Data Processing Addendum
Crossdock — Square↔Shopify integration. Last updated 2026-06-05 (v1).
1. Background and roles
This Data Processing Addendum (the “DPA”) supplements the Crossdock Terms of Service and governs the processing of Personal Data by Crossdock on behalf of the Merchant. For the purposes of the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK General Data Protection Regulation, and the Swiss Federal Act on Data Protection, the Merchant is the Controller and Crossdock is the Processor with respect to Merchant Data. This DPA satisfies the contractual requirements of GDPR Article 28 and incorporates the security and breach-notification obligations of GDPR Articles 32, 33, and 34. References to “GDPR” in this DPA include the UK GDPR and the Swiss FADP unless the context requires otherwise.
2. Definitions
Capitalised terms not defined in the Terms of Service have the meanings given to them in GDPR Article 4. In particular, “Personal Data”, “Processing”, “Data Subject”, “Sub-processor”, and “Personal Data Breach” have their Article 4 meanings. The Merchant is the Controller and Crossdock is the Processor for all Personal Data Crossdock processes in the course of providing the service. “Merchant Data” means the Personal Data Crossdock processes on behalf of the Merchant under this DPA.
3. Scope of processing
Crossdock will process Merchant Data only on the documented instructions of the Merchant, including with regard to transfers of Personal Data to a third country or an international organisation, unless required to do so by a law to which Crossdock is subject; in such a case, Crossdock will inform the Merchant of that legal requirement before processing unless that law prohibits such information on important grounds of public interest. The Terms of Service, this DPA, and the Merchant’s use of the service constitute the Merchant’s complete and final documented instructions to Crossdock for processing Merchant Data; any other instruction shall be agreed in writing. Crossdock will not process Merchant Data for any purpose other than providing the synchronisation service described in §1 of the Terms of Service. Crossdock does not engage in profiling, derived-data products, or secondary use of Merchant Data.
4. Categories of personal data and data subjects
The categories of Personal Data and the categories of Data Subjects processed under this DPA are set out in Annex 1. Crossdock does not process special categories of personal data within the meaning of GDPR Article 9 and does not request, accept, or store payment-card numbers or other financial-account credentials.
5. Duration
Crossdock will process Merchant Data for the duration of the Merchant’s Crossdock subscription. Following termination of the subscription, Crossdock retains shop-scoped Merchant Data only for the post-uninstall grace window described in §14 below — approximately 96 hours in total (Shopify’s 48-hour hold plus Crossdock’s 48-hour scheduled cascade) — after which the data is irreversibly deleted via the shop/redact webhook cascade. Operational audit-log records are retained for 24 months following the originating event per the Privacy Policy locked-text clause, with customer-identifying fields embedded in audit diffs subject to redaction-on-request within the 30-day GDPR response window.
6. Sub-processors
Crossdock engages the Sub-processors listed at https://crossdock.app/legal/subprocessors (the Subprocessor List) and reproduced for convenience at Annex 4. The Merchant is deemed to have given general authorisation to those Sub-processors as a condition of using the service. Crossdock will give the Merchant at least thirty days’ advance notice of any intended change to the Subprocessor List by publishing the updated list at the URL above, by surfacing a notice banner in the embedded admin in the same commit that integrates the new Sub-processor, and, where the Merchant has a shop-owner or notification email address on file, by email to that address. The Merchant has the right to object to the change within the notice period by sending written notice to the Crossdock support address listed in the Privacy Policy footer; if the Merchant does not object, the Merchant is deemed to have consented. If the Merchant objects on reasonable data-protection grounds, Crossdock will use commercially reasonable efforts to provide the service without the objected-to Sub-processor or, if that is not feasible, the Merchant may terminate the affected portion of the service.
7. Confidentiality
Crossdock ensures that persons authorised to process Merchant Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Access to production systems is conditioned on a written confidentiality undertaking as part of the Crossdock personnel onboarding process.
