Data Processing Addendum
This Data Processing Addendum ("DPA") is part of the Terms of Use and applies to every merchant whose store processes personal data of shoppers through loving. It describes how loving processes that data on the merchant's behalf.
Definitions
"Personal data", "controller", "processor", "processing" and "data subject" have the meanings given by applicable data-protection law (including the GDPR, where it applies). "Shopper data" means personal data of a store's customers and visitors processed through the platform.
Roles
For shopper data, the merchant is the controller and loving is the processor. This covers the data shoppers generate on a store: customer accounts and addresses, carts, checkout and order history, reviews and photos, favorites, shopping-assistant conversations and support chats.
loving acts as an independent controller for: merchant and staff account data; platform billing records; usage, security and abuse-prevention logs; and transaction records where loving processes a charge as merchant of record (in countries where Stripe cannot charge on the merchant's behalf).
Processing on instructions
loving processes shopper data only to provide the service as configured and operated by the merchant through the dashboard, the AI builder and the storefront — these product instructions, together with this DPA, are the merchant's documented instructions. loving does not sell shopper data or use it for advertising.
Confidentiality
Persons authorized to process shopper data are bound by confidentiality obligations. Access to production data is restricted to what operating the service requires and is audited.
Security
loving implements appropriate technical and organizational measures, including:
- Encryption of data in transit.
- Encryption at rest for sensitive credentials (for example carrier and printer API keys), and hashing of gift-card codes.
- Tenant isolation: every store's data is scoped to that store throughout the backend, and storefront customer sessions are isolated per store.
- Access controls with granular staff permissions, chosen by the merchant.
- Payment data handled by Stripe; loving never stores full card numbers.
Sub-processors
The merchant grants loving general authorization to engage the sub-processors listed at Sub-processors, each bound by data- protection obligations consistent with this DPA. loving will update that page before adding or replacing a sub-processor that processes shopper data; the dashboard announcement of material changes serves as notice. If the merchant objects on reasonable data-protection grounds and no resolution is found, the merchant may terminate per the Terms.
Assistance with data-subject requests
Shoppers can exercise most rights directly (their storefront account shows their profile, orders and data). Taking into account the nature of the processing, loving will assist the merchant with reasonable measures to respond to data-subject requests — access, correction, export, deletion — that the merchant cannot fulfil through the dashboard alone.
Personal-data breaches
loving will notify affected merchants without undue delay after becoming aware of a personal-data breach affecting shopper data, with the information reasonably available to help the merchant meet its own notification duties.
International transfers
Shopper data may be processed in countries other than the merchant's or the shopper's own, including the United States. Where such transfers require safeguards, the parties rely on appropriate mechanisms such as standard contractual clauses (to be finalized with counsel).
Deletion and return
Shopper data is available to the merchant through the dashboard (including exports) for the life of the store. Deleting the store starts a 30-day recovery window, after which shopper data is permanently deleted, except records loving must retain by law (for example invoices and payment ledger entries), which remain protected under this DPA until deleted.
Audits
loving will make available information reasonably necessary to demonstrate compliance with this DPA — this page, the sub-processor list, and answers to reasonable written security questionnaires. This information-provision model is the agreed audit mechanism for the platform's self-serve tier.
Annex A — processing details
- Subject matter and duration: operating the merchant's storefront and commerce back office, for the life of the store plus the deletion window.
- Nature and purposes: hosting; storage; account management; cart, checkout and order processing; shipping and fulfillment; reviews and favorites; customer support; the storefront shopping assistant; transactional email; fraud and abuse prevention.
- Categories of data subjects: the store's customers and visitors.
- Categories of personal data: identity and contact details (name, email, phone), shipping and billing addresses, order and payment metadata (no full card numbers), account credentials (managed by the auth system), reviews and uploaded images, conversation content with the store's assistant and support, language preference, and technical data (IP-derived approximate location, device and browser information).
- Special categories: none intended; merchants must not direct such data to the platform.