ReviewMaster Data Processing Agreement
Last updated: 20 August 2026
This Data Processing Agreement (“DPA”) forms part of the ReviewMaster Terms of Service between:
Marka Modern Retail Private Limited, operator of ReviewMaster, established in India (“Processor”, “ReviewMaster”, “Marka”, “we”, “us”);
and
the Shopify merchant that installs or uses ReviewMaster (“Controller”, “Merchant”, “you”).
This DPA applies automatically where ReviewMaster processes Customer Personal Data on the Merchant’s behalf.
No separate signature is required unless Applicable Law requires otherwise.
1. Definitions
For this DPA:
- Applicable Data Protection Law means privacy and data-protection law applicable to the Processing, including where applicable the EU GDPR, UK GDPR and laws implementing or supplementing them.
- Controller, Processor, Data Subject, Personal Data, Processing, Personal Data Breach, and Supervisory Authority have the meanings given under Applicable Data Protection Law.
- Customer Personal Data means Personal Data processed by ReviewMaster on behalf of the Merchant through ReviewMaster.
- Subprocessor means a third party engaged by ReviewMaster to Process Customer Personal Data on behalf of the Merchant.
- SCCs means the European Commission Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, as amended or replaced.
- UK Addendum means the then-current legally recognized UK addendum applicable to the EU SCCs or any successor mechanism.
2. Roles
For Customer Personal Data governed by this DPA:
- the Merchant is the Controller or acts on behalf of the relevant Controller;
- ReviewMaster is the Processor.
The Merchant determines the purposes for which Customer Personal Data is processed through enabled ReviewMaster functionality.
ReviewMaster processes Customer Personal Data only:
- on documented instructions from the Merchant;
- as necessary to provide ReviewMaster;
- as required by Applicable Law.
Installing ReviewMaster, selecting settings, enabling integrations, activating communications, issuing instructions through the dashboard and otherwise using ReviewMaster constitute documented instructions.
If ReviewMaster is required by law to Process Customer Personal Data other than on the Merchant’s instructions, we will inform the Merchant before Processing unless Applicable Law prohibits that notice.
ReviewMaster will immediately inform the Merchant if, in our reasonable opinion, an instruction infringes Applicable Data Protection Law, unless prohibited from doing so.
3. Processing Details
The information required by Article 28(3) GDPR/UK GDPR is described below and in Annex 1.
3.1 Subject matter
Providing ReviewMaster’s product-review, review-request, moderation, display, verification, questions-and-answers, analytics, incentive and enabled review-integration functionality.
3.2 Duration
For the period during which ReviewMaster is installed and used, plus the limited deletion and backup periods described in this DPA.
3.3 Nature and purposes
Processing may include:
- receiving eligible Shopify order information;
- creating review invitations;
- sending initial invitations and follow-up reminders configured by the Merchant;
- associating submitted reviews with eligible purchases;
- determining verified-purchase status;
- storing review information;
- displaying published reviews;
- receiving questions;
- transmitting answers;
- facilitating incentives configured by the Merchant;
- preventing duplicate or abusive submissions;
- calculating review analytics;
- sending Merchant notifications;
- transmitting eligible reviews to integrations enabled by the Merchant;
- providing support;
- performing security and reliability operations.
4. Merchant Obligations
The Merchant represents and warrants that:
- it has a valid lawful basis for the Processing it instructs;
- it has provided all privacy notices required by Applicable Data Protection Law;
- it has obtained consent wherever consent is legally required;
- it is legally entitled to disclose Customer Personal Data to ReviewMaster;
- its instructions comply with Applicable Data Protection Law;
- its use of review invitations, reminders and incentives complies with applicable privacy, consumer-protection and electronic-marketing laws;
- it will not instruct ReviewMaster to collect or use Personal Data that is unnecessary for ReviewMaster’s functions;
- it will not intentionally use ReviewMaster to solicit special-category/sensitive Personal Data unless the parties have expressly agreed appropriate safeguards beforehand.
The Merchant remains responsible for the accuracy, quality, legality and lawful acquisition of Customer Personal Data supplied to ReviewMaster.
The legal classification of a review invitation or reminder varies by jurisdiction and content. ReviewMaster does not warrant that such communications are universally transactional or exempt from marketing law.
