Docs, Billing, privacy, and data

Data processing and subprocessors

What data passes through the app, the one named subprocessor, where the app is hosted, and where to find the data processing agreement.

Category
Account
Updated
26 September 2026
Applies to
TreStack Timer, every plan

What passes through the app

Little that is personal. The app holds your store details and contact email, your timer settings, and daily counts per timer. It holds no data about your customers, and the count events from the storefront carry no shopper identifier.

Subprocessors

Chaport provides the live chat inside the app admin. It is never on your storefront. It receives the shop name, the myshopify domain, and the plan, plus whatever you write in the chat.

The app runs on one server operated by the studio, hosted by Contabo, with Cloudflare in front of timer.trestack.app. Cloudflare sees the IP address of each request, including the count events from your storefront, and keeps none of our data. Images you upload are stored in your own Shopify Files, not by us.

The agreement

The data processing agreement is published on the DPA page of this site. If your legal team needs a signed copy or has questions about it, write to [email protected] with your legal entity name and the name of the signatory.

Getting an agreement in place, in four steps.

In order. Each step assumes the one before it is finished, so skipping one is how the last step fails for a reason that looks unrelated.

  1. Step one

    Read the DPA page

    It is public, so there is nothing to request before reading it.

  2. Step two

    Check the subprocessors

    Chaport for chat inside the app admin, Contabo for hosting, Cloudflare in front of the app. Check them against your own policy.

  3. Step three

    Ask for a signed copy if you need one

    [email protected], with your legal entity name and signatory.

  4. Step four

    Keep the contact email current

    The app holds the contact email from your Shopify settings. Keep it pointing at somebody who reads it.

Settings reference

The controls this page touches, with what each one does and the default the app ships where there is one.

Customer data
None held. Count events carry no shopper identifier.
Live chat
Chaport, inside the app admin only. Shop name, myshopify domain, plan, and what you write.
Hosting
One server operated by the studio, hosted by Contabo, behind Cloudflare.
Uploaded images
Stored in your own Shopify Files.
Agreement
Published on the DPA page. Signed copies on request.

If this does not work

The failures most likely on this procedure, with the check that resolves each one. If none of them fit, we would rather have the store URL than a guess.

Send us the store URL
Your legal team needs changes to the agreement

Send the changes marked against our published text rather than a fresh template. It is quicker for both sides to discuss a redline.

You would rather not use the live chat

Write to [email protected] instead. The chat is optional, and email reaches the same people.