Data Processing Agreement
Last updated: September 29, 2026
This Data Processing Agreement (“DPA”) forms part of the StoreCheckup Terms of Service and governs the processing of Personal Data by StoreCheckup on behalf of a customer in connection with the StoreCheckup services.
This DPA is intended to apply where StoreCheckup processes Personal Data on behalf of a customer as a data processor under applicable data protection laws, including the EU General Data Protection Regulation (“GDPR”) where applicable.
1. Definitions
For purposes of this DPA:
- “Customer” means the StoreCheckup customer who uses the Services and determines the purposes for which Customer Data is processed.
- “StoreCheckup,” “we,” “us,” or “our” means the provider of the StoreCheckup Services.
- “Personal Data” means information relating to an identified or identifiable natural person, as defined by applicable data protection law.
- “Customer Data” means Personal Data processed by StoreCheckup on behalf of the Customer in connection with the Services.
- “Processing” and “process” have the meanings given to them under applicable data protection law.
- “Subprocessor” means a third party engaged by StoreCheckup to process Customer Data on behalf of the Customer.
- “Data Protection Laws” means applicable laws and regulations relating to privacy and the protection of Personal Data, including the GDPR where applicable.
2. Roles of the Parties
For Customer Data processed through the Services on the Customer’s behalf, the Customer acts as the data controller and StoreCheckup acts as the data processor, unless applicable law provides otherwise.
The Customer is responsible for determining the purposes and lawful basis for processing Personal Data collected through its store and for providing any notices, obtaining any consents, and fulfilling any other obligations required of it under applicable Data Protection Laws.
StoreCheckup will process Customer Data only as necessary to provide the Services and in accordance with the Customer’s documented instructions, this DPA, the Terms of Service, and applicable Data Protection Laws.
Where StoreCheckup processes information for its own independent purposes, such as managing Customer accounts, billing, service security, fraud prevention, or complying with legal obligations, that processing may be governed separately by the StoreCheckup Privacy Policy.
3. Subject Matter and Purpose of Processing
The subject matter of the processing is the provision of StoreCheckup’s monitoring, testing, diagnostic, reporting, and related services.
Depending on the CheckUps enabled by the Customer, StoreCheckup may process Customer Data in order to:
- perform automated tests against the Customer’s online store;
- test checkout and purchasing processes;
- verify shipping, pricing, stock, and product-related information;
- verify advertising pixels, links, and landing pages;
- verify customer and order-related communications where supported;
- monitor technical and operational conditions;
- identify errors, failures, or unusual conditions;
- generate reports, alerts, logs, and CheckUp results;
- investigate technical problems and provide customer support; and
- maintain, secure, and improve the Services where such processing is carried out on the Customer’s behalf.
StoreCheckup will not use Customer Data for unrelated purposes or sell Customer Data to third parties.
4. Duration of Processing
Processing will continue for the duration of the Customer’s use of the relevant StoreCheckup Services and for any limited period thereafter necessary to complete deletion, return, backup expiration, legal retention, security investigations, or other processing permitted by this DPA or applicable law.
The applicable retention periods may vary depending on the type of data, the Service involved, and technical requirements. StoreCheckup will not retain Customer Data longer than reasonably necessary for the applicable purpose, unless a longer period is required or permitted by law.
5. Types of Personal Data
Depending on the Customer’s store, configuration, and enabled CheckUps, Customer Data may include:
- names and contact details;
- email addresses;
- customer and account identifiers;
- order and transaction-related information;
- shipping and delivery information;
- product and inventory information associated with an individual;
- technical information associated with a store visitor or customer;
- IP addresses and device, browser, or connection information;
- information contained in customer or order communications where accessed by a relevant CheckUp;
- CheckUp results, technical logs, diagnostic information, and related records; and
- other Personal Data made available to StoreCheckup through the Customer’s store or connected services where necessary to provide the Services.
StoreCheckup does not require Customers to provide special categories of Personal Data. Customers should not intentionally provide sensitive Personal Data to StoreCheckup unless the relevant Service specifically requires it and the processing is lawful.
6. Categories of Data Subjects
Depending on the Customer’s use of the Services, Personal Data may relate to:
- the Customer and its employees, contractors, or authorized users;
- customers and purchasers of the Customer’s store;
- prospective customers and website visitors;
- recipients of store-related communications;
- suppliers or other individuals whose information is contained within store records; and
- other individuals whose Personal Data is processed through the Customer’s connected store or services.
7. Documented Instructions
StoreCheckup will process Customer Data only on documented instructions from the Customer, including instructions contained in:
- the Customer’s use and configuration of the Services;
- the StoreCheckup Terms of Service;
- this DPA;
- applicable account or integration settings; and
- other written instructions provided by the Customer.
If StoreCheckup believes that an instruction violates applicable Data Protection Laws, StoreCheckup may notify the Customer and, where legally required or reasonably necessary, suspend the relevant processing until the matter is resolved.
If StoreCheckup is required by law to process Customer Data other than according to the Customer’s instructions, StoreCheckup will inform the Customer of that requirement where legally permitted to do so.
