Adray

Adray Data Processing Agreement

Version 1.1 — Effective September 19, 2026

This Data Processing Agreement (the "Agreement") forms part of the Adray Terms of Service and applies whenever Adray processes personal data on behalf of a merchant. It should be read together with the Adray Privacy Policy.

By connecting a Shopify store or another ecommerce or lead-generation platform to Adray, the Customer accepts this Agreement. No separate signature is required. A counter-signable copy is available on request at privacy@adray.ai.

1. Parties and roles

This Agreement is between ADRAY, INC., a corporation organised under the laws of the State of Delaware, United States, with its registered office at 1111B S Governors Avenue STE 53849, Dover, Delaware 19904, United States ("Adray", the "Processor"), and the merchant that uses the Services (the "Customer", the "Controller").

The Customer is the controller of the personal data of its own customers and visitors. Adray acts as processor (a data processor / service provider) and processes that data solely to provide the Services in accordance with the Customer's instructions. This mirrors the role already declared in the Adray Privacy Policy.

2. Subject matter and purpose of processing

Adray processes personal data exclusively in order to:

  • Marketing attribution — link each order to the browsing session and ad click that produced it, and compute verified revenue and return on ad spend per channel.
  • Behavioural analytics — measure the journey, friction and abandonment on the Customer's own site, and produce aggregated reports for that same Customer.
  • Sending conversions to the advertising platforms the Customer itself connects and configures (Meta Conversions API, Google Ads), as server-side events on the Customer's behalf.

Adray does not sell personal data, does not share it with other merchants, and does not build profiles that span merchants. No product surface crosses accounts: every query is scoped by the Customer's account identifier.

3. Categories of data and data subjects

Data subjects: customers, prospective customers and visitors of the Customer's site.

Categories of personal data:

CategoryHow it is stored
Buyer email address and phone numberA SHA-256 hash is stored as the indexed matching key. The address and number themselves are also retained — in the order record and in the pixel event that carried them — because they are what the Customer's own buyer reports show and what is sent as a matching key to the platforms the Customer connects. Same retention and same deletion as everything else in this table (sections 6 and 8).
Buyer first and last nameIn the clear, so that it can be sent as a matching key to the platforms the Customer connects.
Locality-level address: city, state or province, postal code, countryIn the clear. Street, house number, unit and geolocation are neither requested nor stored.
Device and session identifiers: first-party cookie, browser fingerprint, IP address, user agentTechnical identifiers used to join visits to orders.
Ad click identifiers: gclid, fbclid, ttclid, wbraid, gbraidExpire after 7 days for attribution purposes.
Order data: amounts, products, dates, financial statusNot personal data in themselves; linked to the data subject.
Session recording (rrweb): site interaction eventsInput fields are masked. See section 6 on retention.

Never processed: card or payment instrument data, end-customer passwords, or special categories of personal data.

4. Adray's obligations

Adray undertakes to:

  • Process the data only in accordance with the Customer's documented instructions and for the purposes in section 2.
  • Minimise: process only the data necessary for those purposes. Contact identifiers are indexed by hash rather than by value, and only the locality-level address fields that the advertising platforms accept are read — street, house number, unit and geolocation are never requested.
  • Maintain confidentiality and impose it on its personnel.
  • Apply the security measures in section 5.
  • Engage no sub-processors other than those listed in section 7 without giving the Customer reasonable prior notice and a right to object.
  • Assist the Customer with data subject requests (access, deletion, objection to the sale or sharing of data) and with enquiries from supervisory authorities.
  • Notify the Customer of any personal data breach without undue delay and, for confirmed incidents of unauthorised access, within 24 hours of confirmation, in accordance with Adray's incident response policy.
  • On termination, delete or return the personal data, save where retention is legally required.
  • Allow the Customer to verify compliance through the information in this Agreement and the technical documentation Adray makes available.

