Skip to content

Data processing agreement

Last updated · Operator: StoreCompliant

This data processing agreement (“DPA”) applies when the StoreCompliant app processes personal data of your shoppers on your behalf. It is the contract required by Article 28 of the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”). It forms part of the terms of use and takes effect, without signature, when you install the app. If you need a countersigned copy for your records, ask at privacy@storecompliant.com.

1. Parties and roles

1.1 The controller is the merchant: the business that installed the StoreCompliant app on its online shop (“you”).

1.2 The processor is StoreCompliant, Yeni Mah. Mezitli, Mersin, 33200, Turkey, the operator of StoreCompliant (“we”, “us”).

1.3 You decide why and how your shoppers’ personal data is processed. We process it only to provide the app to you. Words defined in the GDPR, such as “personal data”, “processing”, “data subject” and “personal data breach”, have the same meaning here.

1.4 This DPA does not cover data about you as our customer, such as your installation, plan and support requests. For that data we are the controller; see the privacy policy.

2. Subject matter and duration

2.1 Subject matter. The processing of shoppers’ personal data that the app carries out for you. In practice this is the withdrawal function: receiving, storing, showing and deleting the withdrawal requests your shoppers send through the form on your shop, and what is technically needed to deliver the app’s components to your storefront.

2.2 Duration. This DPA applies for as long as the app is installed on your shop, and afterwards until all personal data processed under it has been deleted in line with section 10.

3. Nature and purpose of the processing

3.1 Nature. Collection through the withdrawal form, storage, organisation, display to you in the dashboard, comparison with the order the shopper names (on paid plans), creation of a contact in your platform account, triggering of the confirmation email, export at your request (on paid plans), and deletion.

3.2 Purpose. To let you offer an online withdrawal function to your shoppers, acknowledge each withdrawal with a dated confirmation, and keep a record of the requests you received.

3.3 The details of the processing are set out in Annex 1.

4. Your instructions

4.1 We process the personal data only on your documented instructions. Your instructions are: the terms of use, this DPA, the settings you choose in the app’s dashboard and the actions you take there, and any further written instruction you send to privacy@storecompliant.com that is consistent with the service.

4.2 We do not use the personal data for our own purposes, do not sell it and do not use it for advertising.

4.3 If EU or Member State law requires us to process the data in another way, we tell you before doing so, unless that law forbids it on important grounds of public interest.

4.4 If we believe an instruction infringes the GDPR or other EU or Member State data protection law, we tell you without delay. We may hold back from carrying out that instruction until you have confirmed or changed it.

4.5 Instructions that go beyond what the app does, for example a custom export format or a different retention period, need our agreement and may be subject to a reasonable charge agreed beforehand.

5. Your responsibilities as controller

You are responsible for:

  • having a legal basis for the processing and giving your shoppers the information the GDPR requires, in your own privacy notice;
  • the lawfulness of your instructions and of your settings in the app;
  • answering your shoppers’ requests to exercise their rights, with our help under section 8;
  • your own account on the shop platform, including the contact records and emails the platform holds for you, which the platform processes under your agreement with it;
  • giving us an email address for notices under this DPA. The app does not store one, so without it we can reach you only through the app’s dashboard and the platform.

6. Confidentiality and security

6.1 Confidentiality. The people we authorise to process the personal data are bound by a duty of confidentiality, by contract or by law, and have access only as far as they need it to run and support the service.

6.2 Security. We apply the technical and organisational measures described in Annex 2. They are designed to give a level of security appropriate to the risk, taking into account the limited categories of data, the purposes of the processing and the cost of implementation, as Article 32 GDPR requires.

6.3 We may update the measures as technology and the service develop, provided the overall level of protection does not decrease.

6.4 You have assessed the measures in Annex 2 and consider them appropriate for the data you have us process.

7. Sub-processors

7.1 General authorisation. You authorise us to use the sub-processors listed below, and to add or replace sub-processors under this section.