8. Confidentiality
StoreCheckup will ensure that persons authorized to process Customer Data are subject to appropriate confidentiality obligations.
Access to Customer Data will be limited to persons who require access for the performance, security, maintenance, support, or administration of the Services.
9. Security of Processing
StoreCheckup will maintain appropriate technical and organizational measures designed to protect Customer Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure.
Depending on the nature and risks of the processing, such measures may include:
- access controls and authentication;
- least-privilege access;
- encryption or other appropriate protections for data in transit and, where appropriate, at rest;
- secure software and infrastructure practices;
- logging and monitoring;
- backup and recovery procedures;
- vulnerability and security management;
- incident response procedures;
- confidentiality requirements for personnel; and
- measures designed to maintain the ongoing confidentiality, integrity, availability, and resilience of the Services.
Security measures may be updated over time as the Services and underlying infrastructure develop.
10. Subprocessors
StoreCheckup may use trusted third-party service providers to assist in providing the Services. Where such providers process Customer Data on behalf of StoreCheckup, they will be treated as Subprocessors.
StoreCheckup will use Subprocessors only where permitted by applicable Data Protection Laws and will require them to provide appropriate data protection and confidentiality commitments.
StoreCheckup may use general written authorization for the engagement of Subprocessors. Where required, StoreCheckup will inform Customers of material changes to its Subprocessors and provide an opportunity to object where required by applicable law.
StoreCheckup will remain responsible for the performance of its Subprocessors to the extent required by applicable Data Protection Laws.
A current list of Subprocessors will be made available through an appropriate StoreCheckup webpage or other designated means once the Service infrastructure has been finalized.
11. International Data Transfers
Customer Data may be processed in countries outside the European Economic Area where necessary to provide the Services.
Where a transfer of Customer Data is subject to Data Protection Laws governing international transfers, StoreCheckup will use an appropriate lawful transfer mechanism, such as:
- a European Commission adequacy decision;
- applicable Standard Contractual Clauses;
- another legally recognized transfer mechanism; or
- another lawful basis for the transfer where applicable.
StoreCheckup will implement additional safeguards where required by applicable Data Protection Laws.
12. Assistance With Data Subject Rights
Taking into account the nature of the processing, StoreCheckup will provide reasonable assistance to the Customer in responding to requests from individuals exercising their rights under applicable Data Protection Laws.
Such assistance may include reasonable support for requests relating to:
- access;
- correction;
- deletion;
- restriction of processing;
- data portability; and
- other applicable data protection rights.
The Customer remains responsible for responding to requests from its customers and other data subjects.
If StoreCheckup receives a request directly from an individual concerning Customer Data, StoreCheckup will generally direct the individual to the Customer unless applicable law requires otherwise.
13. Personal Data Breaches
StoreCheckup will notify the Customer without undue delay after becoming aware of a Personal Data breach affecting Customer Data processed on the Customer’s behalf.
Where reasonably available, StoreCheckup will provide information concerning the nature of the incident, the categories of data affected, the likely consequences, and the measures taken or proposed to address the incident.
StoreCheckup will reasonably cooperate with the Customer in meeting applicable notification and response obligations.
The Customer remains responsible for determining whether a breach must be reported to a supervisory authority or affected individuals, unless applicable law provides otherwise.
14. Data Protection Impact Assessments and Regulatory Assistance
Taking into account the nature of the processing and the information available to StoreCheckup, StoreCheckup will provide reasonable assistance to the Customer where necessary for:
- data protection impact assessments;
- consultations with supervisory authorities;
- demonstrating compliance with applicable processor obligations; and
- other reasonable compliance activities directly related to StoreCheckup’s processing of Customer Data.
15. Return and Deletion of Customer Data
When the Customer’s use of the relevant Services ends, StoreCheckup will, at the Customer’s choice where required by applicable law, delete or return Customer Data, unless continued retention is required or permitted by law.
Customer Data contained in routine backups may remain temporarily after deletion from active systems. Such data will be deleted or overwritten in accordance with StoreCheckup’s applicable backup and data-retention procedures.
StoreCheckup may retain information where necessary to comply with legal obligations, establish or defend legal claims, maintain security records, prevent fraud, or otherwise as permitted by applicable law.
16. Compliance and Audits
StoreCheckup will make available information reasonably necessary to demonstrate compliance with its processor obligations under applicable Data Protection Laws.
Where required by applicable law, StoreCheckup will allow for and contribute to reasonable audits or inspections by the Customer or an auditor mandated by the Customer, subject to reasonable notice, confidentiality requirements, security requirements, and protection of StoreCheckup’s confidential information and other customers’ data.
Audits should, where reasonably possible, be conducted using existing documentation, security information, certifications, or other relevant materials before requiring an on-site audit.
17. Customer Responsibilities
The Customer is responsible for:
- ensuring that its processing of Personal Data has an appropriate lawful basis;
- providing required privacy notices to its customers and other data subjects;
- obtaining required consents;
- ensuring that its use of StoreCheckup complies with applicable laws;
- providing StoreCheckup only with instructions that are lawful;
- configuring connected stores and integrations appropriately; and
- responding to data subject requests and regulatory requirements for which the Customer is responsible.
