Last updated: September 30, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between TrackYourShelves L.L.C. ("TrackYourShelves", "we", "us") and the business that uses the Service ("you"). It applies whenever we process personal data on your behalf, and it takes effect when you accept the Terms. No signature is needed. If your organization needs a countersigned copy, write to privacy@trackyourshelves.com.
If documents conflict, the order is: an agreement signed by both of us, then the Standard Contractual Clauses where they apply (section 11), then this DPA, then the Terms.
Data Protection Laws means the laws that apply to the processing of Personal Data under the Terms, including, where they apply, the EU General Data Protection Regulation ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended ("CCPA"), and other United States state privacy laws.
Personal Data means information relating to an identified or identifiable person that we process on your behalf in providing the Service ("Business Data" in our Privacy Policy). Security Incident means a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Personal Data. Controller, processor, business, service provider, data subject, consumer and processing have the meanings given in Data Protection Laws.
You are the controller (and, under the CCPA, the business) for Personal Data. We are your processor (and service provider). Annex 1 describes the processing. You are responsible for having a lawful basis for the Personal Data you put into the Service and for the instructions you give us.
This DPA does not cover information we process as a controller for our own purposes, such as your account, billing and our marketing to you. Our Privacy Policy covers that.
We process Personal Data only on your documented instructions. Your instructions are the Terms, this DPA, and the way you use and configure the Service. If the law requires us to process Personal Data otherwise, we will tell you first unless the law forbids it. We will tell you if we believe an instruction breaks Data Protection Laws.
Everyone we authorize to process Personal Data is bound by a duty of confidentiality and has access only to what their work requires.
We maintain appropriate technical and organizational measures to protect Personal Data, taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing. Annex 2 describes them. We may improve them over time, but we will not reduce the overall level of protection.
You give us general authorization to engage sub-processors. The current list, with what each one does, what data it receives and where it is located, is on our Sub-processors page. Each sub-processor is bound by written terms imposing the data protection obligations that Data Protection Laws require, and we remain responsible to you for its work.
We will give at least 30 days' notice of a new sub-processor by updating the Sub-processors page and by email to everyone who has asked at privacy@trackyourshelves.com to receive it. Where the Standard Contractual Clauses apply, this period is not shortened. You may object on reasonable data protection grounds within that notice period. We will try in good faith to resolve it; if we cannot, you may end the affected part of the Service.
The Service lets you find, export, correct and delete Personal Data, which is how most requests from people exercising their privacy rights are answered. If you need more help, we will assist you as far as is reasonable, taking into account the nature of the processing. If a person contacts us directly about Personal Data we hold for you, we will direct them to you and will not answer the request ourselves unless you ask us to or the law requires it. We will also give you reasonable information you need for a data protection impact assessment or a consultation with a regulator.
We will notify you without undue delay, and in any case within 72 hours, after we become aware of a Security Incident affecting your Personal Data. We will send the notice to your account's owner address and include what we know about the nature of the incident, the data and people likely affected, its likely consequences, and what we are doing about it, adding details as we learn them. We will take reasonable steps to contain the incident and limit its effects. Notifying you is not an admission of fault.
You can export Personal Data from the Service at any time. When your account is closed, you have a 30-day window to reopen it. After that we erase Personal Data from our systems, and it leaves our backups within 180 days. The only exceptions are our own billing records for your account, which we keep as the law requires, and de-identified information that can no longer identify anyone, which we will not attempt to re-identify.
We will make available the information reasonably necessary to show that we meet this DPA: this document, our Trust Center, and written answers to a reasonable security questionnaire once a year or after a Security Incident. When we hold independent audit reports or certifications, we will share them under confidentiality.
Where Data Protection Laws or a regulator require an audit that this information does not satisfy, you may conduct one, or have an independent auditor bound by confidentiality conduct one, with at least 30 days' written notice, during normal business hours, once a year and after a Security Incident (and more often if a regulator requires it), at your cost, and in a way that does not expose other customers' data or put the security of the Service at risk.
We store Personal Data in the United States. Our sub-processors process it in the countries shown on the Sub-processors page.
Where the GDPR applies to a transfer of Personal Data from the European Economic Area to us, the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914, Module Two (controller to processor), are incorporated into this DPA, with you as data exporter and us as data importer. Clause 7 does not apply. Under Clause 9, option 2 applies, with the notice period in section 6. The optional wording in Clause 11 does not apply. The supervisory authority is determined under Clause 13(a). Clauses 17 and 18 are completed with Ireland. For Annex I.A, the data exporter is you, at the details in your account, and the data importer is TrackYourShelves L.L.C., 8735 Dunwoody Place, Ste N, Atlanta, GA 30350, USA, privacy@trackyourshelves.com, acting as processor; accepting the Terms is each party's signature. Annex I.B is Annex 1 of this DPA, Annex II is Annex 2, and Annex III is Annex 3.
Where the UK GDPR applies, the International Data Transfer Addendum issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018 (version B1.0) applies to those Clauses, with the tables completed from this DPA and neither party able to end it under Table 4. Where Swiss law applies, the Clauses apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection, the competent authority being the Swiss Federal Data Protection and Information Commissioner, and the term "Member State" in Clause 18(c) not preventing people in Switzerland from bringing a claim where they habitually reside.
Where the CCPA or a similar United States state law applies, we:
You may take reasonable and appropriate steps to make sure our use of Personal Data is consistent with your CCPA obligations, including the audit in section 10, and to stop and remedy any use these terms do not allow. You will tell us of any consumer request we must act on and give us what we need to act on it. We certify that we understand and will comply with these restrictions.
Each party's liability under this DPA is subject to the limits in the Terms, except where Data Protection Laws or the Standard Contractual Clauses do not allow a limit. Any other liability terms apply only under a separate agreement signed by both of us. This DPA lasts for as long as we process Personal Data on your behalf. We may update it to reflect changes in law or in the Service. A change that reduces the protection of Personal Data does not apply to you without your written agreement.
A more detailed description of these measures is available to you under confidentiality on request and forms part of this Annex 2.
The current list is on our Sub-processors page and forms part of this DPA.
Questions about this DPA: privacy@trackyourshelves.com.