# Vanilla Consent merchant terms and data processing agreement Version 2026-09-27. Offered by Vanilla Telecoms Ltd for express acceptance by authorised Shopify merchants. ## 1. Parties and acceptance These terms are between **Vanilla Telecoms Ltd**, company registration number **C34939**, with registered office at **162, Cannon Road, Santa Venera, Malta** ("Vanilla", "we", "us"), and the business identified by the Shopify store accepting them ("Merchant", "you"). The app is supplied for business use. For privacy requests and security incidents concerning Vanilla Consent, contact our **Data Protection Officer at gdpr@vanilla.net.mt**. General product support is available at helpdesk@vanilla.net.mt. The person accepting confirms that they have authority to bind the Merchant. The agreement starts when that person expressly accepts the identified version through the app or another recorded written process. Installing the app or approving a Shopify plan alone does not establish acceptance of these terms. The agreement consists of these terms, the processing schedule below and any signed order form. For personal-data processing, sections 10–17 and the processing schedule take priority over conflicting commercial terms. Applicable mandatory law and any binding international-transfer clauses take priority over this agreement. A privacy notice explains our processing practices; it does not reduce our contractual duties. ## 2. Service and licence Vanilla grants the Merchant a limited, non-exclusive, non-transferable right to use Vanilla Consent for its authorised Shopify stores during the subscription. Vanilla and its licensors retain ownership of the app, documentation and other service materials. The Merchant retains its rights in its data and grants only the rights needed to deliver the agreed service. The service supplies the features actually available under the selected plan. A roadmap, draft feature, preview or test result is not a promise of future delivery. Shopify permissions, plan eligibility, store configuration and supported third-party services may limit availability. Any material limitation will be disclosed before purchase or activation. Vanilla may maintain, improve or replace service components. We will give reasonable advance notice of a material reduction to a paid service, except when an urgent legal, platform or security issue requires earlier action. Affected merchants may cancel future renewal; mandatory refund rights remain unchanged. There is no agreed uptime percentage, dedicated support response time or service credit unless a signed order expressly provides one. ## 3. Merchant responsibilities The Merchant is responsible for its lawful instructions, privacy notices, lawful bases, required consent, retention choices and replies to customer requests. It must review banner wording, translations, cookie classifications, scans, exports and suggested content before relying on them. It must verify the identity and authority of a person receiving customer data. The Merchant must configure and test its theme, tags, pixels, integrations and enabled app features. It must maintain accurate contact details, restrict its staff permissions and protect accounts and exported files. It must not send us payment-card security codes, passwords, government identity documents, health records or other special-category data through privacy-request messages or support unless a separate written arrangement expressly permits and protects that processing. The app assists with privacy workflows. It does not provide legal advice, certify a store's compliance or guarantee that every cookie, tracker, accessibility issue or record in another system will be found. The Merchant remains responsible for systems it controls. These allocations do not excuse Vanilla from its own legal duties or defects for which it is responsible. ## 4. Prices and Shopify billing The Free plan has no subscription charge. The Full plan is **US$19 per month**, with all features then available in Full. Banner impressions are unlimited on both plans. Multilingual banner translations are included in Free. No annual commitment or trial is offered under these terms. Monthly processing allowances reset at 00:00 UTC on the first day of each calendar month. Free includes 30 scan-page attempts and 20 AI translation attempts. Full includes 300 scan-page attempts, 200 AI translation attempts, 50 AI cookie batches of up to 20 cookies each and 500 AI image attempts. Started scans, retries and failed AI attempts count. Starting a scan uses its first page allowance, including any password check. Usage is shared across manual and scheduled versions of each tool, does not roll over and is retained when changing plans. An affected tool stops at its allowance without additional usage charges; basic privacy requests, existing banner controls and manual translations remain available. Short-term processing limits also apply. Current usage and reset dates are shown in Plans. Paid subscriptions, approval, renewal, cancellation, applicable taxes, currency conversion and any proration follow the charge presented by Shopify and Shopify's applicable billing rules. We do not collect a separate off-platform app subscription. A new or increased