Data Processing Addendum
Last updated June 23, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Use or other written or electronic agreement between Ready for Commerce, Inc. ("Ready for Commerce," "we," "us," or "our") and the customer agreeing to those terms ("Customer," "you," or "your") for the provision of the Services (the "Agreement"). This DPA reflects the parties' agreement on the processing of Personal Data in connection with the Services and applies to the extent Ready for Commerce processes Personal Data on Customer's behalf as a processor.
If you are entering into the Agreement and require a signed copy of this DPA, you may sign the version we make available and return it to us; an unsigned copy of this DPA, incorporated into the Agreement, is binding on the parties when you accept the Agreement or use the Services. In case of any conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA controls.
1. Definitions
Capitalized terms not defined in this DPA have the meanings given in the Agreement.
- Applicable Data Protection Law means all laws and regulations applicable to the processing of Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 ("EU GDPR"), the EU GDPR as incorporated into the law of the United Kingdom ("UK GDPR") together with the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection ("FADP"), and U.S. state privacy laws such as the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA").
- Controller, Processor, Data Subject, Personal Data, Processing, Special Categories of Personal Data, and Supervisory Authority have the meanings given in Applicable Data Protection Law; "Business," "Service Provider," "Sell," "Share," and "Sensitive Personal Information" have the meanings given in the CCPA.
- Customer Personal Data means Personal Data contained in Customer Data that Ready for Commerce processes on Customer's behalf as a Processor under the Agreement.
- Data Subject Request means a request from a Data Subject to exercise rights under Applicable Data Protection Law.
- Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
- Standard Contractual Clauses or SCCs means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Decision 2021/914 of 4 June 2021.
- UK Addendum means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
- Subprocessor means any third party engaged by Ready for Commerce to process Customer Personal Data.
2. Roles of the parties
With respect to Customer Personal Data, Customer is the Controller (or a Processor acting on behalf of a third-party Controller) and Ready for Commerce is the Processor. Where Customer is itself a Processor, Customer warrants that it has the third-party Controller's authorization to engage Ready for Commerce as a Subprocessor and to agree to this DPA on the Controller's behalf, and that the instructions and obligations in this DPA are consistent with the third-party Controller's instructions. This DPA does not apply to Personal Data for which Ready for Commerce is the Controller, which is governed by our Privacy Policy.
3. Scope and instructions for processing
Subject matter. Ready for Commerce processes Customer Personal Data only to provide and support the Services as described in the Agreement and the Documentation, and as further described in Annex I.
Documented instructions. Ready for Commerce will process Customer Personal Data only on Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by applicable law; in that case, Ready for Commerce will inform Customer of that legal requirement before processing, unless the law prohibits this on important grounds of public interest. The Agreement, this DPA, and Customer's configuration and use of the Services (including the channels Customer connects and the actions Customer directs) constitute Customer's complete documented instructions. Ready for Commerce will inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law.
Compliance. Each party will comply with its obligations under Applicable Data Protection Law. Customer is responsible for the lawfulness of Customer Personal Data and of Customer's instructions, including having a valid legal basis, providing required notices, and obtaining required consents for the processing contemplated by the Agreement.
4. Confidentiality
Ready for Commerce will ensure that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations (whether contractual or statutory) and are granted access on a need-to-know, least-privilege basis.
5. Security measures
Ready for Commerce will implement and maintain appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to Data Subjects. These measures are described in Annex II — Technical and Organizational Measures. Ready for Commerce may update its measures from time to time, provided the updates do not materially reduce the overall level of security.
6. Subprocessors
General authorization. Customer provides general written authorization for Ready for Commerce to engage Subprocessors to process Customer Personal Data. Ready for Commerce's current Subprocessors are listed in Annex III.
Obligations. Ready for Commerce will impose data-protection obligations on each Subprocessor that are no less protective than those in this DPA, and will remain liable to Customer for each Subprocessor's performance of its data-protection obligations.
Changes and objection. Ready for Commerce will provide notice of any intended addition or replacement of a Subprocessor (for example, by updating Annex III or a subprocessor page and, where Customer subscribes, by notification) at least thirty (30) days before the change takes effect. If Customer has a reasonable, data-protection-based objection, Customer may notify Ready for Commerce within that period; the parties will work in good faith to resolve the objection, and if they cannot, Customer may terminate the affected Service as its sole remedy.
7. Assistance to Customer
Data Subject Requests. Taking into account the nature of the processing, Ready for Commerce will assist Customer by appropriate technical and organizational measures, insofar as possible, to respond to Data Subject Requests. If Ready for Commerce receives a Data Subject Request directly, it will, unless legally prohibited, promptly inform the Data Subject to contact Customer and will not otherwise respond except on Customer's instructions. Customer can access, correct, export, and delete much of the Customer Personal Data within the Services directly.
Other assistance. Taking into account the nature of processing and the information available to it, Ready for Commerce will provide reasonable assistance to Customer with data-protection impact assessments, prior consultations with Supervisory Authorities, and Customer's obligations regarding the security of processing and Personal Data Breaches.
8. Personal Data Breach notification
Ready for Commerce will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to it to help Customer meet its breach-notification obligations. Such notification is not an acknowledgment of fault or liability. Ready for Commerce will take reasonable steps to mitigate and, where possible, remediate the breach.
9. Return and deletion of Customer Personal Data
Upon termination or expiration of the Agreement, Ready for Commerce will, at Customer's choice, delete or return Customer Personal Data, and delete existing copies, unless applicable law requires storage. For a limited period after termination (as described in the Agreement), the Services may allow Customer to export Customer Personal Data; thereafter, Ready for Commerce will delete or de-identify it in the ordinary course, including from backups in accordance with its backup cycles, except as required by law or for the establishment, exercise, or defense of legal claims.
10. Audits
Ready for Commerce will make available to Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by Customer or an independent auditor mandated by Customer, in accordance with this section. To the extent available, Ready for Commerce may satisfy audit requests by providing then-current third-party certifications, audit reports, or security documentation. Any on-site audit will be conducted no more than once per year (except where required by a Supervisory Authority or following a Personal Data Breach), on reasonable prior notice, during business hours, subject to confidentiality obligations, and in a manner that does not disrupt Ready for Commerce's operations or compromise the security of other customers' data.
11. International data transfers
Transfer mechanism. Where Ready for Commerce processes Customer Personal Data that is subject to the EU GDPR, UK GDPR, or FADP and transfers it to a country that has not received an adequacy decision, the following apply and are incorporated into this DPA by reference:
- EEA transfers. The SCCs apply. Module Two (Controller-to-Processor) applies where Customer is a Controller, and Module Three (Processor-to-Processor) applies where Customer is a Processor. The optional docking clause (Clause 7) does not apply. Under Clause 9, Option 2 (general written authorization) applies, with the notice period in Section 6 of this DPA. The optional language in Clause 11 does not apply. For Clause 17, the SCCs are governed by the law of Ireland; for Clause 18(b), disputes will be resolved before the courts of Ireland. Annex I and Annex II of this DPA populate Annexes I and II of the SCCs, and Annex III lists the authorized Subprocessors.
- UK transfers. The UK Addendum applies to and amends the SCCs for transfers subject to the UK GDPR. The information required by Tables 1 to 3 of the UK Addendum is set out in this DPA and its Annexes; for Table 4, the party that may end the UK Addendum is the data importer. The start date of the UK Addendum is the effective date of this DPA.
- Swiss transfers. For transfers subject to the FADP, the SCCs apply with the following adjustments: references to the GDPR are to the FADP where applicable; the competent Supervisory Authority is the Swiss Federal Data Protection and Information Commissioner; and the term "member state" does not prevent Data Subjects in Switzerland from suing in their place of habitual residence.
Conflict. In case of any conflict between the SCCs (and the UK Addendum) and this DPA or the Agreement, the SCCs (and the UK Addendum) prevail with respect to the transfers they govern.
Execution and updates. By entering into this DPA, each party is deemed to have signed the SCCs (and the UK Addendum), including their Annexes, which are populated by Annexes I to III of this DPA. If the European Commission, the UK Information Commissioner, or another competent authority issues new or revised standard contractual clauses or approves a different valid transfer mechanism, the parties will apply the updated mechanism, which will replace the prior version with respect to the transfers it governs, without the need to amend this DPA.
12. Government and law enforcement requests
If Ready for Commerce receives a legally binding request from a public authority, including a law-enforcement or government authority, for disclosure of Customer Personal Data, Ready for Commerce will, unless legally prohibited: (a) review the legality of the request; (b) inform the requesting authority that it is a Processor acting on Customer's behalf and, where appropriate, that the request should be directed to Customer; (c) notify Customer without undue delay so that Customer may seek a protective order or other appropriate remedy; and (d) challenge requests that it considers unlawful, overbroad, or inconsistent with Applicable Data Protection Law, disclosing only the minimum amount of Customer Personal Data necessary to comply with a valid and binding request. Ready for Commerce will document the requests it receives and its responses, to the extent permitted by law. This section is in addition to, and does not limit, the obligations in Clause 15 of the SCCs where the relevant transfers are subject to the SCCs.
13. United States state privacy laws
To the extent the CCPA or other U.S. state privacy laws apply to Customer Personal Data, Ready for Commerce acts as a Service Provider (or Processor) and processes Customer Personal Data only to perform the Services and for the business purposes set out in the Agreement and this DPA. Ready for Commerce will not: (a) Sell or Share Customer Personal Data; (b) retain, use, or disclose it for any purpose other than the business purposes specified, including outside the direct business relationship; or (c) combine it with personal information from other sources, except as permitted by the CCPA. Ready for Commerce certifies that it understands and will comply with these restrictions. Ready for Commerce will notify Customer if it determines it can no longer meet its obligations, and Customer may take reasonable steps to stop and remediate unauthorized processing.
14. Liability
Each party's liability arising out of or related to this DPA, whether in contract, tort, or any other theory, is subject to the limitations and exclusions of liability set out in the Agreement, and any reference in the Agreement to a party's liability means the aggregate liability of that party under the Agreement and this DPA together.
15. General
This DPA is governed by the same law as the Agreement, except where Applicable Data Protection Law or the SCCs require otherwise. If any provision of this DPA is found unenforceable, the remainder remains in effect. This DPA may not be modified except as provided in the Agreement or as required to maintain compliance with Applicable Data Protection Law. This DPA takes precedence over any conflicting provision of the Agreement with respect to the processing of Customer Personal Data. This DPA takes effect when Customer accepts the Agreement and remains in effect for as long as Ready for Commerce processes Customer Personal Data, until all Customer Personal Data has been deleted or returned in accordance with Section 9.
Annex I — Description of processing
A. List of parties.
Data exporter: Customer, the entity that accepts the Agreement, acting as Controller (or as Processor on behalf of a third-party Controller). Contact: the account and billing contact designated in the Services. Activities: use of the Services as described in the Agreement. Role: Controller (or Processor).
Data importer: Ready for Commerce, Inc., 9616 NW 7th Circle #1625, Plantation, FL 33324, United States, acting as Processor. Contact: privacy@readyforcommerce.com. Activities: provision of the Services as described in the Agreement. Role: Processor.
B. Categories of Data Subjects. Customer's authorized users and personnel (such as administrators, managers, editors, and analysts); Customer's business contacts (such as the billing contact and invited users); and any individuals whose Personal Data Customer chooses to include in Customer Data or in connected-channel data. The Services are designed to manage product and pricing data and are not intended to process the personal information of Customer's shoppers or end customers.
C. Categories of Personal Data. Identification and contact data (such as name and email address); account and profile data (such as user identifier, language, and time zone); organization and role data (such as team membership and permissions); authentication and security data (such as IP address, device and browser user-agent, session identifiers, and timestamps); usage and metering data; billing data (such as billing contact and limited payment-card metadata, namely card brand, last four digits, and expiry — full card numbers and security codes are handled by the payment processors and are not stored by Ready for Commerce); and any other Personal Data that Customer includes in Customer Data or connected-channel configurations.
D. Special Categories of Personal Data. None are intended or required. Customer must not submit Special Categories of Personal Data to the Services except where expressly supported and subject to additional safeguards agreed in writing.
E. Frequency of processing. Continuous, for the duration of the Agreement.
F. Nature and purpose of processing. Hosting, storage, retrieval, transmission, synchronization, analysis, and other processing necessary to provide, secure, support, and improve the Services as described in the Agreement, including exchanging data with the channels Customer connects and performing the actions Customer directs (such as catalog synchronization and automated pricing).
G. Duration of processing. For the term of the Agreement, plus the post-termination retention and deletion period described in the Agreement and Section 9 of this DPA.
H. Competent Supervisory Authority. Where Module Two or Three of the SCCs applies, the competent Supervisory Authority is determined in accordance with Clause 13 of the SCCs (for example, the lead authority of the EEA Controller, or, where Customer is established outside the EEA, the authority of the EEA member state of Customer's appointed representative).
Annex II — Technical and organizational measures
Ready for Commerce maintains the following measures, which may be updated provided the overall level of security is not materially reduced.
Encryption in transit. All connections to the Services use HTTPS/TLS, and we apply HTTP Strict Transport Security (HSTS) in production. Connections between application components and databases are encrypted.
Encryption at rest. Customer Personal Data is stored in managed cloud databases and object storage with encryption at rest. Sensitive secrets — including connected-channel OAuth tokens, external data-source credentials, and API keys — are stored in an encrypted secret vault rather than in plaintext database columns or code.
Tenant isolation. The Services are multi-tenant with logical isolation enforced at the database layer through row-level security on every customer data table, scoped to organization membership, so that one organization's data is not accessible to another.
Access control and least privilege. Access is governed by a role-based access-control model with independent organizational and product roles, enforced at the page, action, and database layers. Privileged service credentials are restricted to backend processes, are separated from user-facing access by type-checked controls, and internal service-to-service calls are authenticated with secrets compared using constant-time comparison. Personnel access to production data is limited to those who need it.
Authentication. Authentication is passwordless (email one-time passcode, Google sign-in, and Shopify single sign-on), centralized, and issues short-lived sessions that are refreshed and rotated. Session cookies are HTTP-only and scoped to our domain.
Application and network security. Measures include bot-mitigation (CAPTCHA) on authentication, multi-layer rate limiting on user actions and outbound channel calls, protection against server-side request forgery on user-supplied URLs, signature verification of inbound webhooks using keyed HMAC with constant-time comparison and replay/idempotency protection, and security headers including a content security policy.
Data minimization and pseudonymization. The Services are designed not to store shoppers' personal information; product and pricing data is the focus. Analytics events carry an email domain rather than a full email address, and session replay masks input fields and on-screen text and is disabled on the login service.
Logging and monitoring. We maintain structured application and worker logs with credential scrubbing, error tracking, and a finite set of user-safe incident records, enabling detection and investigation of issues.
Resilience and backups. Customer data is hosted on managed cloud infrastructure with automated daily backups and a retention window (currently seven days), supporting restoration in the event of an incident.
Hosting location. The Services are hosted with managed cloud providers in the United States (application hosting, background-worker hosting, and database hosting in the us-east region).
Vendor management. Subprocessors are engaged under contracts imposing data-protection and security obligations, and secrets are centralized in an encrypted vault.
Organizational measures. Personnel are bound by confidentiality obligations and granted least-privilege access; security responsibilities and incident-handling practices are maintained as part of operating the Services.
Annex III — Subprocessors
The following Subprocessors are authorized to process Customer Personal Data to provide the Services. Some Subprocessors process only limited categories of data, or data other than Customer Personal Data, as noted.
- Supabase — managed database, object storage, and secret-vault hosting. United States.
- Vercel — application (web) hosting. United States.
- Railway — background-worker hosting. United States.
- Stripe — payment processing for direct subscriptions. United States and other countries.
- Shopify — App Store billing and the Shopify channel integration. United States and Canada.
- Resend — transactional email delivery. United States.
- PostHog — product analytics and error tracking. United States.
- Google — authentication (sign-in). United States.
- Cloudflare — bot mitigation and security. United States and other countries.
- Bright Data — web-data retrieval and proxy infrastructure for the Repricer's competitor-monitoring features; processes the content of external web pages a Customer directs us to monitor, not Customer account data. United States and other countries.
- OpenAI — AI-based extraction of pricing information from external web pages for the Repricer's competitor-monitoring features; processes the content of those external pages, not Customer account data, and does not use it to train its models. United States.
- Foreign-exchange rate data provider — currency conversion reference data; does not receive Customer Personal Data. Varies.
A current list of Subprocessors is maintained and made available to Customer, and changes are notified as described in Section 6.