Passerity

Data Processing

Effective September 16, 2026

Passerity is small enough today (solo-founder, no formal company registration) that this page stands in for a formal Data Processing Agreement rather than being one. It's a good-faith, researched description of our current sub-processors and safeguards, not legal advice, and hasn't been reviewed by a lawyer. If you need a signed DPA for your own compliance purposes, contact us and we'll follow up as this business grows into needing one.

Why this looks different from a typical app's DPA

Passerity's Shopify access scopes are limited to read_products and write_products. We never request Protected Customer Data access, and there is no customer record anywhere in Passerity's database. Most of what a typical DPA exists to govern — a vendor processing your customers' personal data on your behalf — doesn't arise here. What we do process on your behalf is your product catalog data and whatever merchant/manufacturer profile information you enter; the sections below cover that.

Sub-processors

Sub-processorPurposeData involved
Shopify Platform Passerity is built on and embeds within Product catalog data (via the Admin API)
Anthropic (Claude API) AI-assisted passport drafting Product title, description, and tags only — never customer data
Fly.io Application hosting and database (PostgreSQL) All merchant-entered data (company/manufacturer profile, passport content, uploaded safety certificates)
Sentry Error monitoring Application error context, with request bodies, query parameters, job arguments, and cookies excluded by default
Postmark Transactional email delivery Email address and message content for support correspondence

Safety certificate uploads are currently stored on Passerity's own Fly.io application server, not a separate third-party storage provider. If that changes, this table will be updated.

Security measures

Security incident response

If a security incident is discovered — through automated monitoring or otherwise — we follow this process: detect, assess what's affected (which shop(s), and whether a Shopify access token or merchant-entered profile data was exposed — there is no customer data to expose), contain (revoke/rotate the affected credential and patch the underlying cause), fix and add a regression test where practical, and notify affected merchants without undue delay once a breach is confirmed.

Data subject requests

Shopify's mandatory customers/data_request and customers/redact webhooks are implemented and always report that Passerity holds nothing to export or redact for any given customer — a structural fact, not a stub, since Passerity has no customer-scoped data model at all. Uninstalling the app (app/uninstalled) erases your shop's own data — company/manufacturer profile and every product passport, including uploaded certificates — and shop/redact acts as a safety net if that somehow didn't already happen.

Contact

Questions about how Passerity processes data, or to request a signed DPA: support@passerity.com.