charge requires the approval Shopify requires. No price increase applies retrospectively. Unless mandatory law or Shopify's rules require otherwise, fees already earned are non-refundable and cancelling prevents future renewals rather than creating a refund for past use. An express refund promise in a signed order takes priority. Development-store discounts do not establish a right to the same price for a production store. ## 5. Acceptable use, suspension and termination The Merchant must not resell the service without permission, probe other stores' data, circumvent access or billing controls, introduce malicious code, infringe third-party rights or use the app unlawfully. Legitimate security reports should be sent privately through the stated support channel. Vanilla may suspend only the affected access when reasonably needed to address non-payment, material misuse, a security threat, illegality or a Shopify restriction. We will give notice and a reasonable chance to remedy where practicable. We may terminate for an unremedied material breach after 14 days' written notice, or immediately where continued service would be unlawful or create a serious security risk. The Merchant may end its subscription through Shopify. Vanilla may discontinue the service on at least 30 days' notice and will refund any prepaid, unused subscription charges attributable to a period after discontinuation. Suspension or termination does not remove required data-return, deletion, assistance or confidentiality obligations. Section 16 governs customer data after termination. ## 6. Service limitations and third parties Vanilla will provide the service with reasonable skill and care. To the extent permitted by law, other implied warranties are excluded. We do not guarantee error-free operation, uninterrupted availability, a particular regulatory outcome or the accuracy of unreviewed automated suggestions. Shopify and merchant-selected third parties operate under their own terms. Vanilla is not responsible for a failure caused solely by their systems or a merchant's configuration outside our control. This does not remove our responsibility for selecting and overseeing our own subprocessors, implementing our integrations correctly, or meeting mandatory duties. ## 7. Liability To the fullest extent permitted by law, Vanilla is not liable to the Merchant for indirect or consequential loss, lost profits, revenue, goodwill, anticipated savings or business opportunity, whether a claim arises in contract, tort or otherwise. Subject to the exceptions below, Vanilla's total aggregate liability to the Merchant arising from the service and this agreement, including the data processing terms, is limited to **the Vanilla Consent subscription fee actually paid or payable for the affected store for the single monthly billing period in which the event first giving rise to the claim occurred**, excluding taxes. Related events are treated as one event occurring when the first related event occurred. This is one combined cap for all claims arising from events first occurring during that billing period, not a separate cap for each event, claim or legal basis. There is **no minimum liability floor and no aggregation of fees from earlier or later months**. Under the current standard prices, the cap for a full-price Full subscription month is **US$19**. If the relevant month is on Free or otherwise carries no subscription charge, the contractual cap is **US$0**, in each case subject to the mandatory exceptions below. A refund given because of the incident does not retrospectively reduce the fee used to calculate the cap. Nothing excludes or limits fraud, wilful misconduct, gross negligence to the extent it cannot lawfully be limited, death or personal injury where exclusion is unlawful, or any other liability that applicable law prohibits limiting. Nothing limits a data subject's statutory compensation rights, a regulator's powers, mandatory contribution rights, or liability that binding international-transfer clauses require to remain uncapped. The cap does not limit the performance of mandatory processing, audit, notification, deletion or assistance duties. The Merchant must take reasonable steps to reduce avoidable loss. Its payment obligations are not reduced by Vanilla's liability cap. ## 8. Merchant indemnity To the extent permitted by law, the Merchant will reimburse Vanilla for reasonable defence costs, settlements approved by the Merchant and damages finally awarded on a third-party claim to the extent caused by the Merchant's unlawful instructions, unlawful data collection, infringement of third-party rights or deliberate misuse of the app. This indemnity does not apply to the extent Vanilla or its subprocessors caused the claim through their own breach, negligence or unlawful conduct. Vanilla must give prompt notice, reasonable cooperation and control of the defence to the Merchant using competent counsel. No settlement may impose an admission, non-monetary duty or unreimbursed payment on Vanilla without its consent. No party may recover the same loss twice. Regulatory fines are included only if and to the extent lawful; mandatory statutory liability and contribution rules prevail. ## 9. Maltese law and commercial disputes **This agreement and any non-contractual obligations arising from it are governed by the laws of Malta. The courts of Malta have exclusive jurisdiction over disputes between Vanilla and the Merchant.