Days of Cover Terms of Service and Data Processing Agreement

Effective Date: July 29, 2026 · Last Updated: August 4, 2026 · Version: 1.2

The version and date above are the operative ones. This document incorporates the Days of Cover Privacy Policy by reference.


Part A: Terms of Service

1. Parties; Acceptance

1.1. These Terms of Service (these "Terms") constitute an agreement between WeLynk LLC, a limited liability company organized under the laws of the State of Alabama (the "Company," "we," "us," or "our"), and the Shopify merchant that installs or uses Days of Cover (the "Merchant," "you," or "your").

1.2. Installation of Days of Cover (the "Service") constitutes acceptance of these Terms. A Merchant that does not accept these Terms must not install or use the Service.

1.3. Governing law and venue. These Terms are governed by the laws of the State of Alabama, United States, without regard to its conflict-of-laws rules. The parties submit to the exclusive jurisdiction of the state and federal courts located in Alabama for any dispute arising out of or relating to these Terms. The United Nations Convention on Contracts for the International Sale of Goods does not apply.


2. The Service

2.1. The Service reads a Merchant's Shopify catalog, inventory, and order history, and presents recommendations as to which products to reorder, at what time, and in what quantity, together with the arithmetic from which each recommendation was derived.

2.2. The Service is read-only with respect to a Merchant's store. It requests four Shopify access scopes, being read_products, read_orders, read_inventory, and read_locations, and holds no write scope of any kind. It is therefore incapable of altering a Merchant's inventory quantities, products, or orders. A purchase order produced by the Service is a document the Merchant elects to send; it is not an action taken by the Service within the store.

2.3. Recommendations are computed by a nightly batch process and reflect the position as at its most recent run. The Service does not perform real-time inventory synchronization and does not represent that it does.


3. Merchant Responsibilities

3.1. A Merchant is responsible for the accuracy of the information it enters into the Service, including unit costs, supplier lead times, and supplier contact addresses.

3.2. A Merchant is responsible for ensuring it has a lawful basis to enter a supplier's contact information into the Service and to direct the Company to transmit a purchase order to that supplier, as described in Part B Section 7.6.

3.3. A Merchant must not use the Service in violation of applicable law, in violation of Shopify's terms, or in a manner that interferes with the Service's operation for other Merchants.


4. Recommendations Are Estimates; Merchant Discretion

This Section is the substance of these Terms and is placed accordingly.

4.1. Every figure the Service produces is an estimate, and acting upon one commits the Merchant's money. Recommendations are derived from the Merchant's own sales history by the method described in the Company's forecasting documentation. Where a store has no recorded unit cost or supplier lead time, the Company estimates one by the automated means described in the Privacy Policy, identifies it within the Service as an estimate, and displays the source from which it came.

4.2. The Service is deliberately conservative. Where a computation admits of more than one defensible treatment, the Service resolves toward recommending a smaller quantity. This is a design property rather than a disclaimer: under-ordering is visible to a Merchant and can be corrected, whereas over-ordering converts a Merchant's working capital into unsold stock in a manner that is not readily visible and not readily reversed.

4.3. Every recommendation may be inspected. Any row within the Service expands to the arithmetic that produced it, including the velocity used, the days excluded from that velocity and the reason for each exclusion, the lead time, the safety stock, and the resulting quantity, with each input labeled as to its source.

4.4. A value a Merchant enters is never overwritten by an automated or estimated value.

4.5. The Merchant retains sole responsibility for its purchasing decisions. The Company does not warrant that any recommendation will prove correct. Demand is affected by seasonality, promotion, supplier performance, and events that no model derived from historical data can anticipate. Stock purchased in reliance on a recommendation is purchased at the Merchant's discretion and risk.


5. Fees and Billing

5.1. The Service is offered on a free plan and on paid plans. Charges for paid plans are assessed through Shopify's billing system, appear on the Merchant's Shopify invoice, and are governed by Shopify's billing terms in addition to these Terms. Current prices and plan limits are displayed within the Service.

5.2. The Company does not restrict access on the basis of an unconfirmed subscription. Where the Company is unable to determine a Merchant's subscription status at a given moment, the Service grants access rather than withholding it.

5.3. Exceeding a plan limit does not result in deletion of data. Where a store's tracked variants exceed the limit of its plan, the excess ceases to be forecast; the underlying records are retained and forecasting resumes upon upgrade.

5.4. A Merchant may cancel at any time by uninstalling the Service. Proration and refunds, if any, are governed by Shopify's billing rules.


