Terms of Service

Profit Pigeon (Pty) Ltd
Effective date: 31 August 2026
Last updated: 31 August 2026


1. The agreement#

These Terms of Service form a binding agreement between Profit Pigeon (Pty) Ltd, registration number 2026/196128/07, a private company incorporated in South Africa with its registered office at Unit 201 Masons Press, Woodlands Road, Woodstock, Cape Town, Western Cape, 7925 ("Profit Pigeon" or "the Company"), and the person or entity that installs or uses the Profit Pigeon application ("the Merchant").

The agreement is accepted when the Merchant installs the application, and it applies for as long as the application remains installed.

Annex A (Data Processing Terms) forms part of this agreement. It governs the processing of personal information and takes effect without separate signature. The Privacy Policy at profitpigeon.com/privacy is also incorporated by reference.

Where these Terms conflict with Annex A in relation to the processing of personal information, Annex A prevails. Clause 6.6 of these Terms is subject to clause A7.4 of Annex A.

A person who accepts these Terms on behalf of an entity warrants that they have authority to bind that entity.


2. The service#

Profit Pigeon is a profit analytics application for Shopify merchants. It reads order data from the Merchant's Shopify store and advertising data from advertising accounts the Merchant connects, combines that data with cost information the Merchant enters, and presents profit reporting, targets, tracking and sensitivity analysis back to the Merchant.

The service is provided as software accessed over the internet. No software is delivered to the Merchant for installation on the Merchant's own equipment.

2.1 Licence#

Subject to compliance with this agreement and payment of the applicable fees, Profit Pigeon grants the Merchant a non-exclusive, non-transferable, non-sublicensable, revocable right to access and use the application for the Merchant's own internal business purposes for the duration of the agreement.

No other rights are granted. All rights not expressly granted are reserved.

2.2 Restrictions#

The Merchant must not:

2.3 Restrictions on the information the Merchant submits#

The Merchant must not enter personal information into free-text fields in the application, including cost descriptions, notes and annotations. Those fields are for amounts and descriptions of cost categories, not for information about identifiable individuals.

The Merchant must not knowingly route through the application any special personal information as defined in section 26 of the Protection of Personal Information Act, any special category of data under Article 9 of the GDPR, any health information, any information concerning criminal conduct, or the personal information of children.


3. Accounts and authorised users#

The Merchant is responsible for all activity under its account, for maintaining the confidentiality of its credentials, and for ensuring that anyone it authorises to use the application complies with this agreement.

The Merchant must notify the Company promptly at developer@profitpigeon.com on becoming aware of any unauthorised access to its account.

The Merchant must be at least 18 years old.


4. Connected accounts#

The application functions by connecting to third-party services, currently Shopify, Meta Ads, Google Ads and TikTok Ads. Each connection is authorised by the Merchant through that service's own authorisation process, and each may be revoked by the Merchant at any time through that service.

Those services are operated by third parties and are not under the Company's control. The Company is not responsible for their availability, accuracy or continued operation, and is not responsible for any change a third party makes to its interface, its terms or its data.

Where a third party restricts, changes or withdraws access to its interface, functionality that depends on it may be reduced or withdrawn. The Company will give the Merchant reasonable notice where it is able to do so.


5. Ownership of data and of the application#

5.1 The Merchant's data#

All data the Merchant submits, and all data read from the Merchant's connected accounts, remains the property of the Merchant. Profit Pigeon acquires no ownership of it.

The Company is granted a limited right to host, store, process, transmit and display that data, solely to the extent necessary to provide the application to the Merchant, to secure it, and to comply with a legal obligation. This right ends when the agreement ends.

The Company does not use the Merchant's data for any other purpose. In particular, the Company does not sell it, does not disclose it to third parties for their own purposes, and does not use it to create, develop, train, fine-tune or improve any artificial intelligence or machine learning system.

The Merchant instructs the Company to aggregate and irreversibly anonymise the Merchant's data to produce statistical information that cannot be attributed to the Merchant, to any store or to any individual. Once anonymised, that information is no longer the Merchant's data and is no longer personal information. It may be retained and used after the agreement ends.

