This addendum forms part of the Terms of Service between Monochrome, Lebanon ("we", "the processor") and the merchant using Inner Circle ("you", "the controller"). It applies whenever we handle personal data on your behalf.
You do not need to sign anything. Accepting the Terms of Service puts this in place, including the Standard Contractual Clauses in section 8. If your organisation requires a signed copy, write to hello@monochrome.digital.
Terms such as "personal data", "processing", "controller", "processor" and "data subject" carry the meanings given in the GDPR.
1. Roles
You are the controller of your shoppers' personal data. You decide what your access request form asks, why, and what happens to the answers.
We are your processor. We handle that data only to provide the app.
We are a separate controller for the information we hold about you and your staff as our customer. That is governed by the Privacy Policy, not by this addendum.
2. What we process, and why
Set out in full in Annex A.
3. Our obligations
We will:
- Process only on your documented instructions. Using the app is your instruction. If the law compels us to process otherwise, we will tell you first unless legally barred.
- Tell you if an instruction looks unlawful, in our reasonable opinion.
- Keep it confidential. Everyone with access is bound by confidentiality.
- Keep it secure, applying the measures in Annex C.
- Help you meet your own obligations, responding to data subject requests, reporting breaches, running impact assessments and consulting regulators, taking into account what we know and what the app can do.
- Notify you of a personal data breach without undue delay after becoming aware of it, with what we know, the likely consequences and what we are doing about it.
- Delete or return the data when the service ends, as in section 7.
- Make available what you need to show we are meeting these obligations, and allow audits as in section 9.
4. Your obligations
You will:
- Have a lawful basis for everything you collect through the app, and get consent where consent is required.
- Tell your shoppers what you collect and why, including that Inner Circle handles it for you. Wording you can adapt is in the merchant disclosure snippet.
- Not collect special category data through the access request form, including health, ethnicity, religion, political views, trade union membership, sexual orientation, biometric and genetic data, nor criminal records, government identifiers or payment card numbers.
- Answer your shoppers' requests. We will help, but they are yours to answer.
- Make sure your instructions to us are lawful.
5. Sub-processors
You give us general authorisation to engage sub-processors. The current list is at sub-processors.md.
We will:
- Bind each one by written contract to obligations no less protective than these
- Remain fully liable to you for their performance
- Give you at least 30 days' notice by email before adding or replacing one
If you reasonably object within those 30 days, we will try to offer a workaround. If we cannot, you may terminate without penalty and receive a pro-rata refund of any prepaid fees.
6. Data subject requests
Shopify routes shopper requests to us automatically, and we act on them as described in the Privacy Policy, section 8. If a shopper contacts us directly we will not respond on your behalf beyond telling them to contact you, and we will pass the request to you promptly.
7. Deletion
On uninstall, Shopify instructs us to erase the store's data 48 hours later, and we delete everything belonging to it: settings, locks, access codes, access requests, granted access, activity records and session data. This is permanent.
Export anything you need before uninstalling. Once deleted it cannot be recovered, and backups age out on their own cycle.
8. International transfers
The application and its database are both in the European Union, in Frankfurt. The database is Neon's eu-central-1; since 13 August 2026 the application's functions are pinned to Frankfurt as well, beside it, where they previously ran in the United States.
Neon and Vercel are both incorporated in the United States. The data they handle for us sits in the European Union, but the companies themselves are American, which is a fact you may need for your own transfer assessment. Both are bound by the written contract described in section 6 and both appear, with the location of the data they hold, on the sub-processor list.
We are established in Lebanon, which has no EU adequacy decision. Where you transfer EEA, UK or Swiss personal data to us:
- The Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two, controller to processor, are incorporated into this addendum and apply to that transfer.
- Clause 7 (docking) applies.
- Clause 9: Option 2, general written authorisation, with 30 days' notice.
- Clause 11: the optional independent dispute resolution body does not apply.
- Clause 17: governed by the law of Ireland.
- Clause 18: disputes before the courts of Ireland.
- Annexes I, II and III of the Clauses are populated by Annexes A, C and the sub-processor list of this addendum.
- For UK data, the International Data Transfer Addendum (version B1.0) issued under section 119A of the Data Protection Act 2018 applies to the above Clauses, with the start date being the date you install the app.
- For Swiss data, the Clauses apply with references read as pointing to the Swiss FADP and the Swiss Federal Data Protection and Information Commissioner.
