← Back to ReviewMaster

ReviewMaster Data Processing Agreement

Last updated: 20 August 2026

This Data Processing Agreement (“DPA”) forms part of the ReviewMaster Terms of Service between:

Marka Modern Retail Private Limited, operator of ReviewMaster, established in India (“Processor”, “ReviewMaster”, “Marka”, “we”, “us”);

and

the Shopify merchant that installs or uses ReviewMaster (“Controller”, “Merchant”, “you”).

This DPA applies automatically where ReviewMaster processes Customer Personal Data on the Merchant’s behalf.

No separate signature is required unless Applicable Law requires otherwise.

1. Definitions

For this DPA:

2. Roles

For Customer Personal Data governed by this DPA:

The Merchant determines the purposes for which Customer Personal Data is processed through enabled ReviewMaster functionality.

ReviewMaster processes Customer Personal Data only:

Installing ReviewMaster, selecting settings, enabling integrations, activating communications, issuing instructions through the dashboard and otherwise using ReviewMaster constitute documented instructions.

If ReviewMaster is required by law to Process Customer Personal Data other than on the Merchant’s instructions, we will inform the Merchant before Processing unless Applicable Law prohibits that notice.

ReviewMaster will immediately inform the Merchant if, in our reasonable opinion, an instruction infringes Applicable Data Protection Law, unless prohibited from doing so.

3. Processing Details

The information required by Article 28(3) GDPR/UK GDPR is described below and in Annex 1.

3.1 Subject matter

Providing ReviewMaster’s product-review, review-request, moderation, display, verification, questions-and-answers, analytics, incentive and enabled review-integration functionality.

3.2 Duration

For the period during which ReviewMaster is installed and used, plus the limited deletion and backup periods described in this DPA.

3.3 Nature and purposes

Processing may include:

4. Merchant Obligations

The Merchant represents and warrants that:

  1. it has a valid lawful basis for the Processing it instructs;
  2. it has provided all privacy notices required by Applicable Data Protection Law;
  3. it has obtained consent wherever consent is legally required;
  4. it is legally entitled to disclose Customer Personal Data to ReviewMaster;
  5. its instructions comply with Applicable Data Protection Law;
  6. its use of review invitations, reminders and incentives complies with applicable privacy, consumer-protection and electronic-marketing laws;
  7. it will not instruct ReviewMaster to collect or use Personal Data that is unnecessary for ReviewMaster’s functions;
  8. it will not intentionally use ReviewMaster to solicit special-category/sensitive Personal Data unless the parties have expressly agreed appropriate safeguards beforehand.

The Merchant remains responsible for the accuracy, quality, legality and lawful acquisition of Customer Personal Data supplied to ReviewMaster.

The legal classification of a review invitation or reminder varies by jurisdiction and content. ReviewMaster does not warrant that such communications are universally transactional or exempt from marketing law.

5. ReviewMaster Processor Obligations

ReviewMaster will:

  1. process Customer Personal Data only on documented instructions, except where legally required otherwise;
  2. ensure persons authorized to Process Customer Personal Data are subject to confidentiality obligations;
  3. maintain appropriate technical and organizational security measures;
  4. engage Subprocessors only in accordance with Section 9;
  5. reasonably assist the Merchant with Data Subject requests;
  6. provide reasonable assistance with the Merchant’s security, breach-notification, data-protection impact assessment and prior-consultation obligations, taking into account the nature of Processing and information available to ReviewMaster;
  7. delete or return Customer Personal Data at the end of Processing as described in Section 11;
  8. provide information reasonably necessary to demonstrate compliance with applicable Article 28-type obligations;
  9. allow audits and inspections subject to the reasonable protections in Section 13.

6. Categories of Data Subjects

Customer Personal Data may relate to:

7. Categories of Personal Data

Depending on the Merchant’s configuration, Customer Personal Data may include:

Identity/contact

Transaction information

Review data

Media

Where media is uploaded to Shopify Files, Shopify stores the underlying media for the Merchant and ReviewMaster may retain related URLs or metadata.

Questions and answers

Incentives

Limited technical data

Where required for security, abuse-prevention or operational analytics:

Raw shopper IP addresses are not persistently stored. Where used for abuse prevention, an IP address may be transformed into a non-reversible or limited-purpose value, as described in the ReviewMaster Privacy Policy.

8. Special-Category and Sensitive Data

ReviewMaster does not intentionally request or solicit special-category Personal Data, including information concerning:

However, reviews, questions and uploaded media are user-generated content. A Data Subject may voluntarily include sensitive information.

The Merchant must not intentionally solicit unnecessary special-category or sensitive Personal Data through ReviewMaster.

If ReviewMaster becomes aware of such information, we may take reasonable steps to restrict or delete it where appropriate and legally permitted.

9. Subprocessors

The Merchant gives ReviewMaster general written authorization to engage Subprocessors.

The current Subprocessor List is maintained at:

https://reviewmaster-app.azurewebsites.net/subprocessors

That list forms part of this DPA.

