Fee figures live in the Shopify-presented plan and the App Store listing, not in this MSA.
Effective date: the date the Merchant accepts this Agreement (Clause 2).
Parties
This Master Services Agreement ("Agreement" or "MSA") is between:
(1) OBSESSION ECOMMERCE DATA TOOLS LTD, a company incorporated in the Republic of Cyprus with company registration number HE 496073, registered office at Nikola Tsadioti, Pearl Park Block 6, Apartment 115, 8035 Paphos, Cyprus, which operates the OB Session Personalization application ("OB Session", "we", "us", "our"); and
(2) the merchant that installs and uses the OB Session application ("Merchant", "you", "your").
OB Session is a product of OBSESSION ECOMMERCE DATA TOOLS LTD. Each of OB Session and the Merchant is a "Party".
1. Definitions
- "App" / "Service" — the OB Session Personalization application and related technology made available to the Merchant for its Shopify storefront: personalized product recommendations for the Store's visitors — rendered in on-page recommendation widgets and/or as personalized ordering of products on collection and other product grids (Collection-page personalization) — powered by a machine-learning model trained solely on behavioural data from the Merchant's own storefront; together with the first-party storefront script delivered through the OB Session Shopify theme app extension, on-store behavioural analytics and A/B testing, attribution of resulting orders, and the merchant-facing app admin — in each case as updated by OB Session from time to time.
- "Collection-page personalization" — personalized ordering of the products shown on the Merchant's collection (category) pages and other product grids such as the homepage, presented in the personalized order before the page loads.
- "Store" — the single Shopify storefront the Merchant connects to the Service.
- "Catalog Data" — the Merchant's products, collections, variants and related metadata, synced from Shopify.
- "Order Data" — order-level records used for attribution and billing (order ID, date, currency, amounts, line items with product/variant references and attribution flags, and a test flag); it contains no customer-identifying fields.
- "Shopper Personal Data" — the pseudonymous behavioural data of the Store's visitors that the Service processes on the Merchant's behalf, as described in the DPA.
- "Merchant Data" — Catalog Data, Order Data and Shopper Personal Data, collectively.
- "Data Collection" — the period beginning when the Merchant enables the OB Session storefront extension and the Service begins accumulating behavioural data to train the Merchant's model.
- "Activation" — the point at which the Service first serves recommendations to the Store's visitors (i.e. the start of the A/B test).
- "Attributed Order / Attributed Revenue" — an order, or the portion of an order, for a line item that was added to cart either (a) directly from a product recommended by the Service (via an OB Session-rendered widget or Collection-page personalization), or (b) from a product page reached by clicking a product recommended by the Service. Attributed Revenue for a line item = (unit price × quantity) − discounts. Test orders do not count. Attribution is interaction-based; it does not include view-through or any share of measured uplift.
- "GMV" (gross merchandise value) — the total value of the Store's orders over a period, used in assessing the Store's eligibility (Clause 3).
- "Attribution Fee" — the graduated usage fee on Attributed Revenue (Clause 7).
- "Fees" — the Attribution Fee, together with any other charges agreed in an Order Form.
- "DPA" — the OB Session Data Processing Agreement, incorporated by reference (Clause 11).
- "Order Form" — a separate written or electronic order document for an enterprise or negotiated engagement (Clause 2.3).
- "Shopify" — Shopify Inc. and its affiliates, the platform on which the App runs.
2. Acceptance and structure of the Agreement
2.1 Acceptance. By installing, enabling, or using the App, the Merchant accepts this Agreement. The individual accepting represents that they are authorised to bind the Merchant (the owner and operator of the Store); where an agency or other party installs or accepts on a store owner's behalf, it does so as the store owner's agent and binds the store owner as the Merchant.
2.2 Components. This Agreement comprises this MSA and the DPA (Clause 11). It does not need to be publicly posted; it is presented to the Merchant on installation.
2.3 Order Forms (enterprise). For an enterprise or otherwise negotiated engagement, the Parties may execute an Order Form. Where an Order Form conflicts with this MSA, the Order Form prevails for that engagement; otherwise this MSA governs.
2.4 Availability. This MSA is presented to the Merchant at installation and is also published at ob-session.com/legal/msa for reference. The OB Session Privacy Policy is published separately and publicly.
