Data Processing Addendum
Last updated August 16, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Use or other written or electronic agreement between Ready for Commerce, Inc. ("Ready for Commerce," "we," "us," or "our") and the customer agreeing to those terms ("Customer," "you," or "your") for the provision of the Services (the "Agreement"). This DPA reflects the parties' agreement on the processing of Personal Data in connection with the Services and applies to the extent Ready for Commerce processes Personal Data on Customer's behalf as a processor.
If you are entering into the Agreement and require a signed copy of this DPA, you may sign the version we make available and return it to us; an unsigned copy of this DPA, incorporated into the Agreement, is binding on the parties when you accept the Agreement or use the Services. In case of any conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA controls.
1. Definitions
Capitalized terms not defined in this DPA have the meanings given in the Agreement.
- Applicable Data Protection Law means all laws and regulations applicable to the processing of Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 ("EU GDPR"), the EU GDPR as incorporated into the law of the United Kingdom ("UK GDPR") together with the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection ("FADP"), and U.S. state privacy laws such as the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA") and the comprehensive privacy statutes of the other U.S. states in which they are in force.
- Controller, Processor, Data Subject, Personal Data, Processing, Special Categories of Personal Data, and Supervisory Authority have the meanings given in Applicable Data Protection Law; "Business," "Service Provider," "Sell," "Share," and "Sensitive Personal Information" have the meanings given in the CCPA.
- Customer Personal Data means Personal Data contained in Customer Data that Ready for Commerce processes on Customer's behalf as a Processor under the Agreement.
- Data Subject Request means a request from a Data Subject to exercise rights under Applicable Data Protection Law.
- Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
- Standard Contractual Clauses or SCCs means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Decision 2021/914 of 4 June 2021.
- UK Addendum means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
- Data Privacy Framework means the EU-U.S. Data Privacy Framework, together with the UK Extension and the Swiss-U.S. Data Privacy Framework, as administered by the U.S. Department of Commerce and recognized by the corresponding adequacy decisions.
- Subprocessor means any third party engaged by Ready for Commerce to process Customer Personal Data.
- Subprocessor List means the current list of Subprocessors published at https://www.readyforcommerce.com/legal/subprocessors, which is incorporated into this DPA and populates Annex III.
- AI Provider means a Subprocessor that applies artificial-intelligence or machine-learning models to data on our behalf, as described in Section 7.
2. Roles of the parties
With respect to Customer Personal Data, Customer is the Controller (or a Processor acting on behalf of a third-party Controller) and Ready for Commerce is the Processor. Where Customer is itself a Processor, Customer warrants that it has the third-party Controller's authorization to engage Ready for Commerce as a Subprocessor and to agree to this DPA on the Controller's behalf, and that the instructions and obligations in this DPA are consistent with the third-party Controller's instructions. This DPA does not apply to Personal Data for which Ready for Commerce is the Controller, which is governed by our Privacy Policy.
3. Scope and instructions for processing
Subject matter. Ready for Commerce processes Customer Personal Data only to provide and support the Services as described in the Agreement and the Documentation, and as further described in Annex I.
Documented instructions. Ready for Commerce will process Customer Personal Data only on Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by applicable law; in that case, Ready for Commerce will inform Customer of that legal requirement before processing, unless the law prohibits this on important grounds of public interest. The Agreement, this DPA, and Customer's configuration and use of the Services (including the channels Customer connects and the actions Customer directs) constitute Customer's complete documented instructions. Ready for Commerce will inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law.
Compliance. Each party will comply with its obligations under Applicable Data Protection Law. Customer is responsible for the lawfulness of Customer Personal Data and of Customer's instructions, including having a valid legal basis, providing required notices, and obtaining required consents for the processing contemplated by the Agreement.
4. Confidentiality
Ready for Commerce will ensure that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations (whether contractual or statutory) and are granted access on a need-to-know, least-privilege basis.
5. Security measures
Ready for Commerce will implement and maintain appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to Data Subjects. These measures are described in Annex II — Technical and Organizational Measures. Ready for Commerce may update its measures from time to time, provided the updates do not materially reduce the overall level of security.
