ScarsityPro — Merchant Terms & Data Processing Agreement
These terms govern your use of the ScarsityPro application (“the app”) on your Shopify store. By installing the app you agree to them. Part B is a data processing agreement and forms part of this contract.
Part A — Service terms
A1. The service
The app displays scarcity and urgency messages on your product pages, based on configuration you control and on data from your own store. Features available on each plan are described in the Shopify App Store listing and inside the app.
A2. Your responsibilities
You decide what your widgets say. You are responsible for ensuring that the messages you publish are accurate and lawful in your market, including consumer protection and advertising rules on urgency claims.
The app offers rules that produce generated numbers (Live Viewers, Cart Activity) as well as rules based on your real inventory and orders. The editor labels which is which. Choosing to publish a generated figure is your decision and your responsibility.
A3. Fees
Paid plans are billed by Shopify and appear on your Shopify invoice. Prices are shown before you subscribe. You can change or cancel your plan at any time from your Shopify admin; cancellation takes effect at the end of the current billing period and the app reverts to the Free plan.
A4. Availability
We aim to keep the service available continuously but do not guarantee uninterrupted operation. The storefront script is designed to fail silently: if the app is unreachable, your product pages render exactly as they would without it.
A5. Liability
To the extent permitted by law, our aggregate liability arising from the app is limited to the fees you paid for it in the twelve months before the event giving rise to the claim. We are not liable for indirect or consequential loss, including lost sales or profits.
A6. Termination
You may uninstall the app at any time. We may suspend or terminate access if the app is used unlawfully or in a way that endangers the service or other merchants. On termination, data is handled as set out in section B7.
A7. Changes
We may update these terms. Material changes are announced to installed merchants before they take effect. Continuing to use the app after that means you accept the revised terms.
A8. Governing law
These terms are governed by the laws of Italy, without regard to conflict of law rules.
Part B — Data Processing Agreement
B1. Roles
For any personal data processed through the app, you are the data controller and Domenico Caliendo is the data processor, acting only on your documented instructions. Installing and configuring the app constitutes those instructions.
B2. What is processed
The app is designed to avoid personal data entirely. What it processes and stores is:
| Category | Detail |
|---|---|
| Store configuration | Your shop domain, access token, plan, currency, timezone and widget settings |
| Aggregate performance | Daily counts of widget views, clicks and add-to-cart clicks — no identifiers attached |
| Product sales counts | From the orders/create webhook, only product_id and quantity, aggregated into a per-product daily total |
The app does not store customer names, email addresses, postal addresses, phone numbers, IP addresses, payment details, order identifiers or cart contents. It sets no cookies and performs no cross-site tracking.
B3. Data subjects and duration
Because no personal data of your customers is retained, there are no data subjects whose data we hold beyond your own account contact details. Processing lasts as long as the app is installed, plus the retention window in section B7.
B4. Confidentiality
Personnel with access to production systems are bound by confidentiality obligations and access is limited to those who need it to operate the service.
B5. Security measures
We apply the following technical and organisational measures:
- All traffic between merchants, storefronts and the app is encrypted in transit over HTTPS, as is the connection to the database.
- Data is encrypted at rest: the database lives on a dedicated LUKS2 volume (AES-XTS, 512-bit key), separate from any other workload on the host, and is not reachable from the public internet.
- The database is not reachable from the public internet and accepts connections only from the application host.
- Storefront requests are authenticated through Shopify’s signed App Proxy; shop identity is derived from that signature and never from a client-supplied parameter, so one store cannot read another’s data.
- Data minimisation by design: order webhooks are parsed for product id and quantity only, and the remaining payload is discarded.
- Administrative access to production is restricted and key-based.
Encryption at rest protects the data if the underlying storage is removed, replaced or decommissioned. It is not a defence against an attacker who has already gained privileged access to a running host, and we do not present it as one.
B6. Sub-processors
We use servers we operate at IONOS in London, United Kingdom to host the application and database. We do not use analytics providers, advertising networks or data brokers. We will inform merchants before adding a sub-processor that would process personal data.
B7. Deletion and return
- On uninstall: your access token and sessions are deleted immediately. Your widget configuration is retained for 48 hours so a reinstall restores your setup.
- 48 hours after uninstall: Shopify sends a
shop/redactrequest and everything belonging to your store is erased — settings, widgets, targeting, statistics and sales counts. - You may request earlier deletion at any time by contacting domenicocaliendo95@gmail.com.
B8. Assistance and audits
We implement Shopify’s mandatory compliance webhooks (customers/data_request, customers/redact, shop/redact). Because no customer personal data is stored, there is nothing to return or erase in response to an individual request; we will confirm this in writing on request. We will provide the information reasonably necessary to demonstrate compliance with this agreement.
B9. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting data processed on your behalf, with the information available to us at the time.
B10. International transfers
Data is processed on servers we operate at IONOS in London, United Kingdom. Where that location is outside the merchant’s own country or economic area, the transfer relies on an applicable adequacy decision or, failing that, on standard contractual clauses. We do not transfer data elsewhere except where required by law.
Our processing of personal data is described in full in our privacy policy, which forms part of this agreement.