Skip to content

Legal

Data processing agreement

The terms under which StockReclaim processes personal data on your behalf, for merchants subject to the GDPR, UK GDPR or similar laws.

Effective September 5, 2026.

This Data Processing Agreement ("DPA") forms part of the Terms of service between you (the "Controller") and Gandhi Polymers, a sole proprietorship registered in India (proprietor: Ankita Bhandiya), trading as StockReclaim (the "Processor"). It takes effect when you install the StockReclaim app (the "App") and applies for as long as the Processor processes personal data on your behalf.

You do not need to sign anything: installing the App is acceptance. If your own compliance process needs a signed copy, email support@stockreclaim.com and we will return a countersigned PDF of this document.

1. Definitions

  • "Data Protection Law" means the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and any other law that applies to the processing of Personal Data under this DPA.
  • "Personal Data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in Data Protection Law.
  • "Standard Contractual Clauses" or "SCCs" means the clauses approved by European Commission Decision (EU) 2021/914, Module Two (controller to processor), and, for UK transfers, the UK International Data Transfer Addendum issued by the Information Commissioner.
  • "Sub-processor" means a third party the Processor engages to process Personal Data on the Controller's behalf.

2. Scope and roles

  • This DPA applies to Personal Data the Processor processes in providing the App to the Controller, as described in Annex I.
  • The Controller is the controller of that Personal Data. The Processor acts only as a processor, on the Controller's behalf.
  • Shopify Inc. is an independent controller and, for the App's access to your store, a separate processor under your agreement with Shopify. This DPA does not cover Shopify's own processing.
  • If this DPA conflicts with the Terms of service on a matter of data protection, this DPA prevails.

3. The Controller's obligations

The Controller warrants that:

  • it has a lawful basis for the processing it instructs, and has given any notices to data subjects that Data Protection Law requires;
  • its instructions to the Processor comply with Data Protection Law;
  • it is responsible for the accuracy of the settings and recipient email addresses it enters in the App, including any third party (for example a bookkeeper) it directs the App to email.

4. The Processor's obligations

The Processor will:

  1. Process only on documented instructions. The Controller's instructions are: the Terms of service, this DPA, the permissions granted to the App at install, and the settings the Controller chooses in the App. The Processor will not process Personal Data for any other purpose. If a law requires the Processor to process otherwise, it will tell the Controller first unless that law prohibits it.
  2. Keep it confidential. Only persons bound by confidentiality obligations have access to Personal Data. At the date of this DPA that is the proprietor alone.
  3. Secure it. Implement the technical and organisational measures in Annex II, and keep them appropriate to the risk as required by Article 32 GDPR.
  4. Engage Sub-processors only as allowed by section 5.
  5. Help with data-subject rights. Taking into account the nature of the processing, assist the Controller with appropriate measures to respond to requests from data subjects. See section 7.
  6. Help with security, breach and impact assessments. Assist the Controller, to the extent the information is available to the Processor, with its obligations under Articles 32 to 36 GDPR.
  7. Delete or return the data at the end. See section 8.
  8. Demonstrate compliance. Make available the information necessary to demonstrate compliance with Article 28 GDPR and allow for audits as set out in section 9.
  9. Flag unlawful instructions. Inform the Controller immediately if, in the Processor's opinion, an instruction infringes Data Protection Law.

5. Sub-processors

  • The Controller gives the Processor general written authorisation to engage the Sub-processors listed in Annex III, and others as described below.
  • The Processor imposes on each Sub-processor, by written contract, data-protection obligations that are no less protective than those in this DPA, and remains fully liable to the Controller for the Sub-processor's performance.
  • Changes. The Processor will give at least 30 days' notice before adding or replacing a Sub-processor, by updating Annex III and announcing the change in the App and on the changelog. The Controller may object on reasonable data-protection grounds within that period by emailing the Processor. If the objection cannot be resolved, the Controller may terminate by uninstalling the App, and section 8 applies.

6. International transfers

  • The Processor is established in India. The App and its database are hosted by Sub-processors in the United States (see Annex III). Personal Data of data subjects in the EEA, the United Kingdom and Switzerland is therefore transferred to countries that have not received an adequacy decision.
  • For such transfers the parties enter into the SCCs, which are incorporated into this DPA by reference and completed as follows: Module Two applies; Clause 7 (docking) is included; Clause 9(a) Option 2 (general authorisation) with the notice period in section 5; Clause 11 optional language is not included; Clause 13 applies as set out in Annex I.C; Clause 17 Option 1, governed by the law of Ireland; Clause 18 forum Ireland. Annex I and Annex II of the SCCs are the Annexes I and II of this DPA. For UK transfers the UK Addendum applies with the same content; for Swiss transfers the SCCs apply with the adaptations required by the Swiss data-protection authority.
  • Onward transfers to Sub-processors are covered by the Sub-processors' own SCC-based data-processing terms with the Processor.
  • If the SCCs are invalidated or replaced, the parties will cooperate in good faith to put an alternative lawful transfer mechanism in place.

7. Data-subject requests and Shopify's privacy webhooks

  • The App implements Shopify's mandatory privacy webhooks. A customers/data_request or customers/redact request from the Controller's store is processed automatically. Because the App holds no personal identifiers of the Controller's customers (Annex I.B), the response in each case is that no such data is held.
  • If a data subject contacts the Processor directly, the Processor will not respond on the merits but will promptly forward the request to the Controller.
  • For any other assistance the Controller reasonably needs to answer a data-subject request, email support@stockreclaim.com.

8. Personal data breach

The Processor will notify the Controller without undue delay, and in any case within 48 hours of becoming aware of a personal data breach affecting the Controller's Personal Data, to the email address associated with the Controller's store. The notice will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. The Processor will provide further information as it becomes available and will cooperate with the Controller's own notification duties.