6. Electronic Mail

6.1. By providing an electronic mail address within the Service's settings, a Merchant elects to receive the reorder digest and the monthly stockout summary described in the Privacy Policy. Each such message carries a link by which the Merchant may stop it in a single action without signing in.

6.2. Following uninstallation the Company sends a single message asking why, at most once per installation, which carries the same link.

6.3. A request to stop is sitewide and stops every message described in 6.1 and 6.2, being every message the Company sends to the Merchant about that store. It does not stop the transactional supplier message described in 6.4, which is sent only because the Merchant instructs it and is addressed to a third party rather than to the Merchant. The consequences of clearing, as distinct from changing, a digest address are described in the Privacy Policy Section 5.8.

6.4. Where a Merchant sends a purchase order from within the Service, the Company transmits it to the supplier address the Merchant entered. That message is transactional, is sent once per instruction, and accordingly carries no stop link and no open tracking. The disclosure it effects is described in Part B Section 7.6.


7. Intellectual Property

7.1. The Service, including its software, interfaces, documentation, and forecasting methods, is and remains the property of the Company. These Terms grant a Merchant a non-exclusive, non-transferable right to use the Service during the term of installation and for no other purpose.

7.2. A Merchant's store data remains the property of the Merchant. The Company claims no ownership of it and processes it solely as described in Part B.

7.3. The Company may use aggregated, de-identified information that does not identify any Merchant or store to operate and improve the Service. The Company does not use one Merchant's data to serve another Merchant, and does not sell Merchant data.


8. Availability

8.1. The Company endeavors to keep the Service available and its nightly computation running, but does not offer a service-level commitment or an availability guarantee.

8.2. The Service depends upon Shopify's platform and application programming interfaces. Changes to, deprecation of, or interruption of those interfaces by Shopify may alter or interrupt the functioning of the Service, and the Company is not responsible for such changes.


9. Disclaimers and Limitation of Liability

9.1. Disclaimer of warranties. The Service is provided "as is" and "as available". To the fullest extent permitted by applicable law, the Company disclaims all warranties, whether express, implied, or statutory, including the implied warranties of merchantability, fitness for a particular purpose, title, and non-infringement, and any warranty arising from a course of dealing or usage of trade. Without limiting Section 4, the Company does not warrant that any recommendation will prove accurate, that the Service will be uninterrupted or error-free, or that defects will be corrected.

9.2. Exclusion of certain damages. To the fullest extent permitted by applicable law, the Company is not liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for any loss of profits, revenue, goodwill, or data.

This exclusion extends expressly to inventory, and the Company states so rather than relying on a general form of words. The Service recommends purchases, so the loss a Merchant is most likely to suffer is stock that was bought and did not sell, or stock that was not bought and would have. The Company excludes liability for the cost, carrying cost, obsolescence, spoilage, or write-down of inventory a Merchant purchases or declines to purchase, and for sales a Merchant did not make. Section 4 explains why those decisions rest with the Merchant.

9.3. Cap on liability. The Company's total aggregate liability arising out of or relating to these Terms or the Service, whether in contract, tort, or otherwise, will not exceed the greater of (a) the total fees the Merchant paid to the Company for the Service in the twelve (12) months immediately preceding the event giving rise to the claim, and (b) one hundred United States dollars (US$100). A Merchant using the Service on the free plan pays no fees, and the Company states plainly that the cap for such a Merchant is therefore US$100.

9.4. Indemnity. A Merchant will indemnify and hold harmless the Company against any third-party claim arising from (a) the Merchant's use of the Service in breach of these Terms or of applicable law, (b) data or content the Merchant enters into or transmits by means of the Service, including a supplier's contact information and the contents of a purchase order, and (c) the Merchant's purchasing decisions. The Company will notify the Merchant promptly of any such claim and will not settle it without the Merchant's consent, which is not to be unreasonably withheld.

Nothing in this Section is intended to exclude or limit liability that cannot be excluded or limited under applicable law.


10. Term and Termination

10.1. These Terms take effect upon installation and continue until the Service is uninstalled.

10.2. A Merchant may terminate at any time by uninstalling the Service, whereupon the Company deletes the Merchant's data on the terms set out in Part B Section 9.

10.3. The Company may suspend or terminate access for non-payment, for breach of these Terms, or where required by law or by Shopify, giving notice where practicable in the circumstances.

10.4. Sections 4.5, 7, 9, and 11, and Part B Section 9, survive termination.


11. General

11.1. Entire agreement. These Terms, together with the Privacy Policy and Part B, constitute the entire agreement between the parties concerning the Service.

11.2. Amendment. The Company may amend these Terms, indicating the change by an updated "Last Updated" date and, in the case of a material amendment, by notice within the Service or by electronic mail. Continued use following effectiveness constitutes acceptance.

