SupplygoodsSupplygoods

Data processing

The annex covering personal data. You are the controller of your customers, we are your processor, the warehouse in China that packs your parcels is a sub-processor, and the one transfer that matters is a delivery address going there.

Last updated 3 September 2026

PrivacyTermsData processingCookies

This is an annex to the terms of use and forms an inseparable part of them. Where it conflicts with the body of those terms, this annex prevails.

Roles

1.1In respect of your customers' personal data, you are the controller and is the processor. You decide why and how that data is processed. processes it on your instruction, in order to have an order sourced and shipped.

1.2In respect of your own account data, being the identity and contact details of your users, their sign-in records and their use of the platform, is the controller. The privacy policy describes that processing.

1.3The warehouse in , China, is a sub-processor. It processes your data on our instruction so that it can pack a parcel and address it. It is a different company from the supplier you buy the goods from: your agreement with the supplier covers the goods themselves and is not covered by this annex.

1.4 processes personal data only on your documented instruction. These terms, together with your use of the platform, are that instruction. will tell you if, in its opinion, an instruction infringes applicable law.

What is processed

2.1Purpose. To provide order processing as described in Art. 3 of the terms of use, and nothing else.

2.2Duration. For as long as the terms are in force, and thereafter only as required to finish orders in progress or to comply with a statutory retention obligation.

2.3Data subjects. Your customers, being the recipients of the parcels.

2.4Categories of data. Name, delivery address, and the email address or telephone number your store holds for delivery purposes, together with the order lines, quantities and amounts attached to that order.

2.5No special categories. No data within the meaning of Art. 9 or Art. 10 GDPR is requested, required or knowingly processed, and you will not introduce any into the platform.

Sub-processors

3.1You give general authorisation for to engage sub-processors. At the date of these terms they are a warehouse in , China, which holds the goods, packs them and addresses the parcel; our hosting provider, for running the application and its database; and our tracking provider, which receives a carrier and a tracking number and nothing else. The supplier you buy the goods from is not on this list: it sets prices and invoices you, and it does not receive your customers' details.

3.2Each of them is named to you on request. Write to and you get the registered name and country of every sub-processor holding your customers' data. We describe them by what they do rather than by name here because a public page naming the company that packs every parcel is a page telling anybody who reads it where to go around us. That is a commercial reason and not a data protection one, so it does not get to cost you the answer.

3.3 imposes on each sub-processor obligations no less protective than those in this annex, and remains fully liable to you for their performance.

3.4 will inform you at least thirty days before adding or replacing a sub-processor. You may object on reasonable data protection grounds, and if the objection cannot be resolved either party may end use of the platform.

Transfer outside the EEA

Not in force. The Standard Contractual Clauses and the transfer impact assessment referred to below are being put in place. Until they are, this section describes an intention rather than a fact.

4.1Providing this service necessarily transfers a delivery address to China. The warehouse that packs and ships a parcel cannot address it otherwise. You instruct to make that transfer.

4.2That transfer is made under the Standard Contractual Clauses adopted by the European Commission, module three, concluded between and the supplier, together with a transfer impact assessment and the supplementary measures identified by it.

4.3Only the data needed to address and deliver a parcel is transferred. No order history, no other purchase and no payment data is transferred, and the platform holds no payment data at any point.

Security

5.1Appropriate technical and organisational measures are taken against loss and unlawful processing, taking into account the state of the art, the cost, and the nature and risk of the processing. These include at least: transport encryption on every connection; access to personal data restricted to those who need it for order processing; passwords stored only as hashes; and access tokens for your store held so that they can be withdrawn when the application is uninstalled.

5.2A duty of confidentiality is imposed on everyone authorised to process the personal data.

Data breaches

6.1 notifies you without undue delay, and in any event within twenty-four hours of becoming aware of a breach affecting your data, and provides the information you reasonably need to meet your own notification obligations.

6.2 does not notify a supervisory authority or a data subject on your behalf unless you ask in writing. That decision belongs to the controller.

Requests, erasure and retention

7.1A request from a data subject is passed to you rather than answered, because you are the controller and hold the relationship with the person asking. The Shopify customers/data_request webhook is handled this way: recorded, and raised for you to answer.

7.2On the Shopify customers/redact webhook, or on your instruction, the name and delivery address are removed from the orders concerned.

7.3On the Shopify shop/redact webhook, which Shopify sends forty-eight hours after the application is uninstalled, your data is deleted, except the financial records in 7.4.

7.4Financial records are kept for seven years, because the law requires it. That is the amount, the date and the order number. It is not the name and the address of the person the parcel went to, and those come off under 7.2 and 7.3 like everything else.

7.5Personal data is otherwise kept only for as long as it is needed for order processing and for handling anything arising from it.

Audit and authorities

8.1The information needed to demonstrate compliance with this annex is made available to you, and an audit by you or an auditor you appoint is allowed, at most once a year and on thirty days of notice, unless a supervisory authority or a data breach requires otherwise. An audit is at your cost, is conducted so as not to disrupt order processing, and is subject to the confidentiality obligations in the terms of use.

8.2If either party receives a request from a supervisory authority to inspect or access personal data covered by this annex, it informs the other in writing before access is granted, unless the law forbids it, and provides a copy of the correspondence.

Duration

9.1This annex takes effect with the terms of use and ends with them by operation of law. Obligations that by their nature are intended to continue survive it.