5. ReviewMaster Processor Obligations
ReviewMaster will:
- process Customer Personal Data only on documented instructions, except where legally required otherwise;
- ensure persons authorized to Process Customer Personal Data are subject to confidentiality obligations;
- maintain appropriate technical and organizational security measures;
- engage Subprocessors only in accordance with Section 9;
- reasonably assist the Merchant with Data Subject requests;
- provide reasonable assistance with the Merchant’s security, breach-notification, data-protection impact assessment and prior-consultation obligations, taking into account the nature of Processing and information available to ReviewMaster;
- delete or return Customer Personal Data at the end of Processing as described in Section 11;
- provide information reasonably necessary to demonstrate compliance with applicable Article 28-type obligations;
- allow audits and inspections subject to the reasonable protections in Section 13.
6. Categories of Data Subjects
Customer Personal Data may relate to:
- customers who purchased products from the Merchant;
- persons invited to submit reviews;
- persons who submit reviews;
- storefront visitors who submit questions;
- storefront visitors interacting with review functionality;
- persons whose information appears in user-generated review content.
7. Categories of Personal Data
Depending on the Merchant’s configuration, Customer Personal Data may include:
Identity/contact
- customer/reviewer name;
- display name;
- email address;
- optional reviewer-supplied or Merchant-supplied location.
Transaction information
- Shopify order identifier;
- order number;
- fulfillment status;
- purchased product information;
- information necessary to verify an eligible purchase.
Review data
- rating;
- title;
- review text;
- submission date;
- verification status;
- incentive status;
- review source;
- Merchant reply.
Media
- customer-submitted photographs or videos;
- associated URLs and metadata.
Where media is uploaded to Shopify Files, Shopify stores the underlying media for the Merchant and ReviewMaster may retain related URLs or metadata.
Questions and answers
- questioner’s name;
- email where provided;
- question;
- Merchant answer;
- product association.
Incentives
- customer email;
- discount-code identifier;
- issuance status;
- expiry information.
Limited technical data
Where required for security, abuse-prevention or operational analytics:
- IP address or limited representation of an IP address;
- browser user-agent;
- timestamp;
- request/event metadata.
Raw shopper IP addresses are not persistently stored. Where used for abuse prevention, an IP address may be transformed into a non-reversible or limited-purpose value, as described in the ReviewMaster Privacy Policy.
8. Special-Category and Sensitive Data
ReviewMaster does not intentionally request or solicit special-category Personal Data, including information concerning:
- health;
- ethnicity or race;
- political opinions;
- religious or philosophical beliefs;
- trade-union membership;
- genetics;
- biometrics used for unique identification;
- sex life;
- sexual orientation.
However, reviews, questions and uploaded media are user-generated content. A Data Subject may voluntarily include sensitive information.
The Merchant must not intentionally solicit unnecessary special-category or sensitive Personal Data through ReviewMaster.
If ReviewMaster becomes aware of such information, we may take reasonable steps to restrict or delete it where appropriate and legally permitted.
9. Subprocessors
The Merchant gives ReviewMaster general written authorization to engage Subprocessors.
The current Subprocessor List is maintained at:
https://reviewmaster-app.azurewebsites.net/subprocessors
That list forms part of this DPA.
ReviewMaster will ensure each Subprocessor that Processes Customer Personal Data is subject to written data-protection obligations that provide a level of protection appropriate to the Processing and materially consistent with ReviewMaster’s applicable obligations under this DPA.
ReviewMaster remains responsible for its Subprocessors to the extent required by Applicable Data Protection Law.
9.1 Changes to Subprocessors
ReviewMaster will provide at least 30 days’ prior notice of a new or replacement Subprocessor that will materially Process Customer Personal Data, unless an urgent change is reasonably required to address a security incident, legal requirement or service continuity issue.
The Merchant may object during the notice period on reasonable, documented data-protection grounds.
The Merchant may not object solely for commercial or competitive reasons.
If:
- the objection is reasonable;
- the parties cannot resolve it;
- ReviewMaster cannot reasonably provide the relevant functionality without the Subprocessor,
the Merchant’s sole remedy in relation to that Subprocessor change is to discontinue the affected functionality or terminate ReviewMaster without penalty for future subscription periods.
10. Data Subject Requests
Taking into account the nature of Processing, ReviewMaster will provide reasonable assistance to enable the Merchant to respond to Data Subject rights requests.
Where Shopify provides an applicable privacy webhook or other approved mechanism, ReviewMaster may use that mechanism to process the request.