The Customer should not connect StoreCheckup to data or systems unless it has the authority and legal basis to permit the applicable processing.
18. Data Minimization
StoreCheckup is designed to process only the information reasonably necessary for the applicable CheckUp or Service.
Customers should configure integrations and permissions appropriately and should avoid making unnecessary Personal Data available to StoreCheckup.
Where a CheckUp can operate without accessing particular Personal Data, StoreCheckup may use technical methods intended to minimize such access.
19. Relationship With the Privacy Policy and Terms of Service
This DPA applies specifically to Personal Data processed by StoreCheckup on behalf of the Customer.
The StoreCheckup Privacy Policy governs StoreCheckup’s own processing of Personal Data for purposes such as account administration, billing, security, service communications, and other independent purposes described in that Privacy Policy.
The StoreCheckup Terms of Service govern the Customer’s general use of the Services.
If there is a conflict between this DPA and the Terms of Service concerning the processing of Customer Data, this DPA will control to the extent of that conflict.
20. Liability
The liability provisions of the StoreCheckup Terms of Service apply to this DPA to the extent permitted by applicable law.
Nothing in this DPA limits or excludes any liability, obligation, or right that cannot lawfully be limited or excluded under applicable Data Protection Laws.
21. Changes to This DPA
StoreCheckup may update this DPA when reasonably necessary to reflect changes to the Services, technology, legal requirements, or data-processing practices.
Where a change materially affects the Customer’s rights or obligations regarding the processing of Customer Data, StoreCheckup will provide reasonable notice where required by applicable law.
The version of the DPA in effect during the applicable processing period will govern that processing.
22. Governing Law
This DPA is governed by the same governing-law provisions that apply to the StoreCheckup Terms of Service, except where applicable Data Protection Laws require otherwise.
23. Contact
For questions concerning this DPA or the processing of Personal Data by StoreCheckup, please contact:
Annex 1: Processing Details
Subject Matter
Processing of Personal Data necessary to provide StoreCheckup’s automated monitoring, testing, diagnostic, reporting, and related services.
Duration
For the duration of the Customer’s use of the applicable Services, together with any limited period necessary for deletion, backup expiration, legal retention, security, or other purposes permitted by this DPA or applicable law.
Nature and Purpose
Processing may include collecting, accessing, retrieving, recording, organizing, analyzing, testing, comparing, transmitting, storing, reporting, and deleting Personal Data where necessary to perform the applicable CheckUps and provide the Services.
Types of Personal Data
Depending on the Customer’s store and enabled Services:
- identification and contact information;
- account and customer identifiers;
- order and transaction-related information;
- shipping information;
- product and inventory information;
- technical and device information;
- IP addresses and online identifiers;
- information contained in relevant store communications;
- technical logs and diagnostic information; and
- other Personal Data made available through the connected store where necessary for the applicable Service.
Categories of Data Subjects
- store owners and authorized users;
- employees and contractors;
- customers and purchasers;
- prospective customers and website visitors;
- recipients of store communications; and
- other individuals whose Personal Data is contained within the connected store.
Processing Operations
Processing may include automated testing, retrieval, analysis, monitoring, troubleshooting, reporting, storage, transmission to authorized service providers, and deletion.
Annex 2: Technical and Organizational Measures
StoreCheckup will maintain security measures appropriate to the nature and risks of its processing.
These measures may include:
- Access Control
Access to Customer Data is restricted to authorized persons with a legitimate need for access. - Authentication and Authorization
Appropriate authentication and authorization mechanisms are used to protect accounts, systems, and administrative functions. - Confidentiality
Personnel and other authorized persons with access to Customer Data are subject to confidentiality obligations. - Encryption and Secure Transmission
Appropriate encryption or equivalent safeguards are used for data transmitted over networks where appropriate. - Logging and Monitoring
Relevant systems may use logging, monitoring, and alerting mechanisms to identify unauthorized access, errors, or security events. - Security Management
StoreCheckup will maintain processes designed to identify and address security vulnerabilities and incidents. - Backup and Recovery
Appropriate backup and recovery procedures may be used to support service availability and data recovery. - Incident Response
StoreCheckup will maintain procedures for identifying, investigating, responding to, and mitigating security incidents. - Data Retention and Deletion
Data will be retained and deleted according to applicable retention requirements and StoreCheckup’s operational procedures. - Service Provider Security
Subprocessors and other relevant service providers will be selected and managed with appropriate consideration of security and data protection requirements.
These measures may evolve as StoreCheckup’s technology, infrastructure, and Services develop.
Annex 3: Subprocessor Information
StoreCheckup may use third-party infrastructure, hosting, payment, communications, analytics, security, monitoring, and other service providers as necessary to operate the Services.
The specific Subprocessors used by StoreCheckup will be identified in the applicable StoreCheckup Subprocessor List once the Service infrastructure and integrations have been finalized.
StoreCheckup will update that information when material changes are made to its Subprocessors, subject to applicable law and the terms of this DPA.