** Either party may seek urgent protective relief from any court that has lawful jurisdiction. This choice does not override mandatory law, the rights or permitted forums of data subjects, a supervisory authority's powers, or the governing-law and forum requirements of binding international-transfer clauses. The parties will first try in good faith to resolve an ordinary commercial dispute through their nominated contacts for 30 days. This does not delay urgent remedies, statutory deadlines or required cooperation. Changes to these terms require notice and valid recorded agreement; publishing a revised webpage alone does not amend agreed processing obligations. If a term is unenforceable, the remainder continues to the extent lawful. A delay in enforcing a right is not a waiver. Assignment may not reduce required data protections or bypass subprocessor or transfer rules. ## 10. Data processing roles and scope For the customer and visitor data described in Schedule A, the Merchant determines the purposes and essential means of processing and acts as controller. Vanilla acts as processor on the Merchant's behalf. If the Merchant acts for another controller, it warrants that it has authority to appoint Vanilla and give the relevant instructions; Vanilla then acts as a subprocessor. Vanilla acts as controller for its own merchant account administration, billing records, business correspondence and legal obligations, as described in its privacy notice. That processing does not authorise reusing shopper data for unrelated purposes. "Applicable Data Protection Law" includes the GDPR, Malta's Data Protection Act (Chapter 586), and other privacy laws that apply to the processing. "Personal data", "processing", "controller", "processor" and "personal data breach" have their meanings under the GDPR where it applies. ## 11. Instructions, confidentiality and security Vanilla will process covered personal data only for the service and on documented lawful instructions, including the Merchant's reviewed app settings and authorised requests. We will not sell covered personal data, use it for our own advertising or use customer records to train general-purpose models. Where another law requires processing, we will inform the Merchant beforehand unless that law prohibits notice. We will promptly flag an instruction we consider unlawful and may suspend that instruction while it is resolved. Only authorised people who need access to perform their duties may process the data. They must be subject to confidentiality duties. Vanilla will apply appropriate technical and organisational measures having regard to processing risks and will maintain the security measures in Schedule B. The service does not make solely automated decisions with legal or similarly significant effects about customers. Optional suggestions require merchant review. Merchant instructions cannot authorise processing prohibited by applicable law. ## 12. Subprocessors and connected services The Merchant gives general written authorisation for the subprocessors identified in Schedule D. Before an additional or replacement subprocessor starts handling covered data, Vanilla will give at least 30 days' notice identifying its function and relevant locations. The Merchant may raise a reasonable, documented data-protection objection within that period. We will try to resolve it through an alternative or suitable safeguard. If resolution is not reasonably possible, either party may terminate the affected feature without penalty and unused prepaid fees for that feature will be refunded where applicable. Vanilla will impose written data-protection obligations on its subprocessors offering the protection required by applicable law and remains responsible to the Merchant for their performance. The Merchant has no right to direct our other suppliers' commercial operations beyond its applicable data-protection rights. Maltashopper Ltd, company number C53942, supplies the Cloudflare, Mailgun and Commslayer service accounts used for Vanilla Consent. Vanilla contracts directly for Google Workspace. For covered merchant-controlled data, the supplier chain is Merchant to Vanilla to Maltashopper to the relevant onward provider. Maltashopper is not authorised by these terms to use covered data for its own retail marketing. Vanilla remains responsible to the Merchant for the subprocessor obligations required by law. Schedule D identifies the arrangement. Vanilla and Maltashopper adopted their separate processing agreement on 27 September 2026. Services independently selected and contracted by a merchant have their own applicable roles and terms. Labelling a service merchant-selected does not remove our duties where we in fact engage it as a subprocessor. No unfinished integration is promised by this schedule. ## 13. International transfers Vanilla will not make a restricted international transfer without a valid mechanism under applicable law and appropriate safeguards. Schedule D identifies the suppliers and processing arrangement. Vanilla