9. Deletion and return of data

  • During the term the Controller can export its exception data at any time as CSV from the App, and can delete its decisions from Settings.
  • On uninstall, Shopify notifies the Processor and, 48 hours later, sends a shop/redact request. On that request the Processor deletes all Personal Data held for the Controller's store — sessions and access token, store record, scan cache, restock claims, last-seen inventory levels, decisions, settings, support tickets with attachments, and feature requests linked to the store — and verifies by reading the database back that nothing remains. Reinstalling within those 48 hours preserves decisions and settings.
  • Copies in encrypted backups are overwritten in the ordinary backup cycle of the database Sub-processor and are not restored except to recover from a system failure, in which case the deletion is re-applied.
  • The Processor may retain Personal Data only where and for as long as a law requires, and then only for that purpose.

10. Audit

  • On written request, no more than once in any 12-month period unless a supervisory authority requires it or a breach has occurred, the Processor will answer the Controller's reasonable written questions about its processing and provide relevant documentation, including the current Annexes and summaries of the security certifications or audit reports of its Sub-processors where available.
  • If the Controller can show that this is insufficient to meet its obligations under Data Protection Law, the Processor will allow an audit by the Controller or an independent auditor bound by confidentiality, on at least 30 days' notice, during business hours, at the Controller's cost, and without access to other controllers' data.

11. Liability and term

  • Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of service, except to the extent Data Protection Law or the SCCs do not permit them to be limited.
  • This DPA lasts as long as the App is installed and continues until all Personal Data has been deleted under section 9.
  • This DPA is governed by the law stated in the Terms of service, except that the SCCs are governed as stated in section 6.

Annex I — Details of the processing

A. Parties

Data exporter / Controller: the merchant that installs the App, at the store domain and contact email held in Shopify.
Data importer / Processor: Gandhi Polymers, trading as StockReclaim, India. Contact: support@stockreclaim.com.

B. Description of the processing

Subject matterAuditing the Controller's Shopify refunds and returns to identify units not returned to sellable inventory, and letting the Controller act on them.
DurationWhile the App is installed, plus the 48-hour window before Shopify's shop/redact request.
Nature and purposeReading order, refund, return, product, inventory and location data live from the Shopify API; computing and caching an audit result; storing the Controller's decisions and settings; sending the emails the Controller enables; handling support requests. The only write to the Controller's store is an inventory adjustment when the Controller clicks "Restock now".
Categories of data subjects(1) The Controller's staff who install or use the App. (2) The Controller's customers, only indirectly through order and refund records.
Categories of Personal Data(1) Staff: name and email address as passed by Shopify at install; email addresses the Controller enters as digest or packet recipients; the content of support tickets and feature requests. (2) Customers: none directly — the App requests no customer name, email, phone or address fields and Shopify does not provide them. It processes order numbers, refund and return records, SKUs, product titles, quantities and amounts, which may be indirectly linkable to a customer only within the Controller's own Shopify admin.
Special categoriesNone.
FrequencyContinuous while installed (scans on a schedule and on demand; webhooks as events occur).
RetentionSee section 9 and the Privacy policy §9.

C. Competent supervisory authority (SCCs Clause 13)

The supervisory authority of the EU Member State in which the Controller is established, or, where the Controller is not established in the EU, the authority of the Member State in which its EU representative is established or in which the data subjects concerned are located. For UK transfers, the Information Commissioner's Office.

Annex II — Technical and organisational measures

  • Encryption in transit: TLS for all connections between Shopify, the App, its database, email provider and the Controller's browser.
  • Encryption at rest: Shopify access tokens are encrypted in the database; database storage is encrypted by the hosting Sub-processor.
  • Tenant isolation: row-level security in the database scopes every record to a single store; application queries are always scoped to the authenticated store.
  • Least privilege: the App requests only the Shopify permissions it needs and no protected customer fields; it holds no copy of the Controller's catalogue, orders or inventory beyond the derived data in Annex I.
  • Authenticity of inbound data: every Shopify webhook is verified against its HMAC signature before processing; the embedded App authenticates every request with a Shopify session token.
  • Access control: production access is limited to the proprietor, protected by multi-factor authentication at the hosting and database Sub-processors; the internal admin console requires a one-time code delivered to the proprietor.
  • Logging and monitoring: structured application logs and error monitoring with personal identifiers disabled; logs retained for up to 90 days.
  • Deletion: automated, verified deletion on shop/redact (section 9).
  • Change control: code is version-controlled; automated tests, lint and type checks run on every change before deployment.
  • Backups and resilience: managed database backups by the Sub-processor; the App runs on redundant machines with health checks.
  • Sub-processor due diligence: each Sub-processor is engaged under its published data-processing terms including SCCs where applicable.

Annex III — Sub-processors

Sub-processorServiceLocation
Fly.io, Inc.Application hosting, logs, background jobsUnited States (Ashburn, Virginia)
Supabase, Inc.Managed PostgreSQL databaseUnited States
Resend, Inc.Transactional email deliveryUnited States
Functional Software, Inc. (Sentry)Error monitoring (personal identifiers disabled)United States
Telegram FZ-LLCInternal operational alerts to the proprietor (store domain and ticket subject only)United Arab Emirates / EU

Shopify Inc. is not a Sub-processor of the Processor; it is the platform under the Controller's own agreement with Shopify. The website host (Hostinger) does not process Personal Data under this DPA.

Last change to this list: 5 September 2026 (initial version).


Questions about this document? Email support@stockreclaim.com. See also our Privacy policy, Terms of service and Data processing agreement.