LEGAL DOCUMENTS
Data Processing Agreement
How we process your storefront customers' data on your behalf.
Version 0.3 · 2026-09-19
The roles
For the buyer data you keep in the panel and in your storefront YOU are the controller, and the company is a processor acting only on your instructions.
For your own account, subscription and invoice data the company is the controller, and the rules for that are in the Privacy Policy.
This agreement is governed by the law of the State of Delaware. Complying with the data protection law of your own country, and your duties to your own buyers, are yours as the controller.
Where your business falls under the data protection law of Türkiye or of the European Union, you are the controller under that law as well, and the company is a processor acting on your documented instructions; the company has no establishment in either place.
Subject, duration and nature of the processing
Subject: storing, displaying, backing up and, on your request, exporting order, customer and payment status records.
Categories: your buyer's name and contact details, delivery and invoice address, order and basket history, payment status, marketing consents, and the messages they send through the storefront's forms. The card number is not among them: the payment completes inside your own payment provider's infrastructure and no card data is stored by the company.
Duration: for as long as the subscription lasts, plus the thirty day export window after it ends.
Managing your domain is part of this: the domain is registered in your name and the account at your registrar stays yours; pointing its nameservers at the company is the authority to manage, on your behalf and for the life of the subscription, the DNS records the service needs - the storefront, the image delivery and the e-mail routing. Messages passing through that routing are processed under this agreement. When the subscription ends the zone is kept for thirty days; within that window the nameservers may be pointed at any other provider, and at the end of it the record is removed from the company's infrastructure.
Instructions and confidentiality
Data is processed only on your instructions and within this agreement. Where the law requires processing, you are told first unless telling you is prohibited.
Staff with access are under a duty of confidentiality and access is limited by role.
Your data is separated per account so that it cannot be mixed with another customer's.
Sub-processors
Sub-processors are used to run the service. The current list is published on the Privacy Policy page with each one's name, function and region.
You are told a reasonable time before a new sub-processor is added and you may object on reasonable grounds.
Written agreements with sub-processors carry obligations equivalent to those in this agreement.
Your storefront's payment provider, your courier and any invoicing or accounting integration you connect are providers you choose: they are your own processors rather than the company's sub-processors, and the agreements with them are yours to make.
| Company | What it does | Where it runs |
|---|---|---|
| Cloudflare, Inc. | Edge network, DNS, certificates, image storage and transactional e-mail | United States and global edge |
| Stripe, Inc. | Subscriptions and card payments | United States and the EU |
| OVH SAS | Application and database hosting | European Union (France) |
Security measures and breach notification
TLS in transit, encryption for backups, role based access, an audit log and regular backups are in place.
If a personal data breach is discovered you are told without undue delay, with the nature of the breach, the categories affected and the measures taken.
No numeric deadline is promised for that notice: the measure is without undue delay once the breach is discovered.
Requests from the people the data is about
Requests from your own buyers to see, correct or delete their data, or to object to its processing, reach you, and answering them is your duty as the controller.
A request that arrives at the company instead is not answered on its merits; it is passed on to you without delay.
Where answering it means reading a record, exporting it or deleting it, the panel's own tools are there for that, and where the panel is not enough we give reasonable technical help.
Return, deletion and audit
When the subscription ends the data stays exportable for thirty days, and is deleted for good at the end of that window once the backup cycle has rolled over.
On request, written confirmation of the deletion is provided.
An audit may be requested once a year and within a reasonable scope. Where an independent audit report exists, that report answers the request.
Questions about this text go to: hello@minatacommerce.com