ReviewMaster will ensure each Subprocessor that Processes Customer Personal Data is subject to written data-protection obligations that provide a level of protection appropriate to the Processing and materially consistent with ReviewMaster’s applicable obligations under this DPA.

ReviewMaster remains responsible for its Subprocessors to the extent required by Applicable Data Protection Law.

9.1 Changes to Subprocessors

ReviewMaster will provide at least 30 days’ prior notice of a new or replacement Subprocessor that will materially Process Customer Personal Data, unless an urgent change is reasonably required to address a security incident, legal requirement or service continuity issue.

The Merchant may object during the notice period on reasonable, documented data-protection grounds.

The Merchant may not object solely for commercial or competitive reasons.

If:

the Merchant’s sole remedy in relation to that Subprocessor change is to discontinue the affected functionality or terminate ReviewMaster without penalty for future subscription periods.

10. Data Subject Requests

Taking into account the nature of Processing, ReviewMaster will provide reasonable assistance to enable the Merchant to respond to Data Subject rights requests.

Where Shopify provides an applicable privacy webhook or other approved mechanism, ReviewMaster may use that mechanism to process the request.

If ReviewMaster receives a request directly from a Customer concerning Customer Personal Data Processed on behalf of a Merchant, ReviewMaster will ordinarily:

  1. identify the relevant Merchant where reasonably possible;
  2. inform the requester that the Merchant controls the relevant Processing;
  3. refer or forward the request to the Merchant where appropriate;
  4. avoid independently responding substantively except where instructed by the Merchant or required by law.

Nothing prevents ReviewMaster from acting directly where Marka independently acts as controller for a particular category of Personal Data.

11. Return, Export and Deletion

At the end of the Processing relationship, and subject to Applicable Law, ReviewMaster will at the Merchant’s choice delete or return Customer Personal Data.

Because Shopify uninstall may rapidly revoke ReviewMaster’s access to the store, the Merchant should use available export functionality or request an export before uninstalling where the Merchant wishes to retain a copy.

Where an export is reasonably available before termination, providing that export satisfies the “return” option.

Following termination/uninstall:

ReviewMaster may retain information where required by Applicable Law, provided that such retained information remains appropriately protected and is not used for unrelated purposes.

12. Customer Deletion and Anonymization

ReviewMaster will not assume that review text becomes anonymous merely because the reviewer’s name or email address has been removed.

Where a valid deletion/redaction instruction applies:

A review may be retained only where:

Marka may separately retain an applicable suppression record where Marka acts as controller and retention is necessary to ensure an opted-out address is not contacted again.

13. Audits and Demonstration of Compliance

On reasonable written request, ReviewMaster will make available information reasonably necessary to demonstrate compliance with applicable processor obligations.

ReviewMaster may satisfy audit-information requests initially through:

The Merchant may conduct an audit or appoint an independent auditor where reasonably necessary.

Except where a regulator, Personal Data Breach or credible material non-compliance reasonably requires otherwise:

The Merchant bears its own audit costs.

Where an audit imposes substantial assistance requirements beyond ReviewMaster’s ordinary compliance obligations, ReviewMaster may charge reasonable documented assistance costs unless the audit establishes ReviewMaster’s material breach of this DPA.

Nothing in this section limits a Supervisory Authority’s lawful powers.

14. Security

ReviewMaster maintains technical and organizational measures designed to provide a level of security appropriate to the risk.

Measures are described in Annex 2 and may be updated where:

ReviewMaster will not materially reduce the overall security of Customer Personal Data during the term without reasonable justification.

15. Personal Data Breach

ReviewMaster will notify the Merchant without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

We will provide information reasonably available to us, which may include:

Where all information is not immediately available, ReviewMaster may provide information in phases rather than delaying the initial notice.

The Merchant remains responsible for determining whether it must notify:

except where ReviewMaster independently has such an obligation.

ReviewMaster maintains a separate incident-response obligation to notify Shopify of qualifying actual or suspected compromise of Shopify Merchant Data within Shopify’s required timeframe.

16. International Transfers

Marka is established in India and ReviewMaster may use infrastructure or Subprocessors located outside the country in which Customer Personal Data originated.

Current locations and providers are identified in the Subprocessor List.

Where Customer Personal Data protected by EEA transfer restrictions is transferred to a recipient in a country requiring a Chapter V GDPR safeguard, the parties agree to use the applicable transfer mechanism described below.

17. European Economic Area Transfers

Where:

the European Commission Standard Contractual Clauses adopted by Decision (EU) 2021/914 are incorporated by reference.

For the Merchant-to-ReviewMaster relationship, unless another module is legally more appropriate:

Module Two — Controller to Processor applies.

For ReviewMaster-to-Subprocessor transfers requiring SCCs, the applicable processor-to-processor mechanism, including Module Three, may be used between ReviewMaster and the relevant Subprocessor.

For Module Two between Merchant and ReviewMaster:

Where additional selections, party details or annex fields are legally required, those required details are deemed completed using the parties’ current account/contact information and the processing information contained in this DPA, to the maximum extent legally permitted.

If that deeming mechanism is insufficient under Applicable Law, the parties will reasonably cooperate to execute the necessary SCC completion page or schedule.

