Data Processing Agreement
The terms on which we hold your customers’ personal data on your behalf. In force from the moment you connect a shop or upload a document. Last updated 12 August 2026.
The parties
This agreement is between you — the business whose books are kept in Alevate, called you or the merchant — and UKPACKAGES LIMITED, a company registered in England and Wales at 12 Constance Street, London E16 2DQ, United Kingdom, which operates Alevate Books and is called we or us.
It applies alongside our Privacy Policy. Where the two disagree about personal data belonging to your customers, this agreement wins.
Who decides what
Your customers are yours. You decide what happens to their personal data; we only do what you have asked us to do by using the product. In the language of the UK GDPR and the EU GDPR, you are the controller and we are your processor.
We do not use your customers’ personal data for our own purposes. We do not sell it, share it, profile anyone with it, or use it to market anything — to you, to your customers, or to anybody else.
What we process, and nothing else
Where you connect a Shopify store, we read your orders in order to keep your books. From each order we take three pieces of personal data:
- Name — so a sale in your ledger can be identified as belonging to a particular order.
- Phone number — so a cash-on-delivery parcel can be matched to its order and to the courier’s settlement sheet.
- Delivery city — and only the city. Courier charges and COD settlements are reconciled by city. We do not read or store the street address, the postcode, or the customer’s email address.
Alongside these we hold the order itself: its number, date, value, line items and fulfilment status. Those are your commercial records rather than personal data, but they are covered by the same care.
Where you upload documents, we hold whatever is in them, which is a matter for you. The Privacy Policy covers that, including the fact that documents are sent to an AI provider to be read.
Who else can see it
We use a small number of sub-processors. Each one holds data only to run the service, and each is bound by terms at least as protective as these:
- Neon — the database your books live in.
- Railway — hosting for the application server.
- Vercel — hosting for the web interface.
- Cloudflare R2 — encrypted off-site backups.
- Cloudinary — storage for documents and photographs you upload.
- Google Cloud (Vertex AI) — reads uploaded documents. It is not sent Shopify order data.
We will tell you before adding or replacing a sub-processor, and you may object. Data may be processed outside your own country by these providers; where that happens it is done under the transfer safeguards those providers offer.
Our staff
Access is granted per business, not per company: a person can open only the sets of books they have been added to, and their role decides what they may do inside them. Everyone with access is under a duty of confidentiality. Access to records is logged.
How it is protected
Data is encrypted in transit with TLS and encrypted at rest by our database provider. Credentials we hold on your behalf — such as a Shopify access token — are separately encrypted with AES-256-GCM before they are stored, so they are not readable even to somebody holding the database.
Backups are taken nightly, encrypted, and held off-site. A weekly job restores the most recent backup into a throwaway database and checks the accounting still balances, so the ability to recover is tested rather than assumed.
Our security measures are described more fully on the Security page. We may improve them at any time; we will not weaken them.
When one of your customers asks
If a shopper asks what is held on them, or asks to be erased, Shopify passes that request to us and we act on it. You do not need to do anything.
On an erasure request we clear the name, the phone number and the city from the affected orders. The transaction itself is kept. A sale is an accounting record and both you and we may be required by law to retain it; what remains after erasure is an order for a sum of money on a date, which identifies nobody. If you need the record itself removed, that is a separate instruction from you, and we will act on it unless the law prevents us.
If a request reaches us that should have gone to you, we will pass it on rather than answer it, and we will help you answer it.
How long we keep it
Your books are kept while you keep them with us. They are your accounting records and carry their own statutory retention, which is why we do not delete them on a timer.
If you remove the Shopify app, we stop reading your shop immediately and delete the access token and the cached product catalogue. Forty-eight hours later, when Shopify confirms the removal, we delete the connection entirely. Your books stay, because they are yours — ending an app connection is not the same as closing your account.
When you do close your account, tell us and we will delete or return your data within 30 days, except where the law requires us to keep something for longer.
If something goes wrong
If personal data we hold for you is lost, exposed or accessed by somebody who should not have seen it, we will tell you without undue delay and in any case within 72 hours of becoming aware, with what we know, what we are doing, and what you may need to do. We will not wait until we have the complete picture to tell you there is one.
Audits, and what you can ask of us
You may ask us to demonstrate that we are doing what this agreement says. We will answer reasonable questions in writing, and we will give you the information you need for your own data protection assessments. We have not yet been audited by a third party; if that changes we will say so on this page.
Changes
If we change this agreement in a way that matters, we will tell you before it takes effect. Continuing to use Alevate after that means you accept the change; if you do not, you may disconnect your shop or close your account.
Questions about any of this: support@alevatebooks.com.