8. Security measures
Crossdock implements the technical and organisational measures set out in Annex 2 to ensure a level of security appropriate to the risk presented by the processing, taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of processing, and the risk of varying likelihood and severity for the rights and freedoms of Data Subjects.
9. Sub-processor obligations
Crossdock imposes on each Sub-processor data-protection obligations no less protective than those imposed on Crossdock under this DPA, and remains fully liable to the Merchant for the performance of each Sub-processor’s obligations.
10. Data subject rights assistance
Crossdock assists the Merchant by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Merchant’s obligation to respond to requests for exercising the Data Subject’s rights under Chapter III of the GDPR. The assistance is provided through the Shopify-managed GDPR webhook flow: customers/data_request for access requests, customers/redact for erasure requests, and shop/redact for the shop-scope cascade after Merchant termination. The receivers, worker handlers, and audit chain are documented in the Privacy Policy.
11. Personal data breach notification
Crossdock notifies the Merchant of a Personal Data Breach affecting Merchant Data without undue delay and in any event within 48 hours after Crossdock becomes aware of it. The notification will, to the extent then known, describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences of the breach, and the measures Crossdock has taken or proposes to take to address the breach and mitigate its adverse effects. Crossdock will provide further information in phases as it becomes available and will cooperate with the Merchant to enable the Merchant’s own notification obligations under GDPR Articles 33 and 34.
12. Data protection impact assessments
Crossdock provides reasonable assistance to the Merchant with any data protection impact assessment or prior consultation with a supervisory authority that the Merchant is required to carry out under GDPR Articles 35 or 36, taking into account the nature of the processing and the information available to Crossdock.
13. International transfers
Crossdock and its US-based Sub-processors process Merchant Data in the United States. For transfers of Personal Data from the European Economic Area to the United States or to any other country that has not received an adequacy decision from the European Commission, the Parties incorporate by reference the Standard Contractual Clauses for the transfer of personal data to third countries, as approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module Two (Controller to Processor) (the “EU SCCs”). For transfers of Personal Data originating in the United Kingdom, the Parties incorporate by reference the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0, issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, laid before Parliament on 2 February 2022 and in force from 21 March 2022 (the “UK Addendum”), which amends and applies the EU SCCs to United Kingdom transfers. For transfers of Personal Data originating in Switzerland, the EU SCCs apply as adapted in accordance with the guidance of the Swiss Federal Data Protection and Information Commissioner (the “FDPIC”): references to the GDPR are read as references to the Swiss Federal Act on Data Protection (the “FADP”); the competent supervisory authority is the FDPIC and, to the extent a transfer is also subject to the GDPR, the supervisory authority identified under the EU SCCs; the governing law is the law of Switzerland; and the term “Member State” is not interpreted so as to prevent Data Subjects in Switzerland from enforcing their rights in their place of habitual residence. The SCCs, the UK Addendum, and the Swiss adaptations are referenced at Annex 3 of this DPA. Annex 1 of the SCCs is populated by Annex 1 of this DPA, Annex 2 of the SCCs is populated by Annex 2 of this DPA, and Annex 3 of the SCCs lists the Sub-processors at Annex 4 of this DPA.
14. Return or deletion of personal data
At the choice of the Merchant, Crossdock returns or deletes all the Personal Data after the end of the provision of services relating to processing, and deletes existing copies unless storage of the Personal Data is required by Union or Member State law. The default mechanism is deletion via the Shopify-issued shop/redact GDPR webhook cascade, which fires approximately 48 hours after the Merchant uninstalls Crossdock from the Shopify Admin and triggers the documented 48-hour scheduled cascade in Crossdock that deletes all shop-scoped data from Crossdock’s production systems. Audit log rows older than 24 months are auto-deleted by scheduled job; customer-identifying fields embedded in audit diffs are subject to redaction-on-request within the 30-day GDPR response window via the customers/redact webhook cascade.
15. Liability
The liability of each Party under this DPA is subject to the limitations and exclusions in §7 of the Terms of Service, including the twelve-month-fees aggregate cap and the carve-out for indirect, incidental, consequential, special, exemplary, and punitive damages. Nothing in this DPA limits or excludes any liability that cannot be limited or excluded under applicable data-protection law.