5.2 The application#

The application, and all software, interfaces, designs, text, documentation and other material comprising it, is owned by the Company and is protected by intellectual property law. Nothing in this agreement transfers any of it to the Merchant.

5.3 Feedback#

Where the Merchant provides suggestions or feedback about the application, the Company may use it without restriction and without obligation. Feedback is not confidential and the Merchant acquires no rights in anything the Company builds as a result.


6. Fees and billing#

6.1 Billing through Shopify#

All fees are charged through Shopify's billing system and appear on the Merchant's Shopify invoice. The Company does not receive or store the Merchant's payment card or bank details.

Fees are quoted and charged in United States Dollars. Where the Merchant's Shopify account is denominated in another currency, Shopify applies its own conversion and any associated charge.

Fees exclude value-added tax and any other tax or duty, which the Merchant is responsible for where applicable.

6.2 Plans#

The application is offered on tiered plans based on the number of orders processed in the Merchant's store each month. The plans in effect at the date of these Terms are in Schedule A. Current pricing is published on the Shopify App Store listing and at profitpigeon.com/pricing.

The Merchant may upgrade or downgrade its plan at any time from within the application, without contacting support. Shopify applies proration on a plan change in accordance with its own rules.

Where the Merchant's order volume exceeds its plan for two consecutive calendar months, the Company will notify the Merchant and the Merchant must move to the appropriate plan. The application continues to function while that is arranged.

6.3 Free trial#

A free trial of 14 days is offered on each paid plan. No fee is charged during the trial.

Shopify tracks trial days consumed across installations over a rolling 180-day period. A Merchant who uninstalls part-way through a trial and reinstalls within that period resumes the trial with the remaining days rather than starting again.

At the end of the trial the subscription continues as a paid subscription and the applicable fee is charged, unless the application has been uninstalled before the trial ends.

6.4 Renewal#

Subscriptions renew automatically every 30 days until the application is uninstalled or the subscription is cancelled.

Charges are generated by Shopify at the start of each 30-day billing cycle. A Merchant who uninstalls after a charge has been generated may still see that charge on their Shopify invoice.

6.5 Cancellation#

The Merchant may cancel at any time by uninstalling the application. Cancellation takes effect immediately.

Shopify does not apply a credit for the unused portion of a billing period on cancellation. The Merchant retains access for the remainder of the period only where Shopify's own mechanics allow it.

6.6 Refunds#

Fees are not refundable. No refund, in whole or in part, is given for a billing period that has begun, for unused time, or for a period during which the Merchant did not use the application.

This clause is subject to clause A7.4 of Annex A, which entitles a Merchant who objects to a new sub-processor not to be charged for any billing period beginning after termination.

This clause does not limit any right the Merchant has that cannot be excluded by law. Where the Company has charged in error, or has charged an amount not due under this agreement, the Company will correct it.

6.7 Changes to fees#

The Company may change its fees. An existing Merchant is given at least 30 days written notice before a change applies to them, and may cancel before it takes effect. A fee change is applied through a new charge presented by Shopify for the Merchant's approval, which the Merchant may decline.

6.8 Non-payment#

Where a charge is declined or a subscription lapses for non-payment, the Company may suspend access after giving notice. Data is retained during suspension and is deleted in accordance with clause 9 if the agreement terminates.


7. Availability and support#

The Company will use reasonable efforts to keep the application available and to correct faults reported to it.

No uptime level is guaranteed. The application depends on third-party interfaces and on hosting infrastructure, and may be unavailable during maintenance, during a third-party outage, or for reasons outside the Company's control. The Company will give advance notice of planned maintenance where it is practicable to do so.

Support is provided by email at developer@profitpigeon.com during South African business hours. No response time is guaranteed.

The Company may modify, add to or withdraw features. Where a change removes material functionality the Merchant relies on, at least 30 days notice is given and the Merchant may cancel before the change takes effect.


8. No professional advice#

This clause is important and the Merchant should read it.

Profit Pigeon is a reporting and analysis tool. It presents calculations based on data read from connected accounts and on cost information the Merchant enters.

The application does not provide accounting, auditing, tax, financial, investment or legal advice, and nothing it produces should be treated as such. Its output is not a financial statement, is not prepared in accordance with any accounting standard, and is not a substitute for professional advice or for the Merchant's own accounting records.

