Skip to content
StoreFlux
Features Developers Security Pricing Docs FAQ
Sign in Start free
Features Developers Security Pricing Docs FAQ
Start free Sign in
Home/Legal/Data Processing (DPA)

Data Processing Addendum

How StoreFlux processes personal data on behalf of merchants, the safeguards we apply, and the sub-processors we use.

Last updated: October 3, 2026 Applies to storeflux.store, the admin panel and the API
On this page
  1. Roles and scope
  2. Processing instructions
  3. Merchant responsibilities
  4. Confidentiality
  5. Security measures
  6. International transfers
  7. Data-subject requests
  8. Personal-data breaches
  9. Assistance and audits
  10. Return and deletion
  11. Liability and precedence
  12. Contact

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between StoreFlux (“Processor”) and the merchant who uses the Service (“Controller” or “Merchant”). It applies where StoreFlux processes personal data on the Merchant’s behalf in providing the Service, and reflects the requirements of the EU/UK GDPR and comparable laws (“Data Protection Law”). Terms such as “personal data”, “processing”, “controller”, “processor” and “data subject” have the meanings given in Data Protection Law.

01Roles and scope

For personal data that the Merchant or its shoppers enter into a store on the platform (“Customer Personal Data”), the Merchant is the controller and StoreFlux is the processor. For account, billing, website and security data that StoreFlux collects for its own purposes, StoreFlux is an independent controller as described in the Privacy Policy; this DPA does not apply to that data.

ItemDescription
Subject matterHosting and operating the Merchant’s store on the StoreFlux platform
DurationThe term of the Merchant’s subscription plus the post-termination export window
Nature and purposeStorage, retrieval, transmission and processing needed to provide commerce, administration, analytics, messaging and support functions
Data subjectsThe Merchant’s customers, prospects and website visitors, and the Merchant’s staff users
Categories of dataNames, email addresses, phone numbers, addresses, order and return history, wishlist and cart contents, reviews, loyalty and referral records, consent records, store-activity events tied to anonymous session identifiers, and payment references (not card numbers)
Sensitive dataThe Service is not designed to process special-category data; the Merchant must not submit it

02Processing instructions

StoreFlux will process Customer Personal Data only on the Merchant’s documented instructions, which consist of these Terms, this DPA, and the Merchant’s configuration and use of the Service (including through the API and admin panel). If we believe an instruction infringes Data Protection Law, we will tell the Merchant. We will not process Customer Personal Data for our own purposes, sell it, or use it for advertising.

03Merchant responsibilities

The Merchant is responsible for the lawfulness of its collection and use of Customer Personal Data, for providing privacy notices and obtaining consents where required, for the accuracy of data entered, for configuring storefront cookie notices, and for deciding which optional integrations (such as AI providers or advertising platforms) receive data.

04Confidentiality

People authorised by StoreFlux to process Customer Personal Data are bound by confidentiality obligations and receive access only as needed to operate and support the Service.

05Security measures

StoreFlux implements technical and organisational measures appropriate to the risk, including:

  • Tenant isolation: Postgres row-level security enforced at the database layer for tenant-scoped data.
  • Encryption: TLS for data in transit; application-level encryption at rest for gateway secrets and integration tokens.
  • Authentication: PBKDF2-SHA256 password hashing (350,000 iterations), 15-minute access tokens with rotating refresh tokens and replay detection, account lockout, role-based access control.
  • Payments: client-side tokenisation through Stripe and PayPal so card data never reaches StoreFlux servers; distributed locking and idempotency keys on payment and refund operations.
  • Auditability: immutable audit logging of administrative actions.
  • Resilience: managed infrastructure, health checks and backups.
  • Secure development: dependency vulnerability checks and a responsible-disclosure channel (see Security & Disclosure).

Sub-processors

The Merchant gives general authorisation for StoreFlux to engage the sub-processors below. StoreFlux imposes data-protection obligations on each that are no less protective than this DPA and remains responsible for their performance. Some sub-processors only apply when the Merchant enables the related feature.

