SpecDesk Data Processing Addendum

Version: 2026-09-27-v1 · Effective: 27 September 2026

This Data Processing Addendum (DPA) forms part of the SpecDesk Terms of Service. Rexcode Digital Ltd acts as processor and the installing Shopify merchant acts as controller for personal data made available through the merchant's use of SpecDesk.

Processing

SpecDesk processes Shopify shop, order, line-item, product and variant identifiers; merchant-entered personalisation values; production job status; notes; artwork URLs; and activity history. SpecDesk does not request customer names, email addresses, telephone numbers, postal addresses or payment information from Shopify orders.

Processing is limited to order synchronisation, production-job management, personalisation mapping, authenticated exports, support and security/compliance operations.

Security and subprocessors

Rexcode uses HTTPS, authenticated Shopify requests, webhook HMAC verification, tenant-scoped queries, fail-closed database runtime guards and authenticated merchant exports. Current subprocessors are Shopify (store and Admin API), Vercel (application hosting) and Neon (PostgreSQL hosting). They process data only as needed to provide the service.

Retention and deletion

Active production jobs are retained while operationally required. Completed or cancelled jobs are automatically redacted after 90 days: order and line-item identifiers, personalisation values, original properties, notes and artwork references are removed or replaced with non-identifying placeholders. Verified Shopify customer and shop redaction requests take precedence and are processed immediately. Transient webhook request bodies are not stored as raw payloads.

Provider backup and history lifecycles may retain deleted records for the provider's documented recovery window. The merchant may request export or deletion subject to legal obligations and that provider lifecycle.

Requests, incidents and termination

Rexcode supports authenticated Shopify data-request, customer-redaction and shop-redaction webhooks. On uninstall, Shopify sessions are removed; shop redaction removes the shop's jobs, templates and sessions. Rexcode will notify the merchant of a confirmed security incident affecting their data as required by applicable law.

Contact

Rexcode Digital Ltd · hello@rexcode.co.uk