will provide information about applicable locations and transfer safeguards on reasonable request, with confidential details protected. An EU endpoint or a database region alone does not establish EU-only processing. Where Standard Contractual Clauses or another transfer instrument is required, the applicable instrument, module, parties and annexes must be validly completed before the transfer. This agreement does not replace any required transfer instrument or supply missing parties or annexes. Any required transfer assessment and supplementary protections must be completed. The Merchant's general consent to use the app is not a substitute for a lawful transfer mechanism. ## 14. Customer rights and incidents Taking account of the processing and information available to it, Vanilla will assist the Merchant with customer rights requests, security obligations, required breach notices, impact assessments and regulatory consultation. We will route a customer request to the Merchant unless authorised or legally required to act directly. The Merchant decides exemptions and the scope of responses it must make; Vanilla will not independently determine those legal questions for it. Vanilla will notify the Merchant **without undue delay after becoming aware of a personal data breach** affecting covered data. We will provide available information on its nature, likely impact, affected data, contact and mitigation, with updates as facts become known. Initial notice does not await a completed investigation and is not an admission of fault. Each party remains responsible for notices that the law assigns to it. Ordinary self-service assistance is included. Bespoke work beyond it may be charged at reasonable rates agreed in advance where lawful. No disputed fee may obstruct or delay mandatory assistance, an urgent notice or a regulator's lawful access. Vanilla bears costs attributable to remedying its own breach. ## 15. Evidence and audits Vanilla will supply information needed to demonstrate compliance with these processing terms and will allow and contribute to legally required audits and inspections by the Merchant or its authorised independent auditor. For routine requests, the parties will use current documentation and suitable independent reports first. If further inspection is reasonably necessary, it should ordinarily occur during business hours, on 30 days' notice, no more than once in a 12-month period, under reasonable confidentiality and security arrangements. The Merchant pays its auditor and reasonable, pre-agreed additional assistance costs, except where a material breach by Vanilla is established or applicable law requires otherwise. These arrangements must not prevent a necessary audit. The limits on notice, frequency, format and costs do not apply where incompatible with law, required by a competent authority, or reasonably necessary to investigate a material breach. Audits must protect other merchants' information and avoid unnecessary disruption. Alternative evidence or supervised access may protect sensitive systems without concealing relevant processing controls. ## 16. Retention, return and deletion Vanilla will apply Schedule C and the Merchant's lawful settings. The Merchant may choose return or deletion of covered data when ending the service. To choose return of app records, use Settings > Return your app data before uninstalling, save every part and check the final completion marker. This includes the documented app datasets, subject to current expiry and erasure, but excludes service credentials and transient verification secrets. It does not fetch separate Shopify, support-mail, CRM or other provider records. Contact gdpr@vanilla.net.mt before ending the service for assistance, missing categories or separately held records. Vanilla will verify authority, identify the records and coordinate their return through a protected channel. No additional fee may obstruct mandatory return rights. Uninstalling without first choosing return instructs deletion of remaining app records. Uninstall ends app access immediately. Hourly maintenance removes the store after more than 48 hours, and Shopify shop-erasure events may remove it earlier. A support email does not automatically pause deletion; complete or coordinate return while access remains available. Vanilla will not promise to recover already erased records. These practical steps do not remove mandatory return or deletion rights. If Vanilla initiates termination, it will provide a reasonable opportunity for lawful return before deletion, subject to urgent legal or security duties. After return, Vanilla will delete remaining copies unless law requires retention. Restricted recovery copies may persist only for the documented, finite backup period, with no normal business use; deletion instructions must be reapplied before restored data returns to service. We will provide confirmation of deletion on reasonable request and explain any legally required retained categories and periods. Files a Merchant downloads or stores in its own connected account are under its control. The Merchant must apply its own retention and sharing rules to those copies. That does not excuse Vanilla from deleting copies it controls. ## 17. Other