Sub-processor Service Data Location
Cloudflare, Inc., United States Hosting of the app (Cloudflare Workers), the database (Cloudflare D1), network delivery and protection against attacks All personal data processed under this DPA Global network; data can be processed in data centres inside and outside the EEA

7.2 Your shop platform is not our sub-processor. The shop platform you use, such as Wix, is your own provider under your own agreement with it. When the app creates a contact in your platform account, triggers the confirmation email or reads an order, it acts on your instruction inside your account. The platform’s handling of that data is governed by your agreement with the platform.

7.3 Same obligations. We bind each sub-processor by a written contract to data protection obligations that are in substance the same as those in this DPA, in particular on security. We remain responsible to you for our sub-processors’ performance of those obligations.

7.4 Changes. Before adding or replacing a sub-processor we give you at least 30 days’ notice. We do so by updating the list on this page and by a notice in the app’s dashboard, and also by email if you have given us an address for notices.

7.5 Objection. You may object within those 30 days on reasonable grounds relating to data protection, by writing to privacy@storecompliant.com. We will discuss your concern with you in good faith. If we cannot resolve it, you may stop the processing by switching the withdrawal function off or uninstalling the app before the change takes effect. If you do not object in time, the change is treated as accepted.

7.6 In an emergency, for example to keep the service secure or available, we may replace a sub-processor at shorter notice. We tell you as soon as we can, and section 7.5 applies from that notice.

8. Helping you with shoppers’ rights and your other duties

8.1 Requests from shoppers. The dashboard lets you see each withdrawal request and, on paid plans, export the log. If a shopper asks you for access, correction, erasure, restriction, portability or objects, and you cannot deal with it through the dashboard, write to us and we will help you, for example by providing or deleting the records concerned, within a time that lets you meet your own deadline.

8.2 Requests sent to us. If a shopper sends a request directly to us, we do not answer it ourselves, except to tell the shopper that we have passed it on. We forward it to you without undue delay, provided the shopper tells us which shop it concerns.

8.3 Other duties. Taking into account the nature of the processing and the information available to us, we give you reasonable help with your duties under Articles 32 to 36 GDPR: security of processing, notification of personal data breaches, data protection impact assessments and prior consultation of the supervisory authority.

8.4 Help that goes clearly beyond what this section describes, or that is needed because of your own breach, may be charged at a reasonable rate agreed beforehand.

9. Personal data breaches

9.1 We notify you without undue delay after we become aware of a personal data breach affecting personal data processed under this DPA.

9.2 The notice describes, as far as we know it at the time: the nature of the breach; the categories and approximate number of shoppers and records concerned; the likely consequences; the measures taken or proposed to deal with it and limit its effects; and whom to contact for more information. Where we do not have all of this at once, we provide it in stages without further undue delay.

9.3 We notify you through the app’s dashboard and by email to the address you have given us for notices.

9.4 We take reasonable steps to contain and remedy the breach and co-operate with you so that you can meet your own duties to notify the supervisory authority and, where required, the shoppers concerned. Those notifications are your decision and your responsibility. A notice from us under this section is not an admission of fault or liability.

10. Deletion and return of data

10.1 During the term. Each withdrawal request is deleted automatically three years after it was sent. You can ask us to delete individual requests, or all of them, earlier by writing to privacy@storecompliant.com.

10.2 Return. You can read the full log in the dashboard at any time while the app is installed and, on paid plans, export it as a CSV file. If you need a copy of your shoppers’ data and cannot export it, ask us before you uninstall and we will provide one in a common format.

10.3 At the end. When the app is removed from your shop, the withdrawal requests held for your shop are deleted at the time of removal. Any other data of your installation is deleted within 90 days. Copies in our hosting provider’s backup or recovery systems, if any, are overwritten in the provider’s normal cycle and are not used in the meantime.

10.4 We keep personal data beyond these points only where EU or Member State law requires us to store it, and then only for that purpose.

10.5 The contact records and emails held in your own platform account are not deleted by us. They remain under your control.

11. Information and audits

11.1 Information. On request we give you the information reasonably needed to show that we meet our obligations under Article 28 GDPR and this DPA, including a description of the measures in Annex 2 as they stand at the time.

