Shopify mandates a GDPR-compliant privacy policy and a Data Processing Agreement for every app accessing customer data. WordPress.org and AppSumo are heading the same direction. Rowpa generates yours in under an hour and publishes a Trust Center URL you can link from your app listing.
You built an app. You list it on Shopify or WordPress.org. EU and UK merchants install it. Now you're a data processor with hundreds of merchant tenants, each of whom has their own customers. Compliance webhooks must redact customer data on request. Your privacy notice must explain processing, retention, and sub-processors. Your DPA must be available, current, and signed.
Most indie ecosystem developers don't have this. Most haven't been audited yet. The first audit will be expensive.
Free - 1 user, unlimited activities and vendors, and you can preview a whole pack before paying to send it. Starter £34/mo - unlimited ROPA, full vendor library, Trust Center URL, public DPA hosted. Business (£79) only if you're running ads and need the site scanner.
Build the record free. Pay only when you send something. No credit card.
Start free