The accuracy of the output depends entirely on the accuracy and completeness of the data provided to it. Cost information entered by the Merchant is not verified by the Company. Data read from third-party interfaces may be incomplete, delayed or restated by the third party.

The Merchant is responsible for its own business, tax and financial decisions, and should verify any figure before relying on it for a decision of consequence.


9. Term, termination and what happens to data#

9.1 Term#

The agreement begins when the application is installed and continues until terminated.

9.2 Termination by the Merchant#

The Merchant may terminate at any time, for any reason, by uninstalling the application.

9.3 Termination by the Company#

The Company may terminate on 30 days written notice. The Company may terminate or suspend immediately where the Merchant materially breaches this agreement and does not remedy the breach within 14 days of written notice, where the Merchant's use poses a security or legal risk, or where the Company is required to do so by Shopify or by law.

9.4 Export#

The Merchant may export its data from the application at any time while the agreement is in force.

Following termination, the Merchant's data is retained for 14 days so that an export may be requested and provided. An export requested within that period is provided in a structured, commonly used, machine-readable format.

9.5 Deletion#

The Company deletes the Merchant's store data and cost information within 30 days of the application being uninstalled, and no earlier than the end of the 14-day export period in clause 9.4. Backups containing that data are purged within a further 30 days, so no later than 60 days after uninstall.

Records the Company is required by law to retain, being accounting records under the Companies Act 71 of 2008 and tax records under the Tax Administration Act 28 of 2011, are retained for the period the law requires, are isolated, and are used for no other purpose.

A certificate of deletion is provided on written request at no charge.

9.6 Survival#

Clauses 5.1, 5.2, 5.3, 6.6, 8, 9.4, 9.5, 10, 11, 12, 13, 15 and 16, and Annex A clauses A11 and A17, survive termination.


10. Warranties and disclaimers#

The Company warrants that it will provide the application with reasonable skill and care, and that it has the authority to enter into this agreement.

Beyond that warranty, and to the fullest extent permitted by law, the application is provided as it is and as available. The Company does not warrant that it will be uninterrupted, error free or secure, that faults will be corrected, that it will meet the Merchant's requirements, or that any figure it produces is accurate or complete.

Nothing in this clause excludes a warranty or condition that cannot be excluded under the law applying to the Merchant, including under the Consumer Protection Act 68 of 2008 where it applies.


11. Limitation of liability#

11.1 What is not limited#

Nothing in this agreement excludes or limits either party's liability for:

11.2 Material obligations#

Where the Company breaches a material obligation, being an obligation without which the purpose of this agreement cannot be achieved and on the performance of which the Merchant may reasonably rely, the Company's liability for ordinary negligence is not excluded. It is limited to the loss that was foreseeable and typical for an agreement of this kind at the time it was concluded.

11.3 Exclusion of indirect loss#

Subject to clauses 11.1 and 11.2, and to the fullest extent permitted by law, neither party is liable to the other for loss of goodwill, loss of anticipated savings, or for any indirect or consequential loss, however arising.

11.4 Cap#

Subject to clauses 11.1 and 11.2, and to the fullest extent permitted by law, the Company's total aggregate liability arising out of or in connection with this agreement, whether in contract, delict or otherwise, is limited to the greater of:

11.5 Allocation of risk#

The Merchant acknowledges that the fees reflect the allocation of risk in this clause.

11.6 Local law#

Where the law applying to the Merchant does not permit the exclusions or limitations in this clause, they apply to the maximum extent that law permits, and no further.


12. Indemnities#

12.1 By the Merchant#

The Merchant indemnifies the Company against any third-party claim, and any loss, damage, cost or expense reasonably incurred as a result, arising from:

12.2 By the Company#

The Company indemnifies the Merchant against any third-party claim that the application, as supplied by the Company, infringes that third party's intellectual property rights, and against any loss, damage, cost or expense reasonably incurred as a result. This indemnity is subject to the cap in clause 11.4.

12.3 Procedure#

The party seeking indemnity must notify the other promptly of any claim, must not settle it without the other's consent, and must provide reasonable assistance.

The indemnifying party may assume conduct of the defence, with legal representatives reasonably acceptable to the other party, at its own cost.

