Data processing addendum
Effective October 6, 2026
The short version. Olympus is built so your customers' data stays in your own Railway project, and we never hold it. In a few narrow places oldbones.ai handles it on its way to your Olympus: Shopify's access tokens during connection, and Shopify's privacy notices about your customers. This addendum covers those, and commits us to handling them only for you, securely, and not keeping them.
1. Parties and scope
This addendum is part of the terms of service between you (the merchant) and Old Bones Therapy, Inc. ("we"). It applies when oldbones.ai processes personal data about your customers on your behalf ("your customer data"). For that processing you are the controller (or "business") and we are your processor (or "service provider"). It doesn't cover your own account details, such as your email, which our privacy policy covers.
Most of Olympus's processing of your customer data happens in your Olympus, in your Railway account, under your control. We have no access to it and are not its processor.
2. What we process
| Subject matter | Connecting your Shopify store to your Olympus, and passing Shopify's notices to it |
|---|---|
| Nature | Receiving, exchanging and passing on; never storing beyond what Section 6 allows |
| Data subjects | Your customers, as named in Shopify's notices |
| Data | Shopify access tokens for your store; the customer identifiers, and any contact details Shopify includes, in privacy notices (requests to see or delete a customer's data) |
| Duration | Only as long as each request takes. A record that a notice arrived (shop, type and time) is kept 12 months |
3. Only on your instructions
We process your customer data only to provide the services, as these terms and your use of Olympus instruct, or where the law requires it (in which case we'll tell you first unless the law prevents it). We won't sell it, share it for advertising, combine it with other data, or use it for any other purpose. We'll tell you if we think an instruction breaks data protection law.
4. Confidentiality
Only people who need to run the services can access systems handling your customer data, and they're bound to keep it confidential.
5. Security
We protect your customer data with measures suited to the risk, including: HTTPS for all traffic; requests between oldbones.ai and your Olympus signed with a key only the two share; Shopify tokens held only in memory and never written to storage; stored data encrypted at rest by our hosting provider; and access to our systems limited to the people who run them.
6. Deletion
We don't keep your customer data beyond each request. When these terms end, nothing of it remains with us to return or delete, except the 12-month record of notices described in Section 2, which holds no customer details.
7. Subprocessors
You authorize these subprocessors, which host or carry the services: Railway (hosts oldbones.ai) and Cloudflare (DNS and network). We bind each to data protection terms at least as protective as this addendum and remain responsible for them. We'll update this page at least 30 days before adding one, and you may object by emailing us; if we can't resolve the objection, you may end the terms.
8. Helping you
We pass every privacy request Shopify sends about your customers to your Olympus, which answers from the data it holds and deletes what it must. We'll give you reasonable help with other requests from your customers, and with any data protection assessment or regulator inquiry that concerns the services.
9. Breaches
If we become aware of a breach affecting your customer data, we'll tell you without undue delay, and within 72 hours, with what we know and what we're doing about it, and keep you updated.
10. Information
On request, we'll give you the information you reasonably need to show that we meet this addendum, such as answers to security questionnaires.
11. International transfers
We process your customer data in the United States. Where the law of the European Economic Area, Switzerland or the UK requires safeguards for that, the EU Standard Contractual Clauses (controller to processor, module two), with the UK addendum where it applies, are incorporated into this addendum.
12. California
As your service provider under the California Consumer Privacy Act, we won't sell or share your customer data, retain, use or disclose it outside our direct business relationship with you or for any purpose other than providing the services, or combine it with personal information from other sources, except as the CCPA allows.
13. Precedence
If this addendum conflicts with the terms of service on the processing of your customer data, this addendum wins.