Data Processing Addendum
Last updated: July 16, 2026
1. Introduction and Roles
This Data Processing Addendum ("DPA") forms part of the Terms of Service between SellDrop LLP, a limited liability partnership registered in England and Wales with registration number OC461138 whose registered office is at 128 City Road, London, EC1V 2NX, United Kingdom ("SellDrop", "we", "us"), and each merchant that uses the SellDrop platform ("you"). It applies where we process personal data relating to your buyers and customers on your behalf in the course of providing the Service.
For that personal data, you are the controller and we are your processor within the meaning of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. You are responsible for ensuring you have a lawful basis for the processing and for providing any required privacy information to your buyers. This DPA does not apply to personal data for which we are the controller, which is described in our Privacy Policy.
2. Scope of Processing
- Subject matter and duration: The processing of buyer personal data needed to operate your store on the platform, for as long as you hold a merchant account (plus the deletion period in Section 8).
- Nature and purpose: Hosting your storefront, processing and recording orders, delivering digital products, sending transactional emails on your behalf, providing order history and analytics to you, and providing customer accounts for your buyers.
- Categories of data subjects: Your buyers, customers, and prospective customers.
- Categories of personal data: Names, email addresses, order and delivery details, transaction identifiers, IP addresses and device information, and any other personal data your buyers submit through your store. The Service is not intended for special category data, and you must not use it to collect any.
3. Our Obligations as Processor
When processing buyer personal data on your behalf, we will:
- Process it only on your documented instructions, which are set out in the Terms of Service, this DPA, and your configuration of the Service, unless we are required to process it by law (in which case we will inform you unless the law prevents us).
- Ensure that persons authorised to process it are bound by confidentiality obligations.
- Implement appropriate technical and organisational security measures as required by Article 32 UK GDPR.
- Engage sub-processors only as described in Section 4.
- Assist you, taking into account the nature of the processing, in responding to data subject rights requests and in meeting your obligations relating to security, breach notification, and data protection impact assessments.
- Delete or return the personal data at the end of the relationship as described in Section 8.
- Make available the information reasonably necessary to demonstrate compliance with this DPA, as described in Section 7.
Nothing in this DPA prevents us from removing content or acting on our own behalf as described in the Content Safety sections of the Terms of Service and Privacy Policy; when we scan uploaded content for known illegal material and report it to authorities, we act as a controller in our own right.
4. Sub-processors
You give us general written authorisation to engage sub-processors to provide the Service. We will impose data protection obligations on each sub-processor that are materially equivalent to those in this DPA, and we remain responsible to you for their performance. Our current sub-processors are:
- Supabase (database and authentication infrastructure).
- Vercel (application hosting).
- Cloudflare (content delivery, security, and file storage).
- Upstash (caching and background processing infrastructure).
- Resend (transactional email delivery).
- Proxycheck.io (fraud prevention: receives visitor IP addresses at checkout to detect VPNs, proxies, and high-risk connections).
We will give you notice of any intended addition or replacement of a sub-processor by updating this page and, for material changes, through the dashboard or by email. If you reasonably object to a change on data protection grounds, you may close your account before the change takes effect.
Stripe is not our sub-processor. Payments on the platform are processed through your own Stripe account under your direct agreement with Stripe, and Stripe processes payment data under its own terms and privacy policy.
5. International Transfers
Some sub-processors process personal data outside the United Kingdom. Where a transfer of buyer personal data outside the UK takes place, we will ensure it is covered by UK adequacy regulations or by appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, and you authorise those transfers on that basis.
6. Personal Data Breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting buyer personal data we process on your behalf, and will provide the information reasonably required for you to meet your own notification obligations, including the nature of the breach, the categories and approximate numbers of data subjects and records affected, the likely consequences, and the measures taken or proposed.
7. Audits and Information
On written request no more than once in any 12-month period, we will make available the information reasonably necessary to demonstrate compliance with this DPA, such as summaries of our security measures and relevant certifications or audit reports from our sub-processors. Where that information is insufficient, we will allow for and contribute to audits conducted by you or an auditor mandated by you, at your cost, on reasonable notice, during business hours, and subject to confidentiality obligations.
8. Deletion and Return
You can export your buyer and order data through the dashboard at any time while your account is open. When your merchant account closes, we will delete the buyer personal data we process on your behalf within 90 days, except where we are required or permitted by law to retain it (for example, transaction records retained under tax and accounting law, or records connected to fraud or illegal content investigations, which we retain as controller).
9. Precedence and Liability
This DPA is governed by the same law as the Terms of Service. If there is a conflict between this DPA and the Terms of Service regarding the processing of buyer personal data, this DPA prevails. Each party's liability under this DPA is subject to the exclusions and limitations of liability in the Terms of Service.
10. Contact
Questions about this DPA or our processing of buyer personal data should be sent to privacy@selldrop.io.