6. Subprocessors
General authorization. Customer provides general written authorization for Ready for Commerce to engage Subprocessors to process Customer Personal Data. Ready for Commerce's current Subprocessors are set out in the Subprocessor List and reproduced in Annex III. The Subprocessor List is the controlling version between updates of this DPA.
Obligations. Before engaging a Subprocessor, Ready for Commerce carries out a reasonable assessment of its data-protection and security practices. Ready for Commerce will impose data-protection obligations on each Subprocessor by written contract that are no less protective than those in this DPA, will engage each Subprocessor only for the function described in the Subprocessor List, and will remain liable to Customer for each Subprocessor's performance of its data-protection obligations as if that performance were its own.
Changes and objection. Ready for Commerce will provide notice of any intended addition or replacement of a Subprocessor — by updating the Subprocessor List and, where Customer subscribes to notifications at that page, by email — at least thirty (30) days before the change takes effect. If Customer has a reasonable, data-protection-based objection, Customer may notify Ready for Commerce within that period; the parties will work in good faith to resolve the objection, and if they cannot, Customer may terminate the affected Service as its sole remedy.
Emergency replacement. Where a Subprocessor must be engaged or replaced on shorter notice to protect the security, availability, or lawful operation of the Services, Ready for Commerce may do so before the notice period elapses and will inform Customer promptly afterward, together with the reason. Customer's objection right in the preceding paragraph then applies from the date of that notice.
7. Artificial-intelligence processing
Where AI is used. Certain features of the Services are performed with the assistance of artificial-intelligence models operated by AI Providers listed in the Subprocessor List. Today those features are: (a) in the Repricer, extracting a price from an external web page a Customer has directed us to monitor, from the page's text or from a screenshot of it; and (b) in the PIM, transforming a product image at a user's request — upscaling it, removing its background, or isolating a subject within it. Both are performed only on Customer's instruction, in response to a configuration or action Customer takes.
What is sent, and what is not. Ready for Commerce sends an AI Provider only the data the requested operation requires: for price extraction, the content of the external page in question; for image transformation, the image the user selected and the parameters of the operation. Account credentials, authentication data, billing data, and Customer's catalog as a whole are not sent to an AI Provider.
No training on Customer Personal Data. Ready for Commerce does not use Customer Personal Data to train, fine-tune, or otherwise develop generally available artificial-intelligence models. Ready for Commerce does not authorize any AI Provider to use data submitted on Customer's behalf to train that provider's models, engages each AI Provider on terms consistent with that restriction where the provider offers them, and sets the provider's control accordingly where one is available. Ready for Commerce will not enable an AI Provider setting that permits such training without Customer's prior written consent.
Retention at the AI Provider. An AI Provider may retain the data submitted to it for a limited period in order to deliver the result, to monitor for abuse of its service, or to make generated output available for retrieval, in each case under that provider's own published terms. Ready for Commerce sends only what the operation requires and does not ask an AI Provider to retain anything beyond what delivering the result requires.
Output is not a decision about a person. AI output in the Services concerns products, images, and prices, not individuals. It is probabilistic and may be inaccurate or incomplete, and Customer remains responsible for reviewing it before relying on it. Ready for Commerce does not use artificial intelligence to carry out profiling of, or to make automated decisions producing legal or similarly significant effects concerning, any Data Subject.
8. Assistance to Customer
Data Subject Requests. Taking into account the nature of the processing, Ready for Commerce will assist Customer by appropriate technical and organizational measures, insofar as possible, to respond to Data Subject Requests. If Ready for Commerce receives a Data Subject Request directly, it will, unless legally prohibited, promptly inform the Data Subject to contact Customer and will not otherwise respond except on Customer's instructions. Customer can access, correct, export, and delete much of the Customer Personal Data within the Services directly.
Other assistance. Taking into account the nature of processing and the information available to it, Ready for Commerce will provide reasonable assistance to Customer with data-protection impact assessments, prior consultations with Supervisory Authorities, and Customer's obligations regarding the security of processing and Personal Data Breaches.
9. Personal Data Breach notification
Ready for Commerce will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to it to help Customer meet its breach-notification obligations. Such notification is not an acknowledgment of fault or liability. Ready for Commerce will take reasonable steps to mitigate and, where possible, remediate the breach.