An indemnity under this clause is limited to claims actually brought by a third party, and does not extend to any loss caused by the indemnified party's own breach, negligence or misconduct.


13. Confidentiality#

Each party may receive information from the other that is confidential. Each party must keep the other's confidential information confidential, use it only for the purposes of this agreement, and disclose it only to personnel and advisers who need it and who are bound by equivalent obligations.

This does not apply to information that is public through no breach of this clause, that was already lawfully held, that is independently developed, or that must be disclosed by law, in which case the disclosing party gives notice where it is lawful to do so.

These obligations continue for three years after termination, and indefinitely in respect of any information that constitutes a trade secret.


14. Changes to these Terms#

The Company may amend these Terms.

An amendment is material where it increases fees, reduces the functionality the Merchant relies on, reduces the Company's obligations, increases the Merchant's obligations, or changes how personal information is processed. Any amendment the Merchant reasonably identifies as material is treated as material.

Where an amendment is material, the Merchant is given at least 30 days written notice by email and in the application before it takes effect. A Merchant who does not accept a material amendment may terminate before it takes effect by uninstalling the application, and their data is handled in accordance with clauses 9.4 and 9.5.

Amendments that are not material, including corrections and clarifications, take effect on publication.

The current version is always published at profitpigeon.com/terms with its effective date. Previous versions may be requested from developer@profitpigeon.com.


15. General#

15.1 Governing law and jurisdiction#

This agreement is governed by the law of the Republic of South Africa.

The parties submit to the exclusive jurisdiction of the High Court of South Africa, Western Cape Division, Cape Town.

This choice does not deprive the Merchant of the protection of any provision of the law of the Merchant's own country that cannot be derogated from by agreement. Where Annex A incorporates the Standard Contractual Clauses, the governing law and forum stated in those Clauses apply to them.

15.2 Disputes#

Before commencing proceedings, a party must give the other written notice of the dispute and the parties must attempt in good faith to resolve it within 30 days. This does not prevent either party from seeking urgent interim relief.

15.3 Force majeure#

Neither party is liable for a failure to perform caused by an event beyond its reasonable control, including a failure of a third-party service on which the application depends. This does not excuse an obligation to pay.

15.4 Assignment#

The Merchant may not assign this agreement without the Company's written consent, which will not be unreasonably withheld. The Company may assign it to a successor in connection with a merger, acquisition or sale of substantially all of its assets, on written notice to the Merchant.

15.5 Notices#

Notices to the Company go to developer@profitpigeon.com. Notices to the Merchant go to the email address on the Merchant's account, or are given in the application.

15.6 Severability#

Where any provision is held invalid or unenforceable, it is modified to the minimum extent necessary to make it enforceable, and if that is not possible it is severed. The remainder is unaffected.

15.7 No waiver#

A failure to enforce a provision is not a waiver of it.

15.8 Entire agreement#

This agreement, together with Annex A and the Privacy Policy, is the entire agreement between the parties in relation to the application, and replaces any prior discussion or representation.

15.9 Relationship#

The parties are independent contractors. Nothing in this agreement creates a partnership, joint venture, agency or employment relationship.


16. Shopify#

The following applies to every Merchant who obtains the application through Shopify, and is required by the Shopify API License and Terms of Use.

  1. Profit Pigeon (Pty) Ltd is solely responsible for the application.
  2. Shopify is not liable for any fault in the application, or for any harm arising from its installation or use.
  3. Except where Shopify expressly states otherwise, Shopify cannot assist with the installation or use of the application.
  4. Profit Pigeon (Pty) Ltd is solely responsible for any liability arising from the Merchant's access to or use of the application, including the development, marketing, distribution and support of the application, and including the Company's access to, use of, distribution of, or storage of the Merchant's data.

The Merchant's relationship with Shopify is governed by Shopify's own terms. Nothing in this agreement varies them.


Schedule A: Plans#

Plans in effect at the effective date of these Terms. Tiers are based on the number of orders processed in the Merchant's Shopify store per calendar month. Current pricing is published on the Shopify App Store listing and at profitpigeon.com/pricing.

