Skip to content
Legal

Data Processing Agreement

Version 2026-08-22. This agreement forms part of the Terms of Service and is accepted when you create a Corven OS workspace.

1. Roles of the parties

You (the merchant) are the controller of the personal data contained in your store and marketplace data. Corven OS is the processor and processes that data only on your documented instructions, which are given by your use of the product and by the connections you authorize. Where a marketplace such as Shopify is itself a controller or processor of the same data, nothing here changes your agreement with that marketplace.

2. Subject matter, duration, nature and purpose

The subject matter is the operation of the Corven OS merchant operations platform. Processing lasts for as long as your workspace is active plus the retention periods described in section 8. The nature and purpose of processing is limited to store management (synchronizing and displaying orders, products, listings, inventory, fulfillment and settlement records) and analytics (computing aggregate metrics, profitability, forecasts and operational recommendations for you).

3. Categories of data and data subjects

Data subjects are your team members and, indirectly, your customers. For Shopify connections Corven OS requests protected customer data at Level 1 only and does not request the optional protected fields. Corven OS therefore does not receive or store Shopify customer names, email addresses, phone numbers or addresses. The Shopify data processed is limited to order identifiers and numbers, order and fulfillment status, line items, quantities, prices, taxes, discounts, refunds, shipment and tracking references, inventory levels, product and variant records, and settlement amounts.

4. Permitted purposes and limitations

Corven OS processes your data solely to provide, secure, support and improve the service for you. We do not sell your data or your customers' data, do not share it for advertising or cross-context behavioral advertising, do not use it to build profiles of individuals, and do not use it to train general-purpose AI models. Analytical outputs are produced for your workspace only.

5. Confidentiality

Access to merchant data is limited to personnel who need it to operate the service and who are bound by confidentiality obligations. Internal support access to a workspace is read-only, time-limited, requires a stated reason, is visible in the product, and is recorded in an append-only audit log.

6. Security safeguards

Corven OS maintains technical and organizational measures appropriate to the risk, including TLS encryption in transit for all traffic, encryption at rest of the managed database and object storage, AES-256-GCM application-level encryption of marketplace access tokens and refresh tokens with server-side-only decryption, tenant isolation enforced by row-level security in the database, role-based access control checked server-side, least-privilege database functions with pinned search paths, redaction of credentials from diagnostics and exports, and append-only audit logging of privileged actions. Full detail is published on the security page.

7. Subprocessors

You authorize the following subprocessors. We remain responsible for their performance and will give notice before adding a subprocessor that processes merchant data, so you may object.

  • Supabase — managed Postgres database, authentication, and object storage (hosting of all workspace data).
  • Cloudflare — application hosting, edge delivery, and TLS termination.
  • Resend — transactional email delivery (account, invitation, and notification email addresses only).
  • Plaid — bank and card account connectivity, only where you explicitly connect a financial account.

Marketplaces you connect (Shopify, Amazon, Walmart and others) are sources and recipients of your data at your instruction, not subprocessors of Corven OS.

8. Retention, deletion and return

Marketplace order and transaction records are retained for up to 24 months from the order date and are then deleted automatically by a scheduled database job. When you disconnect or uninstall a store, its stored access tokens are destroyed immediately and the remaining store data is purged within 30 days. On receipt of a Shopify shop/redact request we delete the shop's orders, order items, refunds, shipments, listings, payouts and health records and destroy its credentials. You may request deletion or an export of your workspace data at any time by contacting us, and we will act within 30 days. We retain only records we are legally required to keep, and audit records that contain no customer personal data.

9. Merchant and customer privacy requests

Corven OS assists you in responding to data subject requests. Shopify's mandatory customers/data_request, customers/redact and shop/redact webhooks are implemented and execute real database operations rather than being acknowledged only. For requests reaching us directly, contact hello@corvenos.com.

10. Personal data breach notification

If Corven OS becomes aware of a personal data breach affecting your data, we will notify you without undue delay and in any case within 72 hours of confirmation, describing the nature of the breach, the data and data subjects affected so far as known, the likely consequences, and the measures taken or proposed. Security matters may be reported to security@corvenos.com.

11. Audits and cooperation

On reasonable written request, and no more than once in a twelve-month period unless required by a supervisory authority, Corven OS will provide the information reasonably necessary to demonstrate compliance with this agreement and will cooperate with data protection impact assessments and prior consultations relating to the service.

12. International transfers

Data is hosted in the region configured for your workspace. Where a transfer of personal data out of the EEA or the UK occurs, it is made under an approved transfer mechanism, including the applicable standard contractual clauses, which are incorporated into this agreement by reference.

13. Order of precedence and changes

This agreement supplements the Terms of Service and prevails over them on matters of data protection. We may update it as the product and its subprocessors change; material changes are posted here with a new version date before they take effect.