Data
Processing

How Arnio Processes Merchant Data

This Data Processing Agreement governs how Arnio processes personal data on behalf of merchants. Arnio acts as a data processor. Merchant Data belongs to the Merchant. This DPA is designed for compliance with GDPR, UK GDPR, CCPA, and other applicable data protection laws.


1. Purpose & Scope

This Data Processing Agreement ("DPA") governs how Arnio Inc. ("Arnio") processes personal data on behalf of merchants ("Merchant") who use the Arnio platform. It supplements and forms part of the Arnio Terms of Service.

Arnio processes Merchant Data solely to provide the services described in the Terms of Service. This DPA reflects both parties' obligations under applicable data protection law.

2. Definitions

  • "Merchant Data" means any personal data processed by Arnio on behalf of the Merchant in connection with the Arnio service.
  • "Shopper Engagement Signals" means Behavioral Data collected by Arnio's tracking script, including page views, product interactions, cart activity, and session-level events.
  • "Behavioral Data" means anonymized or pseudonymized activity data collected from visits to a Merchant's storefront.
  • "Customer-specific Insights" means derived analysis or classifications generated from a specific Merchant's Shopper Engagement Signals.
  • "Data Protection Laws" means GDPR, UK GDPR, CCPA, CPRA, and any other applicable data protection legislation.
  • "Subprocessor" means a third-party service provider engaged by Arnio to assist in processing Merchant Data.
  • "Data Subject" means the individual to whom Merchant Data relates.
  • "Personal Data Breach" means unauthorized access to, accidental loss of, or unlawful destruction of Merchant Data.

3. Roles of the Parties

Arnio acts as a data processor. The Merchant acts as the data controller.

Arnio processes Merchant Data only on documented instructions from the Merchant, as set out in this DPA and the Arnio Terms of Service. Arnio will inform the Merchant if it believes an instruction violates applicable law.

4. Scope of Processing

Arnio processes Merchant Data for the following purposes only:

  • Collecting Shopper Engagement Signals on the Merchant's storefront via the Arnio tracking script.
  • Analyzing Behavioral Data to generate intent scores and shopper classifications.
  • Routing high-intent shoppers into the Merchant's connected platforms, including Klaviyo.
  • Providing the Arnio dashboard, reporting, and activity features.
  • Ensuring platform security, reliability, and performance.

Arnio will not process Merchant Data for any other purpose without the Merchant's explicit written instruction.

5. Categories of Data Processed

Arnio may process the following categories of Merchant Data:

  • Anonymous visitor identifiers (no persistent cross-site tracking).
  • Session-level Shopper Engagement Signals: pages viewed, products viewed, collection views, cart activity, checkout events.
  • Traffic attribution data: UTM parameters, referrer URLs, ad click identifiers (GCLID, FBCLID, TTCLID).
  • Country derived from IP address. IP addresses are not stored.
  • Shopper identity signals received from Shopify, Klaviyo, or checkout, when available.
  • Derived intent scores and shopper classifications.

6. Merchant Ownership of Data

Merchant Data belongs to the Merchant. Arnio claims no ownership of Merchant Data, Shopper Engagement Signals, or Customer-specific Insights.

Upon termination of the Arnio service, Merchant Data will be returned or deleted at the Merchant's election within 30 days. Written certification of deletion is available on request.

7. Technical & Organizational Security Measures

Arnio implements appropriate technical and organizational measures to protect Merchant Data, including:

  • TLS 1.2+ encryption for all Merchant Data in transit.
  • AES-256 encryption for Merchant Data at rest.
  • Role-based access controls with least-privilege enforcement.
  • Multi-factor authentication required for all team members with access to production systems.
  • Logical isolation of Merchant Data by merchant identifier.
  • Automated backups with verified integrity.
  • Regular vulnerability assessments and dependency auditing.

A full description of Arnio's security measures is available in the Arnio Security Overview at arnio.co/security.

8. Confidentiality

Arnio ensures that all personnel authorized to access Merchant Data are subject to confidentiality obligations. Access is limited to individuals who require it to perform their role.

Confidentiality obligations apply during and after the end of each individual's engagement with Arnio.

9. Subprocessors

Arnio engages third-party subprocessors to assist in delivering its services. By agreeing to the Arnio Terms of Service, the Merchant provides general authorization for Arnio to use subprocessors.

Arnio will notify the Merchant at least 30 days before adding or replacing a subprocessor. Data protection obligations no less protective than those in this DPA are imposed on all subprocessors, and Arnio remains liable to the Merchant for each subprocessor's performance.

A current list of Arnio's subprocessors is available on request at:

security@arnio.co

10. AI & Data Usage

Arnio uses machine learning models to generate intent scores and shopper classifications from Shopper Engagement Signals. These models are operated solely to provide the Arnio service to the Merchant from whose storefront the data was collected.

Merchant Data and Shopper Engagement Signals are never:

  • Used to train public AI or machine learning models.
  • Shared with other merchants or used to build Customer-specific Insights for other merchants.
  • Sold to third parties, data brokers, or advertising networks.

Aggregated, anonymized platform analytics (system performance metrics, error rates, and feature usage patterns) may be used to improve Arnio's reliability and security. This data cannot be used to identify individual merchants or shoppers.

11. Identity Resolution

Visitors to a Merchant's storefront remain anonymous until an authorized identity signal is received. Arnio does not infer, guess, or purchase identity.

Authorized identity signals include:

  • Shopify customer data, when the shopper is logged in or has previously completed a purchase.
  • Checkout data (name and email) when submitted by the shopper during a transaction.
  • Klaviyo profile data, when the shopper has engaged with the Merchant's Klaviyo communications.

Identity resolution is performed within the Merchant's account only. A shopper identified in one Merchant's account is never used to populate another Merchant's account.

12. Data Subject Rights

Arnio will assist the Merchant in fulfilling obligations to respond to Data Subject requests under applicable law, including:

  • Right to access their personal data.
  • Right to rectification of inaccurate data.
  • Right to erasure of personal data.
  • Right to restriction of processing.
  • Right to data portability.
  • Right to object to processing.

Data Subject requests may be submitted to hello@arnio.co or through the Merchant's Arnio account.

13. Breach Notification

In the event of a confirmed Personal Data Breach affecting Merchant Data, Arnio will notify the affected Merchant within 48 hours of discovery. Notification will include:

  • The nature and likely cause of the breach.
  • Categories of Merchant Data involved.
  • Estimated number of affected records.
  • Measures taken or planned to address the breach.

14. Data Retention

Arnio retains Merchant Data for the duration of the active service relationship, and for up to 90 days following termination to allow for data export and transition.

After the retention period, Merchant Data is deleted unless the Merchant has requested earlier deletion or applicable law requires a longer retention period.

15. Data Deletion

Merchants may request deletion of all Merchant Data at any time by contacting Arnio at hello@arnio.co or through the Arnio dashboard.

Deletion will be completed within 30 days of the request. Written certification of deletion is available on request.

16. International Data Transfers

Arnio primarily processes Merchant Data in the United States. If Merchant Data is transferred to a jurisdiction without adequate data protection standards, Arnio will ensure appropriate safeguards are in place, including Standard Contractual Clauses where required by applicable law.

17. Contact Information

Questions about this DPA, to request a signed copy, or to submit a Data Subject request:

hello@arnio.co

Last updated: July 2026 · Arnio Inc. · Austin, Texas