PlanMonthly fee (USD)Orders per month
Starter39Up to 500
Growth79Up to 1,500
Scale129Up to 5,000
Enterprise249Unlimited

All plans include every feature of the application. Plans differ by order volume only.

A free trial of 14 days applies to each plan, as set out in clause 6.3.



Annex A: Data Processing Terms#

Version 1.0. Forms part of the Terms of Service.

A1. Scope#

These Data Processing Terms apply where Profit Pigeon processes Personal Data on the Merchant's behalf. They take effect when the Merchant accepts the Terms of Service and require no separate signature.

They do not apply where Profit Pigeon determines the purposes of processing. Merchant account information, billing information, support correspondence and website visitor information are processed by Profit Pigeon as controller and responsible party, and are governed by the Privacy Policy rather than by this Annex.

These Terms serve four regimes in one instrument. Where a term of one regime conflicts with another, the term giving the higher level of protection to the data subject applies.

RegimeMerchantProfit PigeonWhere addressed
POPIA (South Africa)Responsible partyOperatorA2 to A12, and A13
GDPR and UK GDPRControllerProcessorA2 to A12, and A14
CCPA and US state lawsBusiness or controllerService provider or processorA15
Privacy Act 1988 (Australia)APP entityOverseas recipientA16

A2. Definitions#

Personal Data means personal information or personal data as defined in the applicable law, which Profit Pigeon processes on the Merchant's behalf.

Processing has the meaning given in the applicable law.

Data Subject means the individual to whom Personal Data relates.

Sub-processor means a third party engaged by Profit Pigeon to process Personal Data on its behalf.

Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.

Applicable Data Protection Law means every law relating to the protection of Personal Data that applies to the processing.

A3. Roles and instructions#

A3.1 The Merchant is the Controller and Responsible Party. Profit Pigeon is the Processor and Operator.

A3.2 Profit Pigeon processes Personal Data only on the Merchant's documented instructions, including in relation to transfers to a third country, unless required to process by a law of the European Union, a Member State, the United Kingdom or South Africa to which Profit Pigeon is subject. In that case Profit Pigeon informs the Merchant of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

The Merchant's documented instructions comprise:

Profit Pigeon does not process Personal Data for its own purposes. It does not sell it, does not disclose it to any third party for that third party's own purposes, and does not use it to create, develop, train, fine-tune or improve any artificial intelligence or machine learning system.

A3.3 Where Profit Pigeon considers that an instruction infringes Applicable Data Protection Law, it will inform the Merchant immediately and may suspend performance of that instruction until it is withdrawn, amended or confirmed.

A3.4 The Merchant warrants that it has a lawful basis for the processing it instructs, that it has given every notice and obtained every consent required in relation to the Personal Data, including any notice required by section 18 of POPIA, Articles 13 and 14 of the GDPR and Australian Privacy Principle 5, and that its instructions comply with Applicable Data Protection Law.

Because Profit Pigeon has no direct relationship with the Merchant's customers, the obligation to give those individuals notice rests with the Merchant. Profit Pigeon relies on Article 14(5) of the GDPR in respect of Personal Data not obtained from the Data Subject directly.

The Merchant must not instruct the processing of special personal information as defined in section 26 of POPIA, special categories of data under Article 9 of the GDPR, information concerning criminal conduct, or the Personal Data of children.

A4. Details of the processing#

Set out in Annex A1.

A5. Confidentiality#

Profit Pigeon ensures that every person authorised to process Personal Data is bound by a written obligation of confidentiality, or is under an appropriate statutory obligation of confidentiality. That obligation survives the end of their engagement.

Access to Personal Data is limited to personnel who require it to perform their duties, and is revoked when it is no longer required.

A6. Security#

Profit Pigeon implements and maintains the measures in Annex A2, which are appropriate to the risk and which meet the requirements of section 19 of POPIA, Article 32 of the GDPR and Australian Privacy Principle 11. Those measures are reviewed periodically. Profit Pigeon may change a measure provided the overall level of security is not reduced.

A7. Sub-processors#

A7.1 The Merchant gives general authorisation for Profit Pigeon to engage Sub-processors, subject to this clause.

A7.2 The current Sub-processors, with the purpose and country of each, are published in section 9 of the Privacy Policy at profitpigeon.com/privacy.