If ReviewMaster receives a request directly from a Customer concerning Customer Personal Data Processed on behalf of a Merchant, ReviewMaster will ordinarily:
- identify the relevant Merchant where reasonably possible;
- inform the requester that the Merchant controls the relevant Processing;
- refer or forward the request to the Merchant where appropriate;
- avoid independently responding substantively except where instructed by the Merchant or required by law.
Nothing prevents ReviewMaster from acting directly where Marka independently acts as controller for a particular category of Personal Data.
11. Return, Export and Deletion
At the end of the Processing relationship, and subject to Applicable Law, ReviewMaster will at the Merchant’s choice delete or return Customer Personal Data.
Because Shopify uninstall may rapidly revoke ReviewMaster’s access to the store, the Merchant should use available export functionality or request an export before uninstalling where the Merchant wishes to retain a copy.
Where an export is reasonably available before termination, providing that export satisfies the “return” option.
Following termination/uninstall:
- credentials permitting access to the Merchant store will be deleted, revoked or rendered unusable;
- Customer Personal Data in ReviewMaster’s active systems will be deleted in accordance with Shopify requirements and Applicable Law;
- originals, copies and reproductions of Shopify Merchant Data will be deleted within the period required by Shopify, and in any event ordinarily substantially earlier through the applicable redaction flow;
- residual copies contained solely in encrypted backups will be placed beyond active use and automatically deleted or overwritten within no more than 35 days after the relevant production deletion.
ReviewMaster may retain information where required by Applicable Law, provided that such retained information remains appropriately protected and is not used for unrelated purposes.
12. Customer Deletion and Anonymization
ReviewMaster will not assume that review text becomes anonymous merely because the reviewer’s name or email address has been removed.
Where a valid deletion/redaction instruction applies:
- direct identifiers will be deleted or anonymized;
- associated requests, incentive information and applicable Customer records will be deleted where required;
- free-text content, media or other fields that independently identify the Customer will also be deleted or irreversibly anonymized where required by Applicable Data Protection Law and the Merchant’s lawful instructions.
A review may be retained only where:
- the Merchant lawfully instructs retention;
- the content has been genuinely and irreversibly anonymized; or
- Applicable Law independently permits or requires retention.
Marka may separately retain an applicable suppression record where Marka acts as controller and retention is necessary to ensure an opted-out address is not contacted again.
13. Audits and Demonstration of Compliance
On reasonable written request, ReviewMaster will make available information reasonably necessary to demonstrate compliance with applicable processor obligations.
ReviewMaster may satisfy audit-information requests initially through:
- security documentation;
- questionnaires;
- applicable policies;
- available certifications;
- independent reports;
- written descriptions of safeguards.
The Merchant may conduct an audit or appoint an independent auditor where reasonably necessary.
Except where a regulator, Personal Data Breach or credible material non-compliance reasonably requires otherwise:
- audits may occur no more than once in any 12-month period;
- at least 30 days’ written notice must be provided;
- audits must occur during normal business hours;
- the audit must not unreasonably interfere with ReviewMaster operations;
- the auditor must not be a direct competitor of ReviewMaster;
- the auditor must sign reasonable confidentiality obligations;
- the audit must not access another Merchant’s data;
- ReviewMaster may restrict access to information that would create material security risk.
The Merchant bears its own audit costs.
Where an audit imposes substantial assistance requirements beyond ReviewMaster’s ordinary compliance obligations, ReviewMaster may charge reasonable documented assistance costs unless the audit establishes ReviewMaster’s material breach of this DPA.
Nothing in this section limits a Supervisory Authority’s lawful powers.
14. Security
ReviewMaster maintains technical and organizational measures designed to provide a level of security appropriate to the risk.
Measures are described in Annex 2 and may be updated where:
- security improves;
- technology changes;
- equivalent or better safeguards are adopted.
ReviewMaster will not materially reduce the overall security of Customer Personal Data during the term without reasonable justification.
15. Personal Data Breach
ReviewMaster will notify the Merchant without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
We will provide information reasonably available to us, which may include:
- nature of the breach;
- affected categories of Data Subjects;
- affected categories of Personal Data;
- approximate volume where known;
- likely consequences;
- measures taken or proposed;
- contact information for follow-up.
Where all information is not immediately available, ReviewMaster may provide information in phases rather than delaying the initial notice.
The Merchant remains responsible for determining whether it must notify:
- Data Subjects;
- Supervisory Authorities;
- customers;
- other regulators,
except where ReviewMaster independently has such an obligation.