11.3. Severability. If a provision is held unenforceable, the remainder continues in effect.

11.4. Assignment. A Merchant may not assign these Terms without the Company's consent. The Company may assign them in connection with a merger, acquisition, or sale of assets.

11.5. No waiver. A failure to enforce a provision is not a waiver of it.


Part B: Data Processing Agreement

This Part applies where a Merchant is subject to Regulation (EU) 2016/679 ("GDPR"), the UK General Data Protection Regulation, the California Consumer Privacy Act as amended by the California Privacy Rights Act, or comparable legislation, and governs the Company's processing of personal data on the Merchant's behalf. It forms part of these Terms. Where this Part conflicts with Part A as to the processing of personal data, this Part prevails.


1. Roles of the Parties

1.1. The Merchant is the controller. The Company is the processor. With respect to store data accessed from the Merchant's Shopify store, the Company processes solely on the Merchant's documented instructions, of which these Terms and the Merchant's use of the Service are the documented form, and for no independent purpose of its own.

1.2. With respect to the Merchant's own account and contact information, and the product-analytics records described in Section 4.9 of the Privacy Policy, the Company acts as a controller. That processing is described in the Privacy Policy.

1.3. The Company acts as a "service provider" within the meaning of the California Consumer Privacy Act. It does not retain, use, or disclose personal information for any purpose other than performing the Service, and does not sell or share personal information.


2. Subject Matter and Details of Processing

Subject matter Provision of inventory forecasting and reordering functionality to the Merchant's store
Duration For so long as the Service remains installed, plus the retention described in Section 9
Nature and purpose Reading catalog, inventory, and order data; computing forecasts; producing purchase orders; delivering electronic mail to the Merchant
Types of personal data The Merchant's store and contact electronic mail addresses; supplier contact electronic mail addresses entered by the Merchant; the store's myshopify.com domain and store name
Categories of data subject The Merchant and its staff; suppliers whose contact addresses the Merchant enters
Special categories None. The Service neither requests nor processes special categories of personal data

3. Data the Company Does Not Process

3.1. The Company does not receive, process, or store the personal data of a Merchant's customers. It holds Protected Customer Data at Level 1 under Shopify's requirements and has not applied for, and will not apply for, a higher level.

3.2. This is enforced by construction rather than by undertaking. Every order webhook to which the Service subscribes declares an include_fields restriction naming only order identifiers, timestamps, financial status, currency, the test flag, and line items, with the consequence that Shopify does not transmit a customer object to the Company at all; and no query the Service issues selects a customer field. Both are verifiable by inspection of shopify.app.toml and of the Service's queries respectively.


4. Obligations of the Company

The Company shall:

4.1. process personal data only on the Merchant's documented instructions, including as to international transfers, and inform the Merchant if it considers an instruction to infringe applicable data-protection law;

4.2. ensure that persons authorized to process personal data are bound by an appropriate obligation of confidentiality;

4.3. implement the technical and organizational measures described in Section 5;

4.4. engage sub-processors only on the terms set out in Section 6;

4.5. taking into account the nature of the processing, assist the Merchant by appropriate measures in fulfilling its obligation to respond to requests to exercise data-subject rights. Requests raised through Shopify's own privacy tooling reach the Company directly and are handled by the endpoints described in Section 9.4, without action by the Merchant;

4.6. assist the Merchant in ensuring compliance with its obligations as to security of processing, notification of personal-data breaches, data-protection impact assessments, and prior consultation with a supervisory authority;

4.7. notify the Merchant without undue delay after becoming aware of a personal-data breach affecting personal data processed on the Merchant's behalf, and provide such information as the Merchant reasonably requires to meet its own notification obligations;

4.8. at the Merchant's election, delete or return personal data at the end of the provision of the Service, on the terms set out in Section 9; and

4.9. make available to the Merchant the information necessary to demonstrate compliance with this Part, and allow for and contribute to audits conducted by the Merchant or an auditor it mandates. That obligation is satisfied by the Company's provision of relevant documentation, including this Part, the Privacy Policy, and the sub-processor terms referred to in Section 6, and by the Company's answering the Merchant's reasonable written questions. A Merchant requiring an on-site inspection or a bespoke audit may request one in writing, not more than once in any twelve (12) month period, on thirty (30) days' notice, at the Merchant's own cost and subject to reasonable confidentiality terms.


