GDPR Compliance

Last updated: July 4, 2026

TriSend is committed to protecting the privacy and rights of individuals in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"). This page explains our role, the data we process, and how we fulfill our obligations under GDPR.

1. Our Role

Under GDPR, the merchant (you) is the data controller — you determine the purposes and means of processing your customers' personal data. TriSend acts as a data processor, processing personal data on your behalf to deliver marketing services.

This means you are responsible for ensuring you have a lawful basis (e.g., consent, legitimate interest) for collecting and processing your customers' data. TriSend processes this data strictly according to your instructions through the App.

2. Data Processing Agreement

By using TriSend, a Data Processing Agreement (DPA) is established between you (controller) and TriSend (processor) in accordance with Article 28 of the GDPR. Key provisions include:

3. Lawful Basis for Processing

As the data controller, you must ensure an appropriate lawful basis exists for processing. Common bases for marketing communications include:

Lawful BasisWhen Applicable
Consent (Art. 6(1)(a))Customer explicitly opts in to receive marketing emails, SMS, or WhatsApp messages.
Legitimate Interest (Art. 6(1)(f))Existing customers who may reasonably expect to receive related product marketing.
Contract (Art. 6(1)(b))Transactional messages related to an existing order or service.

4. Personal Data We Process

On behalf of merchants, TriSend processes the following categories of personal data:

CategoryData TypesPurpose
Contact dataName, email, phone numberSending marketing messages, audience segmentation
Order dataOrder history, revenue, products purchasedRevenue attribution, product recommendations
Engagement dataOpens, clicks, conversionsCampaign analytics, automation triggers
Consent recordsOpt-in timestamps, consent source, channel preferencesCompliance tracking, preference management

5. Data Subject Rights

Under GDPR, data subjects (your customers) have the following rights. TriSend assists you in fulfilling these rights through Shopify's mandatory webhooks and in-app tools:

6. Shopify Mandatory Webhooks

TriSend fully implements all three of Shopify's mandatory GDPR compliance webhooks:

customers/data_request

When a customer requests their stored data, Shopify sends this webhook. TriSend compiles all personal data associated with the customer (contact info, engagement history, consent records) and makes it available for export.

customers/redact

When a customer requests deletion of their data, Shopify sends this webhook. TriSend permanently deletes all personal data associated with the customer, including contact records, engagement history, and consent records. Anonymized aggregate analytics data may be retained.

shop/redact

When a merchant uninstalls TriSend, Shopify sends this webhook 48 hours after uninstallation. TriSend deletes all shop data, customer records, campaigns, templates, automations, and analytics within 30 days of receiving this webhook.

7. Data Storage & Transfers

TriSend stores data on infrastructure located in the European Union:

Where data is transferred outside the EU (e.g., via AWS or Twilio for message delivery), appropriate safeguards are in place including Standard Contractual Clauses (SCCs) and the providers' GDPR compliance certifications.

8. Security Measures

TriSend implements technical and organizational measures to protect personal data, including:

9. Data Retention

10. Data Breach Notification

In the event of a personal data breach, TriSend will notify affected merchants without undue delay and no later than 72 hours after becoming aware of the breach, in accordance with Article 33 of the GDPR. The notification will include the nature of the breach, categories of data affected, and measures taken to address the breach.

11. Contact Our Data Protection Team

For GDPR-related inquiries, data subject access requests, or to exercise any of your rights, contact us at privacy@trisend.app.

For general questions about our data practices, see our Privacy Policy.