3. Eligibility
3.1 The Service is intended for stores that meet OB Session's eligibility criteria — which include (without limitation) a minimum store GMV, a catalog of sufficient breadth (more than a single product type), and sufficient traffic to train and test the Merchant's model — and which OB Session may set, assess and update at its discretion.
3.2 Eligibility is assessed before any Data Collection or Fees begin — from the Store's GMV, catalog and traffic on or after installation. OB Session may decline to onboard or activate a Store at any time, and may suspend or terminate the Service, if it determines — at any point, including during Data Collection — that the Store does not meet the eligibility criteria or that the Service is otherwise unsuitable for the Store.
3.3 Fees already charged are non-refundable. No Fees accrue before Activation (Clause 7), so where termination for non-qualification occurs before Activation, no Fees are due, and neither Party has further liability in respect of the eligibility determination beyond Fees already accrued.
3.4 Installation is not approval. Installation does not by itself guarantee onboarding or activation — eligibility is determined under this Clause 3.
4. Licence and access
4.1 Licence to the Merchant. Subject to this Agreement, OB Session grants the Merchant a non-exclusive, non-transferable, non-sublicensable, revocable licence to access and use the Service for its own internal business purposes in connection with the Store, during the term.
4.2 One Store. Each installation covers a single Shopify Store. The relationship is with the Store's administrator account.
4.3 Access OB Session needs. The Merchant authorises OB Session to access the Store, the Catalog Data and Order Data via Shopify's APIs, and to deliver the storefront script through the OB Session Shopify theme app extension, in each case as required to provide the Service.
5. Service phases
5.1 Phases. The Service is activated in phases: eligibility assessment (Clause 3), Data Collection, an A/B test, and live operation — at the scope the Merchant selects and may change at any time. Whether and when the Service progresses from one phase to the next — including whether the Store has accumulated sufficient data and when the Merchant's model is ready — is determined by OB Session. The individual onboarding steps within these phases are described in the Service documentation and the App admin; that material is provided for guidance only, may be updated by OB Session at any time, and does not form part of this Agreement.
5.2 Estimates are not commitments. Any timeframes OB Session communicates (for preparation, data sufficiency, or A/B-test duration) are good-faith estimates only and not binding. The time to accumulate sufficient data depends on the Store's traffic and consent rates, and a low-traffic Store may take a long time to qualify or may never reach the required thresholds.
5.3 Merchant-controlled steps. Enabling the OB Session extension in the Store's theme (which begins Data Collection), configuring the Store's consent framework, and selecting the A/B-test and roll-out scope are Merchant actions; OB Session is not responsible for delays or outcomes resulting from the Merchant not completing them.
5.4 Reinstallation. Because OB Session deletes the Merchant's data on uninstall (Clause 8 and the DPA), a Merchant that later reinstalls starts afresh: Data Collection and the A/B test must occur again before the Service can run at full scope.
6. Merchant responsibilities
6.1 The Merchant: (a) is responsible for its Store, its Catalog Data, and the accuracy and legality of the data it makes available; (b) has and maintains a valid lawful basis, and provides all notices and obtains all consents, required for the Service to process Shopper Personal Data and to set or read identifiers on a visitor's device, configured through the Store's consent framework (as further set out in the DPA); (c) complies with its agreement with Shopify; and (d) uses the Service in accordance with this Agreement, including Clause 15 (Acceptable use).
7. Fees and billing
7.1 Billing through Shopify. All Fees are charged through Shopify's billing (Shopify App Pricing / Billing API). OB Session does not invoice the Merchant directly. The Merchant's acceptance of the in-app charge through Shopify is required for billing to proceed.
7.2 Usage-only plan. The Service is offered on a single usage-based plan with no recurring subscription fee. The only Fee for the Service is the Attribution Fee (Clause 7.3); the Merchant approves the plan and its usage terms through Shopify.
7.3 Attribution Fee. The Attribution Fee is a graduated percentage of Attributed Revenue per billing cycle. The Attribution Fee begins at Activation (when recommendations first serve) — there is no Attribution Fee before Activation.
