WATCHWICK / TRUST & TRANSPARENCY
Data processing terms
Updated: 9 October 2026 · Operates on Oracle Cloud (Hyderabad, India)
These terms describe Watchwick's current processing arrangements and the information needed for a merchant data processing agreement. They are not a certification of legal compliance, an executed set of Standard Contractual Clauses, or proof of an agreement with a provider.
Where a binding DPA or international-transfer instrument is required, the merchant and Watchwick must review and execute the applicable agreement with completed party, processing and security details before the relevant processing begins. Contact legal@watchwick.com. The operational summary below does not supply missing legal approvals or contractual signatures.
1. Parties and scope
Watchwick is operated by Duvvuru Shathwik Reddy, trading as Watchwick, in Hyderabad, India (Udyam UDYAM-TS-20-0220111). For store monitoring, the merchant determines the purpose and Watchwick provides synchronization, exception detection, baselines, incident evidence and configured notifications. Website analytics, business enquiries and account administration have separate responsibilities described in the privacy policy.
Documented service instructions include the authorized installation, enabled monitors, thresholds, business hours, permitted staff roles and notification settings. Watchwick does not automatically fulfill orders, capture payments, issue refunds or change inventory. Shopify billing and bulk read-job administration use their required API operations without changing commerce records.
2. Data and people
Processing covers operational order/fulfillment/payment/refund/catalog/inventory/location records and linked identifiers; staff user IDs, verified email, roles, flags and audit history; encrypted authentication/Slack credentials; and merchant-authored notes or references. Operational identifiers can be linked to customers by the merchant, so they are not treated as necessarily anonymous.
Operational queries exclude direct customer name, email, phone and address fields. Tracking strings are transiently received for counting and discarded during normalization. Mandatory privacy webhooks can transiently contain customer identity fields, which are discarded rather than persisted as customer profiles. Merchant-entered free text must avoid unnecessary personal information.
3. Controls and assistance
Current controls include tenant transactions and row-level policies, role checks, encrypted Shopify/Slack tokens, public HTTPS/HSTS, minimized webhook persistence, append-only tenant audit history and CSV formula-prefix protection. These are scoped controls, not an absolute confidentiality guarantee or a security certification.
Privacy and security requests should be sent to privacy@watchwick.com and security@watchwick.com. Applicable access, deletion, incident-notification and audit obligations must be addressed in the executed agreement and operating procedures. No fixed breach response SLA or appointed Data Protection Officer is represented by this page.
4. Duration, deletion and return
Store processing lasts through the authorized installation and the deletion period described in the privacy policy. On uninstall, the service marks the store inactive and deletes Shopify sessions/Slack credentials. A valid shop/redact request deletes live store records; an hourly fallback selects uninstalled stores older than 48 hours. Completion is recorded and failures require retry and monitoring; there is no promise of an exact 48-hour maximum.
Routine record cleanup runs daily at the age thresholds in the privacy policy. Encrypted backups expire through scheduled 14-day purge and may contain earlier records until expiry. Restores must reconcile recorded deletions while offline. Previously delivered email/Slack copies follow provider/recipient retention controls. Export permissions and the scope of an access/return request must be agreed and verified.
5. Providers and transfers
Primary production hosting/database storage is on OCI in Hyderabad, India. The public provider register describes configured, optional and website providers and must be reconciled with actual contracts and account settings. Merchant notification permissions do not themselves establish a legal transfer mechanism.
For an applicable restricted transfer, determine the correct mechanism, assess the transfer and complete the relevant annexes/security details. EU SCCs may be relevant to an EEA transfer; a UK transfer can require a UK Addendum, IDTA or another applicable safeguard. This page does not claim that those instruments or provider DPAs have already been executed. Material provider changes and objection/notice arrangements must be addressed in the applicable agreement.
6. Review and agreement
Ask legal@watchwick.com for the applicable merchant agreement and processing details. Provide the jurisdictions and processing context needed for review, without sending real customer records. Before using Watchwick where a DPA or transfer safeguard is required, complete that review and agreement rather than assuming this public summary is a signed instrument.