Last updated: March 17, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between the merchant ("Data Controller", "you") and AskOrigin ("Data Processor", "we", "us") governing the processing of personal data in connection with your use of the AskOrigin application. By installing or using AskOrigin, you agree to the terms of this DPA.
AskOrigin processes Personal Data solely to provide marketing attribution services to the Data Controller. The categories of data processed and purposes are described in our Privacy Policy, sections 3 and 4.
Processing includes:
AskOrigin shall:
The Data Controller shall:
Personal Data is retained for the duration of the merchant relationship. Upon termination (app uninstall or shop erasure request), all Personal Data associated with the Data Controller's store is permanently deleted from our systems. Individual customer data is deleted upon receipt of a customer erasure request via Shopify's GDPR webhooks.
AskOrigin implements the following technical and organizational security measures:
In the event of a Personal Data breach, AskOrigin shall notify the Data Controller without undue delay and no later than 72 hours after becoming aware of the breach. The notification will include:
AskOrigin currently uses the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase Inc. | Database hosting, edge functions, authentication | United States |
| Netlify Inc. | Application hosting and deployment | United States |
| Google LLC | Google Ads campaign cost import and server-side conversion upload (activated only when merchant connects their Google Ads account) | United States |
| Meta Platforms Inc. | Server-side conversion events via Meta Conversions API (activated only when merchant connects their Meta Business account) | United States |
We will notify the Data Controller of any intended changes to sub-processors, giving the Data Controller the opportunity to object.
Personal Data may be transferred to and processed in the United States, where our sub-processors are located. Where such transfers occur, we ensure appropriate safeguards are in place, including standard contractual clauses approved by the European Commission, to protect Personal Data in accordance with GDPR requirements.
This DPA is effective from the date the Data Controller installs AskOrigin and remains in effect for the duration of the service. Upon termination, AskOrigin will delete all Personal Data within 30 days unless applicable law requires continued storage. The Data Controller may also trigger immediate deletion by uninstalling the app, which initiates Shopify's shop erasure webhook.
This DPA shall be governed by the same laws that govern the agreement between the Data Controller and AskOrigin. For Data Controllers established in the European Economic Area, this DPA shall be governed by the laws of the Data Controller's jurisdiction to the extent required by GDPR.
For questions regarding this DPA or to exercise your rights, contact us at:
Email: [email protected]
Website: https://askorigin.com