Effective July 23, 2026
This Data Protection Agreement ("Agreement") is between Nehemiah Apps ("Processor," "we," "us") and the merchant installing the Bloomly application on their Shopify store ("Merchant," "you," "Controller"). It applies automatically from the point Bloomly is installed on your store, and describes how we process personal data belonging to your customers on your behalf.
For the personal data described in this Agreement, you are the data controller and Nehemiah Apps is the data processor. We process this data only to provide the Bloomly service to you, and only under your instructions as expressed through your use and configuration of the app.
On your behalf, Bloomly processes recipient details (name, phone, delivery address type, delivery instructions), card messages, sender information, occasion and substitution data, any custom fields you've configured, video greeting links or files, and — if you use the occasion-reminder feature — your buyers' Shopify customer ID, email, and name. This is described in full in our Privacy Policy, which forms part of this Agreement by reference.
We process this data solely to: render the recipient-details form on your product pages, carry recipient details into resulting orders, display and print gift cards and worksheets, run pre-print error checks, generate video-greeting QR codes, and (only if you enable it) surface occasion reminders or run spelling/translation checks that you explicitly trigger and approve.
We treat all personal data processed through Bloomly as confidential, and limit access to it to what's needed to operate and support the service.
We encrypt data in transit (HTTPS/TLS) between your storefront, your admin, and our servers, encrypt recipient/sender details, card messages, and buyer identity at rest in our database, apply the retention periods described in our Privacy Policy, and maintain access controls over our infrastructure appropriate to the size and nature of the data we process.
We use the following subprocessors to provide the Bloomly service:
| Subprocessor | Purpose |
|---|---|
| Shopify | Platform the app is built on; order and customer data originates from Shopify |
| Our hosting provider | Runs the application server and database |
| Anthropic | Processes card message text only when you explicitly trigger a spelling-check or translation action |
We'll update this list and notify you of material changes to it.
Bloomly implements Shopify's mandatory data protection webhooks (customer data request, customer redaction, shop redaction), which give you the tools to respond to your customers' data rights requests. We'll assist you with requests that require our direct involvement.
If we become aware of a security incident affecting personal data processed through your store, we will notify you without undue delay after becoming aware of it, and provide the information reasonably available to us about the incident.
Personal data is retained per the schedule in our Privacy Policy — recipient phone, card message, and custom fields are deleted automatically 90 days after an order is marked Completed; buyer identity used for occasion reminders is retained longer by design, but is deleted immediately upon an explicit customer redaction request.
Uninstalling the app does not, by itself, trigger deletion of previously processed data — it remains subject to the retention schedule above. If you'd like your store's data deleted following uninstallation, contact us at the address below and we will process that request.
You are responsible for: (a) having a lawful basis to collect and share your customers' personal data with us for the purposes described in this Agreement; (b) obtaining any consents or providing any notices required under laws applicable to your business beyond what Bloomly's built-in mechanisms provide; and (c) reviewing content your customers submit through the app (card messages, custom field values, video greeting links) before it is printed, displayed, or otherwise acted on — we do not monitor, endorse, or pre-screen this content.
Bloomly is designed to reduce common data-entry and delivery-communication errors, but we do not guarantee error-free order fulfillment, delivery, or printing outcomes, and we are not liable for delivery failures, printing errors, or business losses arising from your own configuration or use of the app, or from content your customers submit.
To the maximum extent permitted by applicable law, Nehemiah Apps' total aggregate liability arising out of or related to this Agreement is limited to the fees you paid us in the 12 months preceding the claim, and Nehemiah Apps is not liable for any indirect, incidental, consequential, special, or punitive damages, or for lost profits, revenue, or data, even if advised of the possibility of such damages. Nothing in this section limits liability that cannot be limited under applicable law.
You agree to indemnify and hold Nehemiah Apps harmless from any claim, loss, or damage (including reasonable legal fees) arising from: (a) your violation of applicable law in connection with your use of the app; (b) content you or your customers submit through the app that is unlawful or infringes a third party's rights; or (c) your failure to meet the responsibilities described in Section 9.
This Agreement is between Nehemiah Apps and you. It does not create any rights for your customers or any other third party to bring a claim against Nehemiah Apps directly under this Agreement — their statutory data protection rights (Section 6) remain unaffected.
This Agreement remains in effect for as long as Bloomly is installed on your store, and survives with respect to any data retained afterward per Section 8 and any obligations that by their nature should survive (including Sections 11, 12, and 13).
This Agreement is governed by the laws of the Republic of the Philippines, without regard to conflict-of-law principles. Any dispute arising from this Agreement will first be raised with the other party in good faith and, if unresolved within 30 days, is subject to the exclusive jurisdiction of the courts of the Philippines, except as otherwise set out in our Terms of Service.
If any part of this Agreement is found unenforceable, the rest remains in effect. This Agreement, together with our Privacy Policy and Terms of Service, is the entire agreement between us regarding personal data processing, and supersedes any prior understanding on that subject. We may update this Agreement from time to time and will post the revised version at this address; material changes will be highlighted. Nehemiah Apps may assign this Agreement in connection with a merger, acquisition, or sale of its business.
Nehemiah Apps
support@nehemiahapps.com