The SCCs prevail over this DPA to the extent of conflict.

18. United Kingdom Transfers

Where UK GDPR international-transfer restrictions apply and the transfer requires an appropriate safeguard, the parties incorporate the legally applicable version of the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, or a successor mechanism recognized by the UK Information Commissioner’s Office.

The information in this DPA and its Annexes will populate the Addendum tables to the maximum extent legally permitted.

Mandatory clauses of the applicable UK transfer instrument prevail in the event of conflict.

19. Switzerland and Other Jurisdictions

Where Swiss data-protection law applies to a transfer, the SCCs will be interpreted and adapted to the extent legally required to cover Swiss law, including references to competent Swiss authorities where necessary.

For other countries requiring international-transfer safeguards, the parties will use the mechanism required by Applicable Law.

20. Government Requests

Where legally permitted, ReviewMaster will notify the Merchant if ReviewMaster receives a binding governmental demand specifically seeking Customer Personal Data Processed on the Merchant’s behalf.

ReviewMaster may challenge or narrow a request where we reasonably believe there are lawful grounds to do so.

We will disclose only information reasonably required by the legally binding request.

21. Data Protection Impact Assessments

Taking into account the nature of Processing and information available to ReviewMaster, we will provide reasonable assistance requested by the Merchant in relation to:

ReviewMaster may charge reasonable fees for substantial assistance that is specific to the Merchant and materially exceeds ordinary support, unless the assistance is required because of ReviewMaster’s breach of this DPA.

22. Controller Processing by Marka

This DPA does not govern processing for which Marka independently acts as controller.

Examples may include:

Such Processing is governed by the ReviewMaster Privacy Policy and Applicable Data Protection Law.

23. India Data Protection

ReviewMaster complies with applicable Indian privacy, cybersecurity and data-protection requirements.

References to the Digital Personal Data Protection Act, 2023and related rules apply only to the extent and from the dates the relevant provisions are legally in force and applicable to ReviewMaster’s Processing.

Nothing in this DPA represents that provisions not yet commenced have already become legally operative.

24. Liability

Liability between the parties arising under this DPA is subject to the limitations and exclusions in the ReviewMaster Terms of Service, except to the extent Applicable Data Protection Law, the SCCs, UK Addendum or another mandatory transfer instrument prohibits such limitation.

25. Priority

If there is a conflict:

  1. mandatory Applicable Data Protection Law applies;
  2. applicable SCCs, UK Addendum or other mandatory transfer instrument applies;
  3. this DPA applies;
  4. the Terms of Service apply.

26. Term and Termination

This DPA begins when ReviewMaster first Processes Customer Personal Data on behalf of the Merchant.

It continues until ReviewMaster no longer Processes Customer Personal Data on the Merchant’s behalf, except provisions that must survive to protect retained Personal Data.

ANNEX 1 — DETAILS OF PROCESSING

A. Parties

Data exporter
The Shopify Merchant using ReviewMaster.
Role: Controller or party acting on behalf of the applicable Controller.
Contact: Merchant contact details held in Shopify/ReviewMaster account records.

Data importer
Marka Modern Retail Private Limited
Operator of ReviewMaster
1st Floor, Plot 558 P, Sector 27, Gurugram (Gurgaon), Haryana 122009, India
Email: tech@houseofmarka.com
Role: Processor.

B. Categories of Data Subjects

C. Categories of Personal Data

D. Sensitive Data

Sensitive or special-category data is not intentionally requested.

Because review content and media are user-generated, a Data Subject may voluntarily submit sensitive information.

The Merchant must avoid intentionally soliciting unnecessary sensitive information.

E. Frequency

Processing occurs on a continuous or event-driven basis while ReviewMaster is installed and enabled.

F. Nature of Processing

G. Purposes

Providing the ReviewMaster services configured by the Merchant.

H. Retention

As stated in Section 11 and the ReviewMaster Privacy Policy.

Residual backup copies are deleted or overwritten within no more than 35 days after applicable production deletion, unless legally required otherwise.

I. Subprocessors

Current Subprocessors and processing locations are maintained at:

https://reviewmaster-app.azurewebsites.net/subprocessors

ANNEX 2 — TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES

ReviewMaster maintains security measures appropriate to the nature, scope and risk of the Processing.

These may include:

1. Transport Security

2. Credential Protection

3. Logical Tenant Separation

4. Access Control

5. Data Minimization

ReviewMaster seeks to request and retain only Shopify information reasonably necessary for ReviewMaster functionality.

6. Media Controls

Where review media is uploaded to Shopify Files:

7. Abuse Prevention

Controls may include:

8. Backup Security

Backups are protected from ordinary public access.

Following production deletion, residual encrypted backups containing affected Customer Personal Data are automatically deleted or overwritten within no more than 35 days, unless Applicable Law requires otherwise.

9. Incident Response

ReviewMaster maintains procedures to:

security incidents and Personal Data Breaches.

10. Software and Infrastructure Maintenance

ReviewMaster uses reasonable processes appropriate to the size and risk of the service for: