ShopShield — your shop. protected.
    Pricing
    Log inGet Started

    Data Processing Agreement

    Last Updated: 10/22/2025

    Parties:

    (1) ShopShield.com, operated by ShopShield, LLC., ("Processor," "we," "us"), and

    (2) The customer or subscriber who has entered into a subscription or other agreement for our services ("Controller," "you").

    1. Purpose

    This Agreement governs how ShopShield.com processes personal data on your behalf while delivering subscription services that (a) monitor publicly available policy or terms-of-service pages on third-party websites, (b) identify and summarize changes, and (c) send notifications or reports to your designated contacts.

    2. Definitions

    Applicable Law means all privacy and data-protection laws, including the EU GDPR, UK GDPR, CCPA/CPRA, and any equivalent local laws.

    Personal Data means any information relating to an identified or identifiable natural person processed by the Processor on behalf of the Controller.

    Processing and related terms have the meaning given in the GDPR.

    Services means the ShopShield.com platform, APIs, web application, and related automation services.

    3. Subject Matter, Nature, and Duration

    Subject Matter: Processing of subscriber account information and delivery of notifications.

    Nature & Purpose: Collection, storage, transmission, and analysis necessary to (i) manage user accounts; (ii) send change alerts and summaries; and (iii) provide analytics and billing.

    Duration: For as long as you maintain an active account or as otherwise required by law.

    4. Roles of the Parties

    You are the Controller of any Personal Data you provide. ShopShield.com acts as your Processor and will process that data solely on your documented instructions, including those contained in your subscription agreement and this DPA.

    5. Categories of Data and Data Subjects

    Data Subjects: your account holders, team members, or end users designated to receive updates.

    Categories of Data: name, email address, billing details, login credentials (hashed), communication preferences, and audit logs.

    ShopShield.com does not collect or process sensitive categories of data.

    6. Processor Obligations

    ShopShield.com shall:

    • Process Personal Data only on your documented instructions.
    • Ensure persons with access are bound by confidentiality obligations.
    • Maintain technical and organizational measures to protect Personal Data against unauthorized or unlawful processing and accidental loss or destruction.
    • Assist you in responding to data-subject requests and compliance obligations (Articles 12–23 GDPR).
    • Notify you without undue delay of any confirmed Personal-Data Breach and provide relevant details.
    • Make available all information necessary to demonstrate compliance and allow reasonable audits (subject to confidentiality and scheduling).
    • Delete or return Personal Data at termination of Services, unless retention is required by law.

    7. Controller Obligations

    You confirm that:

    • You have a lawful basis for all Personal Data provided.
    • You will not instruct us to process data in violation of law.
    • You are responsible for the accuracy and legality of the data you supply.

    8. Sub-Processors

    We may engage sub-processors to perform infrastructure, storage, or communication services.

    Current sub-processors include:

    • Make.com (Celonis SE) – workflow automation
    • Lovable.dev – application hosting and database services
    • Amazon Web Services (AWS) – cloud infrastructure and storage
    • SendGrid (Twilio Inc.) – transactional email delivery
    • Stripe Inc. – payment processing

    We will maintain an updated list at https://shopshield.co/legal/sub-processors and notify you of any material changes. You may object on reasonable grounds within 30 days.

    9. International Transfers

    Where data is transferred outside the EEA, UK, or other jurisdictions requiring adequacy, ShopShield.com will implement appropriate safeguards such as the EU Standard Contractual Clauses (2021/914) and UK Addendum.

    10. Security Measures

    We maintain, at a minimum:

    • Encryption in transit (TLS 1.2+) and at rest (AES-256).
    • Access control via unique credentials and least-privilege roles.
    • Daily off-site backups and integrity checks.
    • Logging and anomaly detection of all administrative actions.
    • Annual review of incident-response and disaster-recovery plans.

    A current summary of technical and organizational measures (TOMs) is available upon request.

    11. Data Breach Notification

    Upon discovering a confirmed Personal-Data Breach, we will:

    • Notify you within 72 hours.
    • Provide known details on the nature, scope, and mitigation steps.
    • Cooperate to meet your legal reporting duties.

    12. Assistance

    ShopShield.com will provide reasonable support for:

    • Responding to data-subject requests.
    • Performing Data-Protection-Impact Assessments.
    • Consulting with supervisory authorities when legally required.

    13. Deletion and Return

    After termination, upon written request, we will either delete or return all Personal Data within 30 days unless retention is required for billing, dispute resolution, or legal compliance.

    14. Liability and Indemnity

    Each party remains liable for its own acts and omissions and shall indemnify the other for damages arising from violations of this DPA or Applicable Law, subject to limitations defined in the main Terms of Service.

    15. Governing Law and Jurisdiction

    This DPA is governed by the same law and forum as specified in your main service agreement with ShopShield.com.

    16. Miscellaneous

    Inconsistencies between this DPA and the main agreement are resolved in favor of the DPA regarding data-protection matters.

    Updates may be made to maintain compliance; continued use constitutes acceptance of the revised DPA.

    Signed on behalf of ShopShield.com