Mcfly Ads
Data Processing Addendum
DRAFT — not signed counsel. Last updated: July 28, 2026. Request a reviewed copy at mcflyadsmmm@gmail.com before treating this as a contract.
This page is a working draft for Shopify merchants who need processor terms. It does not replace a lawyer-reviewed DPA / SCCs. Do not assume EU/UK transfer compliance is complete until counsel signs off.
1. Parties & roles
Merchant (Controller) installs Mcfly Analytics. Mcfly (Processor), operated by Marty Smithson, Utah, USA, processes Shopify store data to provide the Total ROAS desk. For waitlist emails sent directly to Mcfly, Mcfly is Controller (see Privacy).
2. Subject matter
Processing of Shopify order totals, opaque customer identifiers, spend aggregates the Merchant enters or syncs, staff session fields from Shopify login, and operational logs — solely to provide Total ROAS, break-even, allocation, and Level-1 cohort LTV features described in the Product and Privacy policy.
3. Nature & purpose
Hosted SaaS processing via Shopify Admin API and webhooks. No path-attribution pixels. No Level 2 customer PII (name, email, phone, address) requested or stored for store customers.
4. Duration
While the app remains installed, then deletion on uninstall / shop/redact per Privacy (subject to short backup / legal hold windows). Temporary ComplianceDataExport packages ≤ 60 days.
5. Types of personal data
- Shop domain; staff Admin email/name from Shopify session
- Opaque customer id / customerKey; order ids; order amounts; dates; numberOfOrders
- Ad spend aggregates; margin/settings the Merchant enters
- Host/CDN request metadata as described in Privacy
6. Categories of data subjects
Merchant staff users; Merchant’s end customers (pseudonymous identifiers and order economics only).
7. Processor obligations (summary)
- Process only on Merchant/Shopify documented instructions for the service
- Confidentiality for personnel with access
- Appropriate technical and organizational measures (see Security)
- Engage sub-processors listed in Privacy; reasonable notice of material changes
- Assist with data subject requests routed through Shopify GDPR webhooks and Merchant inquiries
- Delete or return Merchant personal data on end of service as described in Privacy
- Make available information reasonably necessary to demonstrate compliance
8. Sub-processors
Current list: Cloudflare, Fly.io, managed Postgres provider, Shopify, Resend (when enabled), FormSubmit.co (waitlist fallback), Google Fonts CDN (marketing site). Full descriptions: Privacy.
9. International transfers
US-based operation and hosting. Transfer mechanisms (SCCs / UK addendum) to be attached by counsel for EU/UK Merchants on request.
10. Liability
Subject to the limitation of liability in the Terms, except where mandatory data-protection law provides otherwise.