Cados Publish Matrix
Data Processing Addendum
Last updated: August 1, 2026
This addendum describes the processing performed by Cados Publish Matrix for a Shopify merchant and supplements the Terms of Service. The merchant determines why the app is used and acts as the controller or business for merchant-provided data. The app operator acts as the processor or service provider for the limited processing described below.
Subject matter and instructions
Processing is limited to operating the merchant-requested publication workflow: authenticate the user, read supported publication state, create a preview, apply confirmed Boolean changes, verify results, retain a bounded history, and evaluate an eligible undo. The merchant's use of the app and confirmed actions are its documented instructions.
Data categories
Processed data can include shop and session identifiers, authentication session records, and a limited acting-user reference. When Shopify returns them for an online session, the session record can include the staff user ID, first and last name, email, locale, and account-owner, collaborator, and email-verification flags.
Other processed data can include product and variant identifiers and display evidence, publication identifiers and values, parent-publication context, attempt and verification status, pair coordination metadata, webhook receipt metadata, bounded error codes, and operational timestamps.
The service is not designed to receive or use Shopify customer records, orders, payment information, checkout information, or shipping information. Customer data request and redact webhooks are authenticated no-ops because no customer data is stored by the app.
Service providers and platform
Vercel provides application hosting and execution. Neon provides managed PostgreSQL storage. Shopify provides the commerce platform, authentication, webhooks, and Admin GraphQL API. The app operator remains responsible for limiting its providers' access to what is needed to deliver these services.
Application Functions are configured to execute in Vercel's Singapore region. Operational database records are stored by Neon in AWS US East (N. Virginia). This means operational data can be transferred between Singapore and the United States and can also be processed by these providers and their disclosed subprocessors in the locations where they operate.
The current Vercel Pro runtime-log window is one day and no external log drain is configured for this project. Neon Free provides a self-service point-in-time restore window of up to six hours or 1 GB of data changes, whichever comes first. The app operator has not configured a separate application-managed database backup export. Neon separately states that it performs daily encrypted, multi-availability-zone backups and retains backup data for 30 days.
Confidentiality and security
The app uses scoped Shopify authentication, tenant-bound database records, authenticated webhooks, and allowlisted structured logging. Application log records contain normalized allowlisted fields. Server render failures are reduced to a bounded error-class code rather than passing a raw error message or stack to the application logger. Access tokens, raw GraphQL responses, raw webhook payloads, and customer data are not copied into publication-change business tables. Merchants should not send those materials in support requests.
Retention, return, and deletion
Publication-change history has a nominal 30-day expiry. A foreground apply, undo, recovery, or reconciliation operation can be claimed only before that deadline. With fewer than five minutes remaining, only that job's expiry moves to five minutes after the claim and never beyond preview time plus 30 days and five minutes. A request at or after the nominal deadline cannot claim the job, and no later claim can renew the grace. Expired history is removed by a subsequent tenant-scoped maintenance pass when the merchant opens the authenticated embedded app. Inactive pair-coordination records that are not marked uncertain become cleanup-eligible 30 days after lease expiry and are removed during the same foreground pass.
An unresolved uncertain-operation quarantine is excluded from generic inactive-record cleanup. A current-state check can reconcile that exact operation earlier. Otherwise, expiry cleanup removes it with its expired job only when the shop, variant, publication, and attempt token match; a newer or different operation for the same pair is preserved.
Webhook receipt metadata receives a seven-day expiry marker. After Shopify authenticates a later webhook, the receipt-claim path removes expired ordinary receipts and completed lifecycle tombstones. Because this is opportunistic rather than a recurring background job, physical deletion can occur after the marker if no later authenticated webhook arrives. Failed or processing uninstall/shop-redact evidence is excluded until verified resolution. A successful uninstall or shop-redact transaction replaces the current receipt's shop hash with a shop-unlinked delivery tombstone for that bounded period.
Shopify-authenticated AppInstallation IDs establish immutable local installation generations. A session credential change atomically clears its prior generation binding; only the exact stored credential can re-confirm and bind the current installation. A changed authority retires the prior generation and removes its application records and sessions. An authenticated app-uninstalled webhook can delete only its receipt-bound generation outside a ten-minute local/Shopify clock margin; the margin remains pending. Shopify documents shop-redact as arriving 48 hours after uninstall. The app combines that schedule with the immutable first receipt time and generation. A positively confirmed live or clearly later generation is preserved; a same-generation missed uninstall is deleted after a ten-minute settlement period and a strictly older causal-time proof. The clock-skew band remains retryable for one hour, then is deleted unless an exact live installation is confirmed. A preserved live or later generation also converts its pending uninstall receipt into an unlinked completed tombstone. A missing session or 401 response alone never authorizes immediate deletion. A currently installed but unconfirmable app can lose app-held records at the one-hour privacy boundary and must reopen or reauthorize to establish a new local generation. Unresolved lifecycle receipt evidence is retained outside generic expiry pruning until conclusively resolved. The exact completed receipt clears its generation link and remains only as the bounded shop-unlinked tombstone used to deduplicate a response retry.
Publication values written through Shopify are held by Shopify, not in the app database. Deleting app data or uninstalling Cados Publish Matrix does not reverse those values or restore their original publication timestamps.
Requests and assistance
The app operator will provide reasonable assistance concerning the limited data it processes, subject to the merchant's verified instructions and applicable obligations. Send data-processing questions to cadosy@gmail.com.