9. Audits
On reasonable written notice, no more than once in any 12 months (unless a regulator requires more or there has been a breach), we will provide the information reasonably needed to demonstrate compliance. Where that is genuinely insufficient, we will cooperate with an audit at your cost, conducted so as not to disrupt our other customers, and subject to confidentiality.
10. Liability
Each party's liability under this addendum is subject to the limits in section 11 of the Terms of Service, except where the Standard Contractual Clauses provide otherwise for data subjects.
11. Conflicts
Where this addendum conflicts with the Terms of Service, this addendum wins on data protection. Where either conflicts with the Standard Contractual Clauses, the Clauses win.
Annex A: Description of the processing
Subject matter. Providing the Inner Circle access-control app for Shopify.
Duration. For as long as the app is installed, plus the 48 hours before Shopify's erasure instruction takes effect.
Nature and purpose. Deciding whether a visitor may purchase; validating and redeeming access codes; recording and maintaining granted access, including the access tier it was granted at; collecting and storing access requests; applying the merchant's automatic approval rules to them; converting requests into Shopify draft orders; maintaining a waitlist and the referrals that order it; recording who asked to be told when a scheduled lock opens, and telling them; sending the resulting email to shoppers on the merchant's behalf; writing access tier names to Shopify customer records as tags; generating notifications; producing campaign and demand statistics for the merchant; detecting and preventing abuse.
Categories of data subject.
- The merchant's staff who use the app
- Visitors to the merchant's storefront who enter an access code
- Visitors who submit an access request or join a waitlist
- Visitors who ask to be notified when a scheduled lock opens
- The merchant's existing Shopify customers, where a lock is evaluated against their tags or email address
Categories of personal data.
| Group | Data |
|---|---|
| Merchant staff | Name, email address, language, account role, Shopify user ID |
| Access requests | Email, and where the merchant's form asks for them: name, phone, company, country. All other answers to the merchant's custom form. Interest list contents. Shopify customer ID. Page submitted from. Merchant's internal notes and decision. |
| Code redemptions | Shopify customer ID, email address, salted one-way hash of IP address, browser user-agent string, page path, timestamp |
| Granted access | Random opaque token, Shopify customer ID, email address, expiry, last-used time, and the access tier it was granted at |
| Waitlist entries | Held on the access request itself: email address, Shopify customer ID, the time they joined, their own referral code, the number of people credited to it, and which entry referred them |
| Drop notifications | Email address, Shopify customer ID, which lock was asked about, the page it was asked from, and whether the announcement has been sent |
| Access tier tags | The tier's name, written to the Shopify customer record as a tag |
| Activity records | Event type, timestamp, associated record ids, and, for the email delivery trail, the recipient's address |
Special category data. None. Prohibited by section 4.3.
Frequency. Continuous, for as long as the app is installed.
Annex B: Sub-processors
See sub-processors.md, which forms part of this addendum.
Annex C: Technical and organisational measures
Authentication and access control
- Every storefront request is verified as genuinely originating from Shopify, using Shopify's signature scheme, before any data is read or written
- Admin access requires an authenticated, valid Shopify session
- Every database query is restricted to the requesting store, so one merchant cannot reach another's data
- Access to production systems is limited to those who need it
Enforcement
- Access decisions are made server-side. Client-side page changes are presentational only and cannot authorise a purchase.
- Cart submissions are intercepted server-side, so a revealed button still cannot complete an order
Data minimisation
- IP addresses are never stored in the clear, only as a salted, truncated one-way hash, salted per store
- Exact stock quantities above a threshold are collapsed before reaching the page, so precise inventory cannot be read from the storefront
- The access token held in the visitor's browser is random, never personal data
- Activity records store record ids rather than copies of personal data
Encryption
- All traffic is over HTTPS
- The database is encrypted at rest by the provider
- The access token is stored in the visitor's browser rather than in an HttpOnly cookie, because Shopify's app proxy strips cookie headers in both directions. It is therefore readable by scripts on the store's own pages, and is designed accordingly: a random value carrying no personal data, scoped to one store, expiring, and revocable by the merchant
Resilience and recovery
- Managed PostgreSQL with the provider's automated backups and point-in-time recovery
- Serverless hosting with automatic failover between instances
Deletion
- Automated handling of Shopify's erasure instructions, as in section 7
- Shopper erasure anonymises access requests, deletes granted access, strips redemption records, and deletes the activity records that carry an address