B2BB2B Rewards Engineby Sugoi Digital
PrivacyDPASubprocessors

B2B Rewards Engine

Data Processing Addendum

The data protection terms governing B2B Rewards Engine's processing of merchant and customer information.

Effective date: September 14, 2026 Last updated: September 14, 2026

This Data Processing Addendum ("DPA") supplements the agreement governing a merchant's use of B2B Rewards Engine (the "App").

This DPA is entered into between:

Merchant: The Shopify merchant using B2B Rewards Engine ("Merchant")

and

Developer: Sugoi Digital LLC, doing business as Sugoi Digital ("Developer").

1. Scope

This DPA applies to Personal Data processed by Developer on behalf of Merchant in connection with B2B Rewards Engine.

"Personal Data" includes information that constitutes personal data, personal information, protected customer data, or a similar concept under applicable data protection law.

2. Roles of the Parties

To the extent applicable to the processing:

  • Merchant acts as the controller, business, or equivalent party that determines the purposes for which its Shopify customer data is used.
  • Developer acts as the processor, service provider, contractor, or equivalent party when processing Merchant Personal Data to provide the App.

Nothing in this DPA changes the parties' legal roles where applicable law assigns those roles differently.

3. Merchant Instructions

Developer will process Merchant Personal Data only:

  • To provide and secure B2B Rewards Engine.
  • In accordance with Merchant's use and configuration of the App.
  • As documented in this DPA and the B2B Rewards Engine Privacy Policy.
  • As necessary to comply with applicable law.

Merchant's installation, use, and configuration of the App constitute documented instructions to process the data necessary to provide those functions.

Developer will not use Merchant Personal Data for unrelated advertising, data-broker activity, or independent customer profiling.

4. Nature and Purpose of Processing

Processing can include receiving, retrieving, storing, organizing, comparing, updating, displaying, redacting, deleting, and otherwise using data necessary to provide:

  • B2B rewards campaign administration.
  • Order qualification.
  • Reward creation and customer restriction.
  • Reward redemption.
  • Customer-account reward visibility.
  • Refund and cancellation reconciliation.
  • Reward reissue and adjustment handling.
  • Merchant analytics and reporting.
  • Privacy request fulfillment.
  • Authentication, security, and service operation.

5. Categories of Data Subjects

Data subjects can include:

  • Merchant owners.
  • Merchant administrators and authorized staff.
  • Shopify customers associated with B2B companies.
  • Shopify B2B company contacts.
  • Customers associated with qualifying or redemption orders.

6. Categories of Personal Data

The App can process merchant authentication data and Shopify Level 1 protected customer data, including:

  • Shopify shop and user identifiers.
  • Authentication and session information.
  • Administrator information supplied through Shopify authentication.
  • Shopify customer IDs.
  • Order IDs and order names or numbers.
  • Order timestamps and statuses.
  • Refund and cancellation information.
  • Order subtotal and reward-related revenue values.
  • B2B company and company-location identifiers.
  • Reward, discount, redemption, reissue, and adjustment history.

The App is not designed to request Shopify customer name, postal address, email address, or phone number for B2B rewards functionality.

7. Duration of Processing

Processing continues while Merchant uses the App and for the limited periods necessary to complete the purposes described in this DPA.

Privacy-request snapshots are subject to an approximately 30-day maximum active retention period unless cleared earlier.

Operational reward history can be retained while the App remains installed when reasonably necessary for rewards administration, reconciliation, reporting, analytics, and auditing.

8. Confidentiality

Developer will limit access to Merchant Personal Data to persons and service providers who require access for legitimate operational, support, security, or compliance purposes.

Persons authorized to process Personal Data are expected to protect its confidentiality.

9. Security Measures

Developer maintains safeguards designed to protect Merchant Personal Data, including:

  • Encryption in transit using TLS.
  • TLS-required production database connections.
  • Server-side SSL enforcement.
  • Encryption at rest through managed database infrastructure.
  • Shopify webhook signature verification.
  • Authenticated merchant and customer-account requests.
  • Shop-scoped application data access.
  • Secret management outside source control.
  • Logging controls intended to avoid protected customer payloads.
  • Automated privacy-request snapshot retention enforcement.
  • Customer- and shop-redaction workflows.

Developer may update its safeguards over time provided that the overall protection of Personal Data is not materially reduced.

10. Data Minimization and Purpose Limitation

Developer will process only Personal Data reasonably necessary to provide the documented App functionality.

Developer will not materially expand its use of protected customer data beyond the disclosed purposes without reviewing and updating its data practices and obtaining required Shopify approval where applicable.

11. Subprocessors

Merchant authorizes Developer to engage subprocessors reasonably necessary to provide the App.

Current subprocessors are identified in Developer's Subprocessor List.

Developer will require subprocessors to protect Personal Data through contractual or other legally appropriate safeguards applicable to the services they provide.

12. Changes to Subprocessors

Developer may add or replace subprocessors as its infrastructure changes.

Developer will maintain a current subprocessor list.

Merchant may contact Developer at hello@sugoidigital.co regarding reasonable data-protection concerns involving a subprocessor.

13. Assistance With Privacy Requests

Developer will provide reasonable assistance to Merchant in responding to privacy requests involving Merchant Personal Data processed by the App.

B2B Rewards Engine implements Shopify privacy workflows for:

  • Customer data requests.
  • Customer redaction requests.
  • Shop redaction requests.

Developer will process authenticated Shopify privacy requests through the App's implemented privacy workflow.

14. Deletion and Return

When the App receives an applicable Shopify customer-redaction request, it will redact or remove matching customer and order identifiers from relevant App records as required.

Following App uninstall or an applicable Shopify shop-redaction request, Developer will delete Merchant App data from the active application database, subject to applicable legal obligations.

Where retention of particular information is required by law, further processing will be limited to the applicable legal purpose.

15. Security Incidents

Developer will maintain processes for identifying, evaluating, containing, and remediating security incidents.

If Developer becomes aware of a confirmed Personal Data breach affecting Merchant Personal Data, Developer will notify Merchant without undue delay where required by applicable law or contractual obligation.

Developer will provide reasonably available information necessary for Merchant to understand the nature and impact of the incident.

16. International Transfers

Merchant acknowledges that Developer and approved subprocessors may process Personal Data outside the jurisdiction where Merchant or a data subject is located.

Where applicable law requires additional transfer safeguards, the parties will cooperate in good faith to implement an appropriate lawful mechanism.

17. Compliance Information

Upon reasonable request, Developer may provide information reasonably necessary to demonstrate compliance with the obligations described in this DPA, subject to confidentiality, security, and protection of other merchants.

Any audit or information rights required by applicable law should be exercised in a manner that avoids unnecessary disruption or compromise of the security or confidentiality of other parties.

18. Restricted Uses

To the extent Developer acts as a processor, service provider, contractor, or similar regulated recipient, Developer will not sell Merchant Personal Data or use it outside the business purposes described in this DPA except as permitted or required by applicable law.

19. Conflict

If this DPA conflicts with another agreement between Merchant and Developer regarding processing of Merchant Personal Data, this DPA controls to the extent of the conflict unless the parties expressly agree otherwise.

20. Contact

Developer: Sugoi Digital LLC, doing business as Sugoi Digital Privacy contact: hello@sugoidigital.co Mailing address: 27010 Coco Flower Ln, Katy, Texas 77493, United States Country: United States

B2B Rewards EngineOperated by Sugoi Digital LLC d/b/a Sugoi Digital
hello@sugoidigital.coKaty, Texas, United States