Sub-processorPurposeWhen it appliesLocation
Amazon Web ServicesCompute, managed PostgreSQL, managed cache (Valkey), S3 file storage, email delivery (SES)AlwaysUnited States
StripeCard payment processing for the Merchant’s storeIf the Merchant enables StripeUnited States / global
PayPalPayPal payment processing for the Merchant’s storeIf the Merchant enables PayPalUnited States / global
AI providers (Anthropic, OpenAI, Groq, Google)Generating insights and content suggestionsOnly if the Merchant enables AI features with a provider key; the demo store uses a platform keyUnited States
Meta PlatformsAdvertising and social-account integrationsOnly if the Merchant connects themUnited States / global
SentryError monitoring (technical diagnostics)Where enabled; not used for shopper contentUnited States / EU

We will give the Merchant at least 30 days’ notice of a new or replacement sub-processor by email or in the admin panel. The Merchant may object on reasonable data-protection grounds within that period; if we cannot accommodate the objection, the Merchant may terminate the affected subscription and receive a refund of prepaid fees for the unused period. Google Analytics is used only on StoreFlux’s own marketing website, with consent, and is not a sub-processor of Customer Personal Data.

06International transfers

Customer Personal Data may be processed in the United States and in other countries where our sub-processors operate. For transfers of personal data from the EEA, UK or Switzerland to a country without an adequacy decision, the parties agree that the Standard Contractual Clauses (and the UK International Data Transfer Addendum, where applicable) are incorporated by reference, with the Merchant as data exporter and StoreFlux as data importer (Module Two, controller to processor). Sub-processor transfers rely on the corresponding Module Three clauses or an adequacy mechanism.

07Data-subject requests

StoreFlux provides tools that let the Merchant respond to requests for access, portability and erasure: the admin panel’s privacy section supports customer data requests (export as machine-readable JSON, and anonymisation of a customer’s personal data) and consent records. If a data subject contacts StoreFlux directly about Customer Personal Data, we will redirect them to the Merchant where we can identify it and will not respond substantively without the Merchant’s authorisation, unless the law requires it. We will provide reasonable additional assistance at the Merchant’s request.

08Personal-data breaches

StoreFlux will notify the Merchant without undue delay, and in any case within 72 hours, after becoming aware of a personal-data breach affecting Customer Personal Data, and will provide the information reasonably available to help the Merchant meet its notification duties. We will take steps to contain and remediate the breach.

09Assistance and audits

Taking into account the nature of processing, StoreFlux will reasonably assist the Merchant with data-protection impact assessments and consultations with supervisory authorities. On reasonable written request, and no more than once a year unless a breach has occurred, StoreFlux will provide information needed to demonstrate compliance with this DPA, which may include summaries of security practices and third-party assessments. Any on-site audit must be agreed in advance, limited in scope and duration, and subject to confidentiality.

10Return and deletion

Within 30 days after the subscription ends, the Merchant may export Customer Personal Data using the API and admin tools. After that period StoreFlux will delete or irreversibly anonymise Customer Personal Data from production systems, and it will age out of backups on their normal rotation, unless retention is required by law.

11Liability and precedence

Each party’s liability under this DPA is subject to the limitations in the Terms of Service. If this DPA conflicts with the Terms on the processing of Customer Personal Data, this DPA prevails. If it conflicts with the Standard Contractual Clauses, the Clauses prevail.

12Contact

To request a countersigned copy of this DPA or ask a data-protection question, email admin.storeflux@gmail.com.

Other policies

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Refund & Cancellation
  • Acceptable Use
  • Security & Disclosure
StoreFlux

The complete headless commerce backend. Build it yourself or let us build it for you.

All systems operational

Product

  • Features
  • API Playground
  • Security
  • Pricing
  • Documentation

Resources

  • Admin panel demo
  • Storefront demo
  • API reference
  • FAQ
  • Contact

Legal

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Refund & Cancellation
  • Acceptable Use
  • Data Processing (DPA)
  • Security & Disclosure

© 2026 StoreFlux. All rights reserved.

· Built on .NET 10, React 19, and PostgreSQL.

StoreFlux