ReviewMaster maintains a separate incident-response obligation to notify Shopify of qualifying actual or suspected compromise of Shopify Merchant Data within Shopify’s required timeframe.
16. International Transfers
Marka is established in India and ReviewMaster may use infrastructure or Subprocessors located outside the country in which Customer Personal Data originated.
Current locations and providers are identified in the Subprocessor List.
Where Customer Personal Data protected by EEA transfer restrictions is transferred to a recipient in a country requiring a Chapter V GDPR safeguard, the parties agree to use the applicable transfer mechanism described below.
17. European Economic Area Transfers
Where:
- the Merchant exports Personal Data protected by the EU GDPR;
- ReviewMaster is the data importer;
- the transfer requires an Article 46 GDPR safeguard,
the European Commission Standard Contractual Clauses adopted by Decision (EU) 2021/914 are incorporated by reference.
For the Merchant-to-ReviewMaster relationship, unless another module is legally more appropriate:
Module Two — Controller to Processor applies.
For ReviewMaster-to-Subprocessor transfers requiring SCCs, the applicable processor-to-processor mechanism, including Module Three, may be used between ReviewMaster and the relevant Subprocessor.
For Module Two between Merchant and ReviewMaster:
- the Merchant is the data exporter;
- ReviewMaster is the data importer;
- Annex 1 of this DPA supplies the processing description to the extent sufficient;
- Annex 2 supplies technical and organizational measures;
- the optional docking clause applies where lawful and useful;
- the parties choose the law and Supervisory Authority selections required by the SCCs based on the data exporter’s circumstances and applicable SCC rules.
Where additional selections, party details or annex fields are legally required, those required details are deemed completed using the parties’ current account/contact information and the processing information contained in this DPA, to the maximum extent legally permitted.
If that deeming mechanism is insufficient under Applicable Law, the parties will reasonably cooperate to execute the necessary SCC completion page or schedule.
The SCCs prevail over this DPA to the extent of conflict.
18. United Kingdom Transfers
Where UK GDPR international-transfer restrictions apply and the transfer requires an appropriate safeguard, the parties incorporate the legally applicable version of the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, or a successor mechanism recognized by the UK Information Commissioner’s Office.
The information in this DPA and its Annexes will populate the Addendum tables to the maximum extent legally permitted.
Mandatory clauses of the applicable UK transfer instrument prevail in the event of conflict.
19. Switzerland and Other Jurisdictions
Where Swiss data-protection law applies to a transfer, the SCCs will be interpreted and adapted to the extent legally required to cover Swiss law, including references to competent Swiss authorities where necessary.
For other countries requiring international-transfer safeguards, the parties will use the mechanism required by Applicable Law.
20. Government Requests
Where legally permitted, ReviewMaster will notify the Merchant if ReviewMaster receives a binding governmental demand specifically seeking Customer Personal Data Processed on the Merchant’s behalf.
ReviewMaster may challenge or narrow a request where we reasonably believe there are lawful grounds to do so.
We will disclose only information reasonably required by the legally binding request.
21. Data Protection Impact Assessments
Taking into account the nature of Processing and information available to ReviewMaster, we will provide reasonable assistance requested by the Merchant in relation to:
- data-protection impact assessments;
- prior consultation with a Supervisory Authority.
ReviewMaster may charge reasonable fees for substantial assistance that is specific to the Merchant and materially exceeds ordinary support, unless the assistance is required because of ReviewMaster’s breach of this DPA.
22. Controller Processing by Marka
This DPA does not govern processing for which Marka independently acts as controller.
Examples may include:
- Merchant business account records;
- security records maintained for Marka’s own systems;
- legal/compliance records;
- platform-wide email suppression records.
Such Processing is governed by the ReviewMaster Privacy Policy and Applicable Data Protection Law.
23. India Data Protection
ReviewMaster complies with applicable Indian privacy, cybersecurity and data-protection requirements.
References to the Digital Personal Data Protection Act, 2023and related rules apply only to the extent and from the dates the relevant provisions are legally in force and applicable to ReviewMaster’s Processing.
Nothing in this DPA represents that provisions not yet commenced have already become legally operative.
24. Liability
Liability between the parties arising under this DPA is subject to the limitations and exclusions in the ReviewMaster Terms of Service, except to the extent Applicable Data Protection Law, the SCCs, UK Addendum or another mandatory transfer instrument prohibits such limitation.
