This Data Processing Addendum ("DPA") forms part of the Terms of Service between IDARDIRECT LLC ("Pass Studio", "we", "us") and the merchant using the Service ("Merchant", "you"). It governs our processing of personal data relating to your customers ("End-Customer Data") that we receive through the Service, including via connected platforms such as Shopify.
1. Roles
For End-Customer Data, the Merchant is the data controller and Pass Studio is the data processor. We process End-Customer Data only on your documented instructions, as expressed through your configuration and use of the Service, and never for our own purposes. For data about the Merchant itself (account, billing), our Privacy Policy applies and we act as controller.
2. Scope of Processing
Subject matter and duration. Processing of End-Customer Data to provide digital wallet pass issuance, loyalty program operation, and related analytics, for the duration of your use of the Service.
Nature and purpose. Issuing and personalising wallet passes; delivering pass installation links by email; maintaining loyalty point balances and reward state; matching a scanned pass to the corresponding customer record (including at point of sale); and providing you aggregate analytics.
Categories of data. Customer identifiers assigned by the connected platform, name, email address, order references, discount-code usage, loyalty activity, and device/pass installation metadata. We do not process payment card data of end customers.
Data subjects. Your customers and loyalty program members.
3. Confidentiality and Access
Access to End-Customer Data is limited to personnel who need it to operate and support the Service, is protected by strong authentication with multi-factor verification, and is logged. All personnel are bound by confidentiality obligations.
4. Security Measures
- Encryption in transit (TLS) for all connections
- Encryption at rest for all data stores and backups (Google Cloud default encryption)
- Separated staging and production environments — production data is not used for testing
- Role-based access controls and audit logging (Google Cloud IAM and Cloud Audit Logs)
- Secrets managed in Google Secret Manager, never stored in code
- Webhook payloads authenticated by HMAC signature verification
5. Sub-processors
You authorise the following sub-processors, engaged solely to operate the Service:
- Google Cloud Platform / Firebase — hosting, storage, authentication, analytics (United States)
- Resend — transactional email delivery (pass installation links)
- Stripe — Merchant billing only; does not receive End-Customer Data
We will notify you of any intended change of sub-processors (by email or in-product notice), giving you the opportunity to object before the change takes effect.
6. Data Subject Requests
Taking into account the nature of the processing, we will assist you in fulfilling your obligations to respond to end-customer requests to access, correct, export, or delete their data. We honour deletion and redaction requests forwarded by you or issued by the connected platform (including Shopify's customer redaction and shop redaction requests). If an end customer contacts us directly, we will redirect them to you.
7. Incident Notification
We will notify you without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting End-Customer Data, and will provide information reasonably required for you to meet your own notification obligations.
8. Deletion and Return
Upon disconnection of an integration, deletion of your account, or your written request, we will delete or irreversibly anonymise the related End-Customer Data within 30 days, except where retention is required by law. Retention periods are detailed in our Privacy Policy.
9. International Transfers
End-Customer Data is processed in the United States. Where End-Customer Data originating from the EEA, UK, or Switzerland is transferred to us, the parties rely on applicable transfer mechanisms, including the European Commission's Standard Contractual Clauses, which are incorporated by reference to the extent required.
10. Audit and Information
On written request, we will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of our security practices.
11. Contact
Questions about this DPA: info@idardirect.com
© 2026 Pass Studio · Published by IDARDIRECT LLC