Legal

Data Processing Agreement

Last updated: October 2026

This Data Processing Agreement ("DPA") forms part of the Terms & Conditions between Revebe Digital Private Limited ("Revebe", "we", "us") and the merchant who installs any of our applications ("Merchant", "you"). It applies whenever we process personal data on your behalf. Where this DPA and the Terms conflict, this DPA governs for matters of personal data.

1. Roles of the Parties

For personal data relating to your customers and to visitors to your store, you are the controller and Revebe is the processor. You decide why and how that data is processed; we process it only to provide the application you installed. Where we process data about you — your account, your billing record — we act as controller, and our Privacy Policy governs that.

2. Processing on Your Instructions

We process personal data only on your documented instructions. Installing an application, and the settings you choose inside it, are your instructions. We do not sell personal data, and we do not use it to train models, to build profiles, or for any purpose of our own. If we are required by law to process data beyond your instructions, we will tell you before doing so unless that law forbids it.

3. What Each Application Processes

The data each application touches is limited to what it needs to work.

4. Confidentiality

Everyone we allow near personal data is bound to keep it confidential, and access is limited to the people who need it to run or support the service.

5. Security

We take appropriate technical and organisational measures, including: all data in transit protected with TLS; access to production systems restricted to named administrators using key-based authentication; application credentials and access tokens held server-side and never exposed to the browser; each merchant's data separated by store; and sensitive fields encrypted in the database where an application stores them. These measures are reviewed as the applications change.

6. Sub-processors

You give general authorisation for us to engage sub-processors. We impose data protection obligations on each one no less protective than those in this DPA, and we remain responsible for their performance. Our sub-processors are:

The advertising platforms a product feed is published to — Google, Meta, TikTok, Pinterest and Snapchat — are not our sub-processors. You choose them, you hold the account, and each processes the data under its own terms as a separate controller. We will give you reasonable notice of any new sub-processor, and you may object on reasonable data protection grounds, in which case you may stop using the affected application and we will refund any unused prepaid fees.

7. Helping You Meet Your Obligations

We will assist you, so far as is reasonable, with data subject requests, with data protection impact assessments, and with consultations with a supervisory authority. We support Shopify's mandatory compliance webhooks: when Shopify sends a customer data request, a customer redaction request or a shop redaction request on your behalf, we answer it. Requests may also be sent to support@revebe.com.

8. Personal Data Breaches

If we become aware of a personal data breach affecting data we process for you, we will notify you without undue delay and in any event within 72 hours, with the nature of the breach, the categories and approximate volume of data involved, the likely consequences, and the measures taken or proposed.

9. Retention, Deletion and Return

We keep personal data only as long as the application needs it. Retention periods for each application are set out in our Privacy Policy. When you uninstall an application, Shopify sends a shop redaction request 48 hours later and we delete that store's data on receiving it. You may ask for an export of the data we hold for you at any time before then, or through our Data Deletion Policy.

10. Audit

On reasonable written request, and no more than once a year unless a supervisory authority requires otherwise, we will provide the information needed to show that we meet this DPA. Where an on-site audit is necessary, it will be at a mutually agreed time, subject to confidentiality, and at your cost.

11. International Transfers

Our servers are in Germany. Where personal data is transferred outside the jurisdiction in which it was collected, we rely on an appropriate transfer mechanism, including the European Commission's Standard Contractual Clauses where they apply, which are incorporated into this DPA by reference.

12. Term

This DPA takes effect when you install an application and continues for as long as we process personal data for you. The sections on confidentiality, security and deletion survive its end.

13. Contact

Revebe Digital Private Limited
18, Umar Commercial, Bahria Town, Lahore, Punjab 53720, Pakistan
Email: support@revebe.com
Phone: +92 328 3281111 · +92 328 3282222
Website: https://revebe.com