Back to RewardLift

Version 2026-09-23

Data Processing Agreement

These terms govern customer-data processing by CARINUSH MEDIA SRL for merchants using RewardLift, including the RewardLift update to GiftCart.

1. Parties and acceptance

The merchant identified by its Shopify store is the controller, or an authorized processor acting for its controller. CARINUSH MEDIA SRL, CUI 49060650, Romania, trading as Balkaniq Apps, is the processor or subprocessor for store-directed customer data. Our registered address is on the company page. The store owner accepts this agreement in Settings before production contact collection, email verification and Shopify contact synchronization are enabled. We record the store, owner's Shopify identifier, time and agreement version. These terms do not change an existing GiftCart subscription price or require existing gift rules to be recreated.

2. Scope and instructions

We process data only on the merchant's documented instructions, including the features and settings it enables, to collect requested reward participation, verify an email address, issue and recover rewards, synchronize contacts and consent into Shopify, and provide related support and security. Processing lasts for the service relationship and the deletion periods below. We will inform the merchant if an instruction appears to infringe applicable data-protection law, and may suspend that instruction while it is clarified. Where a law requires other processing, we will notify the merchant beforehand unless that law prohibits notification.

3. Data and people

Data subjects are store visitors, prospective customers and customers who interact with the configured features. Data includes email addresses, store and campaign identifiers, reward details, confirmation and consent records, Shopify customer identifiers and synchronization status. Operations include collection, storage, organization, transmission to authorized services, retrieval, correction, export and deletion. These features do not require customer names, postal addresses, telephone numbers, payment card data or special-category data. Do not place such information in free-text fields or support requests.

4. Merchant responsibilities

The merchant determines its lawful basis, provides required notices, obtains applicable consent and handles its customer relationship. Verification of an address alone is not marketing consent. The merchant must have authority to give its instructions and must not submit purchased, scraped or otherwise unauthorized contact lists. The merchant remains responsible for customer records already synchronized to its own Shopify account.

5. Confidentiality and security

Access is restricted to authorized personnel bound to confidentiality and limited to their duties. Safeguards include authenticated, tenant-scoped access; verified owner approval for support access; security access logs; restricted service credentials; strong administrator passwords and MFA where available; encrypted database storage and backups; encrypted external connections and database connections; and separation of production and test environments. Keys and recovery material have restricted access. Encryption does not prevent misuse by someone who has compromised an authorized running server. No control is a guarantee against every security incident.

6. Subprocessors

The merchant authorizes the providers listed below for the stated tasks. We require applicable data-protection obligations from subprocessors and remain responsible for our obligations under this agreement. We will notify the merchant through its available store contact or in-app notice at least 30 days before a new subprocessor begins processing its customer data. The merchant may object on reasonable data-protection grounds during that period. We will discuss an alternative; if no reasonable alternative is available, the affected processing may be discontinued.

Shopify is the merchant's commerce platform and the destination the merchant instructs us to use for contact synchronization. GitHub stores private source code, not customer databases or live data backups. Amazon SES is not an active delivery provider for this deployment.

7. International processing

Our operator is in Romania. Providers may process data internationally; legacy Fly.io hosting includes a US region. For restricted international transfers, we will use an applicable adequacy decision or appropriate contractual safeguards, including applicable standard contractual clauses, and supplementary measures where needed. Contact us for provider and transfer information applicable to your store. We do not promise that all provider support or operational processing occurs exclusively in the EU.

8. Retention, return and deletion

Local unconfirmed participation records expire after 30 days, and verified participation records after 365 days from creation. Expired verification-token hashes are cleared by scheduled cleanup. Completed privacy-request identifiers are cleared after 30 days. Uninstalled-store application records are deleted after 30 days, or earlier on an authenticated Shopify redaction request. Online sessions are removed after expiry; customer-data access logs and expired support sessions are retained for up to 365 days. Scheduled cleanup runs hourly; records involved in an active operation are cleared when that operation or its recovery completes.

Encrypted database backups expire after 30 days and are isolated from normal application processing. A restore is quarantined until subsequent deletion requests and retention cutoffs have been reapplied. Keyed suppression hashes are kept as long as needed to prevent unwanted messages; minimal subscriber usage hashes and billing records are kept while the store is installed to prevent duplicate usage charges. They are not a marketing contact list. On termination, we delete or return the merchant's customer data as instructed, subject to the backup window and specific legal retention duties. Records already synchronized into Shopify are controlled by the merchant. Contact support for an authorized export or deletion request.

9. Customer rights and assistance

We assist the merchant with access, correction, portability, restriction, objection and deletion requests within the service's scope. We forward requests received directly from shoppers to the relevant merchant unless legally required to act otherwise. We also provide reasonable information and assistance for data-protection impact assessments, supervisory-authority consultations and security obligations, taking account of the nature of processing and information available to us.

10. Incidents

We notify the affected merchant without undue delay after becoming aware of a personal-data breach affecting its data. Information may be provided in stages and includes the nature of the incident, affected data where known, likely effects, containment and remediation, and a contact for follow-up. We preserve relevant evidence and cooperate with the merchant's response. The merchant determines its own obligations to notify authorities and individuals.

11. Demonstrating compliance

We provide information reasonably necessary to demonstrate compliance with this agreement and cooperate with proportionate audits or inspections by the merchant or its independent auditor. We coordinate scope and timing to protect other merchants' data and service security; urgent regulatory requirements are not excluded. No third-party certification is represented unless explicitly identified with its scope and date.

12. Contact and changes

Write to contact@balkaniq-apps.com for privacy, security or processing instructions, identifying your store. This agreement supplements the app service arrangement and controls conflicting terms about store-directed customer-data processing. Material changes will be versioned and presented for acceptance when required. The privacy notice explains our separate processing for our own business enquiries and service administration.