LeakHunt · WEBx47
Data Processing Agreement
Last updated: 9 September 2026 · Effective from the date you install LeakHunt
This Data Processing Agreement (“DPA”) governs LeakHunt’s access to and processing of personal data on behalf of the merchant who installs it, in accordance with Article 28 of the UK and EU General Data Protection Regulation. It takes effect when you install LeakHunt and forms part of the terms under which you use the app.
1Parties
This DPA is entered into between:
- The Processor: Akash Chaterjee, trading as WEBx47, of Mansarovar, Jaipur, RJ, 302020, IN (“we”, “Processor”), operator of the LeakHunt Shopify app.
- The Controller: the merchant that has installed LeakHunt (“Controller”), being the Shopify store on whose behalf personal data is processed.
This DPA forms part of, and is subject to, the terms under which the Controller uses LeakHunt (the “Main Agreement”).
2Roles & definitions
The Controller determines the purposes and means of processing the personal data. The Processor processes that personal data only on the Controller’s behalf. “Personal data”, “processing”, “data subject”, “controller” and “processor” have the meanings given in the GDPR. “Applicable Data Protection Law” means the EU GDPR, the UK GDPR, and the UK Data Protection Act 2018, as applicable.
3Details of processing
| Subject matter | Provision of the LeakHunt app: finding the Controller’s discount codes on public coupon sites, verifying and disabling them, and rejecting leaked codes at checkout for shoppers running a coupon browser extension. |
|---|---|
| Duration | For the term of the Main Agreement. All data associated with a store is deleted on uninstall, except the billing record described below. |
| Nature & purpose | Authenticating the Controller’s staff through Shopify; sending the Controller’s public storefront domain to LeakScout, the Processor’s in-house scanning service, and checking candidate codes against the Controller’s discounts; storing the Controller’s settings; writing protection markers to shoppers’ carts in the Controller’s Shopify store; counting protected orders; and sending email alerts where enabled. |
| Categories of data subjects | The Controller’s store staff. The Controller’s customers, to the limited extent described below. |
| Personal data stored | Merchant account data (store owner / staff name and email address, store domain) and the email addresses the Controller lists for alerts. |
| Customer data | The Processor stores no personal data about the Controller’s customers. When Extension Guard is on, the coupon extensions detected in a shopper’s browser and the leaked codes to reject are written to that shopper’s cart in the Controller’s Shopify store, where Shopify may copy them onto the order. Order counts are read to report protected orders; no order or customer details are stored. |
| Non-personal data stored | Discount codes found on coupon sites that exist in the Controller’s store, the sites they were found on, their status and first-seen date; whitelisted and intentional codes; scan state; and the store’s billing record. |
4Processor obligations
- Process personal data only on the Controller’s documented instructions, including as set out in this DPA and the Main Agreement, unless required to do otherwise by law.
- Ensure that personnel authorised to process the personal data are bound by an obligation of confidentiality.
- Implement appropriate technical and organisational measures to protect the personal data (see Section 5).
- Not sell the personal data or use it for any purpose other than providing the service.
- Assist the Controller, taking into account the nature of processing, in responding to data subject requests and in meeting its obligations regarding security, breach notification, and impact assessments.
- On termination, delete the personal data within a reasonable period, unless retention is required by law.
- Make available information reasonably necessary to demonstrate compliance with this DPA.
5Security measures
The Processor maintains measures appropriate to the risk, including encryption of personal data at rest and in transit, access controls restricting who can access stored data, separation of production and test environments, and data minimisation limiting stored data to what each feature requires.
6Sub-processors
The Controller authorises the Processor to engage the sub-processors listed below. The Processor remains responsible for their performance and will inform the Controller of intended changes, giving the Controller the opportunity to object.
| Vercel, Inc. | Application hosting — United States |
|---|---|
| Amazon Web Services, Inc. | Database hosting — United States |
| PlanetScale, Inc. | Database platform — United States |
| Upstash, Inc. | Scheduling of background scans — United States |
| Resend, Inc. | Delivery of email alerts — receives the alert addresses the Controller lists and the alert content |
| Railway Corporation | Hosting of LeakScout, the Processor’s in-house scanning service — receives only the Controller’s public storefront domain |
7International transfers
Personal data is stored in the United States, and the Processor operates from India. Where personal data of UK or EU data subjects is transferred outside the UK or EEA, such transfers are made under appropriate safeguards, including the Standard Contractual Clauses adopted by the European Commission and the UK International Data Transfer Addendum, which are incorporated into this DPA by reference.
8Personal data breach
The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s data, and will provide information reasonably available to help the Controller meet its own notification obligations.
9Data subject rights
The Processor will, taking into account the nature of the processing, assist the Controller by appropriate measures in fulfilling the Controller’s obligation to respond to requests from data subjects exercising their rights under Applicable Data Protection Law, and honours Shopify’s mandatory privacy webhooks. As the Processor stores no personal data about the Controller’s customers, a customer data request returns no records and a customer redaction request has nothing to delete; a store redaction request deletes all data associated with the store.
10Deletion & return
On expiry or termination of the Main Agreement, or on uninstall of the app, the Processor will delete the data associated with the Controller’s store within a reasonable period, unless applicable law requires storage. The store’s billing record (store domain and subscription facts, including when a free trial was started) is retained so that a free trial cannot be claimed twice; it contains no personal data beyond the store domain.
11Liability & governing law
Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Main Agreement. This DPA is governed by the same law as the Main Agreement under which the Controller uses LeakHunt.
12Acceptance
By installing or continuing to use LeakHunt, the Controller accepts this DPA. No signature is required for it to take effect; it is incorporated into the Main Agreement under which the Controller uses the app. A merchant that requires a counter-signed copy for its records may request one from the Processor.
LeakHunt is a product of WEBx47. This DPA works alongside the LeakHunt Privacy Policy.