Last updated
Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between you, the merchant (“Customer”), and CartTuck (“CartTuck”). It applies whenever CartTuck processes Personal Data on Customer’s behalf in providing the Service. By using the Service, Customer agrees to this DPA. If you need a countersigned copy, email support@carttuck.com.
1. Definitions
“Data Protection Laws” means all privacy and data protection laws that apply to the processing, including the EU General Data Protection Regulation (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US state privacy laws such as the California Consumer Privacy Act (“CCPA”). “Personal Data”, “controller”, “processor”, “data subject”, “processing” and “personal data breach” have the meanings given in the GDPR. “Customer Personal Data” means Personal Data that CartTuck processes on Customer’s behalf under the Terms.
2. Roles
Customer is the controller of Customer Personal Data (or, where Customer acts for its own client, a processor), and CartTuck is its processor (or subprocessor). Customer is responsible for having a lawful basis for the processing and for giving data subjects any required notices. CartTuck is an independent controller only of the account, billing and security data described in its Privacy Policy.
3. Instructions
CartTuck processes Customer Personal Data only on Customer’s documented instructions, which are the Terms, this DPA and Customer’s configuration of the Service (for example product upload rules and notification settings), unless the law requires otherwise; in that case CartTuck will tell Customer first unless the law prohibits it. CartTuck will tell Customer if it believes an instruction infringes Data Protection Laws.
4. Confidentiality and security
CartTuck ensures that anyone authorized to process Customer Personal Data is bound by confidentiality. CartTuck implements the technical and organizational measures in Annex 2, which are designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. CartTuck may update these measures as long as the overall level of protection is not reduced.
5. Subprocessors
Customer gives general authorization for CartTuck to use subprocessors. The current list is in Annex 3. CartTuck will notify Customer by email or in the dashboard at least 14 days before adding or replacing a subprocessor. Customer may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, Customer may terminate the affected Service and receive a refund of prepaid fees for the unused period. CartTuck imposes data protection terms on each subprocessor that are no less protective than this DPA and remains responsible for its subprocessors’ performance.
6. Assistance
- Data subject requests. CartTuck will promptly pass on any request it receives from a data subject about Customer Personal Data and will not respond except to redirect the data subject to Customer, unless Customer authorizes it. The dashboard lets Customer find, download and delete files; CartTuck will provide reasonable further help.
- Impact assessments and consultations. CartTuck will provide reasonable information to help Customer carry out data protection impact assessments and prior consultations with supervisory authorities.
7. Personal data breaches
CartTuck will notify Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. CartTuck will take reasonable steps to contain and remedy the breach and will provide further information as it becomes available.
8. Deletion and return
Customer can download its files at any time during the subscription. Files are deleted automatically on the retention schedule of Customer’s plan (Free 14 days, Maker 60 days, Pro 180 days, Studio 1 year after a file is attached to an order; unclaimed uploads after 7 days). When Customer uninstalls CartTuck or the Terms end, CartTuck deletes Customer Personal Data within 30 days, unless the law requires CartTuck to keep it.
9. Audits
CartTuck will make available the information reasonably necessary to demonstrate compliance with this DPA. If that information is not enough to meet Customer’s obligations under Data Protection Laws, Customer may, with at least 30 days’ written notice and no more than once a year (unless a supervisory authority requires otherwise or following a personal data breach), audit CartTuck’s compliance by written questionnaire or through an independent auditor bound by confidentiality, at Customer’s cost and without disrupting the Service.
10. International transfers
CartTuck and its subprocessors may process Customer Personal Data in the United States and other countries. For transfers of Personal Data from the EEA, the parties agree to the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 (Module 2 where Customer is a controller, Module 3 where Customer is a processor), which are incorporated by reference with Annexes 1 to 3 of this DPA as their annexes; clause 7 does not apply, option 2 applies in clause 9(a) with the notice period in section 5 of this DPA, the optional wording in clause 11 does not apply, and clauses 17 and 18 are governed by the law and courts of Ireland. For transfers from the UK, the UK International Data Transfer Addendum applies; for transfers from Switzerland, the Clauses apply with the changes the Swiss Federal Act on Data Protection requires.
11. US state privacy laws
Where the CCPA or similar US state laws apply, CartTuck acts as a service provider or processor. CartTuck will not sell or share Customer Personal Data, retain, use or disclose it outside the direct business relationship with Customer or for any purpose other than providing the Service, or combine it with personal information from other sources except as those laws permit. CartTuck will notify Customer if it can no longer meet these obligations.
12. Liability and precedence
Each party’s liability under this DPA is subject to the limitations in the Terms, to the extent Data Protection Laws allow. If this DPA conflicts with the Terms, this DPA controls for the processing of Customer Personal Data; if the Standard Contractual Clauses conflict with this DPA, the Clauses control.
Annex 1: Details of processing
| Subject matter and purpose | Collecting files from Customer’s shoppers through Customer’s Squarespace store, matching them to orders, storing them, and making them available to Customer; related notifications. |
|---|---|
| Nature of processing | Collection, storage, retrieval, automated checks (file type, size and image resolution), transmission to Customer, and deletion. |
| Duration | The term of the Terms plus the deletion period in section 8. |
| Frequency | Continuous. |
| Data subjects | Customer’s shoppers and customers, and people who appear in or are named in uploaded files. |
| Categories of Personal Data | Uploaded files and their contents (for example photos of people); file names and metadata; order numbers, line items and form answers; email addresses; a one-way hash of the IP address. |
| Special categories | None intended. Files may incidentally reveal special-category data (for example in a photo); Customer decides what its shoppers are asked to upload. |
Annex 2: Security measures
- Encryption of all traffic in transit with TLS, and of stored files at rest.
- Squarespace OAuth tokens and webhook secrets encrypted with AES-GCM under a key held as a separate secret.
- Uploads accepted only through short-lived, single-purpose upload URLs (10 minutes) restricted to the exact file type, size and the store’s own storage area.
- File type allowlist enforced by inspecting file contents, not only names; no executables, archives or HTML.
- Downloads only through signed links that expire after 5 minutes, created only for a signed-in merchant, served from a separate domain as attachments that are never rendered in the browser.
- Every merchant request scoped to the merchant’s own store; session cookies are signed and HttpOnly.
- Verification of Squarespace and Stripe webhook signatures before any processing.
- Rate limits on upload sessions per IP address and per store.
- Automatic deletion of files on the plan’s retention schedule and of unclaimed uploads.
- Least-privilege access to production systems for CartTuck personnel, with multi-factor authentication on provider accounts.
- An abuse and takedown process through abuse@carttuck.com.
Annex 3: Subprocessors
| Subprocessor | Service | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting, database, file storage, content delivery, logs | United States and Cloudflare’s global network |
| Stripe, Inc. | Billing (merchant data only) | United States |
| Resend | Transactional email delivery | United States |
Contact
Data protection questions: support@carttuck.com.