16. Governing law and jurisdiction
This DPA is governed by the laws of the State of California, United States, without regard to its conflict-of-laws principles, and any dispute under this DPA is subject to the same dispute-resolution procedure (informal resolution followed by binding individual arbitration administered by the American Arbitration Association under its Commercial Arbitration Rules, seated in San Francisco, California, with a class-action waiver) as is set out in §9 of the Terms of Service. Where mandatory provisions of the data-protection law applicable to the Merchant require a different governing law or forum, those mandatory provisions apply solely to the extent of the conflict.
17. Order of precedence
In case of conflict between this DPA and the Terms of Service or the Privacy Policy, this DPA prevails with respect to the processing of Personal Data. The Subprocessor List published at the URL referenced in §6 is incorporated by reference into this DPA and updates to that list become effective on the terms set out in §6.
Annex 1 — Description of processing
| Attribute | Value |
|---|---|
| Subject matter | Processing of Merchant’s customer and order data to provide the Square POS ↔ Shopify catalog, inventory, and order synchronisation service described in §1 of the Terms of Service. |
| Duration | The term of the Merchant’s Crossdock subscription plus a post-termination grace window of approximately 96 hours (Shopify’s 48-hour hold plus Crossdock’s 48-hour scheduled cascade) after which all shop-scoped data is irreversibly deleted via the shop/redact webhook cascade. Audit-log rows are retained for 24 months for legitimate-interest record-keeping per the Privacy Policy locked-text clause. |
| Nature and purpose | Catalog and inventory synchronisation, order forwarding from Shopify to Square, modifier and option propagation, customer-record mapping where required to attach a Shopify order to a Square customer, and operational audit logging. No profiling, no derived-data products, no secondary purpose. |
| Categories of personal data | Shopify customer identifier; Shopify and Square order identifiers; line-item identifiers; for orders that the Merchant has configured to forward customer detail to Square, the customer’s name, email address, telephone number, and shipping address; OAuth access and refresh tokens for the Merchant’s Shopify and Square accounts (encrypted at rest); shop domain and shop-owner email for billing and operational support correspondence. |
| Special categories of personal data | None. Crossdock does not process special categories of personal data within the meaning of GDPR Article 9. |
| Categories of data subjects | End customers of the Merchant’s Shopify store whose orders are synchronised to Square, and the Merchant’s own shop-owner contact for billing and operational support. |
Annex 2 — Technical and organisational measures
| Measure | Implementation |
|---|---|
| Pseudonymisation and minimisation | Crossdock minimises personal data by design. At v1 only Square↔Shopify identifier mappings and content hashes are persisted; customer email, name, telephone, and address fields are not cached as primary data. The integration fetches full customer records on demand at order-forwarding time and does not retain the payload beyond the request. |
| Encryption at rest | AES-256-GCM envelope encryption for OAuth access and refresh tokens, GDPR data-request export bundles, and any embedded customer-identifying field captured in audit-log diff metadata. The encryption key is held in environment configuration distinct from the database connection string, so a database snapshot alone is not sufficient to decrypt sensitive fields. |
| Encryption in transit | TLS 1.2 or higher for all inbound and outbound API traffic, all database connections (Postgres SNI with sslmode=require), and all background job queue traffic (Redis TLS). |
| Confidentiality and integrity | All Crossdock personnel are bound by written confidentiality obligations as a condition of access to production systems. Webhook signatures are verified on raw request bytes using HMAC-SHA256 before any handler runs, with a five-minute replay window. The audit log uses an append-only Postgres trigger (audit_log_forbid_modify) that refuses UPDATE and DELETE on the audit table, with redaction-on-request implemented via sibling tombstone-insert rows rather than mutation of the original. |
| Resilience and restore | Daily encrypted off-platform backups (Cloudflare R2, GPG envelope, AES-256, 30-day retention) of the production Postgres instance. Restore procedure documented in runbooks/restore-from-r2.md. Point-in-time recovery available via the managed Postgres provider (Neon) for in-window incidents. |