10. Return and deletion of Customer Personal Data
Upon termination or expiration of the Agreement, Ready for Commerce will, at Customer's choice, delete or return Customer Personal Data, and delete existing copies, unless applicable law requires storage. For a limited period after termination (as described in the Agreement), the Services may allow Customer to export Customer Personal Data; thereafter, Ready for Commerce will delete or de-identify it in the ordinary course, including from backups in accordance with its backup cycles, except as required by law or for the establishment, exercise, or defense of legal claims.
11. Audits
Ready for Commerce will make available to Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by Customer or an independent auditor mandated by Customer, in accordance with this section. To the extent available, Ready for Commerce may satisfy audit requests by providing then-current third-party certifications, audit reports, or security documentation. Any on-site audit will be conducted no more than once per year (except where required by a Supervisory Authority or following a Personal Data Breach), on reasonable prior notice, during business hours, subject to confidentiality obligations, and in a manner that does not disrupt Ready for Commerce's operations or compromise the security of other customers' data.
12. International data transfers
Transfer mechanism. Where Ready for Commerce processes Customer Personal Data that is subject to the EU GDPR, UK GDPR, or FADP and transfers it to a country that has not received an adequacy decision, the following apply and are incorporated into this DPA by reference:
- EEA transfers. The SCCs apply. Module Two (Controller-to-Processor) applies where Customer is a Controller, and Module Three (Processor-to-Processor) applies where Customer is a Processor. The optional docking clause (Clause 7) does not apply. Under Clause 9, Option 2 (general written authorization) applies, with the notice period in Section 6 of this DPA. The optional language in Clause 11 does not apply. For Clause 17, the SCCs are governed by the law of Ireland; for Clause 18(b), disputes will be resolved before the courts of Ireland. Annex I and Annex II of this DPA populate Annexes I and II of the SCCs, and Annex III lists the authorized Subprocessors.
- UK transfers. The UK Addendum applies to and amends the SCCs for transfers subject to the UK GDPR. The information required by Tables 1 to 3 of the UK Addendum is set out in this DPA and its Annexes; for Table 4, the party that may end the UK Addendum is the data importer. The start date of the UK Addendum is the effective date of this DPA.
- Swiss transfers. For transfers subject to the FADP, the SCCs apply with the following adjustments: references to the GDPR are to the FADP where applicable; the competent Supervisory Authority is the Swiss Federal Data Protection and Information Commissioner; and the term "member state" does not prevent Data Subjects in Switzerland from suing in their place of habitual residence.
- Data Privacy Framework. Where the data importer is certified under the Data Privacy Framework for the relevant categories of Personal Data, Ready for Commerce may rely on that certification as the transfer mechanism instead of the SCCs, for as long as the certification and the corresponding adequacy decision remain in force. If either lapses, the SCCs apply automatically and without further action by the parties.
- Onward transfers to Subprocessors. Where Ready for Commerce transfers Customer Personal Data to a Subprocessor established in a country that has not received an adequacy decision, Ready for Commerce puts in place the SCCs (or another valid mechanism) with that Subprocessor, imposes the onward-transfer conditions of Clause 8.8 of the SCCs, and carries out and documents a transfer impact assessment taking into account the laws and practices of the destination country. Each Subprocessor's country of establishment is stated in the Subprocessor List.
Conflict. In case of any conflict between the SCCs (and the UK Addendum) and this DPA or the Agreement, the SCCs (and the UK Addendum) prevail with respect to the transfers they govern.
Execution and updates. By entering into this DPA, each party is deemed to have signed the SCCs (and the UK Addendum), including their Annexes, which are populated by Annexes I to III of this DPA. If the European Commission, the UK Information Commissioner, or another competent authority issues new or revised standard contractual clauses or approves a different valid transfer mechanism, the parties will apply the updated mechanism, which will replace the prior version with respect to the transfers it governs, without the need to amend this DPA.