applicable privacy laws Where California law applies and Vanilla acts as service provider or contractor, it will handle covered personal information only for the specified business purposes, will not sell or share it for cross-context behavioural advertising, and will not retain, use or disclose it outside the direct business relationship except as that law permits. It will not combine it with other sources except as permitted for the contracted purposes. Vanilla certifies that it understands and will comply with these restrictions when this agreement takes effect. The Merchant may take reasonable steps to verify compliant use and stop or remedy unauthorised use. Vanilla will inform the Merchant if it can no longer meet the applicable obligations. Mandatory local provisions prevail over an inconsistent commercial term. ## Schedule A. Processing description | Item | Processing description | | ------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | Subject and purpose | Deliver the Merchant's selected consent, recordkeeping, scan and reviewed privacy-request workflows. | | Duration | While the Merchant uses the service, followed by the completed return/deletion and recovery-copy periods. | | People | Store visitors, customers, prospective customers, privacy requesters and authorised merchant staff. | | Consent records | Generated consent identifiers, choices, policy version, time, broad country/device categories and related store identifiers. | | Privacy requests | Request email, type, status, receipt/deadline, verification evidence, notes and voluntarily supplied message/order references. Optional Shopify access may retrieve names, addresses, phone numbers, customer IDs and relevant order data for reviewed fulfilment. | | Operations | Collection, verification, storage, retrieval, restricted display, reviewed changes, export/delivery and deletion. Tenant separation is enforced by authenticated store identity. | | Optional inputs | Reviewed imported records, selected public/store image content, cookie names/domains and merchant wording for translation. The Merchant must avoid embedding unnecessary personal data in these inputs. | | Sensitive data | Not requested or supported as an intended service input. Accidental submissions require restricted handling and deletion or return under a lawful instruction. | | Instructions | These agreed terms, enabled settings, reviewed actions and authorised support instructions. No feature grants the Merchant a right to direct unlawful processing. | ## Schedule B. Security measures - Access to the embedded app uses Shopify authentication, authenticated store boundaries and feature-specific permissions. Private app routes require an access-log write before handling records. Logs contain identifiers and fixed action metadata rather than export contents. - The app uses HTTPS, validates service certificates and refuses redirects on private provider requests. Managed Mailgun messages require TLS and certificate verification. Customer export files use protected, short-lived, single-use links rather than ordinary email attachments. - Cloudflare D1 provides database-wide encryption at rest and protected transport. Credentials, private request fields, queued message contents and temporary customer export files also use application encryption, with keys held separately in Worker secrets. - Service providers supply storage and recovery encryption. Staff computers handling customer records use disk encryption and screen locks. Staff access is limited by job need. The company requires individual access, multi-factor authentication and unique passwords of at least 15 characters with uppercase letters, numbers and symbols where passwords are used. - Production customer records must not enter development fixtures. Local automated tests use isolated synthetic records and random test credentials, with external requests blocked. Approved development stores are separate authenticated tenants. - Provider-managed recovery is restricted. Restores require reapplying erasure and expiry before returning data to service. Vanilla maintains no additional external data backups. Merchant downloads remain the Merchant's responsibility. - The Data Protection Officer owns the written security, retention and incident-response policies. Access, suppliers and incidents are reviewed under those policies. Support uses restricted provider systems; raw customer exports and credentials must not be sent in ordinary email. These measures describe the service controls and organisational duties. They are not a certification, an assurance that every third-party recipient supports secure email, or a guarantee of EU-only processing. Customers and merchants should use the app's protected workflows for customer records and avoid unnecessary personal data in support correspondence. ## Schedule C. Retention periods These periods apply subject to section 16, lawful instructions and documented legal retention duties. | Category | Period and treatment | | --- | --- | | Consent, scan and app audit records | The Merchant's selected period, capped at 365 days, with hourly cleanup. Imported history uses original relevant dates. | | Completed privacy requests and dependent records | The Merchant's