A7.3 Profit Pigeon gives at least 30 days notice before a new Sub-processor begins processing Personal Data. Notice is given by email to the Merchant's account address and by updating that section.

A7.4 The Merchant may object to a new Sub-processor on reasonable data protection grounds by writing to developer@profitpigeon.com within 30 days of the notice.

Where an objection is raised, the parties will discuss it in good faith. Where Profit Pigeon is unable to accommodate the objection, the Merchant may terminate the Terms of Service without penalty by uninstalling the application before the new Sub-processor begins processing, and will not be charged for any billing period beginning after termination. This is the Merchant's sole remedy.

A7.5 Profit Pigeon imposes on every Sub-processor, by written contract, data protection obligations no less protective than those in this Annex, and remains fully liable to the Merchant for each Sub-processor's performance.

A8. Assistance with data subject requests#

Taking into account the nature of the processing, Profit Pigeon assists the Merchant by appropriate technical and organisational measures, insofar as possible, in fulfilling the Merchant's obligation to respond to requests to exercise Data Subject rights.

A8.1 Shopify privacy notifications. Where Shopify sends a customers/data_request notification, Profit Pigeon assembles the Personal Data it holds relating to the identified customer and provides it to the Merchant, for the Merchant to give to the customer. Where Shopify sends a customers/redact notification, Profit Pigeon erases or irreversibly de-identifies the records identified. Where Shopify sends a shop/redact notification, Profit Pigeon treats it as confirmation of the deletion instruction and deletes the store's data within 30 days of uninstall, in accordance with clause A11.

Each action is completed within 30 days of the notification, except where retention is required by law. No fee is charged for this assistance.

A9. Assistance with the Merchant's other obligations#

Taking into account the nature of the processing and the information available to it, Profit Pigeon assists the Merchant in complying with its obligations in relation to security of processing, notification of a Personal Data Breach to a supervisory authority and to Data Subjects, data protection impact assessments, and prior consultation with a supervisory authority.

Assistance includes providing Annexes A1 and A2, responding to reasonable security questionnaires, and providing the information necessary for the Merchant to complete an assessment.

A10. Personal Data Breach#

Profit Pigeon notifies the Merchant of a Personal Data Breach affecting the Merchant's Personal Data immediately, and in any event without undue delay. The Company's internal target is notification within 24 hours of becoming aware.

The notification includes, to the extent known at the time and supplemented as further information becomes available, the nature of the breach including the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for further information.

Profit Pigeon does not notify a supervisory authority or any Data Subject on the Merchant's behalf unless the Merchant instructs it to do so in writing, because the Merchant has the direct relationship with the Data Subjects and the notification obligation rests with them.

Profit Pigeon maintains a record of every Personal Data Breach.

A11. Deletion and return#

On termination of the Terms of Service the Merchant may elect return of its Personal Data, by export, or deletion. Absent an election, the Personal Data is deleted.

Profit Pigeon retains Personal Data beyond that point only where required by law. Any Personal Data so retained is isolated, is protected by the measures in Annex A2, is processed for no purpose other than compliance with that legal requirement, and is deleted when the requirement ends.

A certificate of deletion is provided on written request at no charge.

A12. Audit#

Profit Pigeon makes available to the Merchant the information necessary to demonstrate compliance with this Annex, and allows for and contributes to audits and inspections conducted by the Merchant or by an independent auditor mandated by the Merchant and reasonably acceptable to Profit Pigeon.

In the first instance this is satisfied by providing Annexes A1 and A2, the published Sub-processor list, and a completed response to a reasonable security questionnaire.

Where that is not sufficient, an audit may be conducted subject to the following conditions:

A13. POPIA operator terms#

A14. European Union and United Kingdom transfers#

A14.1 No adequacy decision. South Africa is not the subject of an adequacy decision under Article 45 of the GDPR, and is not covered by adequacy regulations under the UK GDPR.

A14.2 Standard Contractual Clauses. The Standard Contractual Clauses adopted by European Commission Implementing Decision (EU) 2021/914 are incorporated into this Annex and are deemed executed by both parties on acceptance of the Terms of Service.