11.2 Audits. If that information is not enough for you to verify our compliance, you may carry out an audit yourself or through an independent auditor bound by confidentiality who is not a competitor of ours. We will co-operate. To keep audits proportionate for a small provider and to protect other merchants’ data:

  • you give us at least 30 days’ written notice and agree the scope, timing and duration with us beforehand;
  • audits take place during normal business hours, not more than once in any twelve months, unless a supervisory authority requires one or there has been a personal data breach affecting your data;
  • audits are carried out first on the basis of documents and written answers. Access to systems is given only where that is not enough, and never to other merchants’ data or to information that would put the security of the service at risk;
  • for our sub-processors’ infrastructure, which we cannot open to you, we rely on the audit reports and documentation the sub-processor makes available, and share with you what we are permitted to share;
  • each party bears its own costs. If an audit takes more than one working day of our time, we may charge for the additional time at a reasonable rate agreed beforehand, unless the audit reveals a material breach on our part.

11.3 Nothing in this section limits the powers of a supervisory authority.

11.4 We do not ourselves hold security certifications, and we do not claim any.

12. International transfers

12.1 We are established in Turkey, a country outside the European Economic Area (EEA) for which the European Commission has not adopted an adequacy decision. Our sub-processor Cloudflare, Inc. is established in the United States and operates a global network. Personal data is therefore processed outside the EEA. You authorise such transfers under this section.

12.2 Transfer from you to us. Where the GDPR applies to your processing of the personal data, the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), apply between you as data exporter and us as data importer and are incorporated into this DPA by reference. For those clauses:

  • Clause 7 (docking clause) does not apply, and the optional wording in Clause 11 (independent dispute resolution body) does not apply;
  • under Clause 9, Option 2 (general written authorisation) applies, with the list, notice period and right to object in section 7 of this DPA;
  • under Clause 13, the competent supervisory authority is the one that is responsible for you;
  • under Clause 17, Option 1 applies and the clauses are governed by the law of the EU Member State in which you are established or, if you are not established in a Member State, by the law of Ireland; under Clause 18, disputes arising from the clauses are resolved by the courts of that Member State;
  • section 1 and Annex 1 of this DPA provide the information required by Annex I of the clauses, and Annex 2 of this DPA provides the information required by Annex II.

12.3 Onward transfers. We transfer personal data onward to a sub-processor outside the EEA only in accordance with Chapter V GDPR and the clauses in section 12.2: on the basis of an adequacy decision of the European Commission, including, for recipients that take part in it, the EU–US Data Privacy Framework; or on the basis of appropriate safeguards, in particular the European Commission’s standard contractual clauses included in our sub-processor’s data processing terms.

12.4 On request we tell you which transfer mechanism applies to a sub-processor at that time and where its transfer terms can be found.

12.5 If the United Kingdom GDPR or the Swiss Federal Act on Data Protection applies to your processing, the clauses in section 12.2 apply to that transfer as well, read with the changes those laws require.

13. Liability

13.1 Each party’s liability to the other under this DPA is subject to the exclusions and limits in the terms of use, to the extent the law permits.

13.2 Nothing in this DPA limits the rights of data subjects under the GDPR, including the right to compensation under Article 82, or the liability of either party towards a supervisory authority.

13.3 Each party is responsible for the fines imposed on it by a supervisory authority for its own infringements.

14. Order of precedence and final provisions

14.1 If this DPA and the terms of use conflict on the processing of personal data, this DPA prevails. Where the standard contractual clauses apply under section 12, they prevail over this DPA.

14.2 Apart from the standard contractual clauses, which have their own governing law under section 12.2, this DPA is governed by the law named in the terms of use and subject to the jurisdiction set out there, without prejudice to the GDPR and to the competence of the supervisory authorities.

14.3 We may update this DPA where the law, the service or our sub-processors change. Changes are notified as changes to the terms of use; changes of sub-processor follow section 7.

