Data Processing Addendum

Last updated: 2026-07-07

This Data Processing Addendum ("DPA") forms part of the agreement between International Supply Consulting ("Provider") and the merchant ("Merchant") who installs SweetRelease Pre-orders (the "App"). It governs personal data the Provider processes on the Merchant's behalf.

1. Roles

The Merchant is the data controller; the Provider is a data processor that processes personal data only to provide the App and only on the Merchant's documented instructions (installing and using the App constitutes those instructions).

2. Purpose & duration

Personal data is processed to detect preorders, hold and move their fulfillment orders at a gated location, and present them in an operator release queue. Processing lasts while the App is installed, plus the limited retention period below.

3. Personal data & data subjects

Data subjects: the Merchant's customers who place preorders. Personal data: customer name (from the order's shipping/billing address) and email; order and fulfillment data (order number, item summary, fulfillment/location/hold state). The Provider does not process payment card data or the Shopify read_customers resource, and does not use personal data for marketing, profiling, or resale.

4. Sub-processors

Sub-processorPurposeLocation
ShopifySource platform / API + webhooksUS / global
Neon (Postgres)Encrypted application databaseUS
VercelApplication hostingUS

5. Security

Encryption at rest (database + backups) and in transit (TLS); least-privilege access with MFA on administrative accounts; data minimization; test/production data separation; infrastructure access logging; and incident response.

6. Retention & deletion

Personal data is retained only as long as needed and purged on a retention schedule. On the Shopify customers/redact and shop/redact webhooks, and on app uninstall, associated personal data is deleted.

7. Data-subject requests

The Provider implements Shopify's compliance webhooks — customers/data_request, customers/redact, and shop/redact — to help the Merchant respond to data-subject requests.

8. Personal data breach

The Provider will notify the Merchant without undue delay after becoming aware of a personal data breach, with the information the Merchant needs for its own notification obligations (including, where applicable, the GDPR 72-hour requirement).

9. International transfers & audit

Cross-border transfers rely on an appropriate mechanism (e.g., Standard Contractual Clauses). On reasonable written request, the Provider will provide information necessary to demonstrate compliance with this DPA.

10. Contact

Questions or requests: patrickward@isc-na.com.