7.4 Amounts. The current Attribution-Fee rates and revenue thresholds are those presented to the Merchant in the App's plan and in the App Store listing at the time, and in the usage terms the Merchant approves through Shopify. They are not restated in this MSA.
7.5 No charge before Activation. No Fees accrue during installation, setup, preparation, or Data Collection; Fees begin only at Activation.
7.6 Measurement and audit. OB Session's systems are the source of record for Attributed Revenue. On reasonable request, OB Session will provide the underlying order IDs and line items supporting an Attribution Fee so the Merchant can verify it.
7.7 Currency and taxes. Fees are denominated in USD. Attributed Revenue arising in another currency is converted to USD at the European Central Bank daily reference rate current when the revenue is recorded; Shopify converts the resulting charge to the Merchant's billing currency on its invoice. Shopify handles tax collection and remittance; Fees are exclusive of taxes where applicable.
7.8 No refunds; discretionary credits. Except as Shopify's own mechanics provide, Fees are non-refundable; Shopify does not credit the remainder of a billing period on uninstall. OB Session may, at its discretion, issue billing credits (for example, in respect of refunded orders).
7.9 Changes to Fees. OB Session may change its Fees on 30 days' notice. Changed amounts apply to new subscriptions and take effect for an existing Merchant only upon a new Shopify approval; until then the Merchant's current pricing continues. Promotional pricing (e.g. an early-adopter discount) is offered at OB Session's discretion and for a stated period.
8. Term, renewal, termination and suspension
8.1 Term. This Agreement starts on acceptance and continues until terminated. The Merchant's plan subscription renews automatically on successive monthly (30-day) cycles via Shopify.
8.2 Termination by the Merchant. The Merchant may stop using and uninstall the App at any time. On uninstall, Shopify cancels the subscription. Fees already charged are non-refundable, and Attribution Fees accrued up to uninstall remain payable to the extent Shopify can still collect them.
8.3 Suspension / termination by OB Session. OB Session may suspend or terminate the Service: (a) for the Merchant's material breach not cured within 14 days of notice; (b) immediately for unlawful, abusive, or infringing use, or where required by law or by Shopify; (c) for non-qualification (Clause 3); or (d) for convenience, on 30 days' notice to the Merchant.
8.4 Effect of termination. On termination the Merchant's right to use the Service ends, and
OB Session handles Merchant Data in accordance with the DPA (including deletion following Shopify's
shop/redact on uninstall) and deletes the Merchant's dedicated model (Clause 9.2). Clauses that by
their nature should survive — including Clauses 7 (accrued Fees), 9, 10, 12, 13, 14 and 20 —
survive termination.
9. Intellectual property and data rights
9.1 OB Session IP. As between the Parties, OB Session owns and retains all right, title and interest in and to the Service, including the models, the derived behavioural features and signals, all derived insights, and all related software, technology and documentation. No rights are granted except the licence in Clause 4. All rights not expressly granted are reserved.
9.2 The Merchant's dedicated model. The recommendation model trained for the Merchant is owned by OB Session, is used only to serve the Merchant's own Store, and is never pooled with, or applied to, any other merchant. OB Session deletes the Merchant's model on uninstall or on the Merchant's written request. The Merchant has no right to, or licence in, the model itself.
9.3 Merchant ownership. As between the Parties, the Merchant owns its Catalog Data, Order Data and Shopper Personal Data.
9.4 Licence to OB Session (in-term, limited). The Merchant grants OB Session a non-exclusive, worldwide, royalty-free licence, for the term only, to use the Merchant Data solely to provide and operate the Service for the Merchant, to train and operate the Merchant's dedicated model, and to derive the aggregated, de-identified statistics described in Clause 9.5. This licence ends on termination, and OB Session deletes the Merchant Data and the model as set out in Clause 8.4, Clause 9.2 and the DPA.
9.5 No cross-merchant use of Merchant Data. OB Session does not use the Merchant Data — including Catalog Data, Order Data, and Shopper Personal Data — to train any model dedicated to, or to generate recommendations reflecting the Merchant's catalog, products, or the Store's visitors for, any other merchant. OB Session may derive aggregated, de-identified statistics from use of the Service that contain no Catalog Data, no product references, and no Merchant- or Shopper-identifiable information, and may use such statistics to develop, maintain, and improve the Service. (This is consistent with the OB Session Privacy Policy.)