Module Two (Controller to Processor) applies to transfers from the Merchant to Profit Pigeon where the Merchant is a controller. Module Three (Processor to Processor) applies to those transfers where the Merchant is itself a processor.

Onward transfers to Sub-processors are governed by Clause 8.8 of the Clauses, on the basis of clauses concluded directly between Profit Pigeon and the Sub-processor providing an equivalent level of protection.

The Clauses are completed as follows:

ClauseSelection
Clause 7 (docking)Applies
Clause 9 (sub-processors)Option 2, general written authorisation, notice period 30 days
Clause 11 (redress)The optional independent dispute resolution provision does not apply
Clause 17 (governing law)The law of Ireland
Clause 18 (forum)The courts of Ireland
Annex I.A (parties)The Merchant as data exporter, Profit Pigeon (Pty) Ltd as data importer, with the contact details in the Terms of Service and clause A18
Annex I.B (description of transfer)Annex A1
Annex I.C (supervisory authority)Determined in accordance with Clause 13(a). Where the data exporter is established in an EU Member State, the supervisory authority of that Member State. Where the data exporter is not established in an EU Member State but falls within Article 3(2) and has appointed a representative under Article 27(1), the supervisory authority of the Member State in which the representative is established. Where the data exporter is not established in an EU Member State but falls within Article 3(2) without appointing a representative, the supervisory authority of a Member State in which the data subjects are located.
Annex II (security measures)Annex A2
Annex III (sub-processors)Section 9 of the Privacy Policy at profitpigeon.com/privacy

A14.3 United Kingdom. The International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the Information Commissioner under section 119A of the Data Protection Act 2018 is incorporated and is deemed executed on acceptance of the Terms of Service. Tables 1 to 3 are completed by reference to clause A14.2, and in Table 4 neither party may end the Addendum as set out in section 19 of it.

A14.4 Transfer impact assessment. Profit Pigeon has assessed the law and practice of South Africa as it affects the transfer, covering in particular the Regulation of Interception of Communications and Provision of Communication-Related Information Act 70 of 2002, POPIA, and the supplementary measures in Annex A2. The assessment is available to the Merchant on request at developer@profitpigeon.com.

As at the effective date of these Terms, Profit Pigeon has received no request from a public authority for access to Personal Data processed under this Annex. Where such a request is received, Profit Pigeon will challenge it where there is a lawful basis to do so, will disclose only the minimum required, and will notify the Merchant unless legally prohibited from doing so.

A14.5 Article 27 representatives. Profit Pigeon's position on representatives under Article 27 of the GDPR and Article 27 of the UK GDPR is set out in section 2.1 of the Privacy Policy. Where a representative is appointed, it will be named there and Merchants will be notified.

A14.6 Copies. A copy of the Standard Contractual Clauses and the United Kingdom Addendum as completed may be requested from developer@profitpigeon.com at no charge.

A15. United States service provider terms#

Profit Pigeon is a service provider, and where a state law uses that term, a processor. Profit Pigeon:

  1. Does not sell or share Personal Data, as those terms are defined in the applicable state law.
  2. Processes Personal Data only for the limited and specified business purpose of providing the application to the Merchant, as described in Annex A1.
  3. Does not retain, use or disclose Personal Data for any purpose other than that business purpose, and does not retain, use or disclose it for a commercial purpose other than providing the application.
  4. Does not retain, use or disclose Personal Data outside the direct business relationship between Profit Pigeon and the Merchant.
  5. Does not combine Personal Data received from the Merchant with Personal Data received from any other source, except as permitted by the applicable law.
  6. Complies with the obligations applicable to it under the applicable state law and provides the same level of protection it requires.
  7. Grants the Merchant the right to take reasonable and appropriate steps to confirm that Personal Data is used consistently with these obligations, as set out in clause A12, including an audit no more than once in any 12-month period.
  8. Notifies the Merchant without undue delay where it determines that it can no longer meet these obligations.
  9. Grants the Merchant the right, on notice, to take reasonable and appropriate steps to stop and remediate any unauthorised use of Personal Data.
  10. Enables the Merchant to comply with consumer requests, as set out in clause A8.

A16. Australian terms#

Profit Pigeon is an overseas recipient. This Annex is the enforceable contract by which the Merchant takes the steps required by Australian Privacy Principle 8.1.