25. Priority
If there is a conflict:
- mandatory Applicable Data Protection Law applies;
- applicable SCCs, UK Addendum or other mandatory transfer instrument applies;
- this DPA applies;
- the Terms of Service apply.
26. Term and Termination
This DPA begins when ReviewMaster first Processes Customer Personal Data on behalf of the Merchant.
It continues until ReviewMaster no longer Processes Customer Personal Data on the Merchant’s behalf, except provisions that must survive to protect retained Personal Data.
ANNEX 1 — DETAILS OF PROCESSING
A. Parties
Data exporter
The Shopify Merchant using ReviewMaster.
Role: Controller or party acting on behalf of the applicable Controller.
Contact: Merchant contact details held in Shopify/ReviewMaster account records.
Data importer
Marka Modern Retail Private Limited
Operator of ReviewMaster
1st Floor, Plot 558 P, Sector 27, Gurugram (Gurgaon), Haryana 122009, India
Email: tech@houseofmarka.com
Role: Processor.
B. Categories of Data Subjects
- Merchant customers;
- purchasers;
- reviewers;
- product-question submitters;
- storefront visitors interacting with review functionality;
- persons appearing in user-generated content.
C. Categories of Personal Data
- name;
- email address;
- order identifier;
- order number;
- purchased-product information;
- review content;
- rating;
- review title;
- review date;
- verification status;
- incentive status;
- optional reviewer location;
- questions and answers;
- review photos/videos;
- review media URLs;
- limited technical/security identifiers;
- related operational metadata.
D. Sensitive Data
Sensitive or special-category data is not intentionally requested.
Because review content and media are user-generated, a Data Subject may voluntarily submit sensitive information.
The Merchant must avoid intentionally soliciting unnecessary sensitive information.
E. Frequency
Processing occurs on a continuous or event-driven basis while ReviewMaster is installed and enabled.
F. Nature of Processing
- collection;
- receipt;
- organization;
- structuring;
- storage;
- retrieval;
- consultation;
- display;
- transmission;
- publishing;
- syndication;
- restriction;
- anonymization;
- deletion.
G. Purposes
Providing the ReviewMaster services configured by the Merchant.
H. Retention
As stated in Section 11 and the ReviewMaster Privacy Policy.
Residual backup copies are deleted or overwritten within no more than 35 days after applicable production deletion, unless legally required otherwise.
I. Subprocessors
Current Subprocessors and processing locations are maintained at:
https://reviewmaster-app.azurewebsites.net/subprocessors
ANNEX 2 — TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES
ReviewMaster maintains security measures appropriate to the nature, scope and risk of the Processing.
These may include:
1. Transport Security
- HTTPS for external web traffic;
- TLS-protected database and service connections where supported.
2. Credential Protection
- Shopify access credentials are not intentionally exposed to storefront visitors;
- sensitive credentials are encrypted or otherwise protected at rest;
- secrets are maintained outside publicly accessible application code.
3. Logical Tenant Separation
- Merchant records are associated with an individual store;
- application authorization checks restrict Merchant access;
- queries and service operations are scoped to the applicable Merchant.
4. Access Control
- production access limited to authorized personnel;
- access based on job function and operational need;
- confidentiality obligations for authorized personnel.
5. Data Minimization
ReviewMaster seeks to request and retain only Shopify information reasonably necessary for ReviewMaster functionality.
6. Media Controls
Where review media is uploaded to Shopify Files:
- file types may be validated;
- potentially unsafe file formats may be restricted;
- file size and type controls may be applied.
7. Abuse Prevention
Controls may include:
- rate limiting;
- duplicate prevention;
- validation;
- security logging;
- IP-based or cryptographic abuse controls;
- input validation.
8. Backup Security
Backups are protected from ordinary public access.
Following production deletion, residual encrypted backups containing affected Customer Personal Data are automatically deleted or overwritten within no more than 35 days, unless Applicable Law requires otherwise.
9. Incident Response
ReviewMaster maintains procedures to:
- identify;
- investigate;
- contain;
- remediate;
- document;
security incidents and Personal Data Breaches.
10. Software and Infrastructure Maintenance
ReviewMaster uses reasonable processes appropriate to the size and risk of the service for:
- updates;
- dependency maintenance;
- vulnerability remediation;
- environment configuration;
- operational monitoring.