or direct notice when appropriate. Merchant may object on reasonable data-protection grounds by contacting Provider.

8. International processing

Provider and its subprocessors may process data in the United States. Where applicable law requires a transfer mechanism, Provider will use a valid mechanism and supplementary safeguards appropriate to the transfer.

9. U.S. service-provider restrictions

Provider will not sell or share Merchant personal data for cross-context behavioral advertising. Provider will not retain, use, or disclose that data outside the direct business relationship with Merchant or for a purpose other than the business purposes in this DPA, except as permitted by applicable law. Provider will notify Merchant if it can no longer meet these restrictions.

10. Information and audits

Provider will make information reasonably necessary to demonstrate compliance available to Merchant. No more than once annually, unless a confirmed incident or regulator requires otherwise, Merchant may request a reasonable remote audit. Audits must protect other customers, security, confidentiality, and Provider's operations; Merchant bears its audit costs.

11. Order of precedence and contact

If this DPA conflicts with the Terms on personal-data processing, this DPA controls. The remainder of the Terms continues to apply. Questions, objections, and data-protection requests can be sent to team@agegateapp.com.

HonestGate supports Merchant's human-first age-review workflow. Merchant remains responsible for its legal basis, buyer notices, initial staff decisions, reuse policy, and compliance requirements.

HonestGate: Age Gate App
GuideDocsChangelogPrivacyData processingTermsSupportSecurity

Shopify is a trademark of Shopify Inc. HonestGate: Age Gate App is not endorsed by Shopify.