9.6 Feedback. If the Merchant provides feedback, suggestions or ideas about the Service, the Merchant grants OB Session a perpetual, irrevocable, worldwide, royalty-free licence to use and incorporate them into the Service without restriction or compensation.
10. Confidentiality
10.1 Each Party may receive confidential information of the other. The Parties will protect it and use it only to perform this Agreement.
10.2 OB Session Confidential Information expressly includes its pricing, algorithms, models, derived features, technical methods, and Service settings and configuration, which the Merchant will keep confidential and not disclose or use except as necessary to use the Service. These obligations are strict and survive termination.
10.3 Exclusions. Confidentiality does not apply to information that: (a) is or becomes public other than through a breach of this Agreement; (b) the receiving Party already lawfully held; (c) was independently developed without use of the other Party's confidential information; or (d) is rightfully received from a third party without restriction. A Party may disclose confidential information where legally compelled, giving prior notice where lawful. These obligations continue for 3 years after termination, and indefinitely for trade secrets.
11. Data protection
11.1 The Parties' data-protection obligations are governed by the DPA, which is incorporated into this Agreement by reference. In respect of Shopper Personal Data the Merchant is the controller and OB Session is the processor; OB Session is a controller only for the Merchant's own account-contact data, as described in the Privacy Policy. In a conflict between this MSA and the DPA on the processing of personal data, the DPA prevails.
12. Warranties and disclaimer
12.1 AS-IS. The Service is provided "as is" and "as available", to the fullest extent permitted by law. OB Session makes no warranty that the Service will meet the Merchant's requirements, increase sales, achieve any particular result or uplift, or be uninterrupted, timely, secure, or error-free, and gives no guarantee of return on investment or of any sales lift.
12.2 OB Session disclaims all warranties not expressly stated, whether express, implied or statutory, including implied warranties of merchantability, fitness for a particular purpose, and non-infringement, to the fullest extent permitted by law. The Merchant is responsible for its use of the Service and for the results it seeks to achieve.
13. Indemnification
13.1 By the Merchant. The Merchant will defend, indemnify and hold OB Session harmless from any third-party claim, and related losses and reasonable legal costs, arising out of: (a) the Merchant's Store, Catalog Data or Order Data; (b) the Merchant's failure to obtain the consents or provide the notices it is responsible for (Clause 6, and the DPA); or (c) the Merchant's breach of this Agreement or violation of law or third-party rights.
13.2 By OB Session (IP infringement, conditioned). OB Session will defend the Merchant against a third-party claim that the Service, as provided by OB Session and used in accordance with this Agreement, infringes that third party's intellectual property rights, and will pay damages finally awarded (or settlement OB Session approves). This obligation does not apply to claims arising from: (a) the Merchant Data; (b) modifications not made by OB Session; (c) combination of the Service with items OB Session did not supply; or (d) use of the Service in breach of this Agreement. OB Session controls the defence, and its sole obligations and the Merchant's exclusive remedy are those in this Clause; if the Service is or may be enjoined, OB Session may, at its option, procure a right to continue, modify or replace the Service, or terminate the affected use and refund any pre-paid, unused Fees. OB Session's aggregate liability under this Clause 13.2 is subject to the cap in Clause 14.2.
13.3 The indemnified Party will promptly notify the indemnifying Party, allow it to control the defence, and reasonably cooperate.
14. Limitation of liability
14.1 Exclusion of indirect damages. To the fullest extent permitted by law, neither Party is liable for indirect, special, incidental, punitive or consequential damages, or for loss of profits, revenue, business, goodwill, or data, however arising.
14.2 Cap. Except for the matters in Clause 14.3, each Party's aggregate liability under this Agreement is limited to the total Fees paid or payable for the Service in the 12 months preceding the event giving rise to the liability. This is the aggregate cap referred to in the DPA.
14.3 Exceptions to the cap. The cap and the exclusion in 14.1 do not apply to: (a) liability that cannot be limited under applicable law (including a data subject's rights under Article 82 GDPR, as preserved in the DPA); (b) the Merchant's indemnification obligations (Clause 13.1); (c) breach of confidentiality (Clause 10); (d) the Merchant's payment obligations; or (e) a Party's fraud, gross negligence or wilful misconduct.