| Vulnerability management | GitHub Actions dependency scanning at every push (npm audit at high-or-critical severity), gitleaks secret-scanning at every push and pull request to the protected branch, automated Prisma schema-drift detection at every migration commit, and a quarterly review of the Sentry error-grouping dashboard for security-tagged events. |
| Access control | Production database and queue credentials are issued through the managed-provider control plane and rotated on personnel change. Application-level access to Merchant data is mediated through the Shopify-issued session token; Crossdock does not run a parallel user-database. The cron-role privilege segregation (dedicated audit_log_partition_dropper role with EXECUTE only on the partition-drop function) is enforced via Postgres GRANTs. |
| Logging and incident detection | Pino-formatted application logs with structured correlation identifiers, Sentry error telemetry with a beforeSend hook that scrubs PII at the boundary, and a 30-day SLA monitor over GDPR data-subject requests with T-5 and T-2 day pre-deadline Sentry warnings. |
| Sub-processor assurance | Crossdock engages only sub-processors with a public Data Processing Addendum or its equivalent, as listed in Annex 4. The full DPA URL for each sub-processor is published at https://crossdock.app/legal/subprocessors and is verified via an HTTP reachability sweep before each Shopify app-review submission. |
| Data minimisation and storage limitation | Per-payload review of every field Crossdock persists; the Protected Customer Data allow-list at the query layer enforces that only the documented fields enter the database. Audit-log partitions older than 24 months are dropped on a monthly cadence by a scheduled job. |
| Key rotation | Quarterly rotation of the master ENCRYPTION_KEY via the documented two-phase rotation runbook (runbooks/encryption-key-rotation.md). Rotation re-encrypts all token ciphertext under the new key without service interruption. |
Annex 3 — Standard Contractual Clauses
The Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679, approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module Two (Controller to Processor) are incorporated by reference into this DPA. The full text of the Standard Contractual Clauses is available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj. Annex 1 of the SCCs is populated by Annex 1 of this DPA, Annex 2 of the SCCs is populated by Annex 2 of this DPA, and Annex 3 of the SCCs lists the Sub-processors at Annex 4 of this DPA. The optional docking clause (Clause 7) is included. For transfers originating in the European Economic Area, the governing law of the EU SCCs under Clause 17 is the law of the Republic of Ireland and the forum under Clause 18(b) is the courts of Ireland. For transfers originating in the United Kingdom, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0, issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018 and in force from 21 March 2022 (the “UK Addendum”), is incorporated by reference: its Table 1 (parties) and Table 3 (Appendix Information) are populated by Annexes 1, 2, and 4 of this DPA, its Table 2 selects the Module Two EU SCCs incorporated above, neither Party exercises the optional Table 4 right to end the UK Addendum except as that Addendum permits, and under the UK Addendum these clauses are governed by and construed in accordance with the laws of England and Wales. For transfers originating in Switzerland, the EU SCCs apply as adapted per the Swiss Federal Data Protection and Information Commissioner (the “FDPIC”): the FADP replaces references to the GDPR, the FDPIC is the competent supervisory authority for transfers governed by Swiss law, the governing law is the law of Switzerland, and Data Subjects in Switzerland may enforce their rights in their place of habitual residence.
Annex 4 — Sub-processors
The current list of Sub-processors engaged by Crossdock is maintained at https://crossdock.app/legal/subprocessors. Each Sub-processor row carries the vendor name, the purpose of engagement, the processing jurisdiction, the categories of data processed, and a link to the Sub-processor’s own Data Processing Addendum or equivalent. The list is exhaustive for v1 and is amended on the 30-day-notice procedure described in §6.
Affirmative acceptance
By accepting the Terms of Service and using the Crossdock service, Merchant agrees to this Data Processing Addendum.
Related documents
Related documents: Privacy Policy, Terms of Service, Cookie Disclosure, Subprocessor List. Security contact: security.txt (RFC 9116).