5. Technical and organisational measures

  • Encryption in transit — all traffic over HTTPS/TLS.
  • Encryption at rest — PostgreSQL and MongoDB are encrypted by the managed provider; backups inherit that encryption.
  • Pseudonymisation — identity matching and lookups run on SHA-256 hashes of email and phone, which are what the indexes hold; the addresses themselves are kept in the order record and in the pixel event that carried them, are never used as a lookup key, and are covered by the access log below.
  • Platform tokens encrypted in the database, under a dedicated encryption key.
  • Role-based access control (owner / admin / member), per-account isolation on every query, and a separate gate for Adray personnel.
  • Personal data access logging — reads that return a buyer name or email address through the product are recorded durably, with the actor, the account, the surface, the type of data and the number of rows — never the value itself.
  • Two-step verification is mandatory for all Adray personnel on the corporate domain.
  • Environment separation — production and staging run against separate databases.
  • Data loss prevention — point-in-time recovery from the managed providers; destructive data operations run with a journal and a revert path, and maintenance scripts default to a dry run.
  • Incident response — a written policy with defined severities, a named coordinator and deputy, a dedicated register, and the notification deadlines in section 4.
  • Error monitoring with personal data scrubbed before transmission.

6. Retention

  • Analytics data (sessions, events, orders): 730 days, after which it is purged automatically.
  • Session recordings: the raw material is deleted 24 hours after the derived packet is generated, and the storage lifecycle expires objects after 14 days.
  • Privacy request log: retained as a compliance record.
  • At the request of the Customer or the data subject, deletion is immediate and cascading (see section 8).

7. Sub-processors

Adray uses the following sub-processors to provide the Services:

Sub-processorFunctionLocation
RenderApplication and background job hostingOregon, United States
NeonPostgreSQL database (analytics)us-west-2 (Oregon), United States
MongoDB AtlasDatabase (product layer)GCP us-central1 (Iowa), United States
Amazon Web Services (S3)Object storage: session recordings and exportsus-east-1 (Virginia), United States
SentryRuntime error monitoringAs set out in the provider's data processing terms
OpenRouter and the model providers it routes toGenerating summaries and recommendations from the Customer's behavioural and aggregated analytics dataAs set out in the provider's data processing terms
OpenAIAI assistant featuresAs set out in the provider's data processing terms
ResendTransactional emailAs set out in the provider's data processing terms
StripeBilling and payment for the Customer's subscriptionAs set out in the provider's data processing terms

The advertising platforms (Meta, Google, TikTok, LinkedIn) are not sub-processors of Adray. They are destinations that the Customer itself connects with its own credentials, and to which Adray sends data on the Customer's instruction. The Customer is responsible for its relationship with them.

8. Data subject rights and deletion

Adray implements the three Shopify compliance webhooks — customer data request, customer redact and shop redact — and deletion is real, not an acknowledgement: it removes the name and the identity hashes from orders, and removes the data subject from the identity graph, the session packets and the recordings. Every request is logged with its outcome, identifying the data subject by hash and never by value.

Adray also honours the browser's Global Privacy Control signal and exposes opt-out endpoints: a conversion marked as suppressed is not sent to any advertising platform.

9. International transfers

Adray's primary infrastructure is located in the United States (see section 7). Where personal data is transferred out of Mexico, that transfer is covered by standard contractual clauses, copies of which Adray provides on the Customer's request.

Adray's engineering personnel operate from Mexico and access infrastructure hosted in the United States. Three distinct facts are stated here deliberately: the registered office is in Delaware, processing takes place in the United States, and personnel are located in Mexico.

10. Term, changes and contact

This Agreement applies for as long as Adray processes personal data on the Customer's behalf and terminates when the Services conclude, once section 4.8 has been satisfied. In the event of a conflict with the Terms of Service as regards the processing of personal data, this Agreement prevails.

Adray may update this Agreement. Where a change is material — in particular the addition of a sub-processor — Adray will give the Customer reasonable prior notice and a right to object, as provided in section 4.5. The version and effective date at the top of this page identify the text in force.

This Agreement is published in English and Spanish. The two texts are intended to say the same thing; in case of discrepancy, the English text governs, consistent with the Terms of Service of which this Agreement forms part.

Data protection contact: privacy@adray.ai · Security contact: support@adray.ai

ADRAY, INC.
1111B S Governors Avenue STE 53849
Dover, Delaware 19904
United States