15. Acceptable use
15.1 The Merchant will not, and will not permit any third party to: (a) reverse-engineer, decompile, or attempt to derive the source code, algorithms, models or structure of the Service; (b) copy, modify, create derivative works from, resell, sublicense, or distribute the Service; (c) scrape or use automated means to extract the Service or its outputs beyond normal use; (d) use the Service to build or benchmark a competing product; (e) circumvent the Service's billing; or (f) remove proprietary notices.
15.2 The Merchant will not use the Service in connection with illegal goods or any unlawful activity.
15.3 No special-category placements. The Service is not designed to process special-category personal data (Article 9 GDPR). The Merchant will not deploy the Service on any page or placement where the data processed would reveal such data, consistent with the DPA.
16. Compliance
16.1 Export controls and sanctions. Each Party will comply with applicable export-control and economic-sanctions laws (including those of the US, EU and UN). The Merchant represents that it is not located in, or owned or controlled by a party in, a country or by a person subject to such sanctions or embargoes.
16.2 Anti-bribery. Each Party will comply with applicable anti-bribery and anti-corruption laws and will not offer or accept any improper payment in connection with this Agreement.
17. Publicity
17.1 OB Session will not use the Merchant's name or logo as a customer reference without the Merchant's prior consent (opt-in).
18. Third-party platforms
18.1 The Service depends on Shopify (the platform on which the App runs; not a party to this Agreement and governed by the Merchant's own agreement with Shopify) and on Amazon Web Services (OB Session's infrastructure and sole sub-processor under the DPA). OB Session is not liable for the acts, omissions, availability, or changes of Shopify, AWS, or other third-party platforms outside its control.
19. Changes
19.1 To the Service. OB Session may modify, improve, or evolve the Service, and will give notice of any material reduction in core functionality.
19.2 To this Agreement. OB Session may update this Agreement on 30 days' notice (for example in the app admin or by email). Continued use of the Service after the notice period constitutes acceptance of the updated Agreement.
20. Governing law and disputes
20.1 Governing law and jurisdiction. This Agreement is governed by the laws of the Republic of Cyprus, and the courts of Cyprus have exclusive jurisdiction over any dispute arising out of or in connection with it. Nothing in this Clause prevents OB Session from seeking injunctive relief, or recovering unpaid Fees, in any court of competent jurisdiction.
21. General
21.1 Assignment. OB Session may assign this Agreement (for example on a merger, acquisition or financing). The Merchant may not assign without OB Session's prior written consent.
21.2 Notices. Legal notices to OB Session: legal@ob-session.com. Notices to the Merchant: the contact associated with the Store / Shopify record.
21.3 Force majeure. Neither Party is liable for delay or failure caused by events beyond its reasonable control.
21.4 Entire agreement. This Agreement (with the DPA and any Order Form) is the entire agreement on its subject matter and supersedes prior understandings.
21.5 Severability. If any provision is unenforceable, it is limited or severed to the minimum extent necessary and the rest remains in effect.
21.6 No waiver. A failure to enforce a right is not a waiver of it.
21.7 No partnership; no third-party beneficiaries. The Parties are independent contractors; this Agreement creates no partnership, agency or joint venture, and confers no rights on third parties.
21.8 Order of precedence. In a conflict: an Order Form prevails over this MSA for its engagement; this MSA prevails over the DPA except on the processing of personal data, where the DPA prevails.
21.9 Electronic acceptance. This Agreement may be accepted electronically, including by click-acceptance on installation.
Acceptance
This Agreement requires no signature. By installing, enabling or using the OB Session App — and by accepting this Agreement in the App — the Merchant agrees to this Master Services Agreement and to the DPA incorporated into it (Clause 11). OB Session accepts by making the Service available to the Merchant.
OB Session records the accepting Merchant and Store, the version of this Agreement accepted, and the date and time of acceptance; that record is available to the Merchant in the app admin and is the evidence of execution for the purposes of this Agreement.
OBSESSION ECOMMERCE DATA TOOLS LTD · Reg. no. HE 496073 · Nikola Tsadioti, Pearl Park Block 6, Apartment 115, 8035 Paphos, Cyprus