Profit Pigeon will not do any act, or engage in any practice, that would breach the Australian Privacy Principles were those principles to apply to it directly. This applies in particular to APP 6, APP 8, APP 10, APP 11 and APP 12.

Profit Pigeon will assist the Merchant in complying with the Notifiable Data Breaches scheme, including by providing the information required for a statement under section 26WK within the timeframes in clause A10. The Merchant ordinarily notifies the Office of the Australian Information Commissioner and the affected individuals, as the party with the direct relationship with them.

A17. General#

Liability. The limitations and exclusions in clause 11 of the Terms of Service apply to this Annex. They do not limit any liability that cannot be limited under Applicable Data Protection Law, including a Data Subject's right to compensation.

Changes. Profit Pigeon may amend this Annex where necessary to comply with Applicable Data Protection Law or to reflect a change in the service. Clause 14 of the Terms of Service applies to any such amendment.

Term. This Annex takes effect on acceptance of the Terms of Service and continues until all Personal Data has been deleted or returned under clause A11.

Precedence. Where the Standard Contractual Clauses conflict with any other term of this Annex or the Terms of Service, the Standard Contractual Clauses prevail.

A18. Contact#

Data protection contact: developer@profitpigeon.com
Information Officer: Theo van Wyk
Address: Profit Pigeon (Pty) Ltd, Unit 201 Masons Press, Woodlands Road, Woodstock, Cape Town, Western Cape, 7925, South Africa
Registration number: 2026/196128/07


Annex A1: Details of the processing#

Subject matter. The provision of the Profit Pigeon profit analytics application to the Merchant.

Duration. For as long as the Terms of Service remain in force, plus the periods in clause A11.

Nature of the processing. Reading data from the Merchant's connected Shopify and advertising accounts through their respective interfaces, receiving cost information the Merchant enters, storing that data, computing profit and performance metrics from it, and displaying those metrics to the Merchant and to users the Merchant authorises. Storage, structuring, retrieval, use, aggregation, anonymisation and erasure.

Purpose of the processing. To provide the Merchant with profit reporting, cost tracking, target setting and sensitivity analysis in respect of the Merchant's own business, and to produce irreversibly anonymised statistical information as instructed under clause A3.2. No other purpose.

Categories of Data Subject. The Merchant's customers, in respect of pseudonymous order records only.

Merchant account and authorised-user data is processed by Profit Pigeon as controller and is outside the scope of this Annex. See section 5 of the Privacy Policy.

Categories of Personal Data.

CategoryDetail
Pseudonymous customer identifiersThe Shopify customer identifier and customer order index, used solely to classify an order as being from a new or returning customer. No name, email address, telephone number or postal address is processed.
Order recordsOrder identifiers, timestamps, values, taxes, discounts, currency, line items, product and variant identifiers, quantities, unit prices and costs, refunds, shipping amounts, payment gateway identifiers and transaction fees
Advertising recordsAdvertising account, campaign, ad set and ad identifiers and names, spend, currency, spend date, impressions, clicks, conversions
Merchant-entered cost dataCost line descriptions, amounts, targets, notes and annotations. Merchants are prohibited by clause 2.3 of the Terms of Service from entering personal information into these fields. Any personal information appearing there does so contrary to instruction and is deleted on discovery or on the Merchant's request.

Special categories of data. None. The Merchant is prohibited from routing special categories of data, information concerning criminal conduct, or the Personal Data of children through the application.

Frequency of transfer. Continuous, by webhook as events occur in the Merchant's store, and by scheduled synchronisation for advertising data.

Retention. As set out in clause A11 and section 11 of the Privacy Policy.

Sub-processors. As published in section 9 of the Privacy Policy, with the purpose and country of each.

Location of processing. South Africa (AWS af-south-1, Cape Town), together with the sub-processor locations recorded in section 9 of the Privacy Policy.

Competent supervisory authority. For POPIA, the Information Regulator (South Africa). For the Standard Contractual Clauses, as set out in clause A14.2.


Annex A2: Technical and organisational measures#

Encryption#

Access control#

Segregation#

Network and application security#

Resilience#

Organisational measures#

Data minimisation#

Deletion#