5. Technical and Organizational Measures

5.1. The Company implements the following measures, each of which is in effect as at the Effective Date:

(a) encryption of personal data in transit using Transport Layer Security, in respect of all traffic between a Merchant's browser, Shopify, the Company's edge network, its servers, and each sub-processor. Transport-layer security is terminated at the Company's edge; the remaining hops run within an isolated private network on a single host and do not traverse a public network;

(b) encryption of personal data at rest on the storage volume holding the Company's database;

(c) restriction of the application origin at the network layer, such that it is reachable only by way of the Company's edge network;

(d) the absence of any interactive shell service on the application server, administrative access being conducted instead by way of an audited session service;

(e) verification of the authenticity of Shopify webhooks by cryptographic signature;

(f) storage of runtime secrets in a managed secrets service rather than in configuration files. The Service's credentials are scoped to its own secret namespace together with three named portfolio-level credentials that the Company deliberately shares across its applications, being the Shopify Partner token, the electronic-mail token signing key, and the model-provider key. The Service cannot read the secrets of any other application, and in particular the per-application pseudonymization key described in Section 9.3 is not shared;

(g) exclusion of credentials from logs by construction, the Company's access logs discarding the whole of the query string and the referring page rather than filtering a list of named parameters;

(h) access controls limiting personnel access to that necessary to their functions; and

(i) the ability to restore availability and access to personal data in a timely manner following a physical or technical incident, by way of an encrypted backup of the database taken daily and retained for thirty (30) days, held in object storage separate from the application server. The application server may write a backup to that storage and may neither read nor delete one, with the consequence that a compromise of the application server cannot disclose the backup history. Retention and the effect of a backup upon deletion are described in Section 9.6.

5.2. The most substantial measure is architectural rather than procedural: the Service does not receive customer personal data at all, as described in Section 3. Data not held cannot be breached.

5.3. No security program eliminates risk entirely, and the Company does not warrant the absolute security of any information.


6. Sub-processors

6.1. The Merchant provides general written authorization for the Company to engage sub-processors. The Company engages each sub-processor under a written contract imposing data-protection obligations no less protective than those in this Part, and remains liable to the Merchant for the performance of each.

6.2. The Company engages the following sub-processors as at the Effective Date:

Sub-processor Purpose Location
Amazon Web Services, Inc. Cloud hosting (compute and database), transactional electronic mail delivery, and secrets storage United States (us-east-1)
Cloudflare, Inc. Edge network, transport-layer security, and denial-of-service protection. Every request to the Service passes through it United States / global
Anthropic, PBC Automated cost and lead-time estimation, from product metadata only United States

6.3. Shopify is not a sub-processor of the Company. Shopify is the platform upon which the Merchant's store operates and from which the Merchant directs the Company to read data; Shopify's processing is governed by the Merchant's own agreements with Shopify. This Part does not purport to govern it.

6.4. A supplier to whom a Merchant sends a purchase order is not a sub-processor of the Company, for the reason given in Section 7.6.

6.5. The Company shall inform the Merchant of any intended addition or replacement of a sub-processor, and the Merchant may object on reasonable data-protection grounds.


7. Particular Processing Operations

7.1. Automated estimation. Where a product lacks a recorded value, the Company may estimate three: the landed unit cost, the reorder lead time, and the safety-stock fraction. For that purpose it transmits to Anthropic, PBC the following and nothing further: the product title, the variant or option title, the vendor, the product type, the retail price, and the Company's own internal variant identifier.

7.2. The Company does not transmit order data, sales or financial totals, inventory data, free text written by a Merchant, or any customer data to Anthropic.

7.3. Anthropic processes such data as a service provider under contractual restrictions prohibiting use of the data to train its models or for its own purposes.

7.4. This processing does not produce a decision having legal or similarly significant effects concerning any individual. It produces an estimate of a product's cost, which is displayed to the Merchant as an estimate, may be corrected by the Merchant, and is never permitted to overwrite a value the Merchant has entered.

7.5. Inventory history. The Company records one inventory reading per tracked variant, per location, per store-local day, retained for so long as the Service remains installed. This is the Service's principal retained dataset. It contains no personal data of any individual.

7.6. Purchase orders to suppliers. Where a Merchant sends a purchase order, the Company transmits, on that Merchant's instruction, an electronic mail message to the supplier address the Merchant entered, disclosing the store name, the stock-keeping units and product titles on the order, the quantities, the unit costs, the line totals and the order total, any free-text note the Merchant added, and the Merchant's own contact address, which appears both as the reply-to address and in the body. The complete purchase order is additionally attached as a document. The Merchant is the controller of that disclosure, both as to the store data disclosed and as to the supplier's contact information, which the Merchant supplied and warrants it is entitled to provide. The supplier is a recipient of the Merchant's data at the Merchant's direction, not a sub-processor engaged by the Company.