period measured from completion. Open requests are reviewed at least monthly and retained only for a recorded continuing purpose. | | Secure customer-export contents | At most 24 hours prepared; delivery links at most 30 minutes. Use or revocation clears contents. Expiry blocks access immediately and hourly maintenance removes expired contents. | | App records after uninstall | Current hourly automation deletes stores uninstalled for more than 48 hours; Shopify erasure events can remove records earlier. Use the return process in section 16 before uninstalling. | | Cloudflare D1 recovery | Up to 30 days. Erasure and expiry must be reapplied before restored data returns to service. | | Scanner queue | Four days; opaque job references, not customer records or store passwords. | | Monthly processing counters | Approximately one year; store-level totals, with no customer identifiers, prompts or generated text. Removed with the store. | | Worker operational logs | Provider retention up to seven days; invocation logging and tracing disabled and no log export configured. Fixed event/status categories and aggregate processing warnings, without request contents or customer exports. | | Cloudflare account security/audit records | Provider retention of 18 months, separately from customer records in the app. | | Managed Mailgun message retrieval | Turned off for mg.vanilla.net.mt. This does not eliminate transient delivery processing or establish that every historical copy was purged immediately. | | Managed Mailgun delivery-event logs | Five days, verified in the account reporting settings. | | Mailgun critical security records | Provider-stated 365-day period. | | Mailgun suppression records | Purpose-based retention to honour opt-outs and prevent delivery to hard-bounced or complaining addresses. Relevant erasure requests are reviewed without defeating an opt-out. | | Google Workspace privacy/support correspondence | One year under the owner's confirmed archiving rule, subject to documented legal retention duties. Separate from app data and uninstall cleanup. | | Commslayer privacy/support email and attachments | One year, independently confirmed by the owner. Provider recovery copies follow its rolling deletion process; an exact backup expiry is not represented as verified. | | Temporary operator copies | Deleted within 24 hours of the approved task ending, unless a DPO-approved, time-reviewed incident or legal hold applies. No external Vanilla backups are maintained. | | Merchant-controlled exports and connections | The Merchant controls retention of downloads and connected-service copies. A merchant-connected Mailgun account has its own provider settings. | Any exception requires a documented lawful purpose, minimum necessary data, restricted access and a review date. The DPO reviews open requests monthly and holds at least quarterly. Deleting an app record does not instantly erase provider recovery copies or correspondence held under a separate lawful purpose. ## Schedule D. Supplier-account arrangement The supplier-account arrangement is as follows. | Service | Account holder | Role in delivering Vanilla Consent | | --- | --- | --- | | Google Workspace | Vanilla Telecoms Ltd | Direct provider of Vanilla's privacy/support mailboxes. | | Cloudflare | Maltashopper Ltd | Hosting, database and recovery, queues, operations and optional AI supplied through Maltashopper. | | Mailgun | Maltashopper Ltd | Managed transactional email supplied through Maltashopper using the EU sending endpoint. | | Commslayer | Maltashopper Ltd | Privacy/support correspondence handling supplied through Maltashopper. | | Shopify | Merchant's platform relationship | Platform authentication, billing, privacy controls and optional approved customer/order operations; not described as exclusively a Vanilla-appointed processor. | | Merchant-connected services | Merchant-selected account | Mailgun, Google Drive, Klaviyo and other supported connections only when separately configured; the actual connection determines role and applicable provider terms. | Maltashopper's published business office is 162 Cannon Road, Santa Venera SVR 9034, Malta. The public service name identifies each onward provider; Vanilla will provide the applicable contracting and transfer information on reasonable request, subject to appropriate confidentiality. Neither Maltese account ownership nor an EU endpoint is a promise of EU-only processing. No new staff access, account grant or optional integration is authorised merely by listing a supplier. The Merchant contracts with Vanilla for the app. Maltashopper acts under its separate processing agreement with Vanilla. Supplier terms and legal notices are available from [Cloudflare](https://www.cloudflare.com/cloudflare-customer-dpa/), [Mailgun/Sinch](https://sinch.com/legal/terms-and-conditions/other-sinch-terms-conditions/data-processing-agreement/), [Google Workspace](https://workspace.google.com/terms/dpa_terms.html) and [Commslayer/Actuals Oy](https://www.commslayer.com/dpa). These links identify provider documents; they do not make the Merchant a direct party to Vanilla's or Maltashopper's provider contracts. Restricted transfers require a valid applicable mechanism under section 13.