13. Government and law enforcement requests
If Ready for Commerce receives a legally binding request from a public authority, including a law-enforcement or government authority, for disclosure of Customer Personal Data, Ready for Commerce will, unless legally prohibited: (a) review the legality of the request; (b) inform the requesting authority that it is a Processor acting on Customer's behalf and, where appropriate, that the request should be directed to Customer; (c) notify Customer without undue delay so that Customer may seek a protective order or other appropriate remedy; and (d) challenge requests that it considers unlawful, overbroad, or inconsistent with Applicable Data Protection Law, disclosing only the minimum amount of Customer Personal Data necessary to comply with a valid and binding request. Ready for Commerce will document the requests it receives and its responses, to the extent permitted by law. This section is in addition to, and does not limit, the obligations in Clause 15 of the SCCs where the relevant transfers are subject to the SCCs.
14. United States state privacy laws
To the extent the CCPA or other U.S. state privacy laws apply to Customer Personal Data, Ready for Commerce acts as a Service Provider (or Processor) and processes Customer Personal Data only to perform the Services and for the business purposes set out in the Agreement and this DPA. Ready for Commerce will not: (a) Sell or Share Customer Personal Data; (b) retain, use, or disclose it for any purpose other than the business purposes specified, including outside the direct business relationship; or (c) combine it with personal information from other sources, except as permitted by the CCPA. Ready for Commerce certifies that it understands and will comply with these restrictions. Ready for Commerce will notify Customer if it determines it can no longer meet its obligations, and Customer may take reasonable steps to stop and remediate unauthorized processing. Ready for Commerce will also assist Customer in responding to verified consumer requests it receives under those laws, will engage Subprocessors under contracts imposing equivalent restrictions, and will grant Customer the right to take the reasonable and appropriate steps those laws require to verify that its processing is consistent with Customer's instructions, which the audit rights in Section 11 satisfy.
15. Liability
Each party's liability arising out of or related to this DPA, whether in contract, tort, or any other theory, is subject to the limitations and exclusions of liability set out in the Agreement, and any reference in the Agreement to a party's liability means the aggregate liability of that party under the Agreement and this DPA together.
16. General
This DPA is governed by the same law as the Agreement, except where Applicable Data Protection Law or the SCCs require otherwise. If any provision of this DPA is found unenforceable, the remainder remains in effect. This DPA may not be modified except as provided in the Agreement or as required to maintain compliance with Applicable Data Protection Law. This DPA takes precedence over any conflicting provision of the Agreement with respect to the processing of Customer Personal Data. This DPA takes effect when Customer accepts the Agreement and remains in effect for as long as Ready for Commerce processes Customer Personal Data, until all Customer Personal Data has been deleted or returned in accordance with Section 10.
Annex I — Description of processing
A. List of parties.
Data exporter: Customer, the entity that accepts the Agreement, acting as Controller (or as Processor on behalf of a third-party Controller). Contact: the account and billing contact designated in the Services. Activities: use of the Services as described in the Agreement. Role: Controller (or Processor).
Data importer: Ready for Commerce, Inc., 9616 NW 7th Circle #1625, Plantation, FL 33324, United States, acting as Processor. Contact: privacy@readyforcommerce.com. Activities: provision of the Services as described in the Agreement. Role: Processor.
B. Categories of Data Subjects. Customer's authorized users and personnel (such as administrators, managers, editors, and analysts); Customer's business contacts (such as the billing contact and invited users); and any individuals whose Personal Data Customer chooses to include in Customer Data, in connected-channel configurations, or in the external data sources Customer configures. The Services are designed to manage product and pricing data and are not intended to process the personal information of Customer's shoppers or end customers.
C. Categories of Personal Data. Identification and contact data (such as name and email address); account and profile data (such as user identifier, language, and time zone); organization and role data (such as team membership, permissions, invitations, and ownership); authentication and security data (such as IP address, device and browser user-agent, session identifiers, authentication events, and timestamps); activity and audit data recording which user created, changed, or deleted a record and when; collaboration and presence data indicating which users are viewing or editing the same record at the same time; usage and metering data; support and notification records; content Customer submits to the Services, including product media and images; credentials for the external data sources Customer configures, which are held in an encrypted secret vault; billing data (such as billing contact and limited payment-card metadata, namely card brand, last four digits, and expiry — full card numbers and security codes are handled by the payment processors and are not stored by Ready for Commerce); and any other Personal Data that Customer includes in Customer Data or connected-channel configurations.
