This Data Processing Agreement (the "DPA") forms part of the Terms of Service between MarketplaceHub Ltd, a company registered in England and Wales under company number 13815249, with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom ("MarketplaceHub", "we", "us") and the customer who has accepted those Terms (the "Merchant", "you").
It applies whenever we process personal data on your behalf, and it takes precedence over anything in the Terms of Service that conflicts with it. It does not replace our Privacy Policy, which describes the personal data we hold about you as an account holder and for which we are the controller.
"Data Protection Law" means the UK GDPR and the Data Protection Act 2018, and, where they apply to the processing, Regulation (EU) 2016/679 (the "EU GDPR") and any other applicable law on the protection of personal data.
"controller", "processor", "data subject", "personal data", "processing" and "personal data breach" have the meanings given to them in Data Protection Law.
"Merchant Personal Data" means personal data that we process on your behalf under the Terms of Service. In practice it is the personal data attached to the orders, listings and messages of the sales channels you connect.
"Services" means the MarketplaceHub platform as described in the Terms of Service.
For Merchant Personal Data you are the controller and we are the processor. You decide why it is processed; we act only on your documented instructions.
Your instructions are: the Terms of Service, this DPA, the settings you choose in the platform, and anything else you ask us to do in writing that we agree to. Using a feature is an instruction to perform it.
We will tell you if, in our opinion, an instruction infringes Data Protection Law. We may also process Merchant Personal Data where a law we are subject to requires it; where that law permits, we will tell you before we do.
We do not use Merchant Personal Data for our own purposes. No marketing, no personalisation, no profiling, no advertising, no training of models on it, and we do not sell it or disclose it to anyone for their own use. We do not combine it with data from other merchants.
Aggregated statistics that cannot identify any person or any merchant — for example, counts of orders processed platform-wide — are not Merchant Personal Data and we may use them to operate and improve the Services.
Subject matter and duration. The processing lasts for as long as you have an account with us, plus the retention periods in section 9.
Nature and purpose. Collecting orders and listings from the sales channels you connect, storing them, showing them to you in one place, and carrying your decisions — shipment, tracking, cancellation, refund, price and stock changes — back to those channels.
Categories of data subject. Your customers and prospective customers, and the people you authorise to use your account.
Categories of personal data. For a customer: the recipient's name and shipping address, a contact phone number and email address attached to the order, and the contents, totals, currency and refunds of that order. For a user of your account: name, email address and authentication data.
We request the minimum. We do not ask the marketplaces for their customer or buyer profile objects, and we do not request a store's full order history — only the recent orders needed to keep your workspace current. We never hold payment card details.
No special category data. The Services are not designed for personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health, sex life or sexual orientation, or criminal convictions. Do not put such data into them.
We give access to Merchant Personal Data only to people who need it to provide or support the Services. Those people are bound by written confidentiality obligations that survive the end of their engagement, and they are made aware of the confidential nature of the data.
We implement appropriate technical and organisational measures to protect Merchant Personal Data. The measures in force are:
We may change these measures, but not in a way that materially reduces the overall level of protection. The current version of this page is the current set.
We are not certified against ISO 27001 and have not undergone a third-party security audit or penetration test. We say so here rather than leave it to be assumed: we use ISO 27001 as the framework our internal Data Protection Policy is built on, which is a statement of practice and not of certification.
You give us general authorisation to engage sub-processors for the purposes in section 3. We impose data protection obligations on each of them that are no less protective than this DPA, and we remain fully liable to you for their performance.
Our sub-processors today:
| Sub-processor | What it does | Where |
|---|---|---|
| DigitalOcean, LLC | Hosting for the platform and the managed database, and for the message broker, cache, search index and log store that run inside it. All Merchant Personal Data at rest is here. | United States |
| Microsoft Corporation (Azure) | File and image storage; the key vault holding encryption keys and credentials; real-time browser messaging; transactional email delivery; and the AI service that classifies product listings. Product data reaches the AI service; customer identity does not. | United Kingdom and United States |
| Amazon Web Services, Inc. | The message queue Amazon Selling Partner API order notifications arrive on. It carries order and seller identifiers, not customer identity. | United States |
| Stripe, Inc. | Subscription billing. It receives your billing details and order values. No part of a customer's identity is used for billing or held in our billing records. | United States |
| Cloudflare, Inc. | Content delivery, DNS and protection against network attacks. Every public request passes through it in transit. | Global edge network |
The sales channels you connect — Amazon, eBay, Shopify, Etsy and any others — are not our sub-processors. You have your own relationship with each of them, and we exchange data with them because you told us to.