14.4 If a provision of this DPA is invalid, the rest stays in force.

14.5 Notices to us under this DPA go to privacy@storecompliant.com.

Annex 1: Details of the processing

Item Description
Data subjects Shoppers who submit a withdrawal request through the withdrawal form on your shop. Visitors of your storefront, as far as connection data is concerned.
Personal data in a withdrawal request Name; email address; the order number as typed by the shopper; the items concerned, if the shopper listed them; the language of the page; the time zone of the shopper’s browser; the date and time of submission; the reference number given to the request; its status (new or handled, and when it was handled); whether and when the confirmation email was sent.
Additional data on paid plans The result of comparing the request with the order it names (matched, email does not match, or not found) and that order’s number, date and total. The email address on the order is read for the comparison and is not stored.
Data created in your platform account A contact record with the shopper’s name and email address in your own contact list, and the content of the confirmation email. Both are held by your shop platform for you.
Connection data of storefront visitors IP address and browser request data, processed in transit when a visitor’s browser loads the app’s components or the price line. Where you limit a feature to EU and EEA visitors, the country derived from the IP address is used for that decision. This data is not stored by the app.
Special categories of data None are requested. The form asks only for the fields above. You should not use the app to collect special categories of data.
Purpose Offering the online withdrawal function, acknowledging withdrawals and keeping your record of requests; delivering the app’s components to your storefront.
Frequency Continuous, whenever a shopper submits a request or visits your storefront.
Retention Withdrawal requests: three years from submission, or until the app is removed or you ask for deletion, whichever is earlier. Connection data: not stored by the app.
Sub-processors See section 7.

Catalogue data (products, variants, prices and price-change times) and your settings are not shoppers’ personal data and are outside this DPA. The price line the app saves in a visitor’s browser contains no personal data.

Annex 2: Technical and organisational measures

These are the measures in place for the StoreCompliant app at the date of this DPA.

Encryption

  • All traffic between browsers, the shop platform and the app is encrypted in transit (TLS).
  • The database (Cloudflare D1) is encrypted at rest by the hosting provider.

Access control

  • Every request from the merchant dashboard must carry an instance token signed by the shop platform. The app verifies the signature and uses the installation it identifies, so a merchant can see only the data of their own shop.
  • Events sent by the shop platform are accepted only if their signature is valid.
  • Stored records are tied to one installation, and the dashboard reads and changes only the records of the installation named in the verified token.
  • Application secrets and platform credentials are kept in the hosting provider’s secret storage and the database, not in the published code.
  • Access to the production environment is limited to the people at StoreCompliant who need it to operate and support the service.

Data minimisation

  • The withdrawal form asks only for what is needed to identify the shopper and the contract: name, order number, email address and, optionally, the items.
  • The order check reads only the one order the shopper names, and stores only its number, date and total and the result of the comparison.
  • The public storefront endpoints return only the public price line and display settings. They return no personal data.
  • The app sets no cookies on the storefront. The entry it saves in the visitor’s browser contains the public price line only.
  • Diagnostic logs are designed to record the installation concerned and a shortened error message, not the contents of withdrawal requests.

Integrity and protection against abuse

  • Input to the withdrawal form is validated and limited in length on the server.
  • The public form has protection against automated submissions and a limit on the number of requests accepted per shop per hour.
  • The request is stored first; matching, notification and the confirmation email follow, so a failure in those steps does not lose the request.

Deletion

  • An automatic job that runs every hour deletes withdrawal requests older than three years.
  • Withdrawal requests of a shop are deleted when the platform reports that the app has been removed.
  • Remaining installation data is deleted within 90 days of removal.

Availability and resilience

  • The app runs on the hosting provider’s distributed infrastructure. We give no availability commitment; see the terms of use.
  • The storefront keeps the last price line shown in the visitor’s browser, so that it can still be displayed if the server is briefly unreachable.

Organisation

  • Personal data is handled only by people bound by confidentiality.
  • Changes to the app are covered by automated tests before release.
  • Security incidents are assessed when detected and handled under section 9.
  • Sub-processors are chosen with regard to their security and data protection commitments and are bound by contract.

More on how the app handles data: security and data. Questions: privacy@storecompliant.com. See also the legal notice and the cookie policy.