D. Special Categories of Personal Data. None are intended or required. Customer must not submit Special Categories of Personal Data to the Services except where expressly supported and subject to additional safeguards agreed in writing.
E. Frequency of processing. Continuous, for the duration of the Agreement.
F. Nature and purpose of processing. Hosting, storage, retrieval, transmission, synchronization, analysis, and other processing necessary to provide, secure, support, and improve the Services as described in the Agreement, including exchanging data with the channels Customer connects and performing the actions Customer directs — such as catalog synchronization, bulk import and export, ingestion from the external data sources Customer configures, automated pricing and price submission, retrieval of the external web pages Customer directs us to monitor, and the artificial-intelligence-assisted operations described in Section 7.
G. Duration of processing. For the term of the Agreement, plus the post-termination retention and deletion period described in the Agreement and Section 10 of this DPA.
H. Competent Supervisory Authority. Where Module Two or Three of the SCCs applies, the competent Supervisory Authority is determined in accordance with Clause 13 of the SCCs (for example, the lead authority of the EEA Controller, or, where Customer is established outside the EEA, the authority of the EEA member state of Customer's appointed representative).
Annex II — Technical and organizational measures
Ready for Commerce maintains the following measures, which may be updated provided the overall level of security is not materially reduced.
Encryption in transit. All connections to the Services use HTTPS/TLS, and we apply HTTP Strict Transport Security (HSTS) in production. Connections between application components and databases are encrypted.
Encryption at rest. Customer Personal Data is stored in managed cloud databases and object storage with encryption at rest. Sensitive secrets — including connected-channel OAuth tokens, external data-source credentials, and API keys — are stored in an encrypted secret vault rather than in plaintext database columns or code.
Tenant isolation. The Services are multi-tenant with logical isolation enforced at the database layer through row-level security on every customer data table, scoped to organization membership, so that one organization's data is not accessible to another.
Access control and least privilege. Access is governed by a role-based access-control model with independent organizational and product roles, enforced at the page, action, and database layers. Privileged service credentials are restricted to backend processes, are separated from user-facing access by type-checked controls, and internal service-to-service calls are authenticated with secrets compared using constant-time comparison. Personnel access to production data is limited to those who need it.
Authentication. Authentication is passwordless (email one-time passcode, Google sign-in, and Shopify single sign-on), centralized in one service, and issues short-lived sessions that are refreshed and rotated. No user passwords are set, transmitted, or stored anywhere in the platform. Session cookies are HTTP-only and scoped to our domain, and post-login redirects are validated against an allowlist.
Application and network security. Measures include bot mitigation on authentication (Cloudflare Turnstile), multi-layer rate limiting on user actions and outbound channel calls, protection against server-side request forgery on user-supplied URLs, signature verification of inbound webhooks using keyed HMAC with constant-time comparison and replay/idempotency protection, and security headers including a content security policy.
Change management. Changes to the Services are version-controlled and pass an automated quality gate — formatting, linting, static type checking, internationalization parity, and the data-integrity harnesses that guard pricing and identifier logic — before they reach production. Production deployments are made from the reviewed main branch, and prior versions can be restored.
Data minimization and pseudonymization. The Services are designed not to store shoppers' personal information; product and pricing data is the focus. Analytics events carry an email domain rather than a full email address, and session replay masks input fields and on-screen text and is disabled on the login service. Structured logs are scrubbed of credentials.
Product media. Product images and other media uploaded to the PIM are stored in an object-storage bucket that is readable over the internet by anyone holding the object's address, at long, unguessable paths. This is deliberate: connected sales channels, hosted image-optimization services, and the artificial-intelligence image operations described in Section 7 must be able to fetch an image directly by URL. Media is therefore protected by the secrecy of its address rather than by a session check, and Customer should not upload confidential or personal material as product media.
Logging and monitoring. We maintain structured application and worker logs with credential scrubbing, error tracking, and a finite set of user-safe incident records, enabling detection and investigation of issues.
Resilience and backups. Customer data is hosted on managed cloud infrastructure with automated daily backups and a retention window (currently seven days), supporting restoration in the event of an incident.