8. International Transfers

8.1. The Company processes personal data in the United States. Where personal data originating in the European Economic Area, the United Kingdom, or Switzerland is transferred to the United States, the transfer is made in reliance upon the transfer mechanism incorporated in the relevant sub-processor's data-processing terms.

8.2. The mechanism relied upon is the European Commission's Standard Contractual Clauses, and the equivalent United Kingdom addendum where applicable, as incorporated into the data processing terms of each sub-processor named in Section 6. Where a Merchant requires the Company to enter into those Clauses with the Merchant directly, the Company will do so on written request.


9. Retention, Return, and Deletion

9.1. Order, product, inventory, cost, purchase-order, and derived records, and the inventory history described in Section 7.5, are retained for so long as the Service remains installed.

9.2. Uninstallation. Upon uninstallation the stored Shopify access credential is deleted immediately and the store's data is scheduled for deletion. Reinstallation within the recovery window cancels the pending deletion.

9.3. Product-analytics records are pseudonymized, not deleted. Upon deletion, the store's myshopify.com domain within those records is replaced by an irreversible-in-practice keyed hash and the de-duplication key is cleared; the records themselves are retained indefinitely. This is pseudonymization and not anonymization. myshopify.com domains are public and may be enumerated, so a party holding the Company's key could reconstruct the mapping. The Company holds that key in a managed secrets service under its sole control, holds a key distinct from that of any other application it operates, and treats it with the sensitivity of the data it protects. Where the key is unavailable at the moment an erasure must be completed, the records are DELETED outright rather than pseudonymized, deletion being the safer failure. The retained records contain no customer data and no text entered by a Merchant.

9.4. Shopify compliance webhooks. The Company honors the mandatory Shopify compliance webhooks. Because it stores no customer personal data, a customers/redact request is satisfied without further action and a customers/data_request is answered accordingly; a shop/redact request results in deletion on the terms of Sections 9.2, 9.3, and 9.5.

9.5. A store that returns discharges an erasure request. Shopify issues a shop/redact request approximately forty-eight (48) hours after uninstallation and delivers it once, with the consequence that it routinely reaches stores whose Merchant has since reinstalled. Where the Company has recorded an uninstallation, the ordinary recovery window in Section 9.2 applies. Where it has recorded none, which is the reinstallation case, deletion is not reversible, so the Company records the request durably and observes the store for a period falling within the thirty (30) days Shopify allows for completion.

Where, during that period, the store demonstrates that the Service is installed and in use, the request is treated as discharged, the data is retained, and the electronic mail described in Part A Section 6 resumes. A store demonstrates use in either of two ways, each requiring a request authenticated by Shopify, and the two are NOT subject to the same condition: a Merchant opening the Service within the Shopify admin, which counts immediately; or Shopify delivering a webhook of a kind sent only to installed applications, which counts only where it arrives at least forty-eight (48) hours after the request, that margin existing because a webhook queued before the request may be delivered after it. A store that is genuinely gone produces neither signal and is erased within the thirty (30) day period.

The Company states this exception rather than omitting it, because an assertion of unconditional deletion within thirty (30) days would be inaccurate in the reinstallation case, and an inaccurate statement in a data-processing agreement is a more serious defect than an omitted one. A Merchant's request to cease receiving electronic mail is a separate matter and is unaffected.

9.6. Backups, and the window in which deletion is not yet complete. The measure described in Section 5.1(i) has a consequence for deletion, and the Company states it rather than leaving the two sections to contradict one another. Deletion under Sections 9.2, 9.3, and 9.5 is performed against the live database. A store's records may therefore persist within a backup taken before that deletion, for the remainder of that backup's retention period, and in no case for longer than thirty (30) days after the deletion. The Company maintains no archival copy and no copy of indefinite duration.

A backup is not used to reinstate records the Company was required to erase, and the Company does not restore a backup in order to recover records it has erased. Backups serve one purpose, being the reconstitution of the Service following a loss of its production database, and restoring one is a measure of last resort.

The Company states the limit of that undertaking rather than implying a stronger one. A restoration performed after such a loss may return records erased after the restored backup was taken, because the record of the erasure is itself held in the database being restored. Where the Company holds a record of such an erasure, it is carried out again before the Service resumes. This wording matches Section 9.7 of the Privacy Policy, which the Merchant may read at the address given in the preamble.


10. Contact

Requests and notices under this Part may be directed to admin@welynk.com.

Mailing address:

WeLynk LLC
c/o Northwest Registered Agent Service, Inc.
212 W. Troy St. STE B
Dothan, AL 36303

© 2026 WeLynk LLC. All rights reserved.