1. Roles
When you use Zelari, you (the merchant) decide why and how your store data is used. Under data protection law, you are the controller and Zelari is your processor. This DPA sets out how we handle any personal data in your store data on your behalf.
2. Definitions
"Data Protection Laws" means the laws that apply to the personal data we process for you, including the EU General Data Protection Regulation (GDPR), the UK GDPR, and US state privacy laws such as the California Consumer Privacy Act (CCPA). "Personal Data," "Processing," "Controller," and "Processor" have the meanings given in those laws. "Security Incident" means a breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to your personal data.
3. What we process
| Item | Details |
|---|---|
| Purpose | Providing Zelari: capturing inventory changes, detecting anomalies, calculating inventory metrics, writing AI explanations, and sending the emails you turn on. |
| Duration | While Zelari is installed on your store, and until the data is deleted as described in section 10. |
| People the data relates to | You and your staff, and your customers only to the limited extent described below. |
| Types of personal data | Store and account details provided by Shopify (such as shop domain and store contact details), the alert email address you enter in Settings, and order records that include the numeric Shopify customer ID. We do not store customer names, email addresses, phone numbers, or shipping addresses. |
| Sensitive data | None. Zelari does not process special categories of personal data. |
4. Our commitments
We will:
- Process personal data only to provide Zelari, following your instructions as set out in the Terms, this DPA, and your settings in the app
- Tell you if we believe an instruction breaks Data Protection Laws
- Make sure anyone with access to personal data is bound by confidentiality
- Protect personal data with the security measures in section 6
- Help you respond to requests from people exercising their data rights, taking into account the limited data we hold
- Help you with data protection impact assessments and consultations with authorities where the law requires, as reasonably needed
- Never sell personal data or use it for advertising
5. Sub-processors
You authorize us to use the following sub-processors to run Zelari. Each is bound by data protection terms that protect personal data at least as well as this DPA.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Application database | United States |
| Vercel | App and website hosting | United States |
| Inngest | Background jobs, such as anomaly detection | United States |
| Anthropic | AI explanations for flagged anomalies | United States |
| Resend | Delivery of alert and digest emails | United States |
We will update this list before adding or replacing a sub-processor, and tell merchants by email about material changes. If you object to a change, you can stop using Zelari by uninstalling it.
6. Security measures
- Encrypted connections (TLS) for all data in transit
- Encryption at rest provided by our database and hosting providers
- Production database access limited to server-side code, with credentials never exposed to browsers
- Access limited to the people who need it to run and support Zelari
- Access to your store only through the Shopify permissions you approve at install
- Logging and monitoring to detect and investigate problems
7. Security incidents
If we become aware of a Security Incident affecting your personal data, we will notify you without undue delay, and no later than 72 hours after becoming aware of it. We will tell you what happened, what data is affected, what we are doing about it, and what you may need to do. Our full process is described in our Security Incident Response Policy. To report a security concern, email support@zelari.io.
8. International transfers
We and our sub-processors process data in the United States. Where Data Protection Laws require it for transfers out of the EU, EEA, UK, or Switzerland, the relevant Standard Contractual Clauses (or the UK Addendum) apply, and we rely on our sub-processors' equivalent transfer safeguards.
9. Audits
On request, we will provide the information reasonably needed to show that we comply with this DPA. If that is not enough, you may request an audit once per year with reasonable notice, at your own cost, in a way that does not compromise the security of other merchants' data.
10. Deletion
When you uninstall Zelari, we stop collecting data from your store. You can ask us to delete your store's data at any time through our Contact Us page, and we will confirm once it is done. When Shopify tells us that one of your customers has asked to be forgotten, we remove that customer's ID from our records. We may keep limited records where the law requires it.
11. US state privacy laws
Where the CCPA or similar laws apply, we act as your service provider. We will not sell or share personal data, keep or use it for any purpose other than providing Zelari, or combine it with data from other sources except as those laws allow.
12. General
This DPA is governed by the same law as our Terms. The limits of liability in the Terms apply to this DPA. If this DPA and the Terms conflict on how personal data is handled, this DPA wins.
13. Contact
Version history
| Version | Effective | Summary |
|---|---|---|
| 1.0 Current | September 27, 2026 | Initial version. |