Hosting location. The Services are hosted with managed cloud providers in the United States: application hosting, background-worker hosting, and database and object storage all in the us-east region. Some Subprocessors that support specific features operate from other countries, as stated in the Subprocessor List.
Vendor management. Subprocessors are assessed before engagement, are engaged under contracts imposing data-protection and security obligations, are scoped to a single documented function, and are recorded in the Subprocessor List. Secrets and credentials are centralized in an encrypted vault rather than held by individuals.
Organizational measures. Personnel are bound by confidentiality obligations and granted least-privilege access; security responsibilities and incident-handling practices are maintained as part of operating the Services.
Annex III — Subprocessors
The following Subprocessors are authorized to process Customer Personal Data to provide the Services, each only for the function stated. Some Subprocessors process only limited categories of data, or data other than Customer Personal Data, as noted. This Annex reproduces the Subprocessor List as of the effective date of this DPA; the Subprocessor List is the controlling version between updates of this DPA, and changes to it are notified as described in Section 6.
- Supabase (Supabase Pte. Ltd.) — managed database, object storage, and encrypted secret-vault hosting for the platform and both products, and the store behind our centralized authentication. United States (us-east-1).
- Vercel (Vercel Inc.) — application and web hosting for the authentication service, the account and billing service, the PIM, the Repricer, and our marketing website. United States (us-east-1).
- Railway (Railway Corp.) — hosting for the background workers that run catalog synchronization, imports and exports, market-data collection, and automated pricing. United States (US East).
- Stripe (Stripe, Inc.) — payment processing, subscription management, and payment fraud prevention for direct subscriptions. United States and other countries.
- Shopify (Shopify Inc.) — App Store billing for subscriptions acquired through Shopify, the Shopify sales-channel integration, and the Shopify single-sign-on bridge. Canada and the United States.
- Resend (Resend, Inc.) — transactional email delivery, including sign-in codes, security notifications, billing notices, operational alerts, and messages sent through our contact form. United States.
- PostHog (PostHog, Inc.) — product analytics, error tracking, masked session replay, and application and worker logs. United States.
- Google (Google LLC) — Google sign-in and Google One Tap, when a user chooses to authenticate with a Google account. United States and other countries.
- Cloudflare (Cloudflare, Inc.) — bot mitigation on our authentication service (Cloudflare Turnstile) and DNS for our domains. United States and other countries.
- fal.ai (fal — Features & Labels, Inc.) — hosted artificial-intelligence image processing for the PIM's image optimizer: upscaling, background removal, and subject segmentation. It receives the product image a user chooses to transform and the parameters of the requested operation, and returns a transformed image that it hosts for a limited period so the interface can load it. No account, authentication, or billing data is sent. United States.
- OpenAI (OpenAI, L.L.C.) — artificial-intelligence extraction of pricing information from the external web pages a Customer directs the Repricer to monitor, from the page's text or from a screenshot of it, when the free structured-data parsers cannot read the price. It receives the content of those external pages, not Customer account data, and data submitted through its API is not used to train its models. United States.
- IPRoyal (IPRoyal Services FZE LLC) — residential-proxy and web-unblocking infrastructure used to retrieve those same external competitor pages when a direct request is blocked. It receives the addresses of the pages a Customer asked us to monitor and returns their content; no Customer account data is sent. United Arab Emirates, with retrieval infrastructure in many countries.
- Browserless (Browserless) — remote headless-browser rendering, the last-resort transport for the same external pages when a page cannot be read any other way. It receives the addresses of those pages and returns a rendered screenshot; no Customer account data is sent. United States.
- Sanity (Sanity AS) — content management for our public marketing website. It hosts our own published copy and does not receive Customer Personal Data. Norway and the United States.
- ExchangeRate-API — daily foreign-exchange reference rates used to convert amounts between currencies. We request only the published rate table; no Customer Personal Data and no Customer request data are sent. Varies.
The sales channels Customer connects — such as Shopify, Amazon, Walmart, eBay, BigCommerce, Square, and Google Merchant Center — are not Subprocessors. They receive data at Customer's direction, under Customer's own account and agreement with them, and process it as Customer's own providers or counterparties.