Data processing
A summary of the data processing agreement, when it applies, your obligations, and what the platform does technically to protect customer data.
On this page
This page is for anyone whose app needs merchants' customer data. Customer data in Dukkan sits behind two scopes (clients:read to read it, clients:write to create and update customer records) and one agreement; this is a summary of both, not the agreement text. Accepting the DPA also covers creating and updating customer records on the merchant's behalf.
When the agreement applies#
The current version of the data processing agreement is 2026-08-19. The developer team's owner accepts it once from the account page, and until then:
- The server refuses to save any app version requesting
clients:readorclients:writewith the messageCustomer-data scope requires the current data processing agreement. - When the agreement version changes, the team loses both scopes until it accepts the new version; existing versions never widen silently.
What customer data covers#
Customer names, phone numbers, emails and delivery addresses: the customer and shipping_address fields of GET /orders/{id}, and the customer records clients:write creates or updates. None of it reaches lists, webhooks or theme storefronts.
Your obligations#
- Limited purpose: you process customer data only to provide the app's function as declared in the listing.
- No selling, no sharing: never sold or shared with third parties except a sub-processor needed for that same function.
- Deletion: you delete the store's and its customers' data on uninstall (App lifecycle) or at the merchant's request.
- Protection: encryption in transit and at rest, restricted access within your team, and an access log.
- Reporting: you notify Dukkan without delay of any incident touching customer data through Support.
- Privacy policy: a valid privacy URL on the listing describing what you process, why, and for how long.
What the platform does#
- Explicit consent:
clients:readandclients:writeappear in a separate, unchecked-by-default section of the consent screen. - Live intersection: your app loses a scope the moment the granting member loses the permission.
- Audit trail: every Platform API call is recorded for the merchant with its path, status and
request_id. - No leakage through events: webhook payloads never carry customer data, by fixed design.
- Immediate revocation: uninstall or suspension revokes tokens at that instant.
Breach#
A breach of the agreement entitles Dukkan to suspend the app immediately with the full effect of suspension, in addition to what the developer terms provide.