StockWait

Data processing agreement

Version 1.0, 25 August 2026.

This agreement applies automatically to every merchant who installs StockWait — you do not need to request or sign it for it to be in force. If your procurement process needs a countersigned copy, email legal@stockwait.com and we will return one.

This DPA forms part of the agreement between Itsybit (“Processor”, “we”), operator of StockWait, and the merchant installing the app (“Controller”, “you”). It governs our processing of personal data relating to your customers.

1. Roles

For shopper personal data you are the Controller and we are the Processor. You determine the purposes and means; we act only on your documented instructions, of which installing and configuring the app is one. For data about you as our customer we act as Controller — see the privacy policy.

2. Subject matter, duration, nature and purpose

Subject matter: providing back-in-stock waitlist and notification services. Duration: for as long as the app is installed, plus the retention periods in section 6. Nature and purpose: collecting waitlist signups, storing them, sending the notifications those people asked for, and reporting on the result.

3. Categories of data and data subjects

Data subjects: your customers and site visitors who join a waitlist, and your customers who place an order following an alert.

Categories: email address; phone number where separately consented; a cryptographic hash of either; product and variant identifiers; price shown at signup; locale; consent metadata (source, timestamp, IP address, version of the consent wording); message delivery events; click and order-attribution records.

No special categories of personal data are processed. We do not collect names, postal addresses, payment details, or browsing history.

4. Our obligations

5. Security measures

Encryption in transit (TLS) and at rest. Merchant access credentials encrypted with AES-GCM under keys held in a dedicated secrets store, never in configuration or environment variables. Webhook signatures verified in constant time before parsing. Strict tenant isolation, enforced by an automated test that inspects the database schema rather than by review convention. Access to shopper contact details is logged — who, what and how many people — with lookups of an individual recorded by hash rather than by address. Test and production data are fully separated; production data is never copied into a test environment.

Our full control set, including backup and data-loss prevention, is published alongside our privacy policy. We hold no third-party security certification such as SOC 2 or ISO 27001, and we say so rather than implying otherwise.

6. Retention and deletion

On uninstall, all merchant configuration and shopper personal data is deleted after 60 days. Deletion is performed by a scheduled job on a deadline set at uninstall; it does not depend on any later webhook arriving.

Two items are deliberately retained after a deletion request: a non-reversible hash of the address, and the consent record minus the IP address. The hash keeps a person on the suppression list so they are not mailed again; the consent record is your evidence that the person asked to be contacted. Both are retained on the basis of your and our legitimate interest in preventing unwanted messages and in defending against claims. This is set out in full in section 4 of the privacy policy.

7. Data-subject requests

Requests arriving through Shopify’s compliance webhooks are actioned automatically: access requests assemble everything held, and erasure requests delete immediately, subject to section 6. The work completes before we return a success response, so a success is a confirmation rather than an acknowledgement. Requests reaching us directly are forwarded to you and actioned by us.

8. Subprocessors

You give general authorisation for the subprocessors below. Each is bound by terms no less protective than this agreement.

SubprocessorPurposeLocation
Cloudflare, Inc.Compute, database, queues, object storageGlobal edge
Resend, Inc.Transactional email deliveryUS / EU
Twilio, Inc.SMS delivery, only where SMS is enabledUS
Shopify Inc.Platform of record for product, inventory and order dataMerchant’s Shopify region

9. Audit

We will make available the information reasonably necessary to demonstrate compliance with this DPA and, on reasonable notice and no more than once a year (or after a personal data breach), contribute to an audit conducted by you or an auditor you appoint, subject to confidentiality and to not compromising other merchants’ data.

10. Personal data breach

We will notify you without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting your customers’ data, with the nature of the breach, the categories and approximate number of people affected, the likely consequences and the measures taken. Notification is sent at the 72-hour mark even if the investigation is incomplete: an accurate partial notice on time is more useful to you than a complete one that arrives late.

11. International transfers

Where personal data is transferred outside the EEA or the UK, the transfer is governed by the European Commission’s Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), together with the UK International Data Transfer Addendum where applicable. They are incorporated into this agreement by reference, with this DPA supplying Annexes I and II: the parties are as identified above, the data and data subjects are those in section 3, and the technical and organisational measures are those in section 5.

12. Precedence and changes

Where this DPA conflicts with our general terms, this DPA governs matters of personal data. Material changes are announced by email at least 30 days before taking effect.

13. Contact

legal@stockwait.com for this agreement; privacy@stockwait.com for data requests; security@stockwait.com for security reports.