Skip to content
Storeware

Data Processing Addendum

Last updated 6 September 2026

This is a draft. It has not yet been reviewed by a lawyer, and passages in braces are facts still to be filled in. It does not yet bind anyone.

The terms on which Storeware processes shopper data for a merchant.

What this is

This addendum forms part of the Terms of Service and applies whenever we process personal data on your behalf. You are the controller. We are the processor. Where the two conflict on data protection, this document wins.

Scope

Subject matter: providing the Storeware platform.

Duration: as long as your account is open, plus the retention period in the Privacy Policy.

Categories of data subject: your customers, and people who visit your shop or contact you through it.

Categories of data: names, email addresses, delivery and billing addresses, phone numbers, order contents and history, questions asked of the shop, and any preference a shopper chose to have remembered.

We do not process special category data on your behalf, and the platform must not be used to collect it.

What we undertake

To process personal data only on your documented instructions, which the ordinary use of the platform constitutes, unless the law requires otherwise.

To make sure everyone with access is bound by confidentiality.

To hold appropriate technical and organisational measures: encryption in transit and at rest, tenant isolation enforced in the database rather than only in application code, least privilege access, and encryption of stored third party credentials.

To assist you with data subject requests, and to tell you without undue delay if we receive one directly.

To assist you with impact assessments and with regulator consultations, so far as the information is ours to give.

To tell you without undue delay after becoming aware of a personal data breach, with what we know and what we are doing.

To delete or return personal data at the end of the agreement, on the timetable in the Terms of Service.

To make available the information needed to demonstrate compliance, and to allow audits on reasonable notice.

Sub processors

You give general authorisation for the sub processors listed in the Privacy Policy: Stripe, Supabase, Cloudflare, Pinecone, OpenAI and Resend.

We will give at least 30 days notice before adding or replacing one, and you may object on reasonable data protection grounds. If we cannot resolve the objection, you may terminate the affected service.

Each sub processor is bound by terms no less protective than these.

International transfers

Personal data is processed in the United States. Transfers from the United Kingdom and the European Economic Area rely on the standard contractual clauses, together with the United Kingdom addendum where it applies.

Liability

The limits in the Terms of Service apply to this addendum, except where data protection law does not permit them.