Skip to main content
Stoify

Data Processing Addendum

These terms explain how Stoify processes merchant customer data when providing the platform.

Effective date:

Stoify's identity

This addendum is provided by Stoify. Questions can be sent to support@stoify.app.

Scope and roles

This Data Processing Addendum applies when a merchant uses Stoify to process personal data on the merchant's behalf in connection with the Stoify service. It forms part of the agreement between the merchant and Stoify.

The merchant is normally the controller and Stoify is the processor for customer, order, and storefront personal data processed through the service. Each party may be an independent controller for its own account, billing, support, security, and legal-compliance data.

Instructions and purpose

Stoify will process merchant personal data only on the merchant's documented instructions, including the merchant's use of the service and configuration of its storefront, unless applicable law requires otherwise. Stoify will inform the merchant before processing under a legal requirement unless the law prevents that notice.

Processing may include hosting, storing, retrieving, organising, transmitting, backing up, securing, troubleshooting, and deleting personal data as needed to provide and support the service. The categories of data and data subjects depend on the merchant's use of Stoify and can include customer contact, order, delivery, account, and support information.

Confidentiality and security

Stoify limits access to merchant personal data to people who need it to operate, secure, or support the service and who are bound by confidentiality duties. Stoify uses technical and organisational measures appropriate to the risk, including access controls, scoped site permissions, authentication safeguards, encryption in transit where supported, monitoring, and secure credential handling.

No service can guarantee absolute security. Merchants are responsible for protecting their account credentials, assigning appropriate team permissions, configuring their storefront lawfully, and promptly telling Stoify about a suspected unauthorised access or security issue.

Subprocessors and international transfers

Stoify may use carefully selected service providers for infrastructure, storage, authentication, payment billing, email delivery, security, analytics, and support. A subprocessor may process merchant personal data only as necessary to provide its contracted service and subject to written data-protection obligations appropriate to its role.

Where personal data is transferred outside the UK or European Economic Area, Stoify will use a lawful transfer mechanism where one is required, such as an adequacy decision or appropriate contractual transfer terms. Merchants can contact us for current subprocessor or transfer information relevant to their use of Stoify.

Assistance, incidents, and requests

Taking account of the nature of processing, Stoify will provide reasonable assistance through the service or support channels for a merchant's data-subject requests, data-protection impact assessments, consultations with regulators, and compliance enquiries where legally required and where the merchant cannot reasonably obtain the information another way.

If Stoify becomes aware of a personal-data breach affecting merchant personal data, it will notify the merchant without undue delay and provide information reasonably available to help the merchant meet its own obligations. The merchant remains responsible for deciding whether notification to individuals or a regulator is required.

Deletion, return, and audit information

At the end of the service, the merchant is responsible for exporting information it needs before access ends. Stoify will delete or return merchant personal data in accordance with the service settings and agreement, except where retention is required by law or data remains temporarily in protected backups before routine deletion.

Stoify will make information reasonably necessary to demonstrate compliance with this addendum available to the merchant, subject to confidentiality, security, and the protection of other customers. Any audit request must be reasonable, proportionate, and coordinated with Stoify in advance.

This page is general information about Stoify's current data-processing terms and is not legal advice.

Newsletter

Keep up with new Stoify features without watching every commit

Subscribe for launch notes, product updates, and practical ideas on storefront analytics, conversion, and calmer commerce operations.

Double opt-in enabled. Unsubscribe anytime.

Product updates, launch notes, and thoughtful ecommerce ideas. Double opt-in enabled. Unsubscribe anytime. See our Privacy Policy.

Ready to simplify your commerce business?

Power the next generation of storefronts with Stoify. Start for free, launch faster, and scale without the usual complexity.