Legal
Data processing addendum
1. Roles and scope
For Customer Data — personal data of visitors, sign-ups and buyers that the Customer's campaigns, pages and snippet report to Shopmycode — the Customer is the controller (data fiduciary) and TTL Media Private Limited ("Processor") is the processor. For its own account holders and for the counted open of a link, Shopmycode is an independent controller as described in the Privacy policy; that data is outside this addendum.
2. Details of the processing
| Subject matter | Running the Customer's referral and affiliate campaigns on Shopmycode |
|---|---|
| Duration | For as long as the Customer has an account, plus the deletion period in §9 |
| Nature and purpose | Counting opens, page presence and results; attributing them to links and marketers; showing live numbers and journeys; calculating and settling rewards; fraud prevention |
| Data subjects | Visitors to the Customer's links and pages; people who sign up or buy through them |
| Categories of data | Time of open, country/region/city, device family, browser, language, referrer, campaign tag, visitor and device ids (where allowed), keyed IP hash, page path and title on the Customer's site, time on page, goal name and page address, and any user id the Customer chooses to send. No special-category data is expected; the Customer must not send any. |
3. Customer's instructions and responsibilities
- The Terms, this addendum and the Customer's settings in the app are the complete instructions. Additional instructions may be agreed in writing.
- The Customer warrants it has a lawful basis for the processing, gives visitors the notices its law requires — including describing the Shopmycode snippet and identifiers in its own privacy and cookie notices — and obtains consent where its law requires consent before identifiers are set.
- The Customer sends only the data the service needs and never sends passwords, payment card numbers, government ids or special-category data through the snippet or API.
4. Processor's obligations
- Process Customer Data only on the Customer's documented instructions, and tell the Customer if an instruction appears to break the law.
- Keep it confidential; staff with access are bound by confidentiality and trained.
- Apply the security measures in §7.
- Help the Customer answer data-subject requests (access, deletion, correction, portability, objection): the app provides visitor journeys and deletion per visitor id, and the Processor will act on a written request within 10 business days.
- Help with data-protection impact assessments and consultations with authorities, on request, with the information the Processor holds.
- Delete or return Customer Data at the end of the service (§9).
- Make available the information needed to demonstrate compliance and allow audits (§8).
5. Sub-processors
The Customer authorises the sub-processors listed in the Privacy policy §5 (currently Amazon Web Services in Mumbai for hosting and email; PayU and Easebuzz for payments; Meta (WhatsApp) for sign-in codes by phone; Apify and Google for profile look-ups a user requests). The Processor flows down equivalent data-protection obligations to each and remains liable for them. Changes are announced on that page and by email to the brand's primary admin at least 30 days in advance; the Customer may object on reasonable data-protection grounds within that period, in which case the parties will look for a solution and, failing one, the Customer may end the affected service without penalty.
6. International transfers
Customer Data is stored in India. Where the Customer or its data subjects are in the EU/EEA, the UK or Switzerland, transfers to the Processor are made under the EU Standard Contractual Clauses (Module 2, controller to processor), the UK International Data Transfer Addendum and the Swiss amendments, which are incorporated into this addendum by reference and provided in full on request. The limited-tracking path for visitors from those regions (no identifiers, no device characteristics) is the Processor's supplementary measure.
7. Security measures
- Encryption in transit (TLS) on every domain; encrypted volumes and daily encrypted backups at rest.
- No passwords: one-time codes, hashed, expiring in 10 minutes; tokens revocable at any time.
- IP addresses replaced by a keyed one-way hash before storage; network credentials encrypted with a key held outside the database.
- Per-tenant access control: a brand sees only its campaigns; a marketer only their links; a member only the links held by them.
- Rate limits, bot detection and abuse controls on public endpoints; audited admin actions.
- Automatic deletion of raw event data after 13 months.
- Production access restricted to named staff, over SSH keys or AWS Session Manager, logged.
8. Audits
Once a year, or after a security incident, the Customer may request a written description of the Processor's controls and the results of any recent independent review. If that is not enough to satisfy a legal duty, the Customer may audit on 30 days' notice, during business hours, under confidentiality, at its own cost, without disrupting the service.
9. Deletion and return
When a brand account closes, the Customer may export its campaign data from the app beforehand. Customer Data is deleted within 30 days of closure, except what must be kept for settlement, tax and accounting (8 years, kept only for that purpose) and raw events already within their 13-month expiry.
10. Personal-data breaches
The Processor notifies the Customer's primary admin without undue delay, and in any case within 48 hours of becoming aware of a breach affecting Customer Data, with what is known at the time, and keeps the Customer informed so it can meet its own 72-hour (GDPR/UK) and DPDP notification duties.
11. California (CCPA/CPRA) service-provider terms
The Processor is a service provider. It will not sell or share Customer Data, retain, use or disclose it for any purpose other than the business purposes in this addendum or outside the direct business relationship with the Customer, or combine it with personal data from other sources except as the CPRA permits. The Processor will notify the Customer if it can no longer meet these obligations; the Customer may then stop and remedy unauthorised use. The Processor certifies that it understands these restrictions.
12. India (DPDP Act) processor terms
The Processor processes Customer Data only under this contract, implements the security safeguards above, notifies the Customer of breaches as in §10, and deletes the data as in §9 unless retention is required by law. The Customer, as data fiduciary, remains responsible for notices, consent and grievance handling towards its data principals; the Processor assists as in §4.
13. Liability and precedence
Liability under this addendum is subject to the limitations in the Terms of service. If this addendum conflicts with the Terms, the addendum prevails for data protection; if the Standard Contractual Clauses conflict with either, the Clauses prevail.