wesaw
FRJoin the waiting list

Data processing agreement

You are the controller of your customers' personal data. wesaw processes it on your behalf and on your instructions, and this document is what that means in practice: what is processed, by whom, where it sits, how long it stays, and what happens when someone asks for it to be deleted. It forms part of the terms of use and is accepted at the same moment.

The two roles

You are the controller. The processor is wesaw, operated by Avec trois e. This agreement takes effect when you connect a shop and lasts as long as the app is installed. Where this document and the terms of use disagree about personal data, this one wins.

What is processed, and why

Conversion events built from your orders and from the browsing that led to them, for one purpose: letting the advertising platforms you have connected recognise a conversion they would otherwise miss, and letting you check, event by event, what was sent. Nothing is processed for any other purpose, and nothing is processed for our own.

Whose data

The people who buy from your shop and the people who visit it. No employee data, no data about you beyond your own account, and nothing about anyone who has not interacted with your storefront.

Which data

Eight identity fields read from the order: email address, phone number, first name, last name, city, region, postal code and country. Each is normalised and hashed with SHA-256 on our servers before anything leaves them, and only the hash is stored and only the hash is sent. Alongside them: the order number, its amount and currency, the products bought, the page addresses visited, the advertising click identifiers your links carried, the buyer's IP address and browser user agent, the first-party identifiers our own script minted in the browser, and the consent state your storefront reported. No special category data is asked for, and none should ever reach us; if it does, it is because a buyer typed it into a field we read, and you should tell us.

Only on your instructions

wesaw processes this data only on your documented instructions. Your instructions are this agreement plus the configuration of your account: which destinations are connected, which events are declared, and which domains are allowed. Nothing else instructs us. If we were ever required by law to process it otherwise, we would tell you first unless that law forbids it.

Who inside wesaw can see it

One person today, and it is more honest to say that than to describe an access policy for a company of one. The accounts that reach the data carry two-factor authentication. Every read of a customer's data through the dashboard is written to an access log, including ours, recording who read what and about whom; the log stores an order number or a hashed email address, never an email address in the clear. Everyone with access is bound to confidentiality, and that obligation outlives their access.

How it is protected

Traffic is encrypted in transit. The warehouse and the database encrypt at rest, and so do their backups. Your platform token and your webhook secret are encrypted with AES-GCM under a key held only by the application server, and neither is ever displayed again. Webhooks are rejected unless their signature verifies. Development runs against its own database on a developer's own machine, and a configuration that mixes the two refuses to run rather than running quietly. Two measures a larger processor would have are absent and named as absent: no alerting is configured, so a failure is found by someone looking, and no backup restore has ever been tested, so the backups are an assumption rather than a proven recovery.

Who else processes it

Cloudflare, for collection at the edge and the buffer that holds events before storage, pinned to the European Union. Railway, in Amsterdam, for both the event warehouse and the application database that holds your account, your shops and your encrypted tokens. Resend, for the emails we send you, which never carry your customers' data. Each one is engaged under its own written terms, and we remain answerable to you for what they do. You will be told before another one is added, with enough notice to object. The warehouse ran on ClickHouse Cloud in Frankfurt until 19 September 2026; that service stopped answering and it was moved, which is why this list is shorter than it was.

Where it is processed

In the European Union today. The buffer that holds events before they are stored is pinned to an EU jurisdiction in code, and the warehouse is in Amsterdam. Two things are worth saying plainly rather than implying the opposite. Cloudflare's edge runs the collection code at the point of presence nearest the visitor, which is not necessarily in the EU, and what is pinned is where events are stored rather than where that code runs. And introducing a service outside the EU is no longer forbidden by our own rules, so if one is ever introduced it will be named here before it is used.

Helping you answer your customers

When one of your customers asks you for their data or asks you to delete it, write to hello@getwesaw.com naming the order or the email address, and we will find it and act. On Shopify the route is automatic: a deletion request from a customer reaches us signed by Shopify and erases that person's events, and uninstalling erases the shop. A request that reaches us with nothing to target, which happens while Shopify redacts customer fields from apps without protected data access, is recorded as such and answered rather than silently treated as done.

If something leaks

We tell you without undue delay and within 72 hours of learning of it, by email, with what we know, what we do not know yet, and what you need to do at your end. We do not wait until we understand everything: a merchant who learns of a breach from someone else does not come back. If advertising tokens are affected we say so, because those are keys to your own ad account.

How long it is kept, and how it goes

Fourteen months from the event, then the database deletes it rather than anyone remembering to. The delivery log and the browser emission records expire on the same window. On uninstall, Shopify sends a shop redaction request and the shop's events are erased ahead of that window; your account and your team survive it, because that is yours and not your customers'. Deletion on request, through the address above, is honoured within 30 days. What was already delivered to an advertising platform lives in your account there and is deleted there, not by us.

Checking that we do what this says

Ask, in writing, and we answer in writing, including with the parts of the repository that implement what is described here. You may audit, yourself or through an auditor you appoint, on reasonable notice and at most once a year, at your cost unless the audit finds we were in breach. We would rather you checked the product itself: every conversion carries its own record of what was sent and what came back, which is a stronger check than an audit of a promise.

Changes

This document carries its date, and your account records which version you accepted. A change that affects what is processed, who processes it or where, is notified by email before it takes effect, and continuing to use wesaw after that is how the new version is accepted. A change that only clarifies wording is published with a new date and nothing else.