Changes. We will give you at least 30 days' notice before a new sub-processor starts processing Merchant Personal Data, by updating this page and emailing the address on your account. If you have a reasonable objection on data protection grounds, tell us at [email protected] within those 30 days and we will work with you in good faith to find a solution. If we cannot, you may terminate the affected Services without penalty and receive a pro-rata refund of fees paid for the unused period.
Merchant Personal Data is stored in the United States and may be accessed from the United Kingdom. Where a transfer leaves the UK or the EEA to a country without an adequacy decision, it is made under the European Commission's Standard Contractual Clauses (Module Two, controller to processor) together with the UK International Data Transfer Addendum issued by the Information Commissioner's Office.
By accepting the Terms of Service you enter into those clauses with us, with you as data exporter and MarketplaceHub as data importer, and the details in sections 3, 5 and 6 of this DPA supply their annexes. Where you need a signed copy for your own records, ask us at [email protected].
Requests from data subjects. If a data subject contacts us directly about Merchant Personal Data, we will not respond to the substance ourselves. We will tell them to contact you and let you know within 5 business days. The platform lets you search, export and erase a customer's details yourself; where a request needs more than that, we will help you at no charge.
Deletion channels. Where a sales channel provides one, we implement it. For Shopify we support the three mandatory privacy webhooks: a request for a customer's data, a request to erase a customer, and a request to erase a shop. You may also ask us directly at [email protected].
Impact assessments and prior consultation. We will give you reasonable assistance with data protection impact assessments and any prior consultation with a supervisory authority, to the extent they relate to our processing and taking into account the information available to us.
Regulators. If a supervisory authority contacts us about Merchant Personal Data, we will tell you promptly unless the law forbids it.
While your account is open. Customer identity is erased 24 months after the most recent order that uses it, and sooner where the sales channel an order came from requires it: 30 days for orders from Amazon, which is Amazon's own rule for data obtained through its API. A scheduled process removes the name, phone number, email address and shipping address and leaves the order itself intact, because orders are a financial record both of us need to keep. This runs automatically; it is not something either of us has to remember.
Where a customer has ordered more than once, each order counts on the rule for the channel it came from, and the details are kept until the last of those periods has passed. A shorter channel rule never shortens the period for orders placed somewhere else.
Getting your data out. While your account is open you can read your orders, products and their details at any time through our REST API, which returns JSON.
When this agreement ends. On termination, and on written request made within 30 days of it, we will return Merchant Personal Data in a machine-readable format. After that period, or straight away if you ask us to, we delete it. Deletion completes within 90 days of termination.
Backups. Backups run on a rolling seven-day window, so deleted data can remain in a backup for at most seven days after deletion and then ages out on its own. Backups are not restored selectively; while data remains in one it stays encrypted and is not processed for any other purpose.
We may keep Merchant Personal Data where a law requires it, for as long as that law requires and for no other purpose.
We will notify you of a personal data breach affecting Merchant Personal Data without undue delay, and in any event within 72 hours of becoming aware of it. Notification goes to the email address on your account.
The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures we have taken or propose to take, and a contact point. Where we cannot provide all of that at once, we will send what we have and the rest as it becomes available rather than waiting.
We will not make any public statement identifying you as affected without first consulting you, unless the law requires it. Notifying a supervisory authority or your data subjects is your decision as controller; we will give you the information you need to make it.
We will make available to you the information necessary to demonstrate that we meet our obligations under Article 28 of the UK GDPR. In the first instance that means answering your questions and providing our documentation, which is usually enough and is always faster.
Where it is not enough, you may audit our processing, or appoint an independent auditor who is not a competitor of ours to do so, on 30 days' written notice, no more than once in any twelve-month period — and additionally after a personal data breach affecting your data, or where a supervisory authority requires it. An audit takes place during business hours, must not unreasonably disrupt our operations, must not access another merchant's data, and is subject to confidentiality. You bear your own costs; we bear ours.
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service. Nothing in this DPA limits either party's liability to a data subject under Data Protection Law.
This DPA takes effect when you accept the Terms of Service and continues for as long as we process Merchant Personal Data. Sections 4, 9, 10, 11 and 12 survive its end.
We may update this DPA where a change in law, in the Services or in our sub-processors requires it. We will give at least 30 days' notice of a material change by updating this page and emailing the address on your account. Changes will not materially reduce the protections here.
This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction — except that where the Standard Contractual Clauses in section 7 specify a governing law or forum for a matter, those apply to that matter.
Data protection questions, sub-processor objections, audit requests and deletion requests: [email protected], or by post to:
MarketplaceHub Ltd
71-75 Shelton Street
Covent Garden
London, WC2H 9JQ
United Kingdom
Registered in England and Wales, company number 13815249