Shopait
PricingContact
Join early access

On this page

1. The processing2. What we commit to3. Subprocessors4. International transfers5. Your part6. Security measures7. Order of documents

Legal

Data Processing Addendum

Draft — effective October 8, 2026

This addendum forms part of the Terms of Service between the merchant ("you") and the operator of Shopait ("we"). It applies when we process personal data on your behalf to run your store — mainly data about your customers and visitors. You are the controller of that data; we are your processor. It is meant to meet Article 28 of the GDPR and the processor rules of Vietnam's personal data protection law.

This is a draft. It describes how Shopait works today, written in plain words and not yet reviewed by a lawyer. It will be reviewed — and updated with notice — before Shopait charges its first customer. If anything here is unclear or seems wrong, write to support@shopait.com.

Who operates Shopait

Shopait is operated by Do Xuan Truong, an individual, Vietnam. A company will take over this role once it is registered; we will update this page when it does.

Write to us about anything on this page: support@shopait.com.

1. The processing

Subject and durationRunning your store on Shopait, for as long as you use the Service and until the data is deleted as described below.
Nature and purposeHosting, storing, displaying, sending (emails, messages), analysing (store reports) and otherwise processing data as needed to provide the Service you use.
Data subjectsYour customers and prospects, visitors of your store, recipients of your emails and messages, and people whose data you upload.
Types of dataNames, contact details, addresses, order and payment details (payment tokens only — never full card numbers), account credentials of your customers, marketing consent, store analytics and device data, messages and reviews, and other data you choose to collect.
Special categoriesNot needed by the Service. Do not collect health, biometric or similar data through your store unless the law allows it and you have assessed it.

2. What we commit to

  • Instructions. We process the data only on your documented instructions: these terms, your settings and actions in the admin, and your use of the APIs — unless the law requires otherwise, in which case we will tell you (unless the law forbids it).
  • Confidentiality. Everyone with access to the data is bound by confidentiality.
  • Security. We apply the measures in section 6.
  • Help with requests. We give you tools to answer your customers: requesting a customer's data, and erasing a customer (personal details removed 10 days after the request, or 6 months after their last order if later). We help further on request.
  • Help with compliance. We give you the information you reasonably need for impact assessments and consultations with authorities.
  • Breaches. We tell you without undue delay after becoming aware of a breach affecting your data, with what we know, and keep you updated.
  • End of the Service. You can export your data with the admin's export features or the Admin API. After you close your store and ask us to, we delete the data, except what the law requires us to keep; backups expire within 14 days.
  • Audits. We give you the information needed to show we meet this addendum, and answer reasonable questions in writing.

3. Subprocessors

You authorise us to use the subprocessors below. Many are used only when the feature is enabled on the platform or in your store. We will update this list before adding or replacing a subprocessor and tell account holders of material changes; you can object by writing to support@shopait.com, and if we cannot address the objection you may close your store.

SubprocessorWhat forWhereWhen
Amazon Web Services (Lightsail, SES, S3, Secrets Manager)Servers, database, backups, sending email, file storage, keeping secretsSingaporeAlways
CloudflareDNS, content delivery, protection against attacks; file storage (R2) if usedGlobal networkAlways; storage if enabled
StripeCard payments, saved cards, payouts of the store card gatewayUnited States and othersIf enabled
PayPalPayPal paymentsUnited States and othersIf enabled
VNPayDomestic card and QR payments in VietnamVietnamIf enabled
Anthropic, OpenAI, Google (Gemini, Cloud Translation)AI features through the platform's AI gateway; machine translationUnited StatesIf enabled and used
TwilioText messages (SMS)United StatesIf enabled
hCaptcha (Intuition Machines)Spam protection on formsUnited StatesIf enabled
Google Maps Platform, Mapbox or OpenStreetMap (Nominatim)Address suggestions and map locations at checkout and in the adminUnited States / European UnionIf enabled
EasyPostShipping labels bought through the platformUnited StatesIf enabled
Apple (APNs), Google (Firebase Cloud Messaging)Notifications to the mobile appsUnited StatesIf the mobile apps are used

Apps, payment providers and carriers that you install or connect in your store are not our subprocessors: they receive data because you chose them, under their own terms.

4. International transfers

The data is hosted in Singapore and some subprocessors process it in other countries (above). Where the law of your customers' country requires a transfer mechanism, we rely on our subprocessors' contractual safeguards, such as the European Commission's standard contractual clauses where they offer them. We are reviewing these requirements with legal counsel; until this draft is final, write to support@shopait.com if you need signed clauses.

5. Your part

  • Have a lawful basis for the data you collect and tell your customers how you use it (your store's privacy policy).
  • Turn on the consent banner where your customers' law requires consent for analytics or marketing (for example the EU or Vietnam).
  • Only upload data you are allowed to process, and answer your customers' requests.

6. Security measures

  • Encryption in transit (HTTPS, HSTS); secrets stored in the database encrypted with AES-256-GCM.
  • Passwords hashed with scrypt; two-step verification and passkeys; sign-in codes for new browsers; rate limits.
  • Separation of each store's data in the database; staff permissions per store.
  • Payment card data handled by payment providers' own fields — never stored by us.
  • Daily backups kept 14 days; server snapshots; monitoring of availability.
  • Uploaded files served from an isolated origin; apps' tracking pixels in an isolated frame.
  • Administrative access to production limited to the operator, with keys and secrets kept in a secrets manager.

7. Order of documents

If this addendum and the Terms of Service conflict on the processing of personal data, this addendum prevails. Liability under it is subject to the Terms of Service, to the extent the law allows.

Other policies

Privacy PolicyTerms of ServiceAcceptable Use PolicyTalk to us
Shopait

Products

Pricing

Developers

Developer early access

Account

Join early access

Company

ContactPrivacyTermsData processingAcceptable use
© 2026 Shopait. All rights reserved.

Choose region and language