Data Processing Addendum (DPA)
Effective date: 24 August 2026 · Version 1.1
This DPA forms part of the Terms of Servicebetween Creativity Insight UK Ltd trading as Agentic Cart ("Processor") and the merchant customer ("Controller"). It governs processing of personal data on behalf of the Controller under UK GDPR, the UK Data Protection Act 2018, and EU GDPR where applicable. Email legal@agentic-cart.com if you need a countersigned PDF of this same text.
1. Roles
You are the data controller for your customers' personal data within Store Data. We act as data processor when handling such data to provide the Service. We are an independent controller for merchant and team-member account data (as described in our Privacy Policy).
2. Subject matter and duration
Processing covers Store Data accessed via Shopify OAuth (and optional Meta / Google Ads metrics you connect) for the duration of your active subscription, plus the retention periods in our Privacy Policy.
3. Nature and purpose
Read-only sync of products, inventory, and order-linked SKU analytics; dashboard and agent recommendations; GDPR webhook handling; optional ad-metric sync. We do not store customer names, emails, phones, or postal addresses.
4. Sub-processors
- Supabase — database; London, United Kingdom (eu-west-2)
- Vercel — frontend hosting and request logs (global edge)
- Railway — API hosting, logs, and environment variables
- Resend — transactional email
- Shopify Inc. — platform OAuth, billing, and compliance webhooks
- Meta Platforms, Inc. — optional Ads metrics when you connect Meta
- Google LLC — optional Google Ads metrics when you connect Google Ads
- Upstash — optional Redis queue/cache when configured
- Google Gemini — optional recommendation phrasing when configured
We will update this list when we add a sub-processor. Current hosting regions for Vercel and Railway are not claimed as EEA/UK; Store Data resides in Supabase (UK).
5. Security measures
TLS in transit; database encryption at rest; HMAC verification on Shopify callbacks and webhooks; persist-then-ack for GDPR topics; role checks on store-scoped APIs; httpOnly Secure ac_pivot_auth session cookie. Integration tokens are stored in the database under the service role — not a second field-level encryption layer.
6. Controller instructions and data subject requests
We process Store Data only to provide the Service and to comply with law, including Shopify GDPR webhooks (customers/data_request, customers/redact, shop/redact). We persist those requests before acknowledging them. Customer DSRs that Shopify routes to us are handled as described in the Privacy Policy. Merchant (controller staff) DSRs: email support@agentic-cart.com — we respond within 30 days.
7. International transfers
Store Data is stored in the United Kingdom. Sub-processors outside the UK/EEA process hosting logs, email, or optional ad/LLM APIs under their DPAs and transfer mechanisms (including standard contractual clauses where they rely on them).
8. Deletion and return
On app uninstall, Shopify's shop/redact flow deletes Store Data as described in the Privacy Policy. You may also request deletion or a manual export via support.
9. Governing law
England and Wales, consistent with the Terms of Service.