This Data Processing Addendum (“DPA”) forms part of the Terms of Service between StoreFlux (“Processor”) and the merchant who uses the Service (“Controller” or “Merchant”). It applies where StoreFlux processes personal data on the Merchant’s behalf in providing the Service, and reflects the requirements of the EU/UK GDPR and comparable laws (“Data Protection Law”). Terms such as “personal data”, “processing”, “controller”, “processor” and “data subject” have the meanings given in Data Protection Law.
01Roles and scope
For personal data that the Merchant or its shoppers enter into a store on the platform (“Customer Personal Data”), the Merchant is the controller and StoreFlux is the processor. For account, billing, website and security data that StoreFlux collects for its own purposes, StoreFlux is an independent controller as described in the Privacy Policy; this DPA does not apply to that data.
| Item | Description |
|---|---|
| Subject matter | Hosting and operating the Merchant’s store on the StoreFlux platform |
| Duration | The term of the Merchant’s subscription plus the post-termination export window |
| Nature and purpose | Storage, retrieval, transmission and processing needed to provide commerce, administration, analytics, messaging and support functions |
| Data subjects | The Merchant’s customers, prospects and website visitors, and the Merchant’s staff users |
| Categories of data | Names, email addresses, phone numbers, addresses, order and return history, wishlist and cart contents, reviews, loyalty and referral records, consent records, store-activity events tied to anonymous session identifiers, and payment references (not card numbers) |
| Sensitive data | The Service is not designed to process special-category data; the Merchant must not submit it |
02Processing instructions
StoreFlux will process Customer Personal Data only on the Merchant’s documented instructions, which consist of these Terms, this DPA, and the Merchant’s configuration and use of the Service (including through the API and admin panel). If we believe an instruction infringes Data Protection Law, we will tell the Merchant. We will not process Customer Personal Data for our own purposes, sell it, or use it for advertising.
03Merchant responsibilities
The Merchant is responsible for the lawfulness of its collection and use of Customer Personal Data, for providing privacy notices and obtaining consents where required, for the accuracy of data entered, for configuring storefront cookie notices, and for deciding which optional integrations (such as AI providers or advertising platforms) receive data.
04Confidentiality
People authorised by StoreFlux to process Customer Personal Data are bound by confidentiality obligations and receive access only as needed to operate and support the Service.
05Security measures
StoreFlux implements technical and organisational measures appropriate to the risk, including:
- Tenant isolation: Postgres row-level security enforced at the database layer for tenant-scoped data.
- Encryption: TLS for data in transit; application-level encryption at rest for gateway secrets and integration tokens.
- Authentication: PBKDF2-SHA256 password hashing (350,000 iterations), 15-minute access tokens with rotating refresh tokens and replay detection, account lockout, role-based access control.
- Payments: client-side tokenisation through Stripe and PayPal so card data never reaches StoreFlux servers; distributed locking and idempotency keys on payment and refund operations.
- Auditability: immutable audit logging of administrative actions.
- Resilience: managed infrastructure, health checks and backups.
- Secure development: dependency vulnerability checks and a responsible-disclosure channel (see Security & Disclosure).
Sub-processors
The Merchant gives general authorisation for StoreFlux to engage the sub-processors below. StoreFlux imposes data-protection obligations on each that are no less protective than this DPA and remains responsible for their performance. Some sub-processors only apply when the Merchant enables the related feature.
| Sub-processor | Purpose | When it applies | Location |
|---|---|---|---|
| Amazon Web Services | Compute, managed PostgreSQL, managed cache (Valkey), S3 file storage, email delivery (SES) | Always | United States |
| Stripe | Card payment processing for the Merchant’s store | If the Merchant enables Stripe | United States / global |
| PayPal | PayPal payment processing for the Merchant’s store | If the Merchant enables PayPal | United States / global |
| AI providers (Anthropic, OpenAI, Groq, Google) | Generating insights and content suggestions | Only if the Merchant enables AI features with a provider key; the demo store uses a platform key | United States |
| Meta Platforms | Advertising and social-account integrations | Only if the Merchant connects them | United States / global |
| Sentry | Error monitoring (technical diagnostics) | Where enabled; not used for shopper content | United States / EU |
We will give the Merchant at least 30 days’ notice of a new or replacement sub-processor by email or in the admin panel. The Merchant may object on reasonable data-protection grounds within that period; if we cannot accommodate the objection, the Merchant may terminate the affected subscription and receive a refund of prepaid fees for the unused period. Google Analytics is used only on StoreFlux’s own marketing website, with consent, and is not a sub-processor of Customer Personal Data.
06International transfers
Customer Personal Data may be processed in the United States and in other countries where our sub-processors operate. For transfers of personal data from the EEA, UK or Switzerland to a country without an adequacy decision, the parties agree that the Standard Contractual Clauses (and the UK International Data Transfer Addendum, where applicable) are incorporated by reference, with the Merchant as data exporter and StoreFlux as data importer (Module Two, controller to processor). Sub-processor transfers rely on the corresponding Module Three clauses or an adequacy mechanism.
07Data-subject requests
StoreFlux provides tools that let the Merchant respond to requests for access, portability and erasure: the admin panel’s privacy section supports customer data requests (export as machine-readable JSON, and anonymisation of a customer’s personal data) and consent records. If a data subject contacts StoreFlux directly about Customer Personal Data, we will redirect them to the Merchant where we can identify it and will not respond substantively without the Merchant’s authorisation, unless the law requires it. We will provide reasonable additional assistance at the Merchant’s request.
08Personal-data breaches
StoreFlux will notify the Merchant without undue delay, and in any case within 72 hours, after becoming aware of a personal-data breach affecting Customer Personal Data, and will provide the information reasonably available to help the Merchant meet its notification duties. We will take steps to contain and remediate the breach.
09Assistance and audits
Taking into account the nature of processing, StoreFlux will reasonably assist the Merchant with data-protection impact assessments and consultations with supervisory authorities. On reasonable written request, and no more than once a year unless a breach has occurred, StoreFlux will provide information needed to demonstrate compliance with this DPA, which may include summaries of security practices and third-party assessments. Any on-site audit must be agreed in advance, limited in scope and duration, and subject to confidentiality.
10Return and deletion
Within 30 days after the subscription ends, the Merchant may export Customer Personal Data using the API and admin tools. After that period StoreFlux will delete or irreversibly anonymise Customer Personal Data from production systems, and it will age out of backups on their normal rotation, unless retention is required by law.
11Liability and precedence
Each party’s liability under this DPA is subject to the limitations in the Terms of Service. If this DPA conflicts with the Terms on the processing of Customer Personal Data, this DPA prevails. If it conflicts with the Standard Contractual Clauses, the Clauses prevail.
12Contact
To request a countersigned copy of this DPA or ask a data-protection question, email admin.storeflux@gmail.com.