For merchants

Data Processing
Addendum.

This addendum forms part of the Store Agreement between the merchant identified in the store’s account and Tringify Ecommerce Private Limited (“Tringify”). It applies when Tringify processes personal information on the merchant’s behalf to provide the services. It prevails over conflicting general terms for that processing, subject to mandatory law and any applicable transfer clauses.

1. Roles and instructions

The merchant determines the purposes and essential means of processing its customer information. Tringify acts as processor, or equivalent service provider under applicable law, for the processing described here. If the merchant is itself a processor, it confirms that it is authorised to appoint Tringify.

The Store Agreement, this addendum, the merchant’s configuration and its authorised use of the service form the documented instructions. Tringify will process the information only on those instructions unless applicable law requires otherwise. Where permitted, Tringify will inform the merchant of that requirement and of an instruction it believes infringes applicable data-protection law.

Tringify separately determines the use of information needed for its own account administration, billing, platform security and legal responsibilities. The Privacy Policy describes that processing.

2. Processing covered

  • Purpose: hosting and operating the merchant’s store, maintaining customer and order records, supporting checkout and communications, and providing features and integrations the merchant requests.
  • People concerned: shoppers, customer-account holders, recipients and other people whose information the merchant submits or collects through the service.
  • Information: names, contact details, addresses, account identifiers, orders and transaction references, communications, submitted content, preferences and related technical information.
  • Duration: the period the merchant uses the relevant service, followed by the applicable return, deletion and retention periods.
  • Nature: collection, recording, organisation, storage, retrieval, transmission, correction, export, restriction and deletion as needed to provide the configured services.

The service is not intended as a repository for unnecessary sensitive information. The merchant is responsible for ensuring a lawful basis, necessary notices and permissions, and the appropriateness of information it chooses to submit.

3. Confidentiality and protection

Tringify will apply appropriate technical and organisational safeguards to the processing and ensure that people it authorises to handle the information are subject to confidentiality obligations. Measures include identity and access controls, protected public connections, operational monitoring and recovery procedures appropriate to the service.

The Security page explains account protection and access controls. Any specific security or recovery commitments are set out in the merchant’s agreement. The merchant remains responsible for its users’ permissions, credentials, devices and independently selected integrations.

4. Subprocessors

The merchant authorises the subprocessors used for its services and described in the service-provider list. Tringify will place appropriate data-protection obligations on subprocessors and remains responsible for the processing it entrusts to them as required by applicable law.

For a planned new or replacement subprocessor, Tringify will notify affected merchants through their account or registered contact before the change, normally at least 30 days beforehand. Where an urgent change is necessary to protect the service or meet law, notice will be given as soon as reasonably practicable.

A merchant may raise a reasoned data-protection objection at privacy@tringify.com during the notice period. The parties will seek a reasonable resolution. If processing cannot continue lawfully, the affected processing must stop and the parties will address the affected service under their agreement and applicable law.

5. Privacy requests

Tringify will assist the merchant, taking account of the nature of processing, with requests to exercise applicable privacy rights. The merchant must use its customer privacy tools and respond to requests for which it is responsible. Tringify may direct a shopper to the merchant or relay a request it receives.

Tringify will not independently fulfil a request concerning merchant-controlled information contrary to the merchant’s lawful instructions, except where law requires action. Identity verification, the rights of others and lawful retention requirements must be considered before disclosure or deletion.

6. Personal-data incidents

Tringify will notify affected merchants without undue delay after becoming aware of a personal-data breach involving information processed for them. Information may be provided in stages as it becomes available, including the nature of the incident, information and people affected, likely consequences, and measures taken or proposed.

Tringify will provide reasonable assistance with the merchant’s applicable notification and mitigation duties. The merchant remains responsible for its own regulatory and individual notices. Each party must meet the reporting obligations applicable to it; a contractual notice does not replace a statutory deadline.

7. Information, assessments and audits

Tringify will make information reasonably necessary to demonstrate its obligations under this addendum available to the merchant and assist with applicable assessments or regulator consultations relating to the service.

Where an audit or inspection is required by applicable law, the parties will coordinate its scope, timing, confidentiality and access so that it is effective while protecting other customers’ information and service security. These arrangements must not prevent an audit or regulator access that the law requires.

8. Return, deletion and retention

The merchant can use available export tools while it has access and may request return or deletion of information at the end of the relevant service. The closure process explains when these steps take place. Tringify will delete or return information processed on the merchant’s behalf as instructed and required by law, except for information that must lawfully be retained.

Some copies may remain in backups until those backups expire. Any information that must be retained stays protected and is used only for the purpose that requires it. See data retention for more about what happens after deletion.

9. International processing

Tringify’s primary hosting location is India. Our service providers may also process information in other countries. Where applicable law requires a transfer mechanism, the parties must put the required terms and safeguards in place for that transfer. Contact privacy@tringify.com to arrange the appropriate transfer documentation before submitting information subject to such a requirement.

Mandatory transfer clauses, where entered into, take precedence over conflicting terms as specified in those clauses.

10. Contact and other terms

Contact Tringify Ecommerce Private Limited, India, at privacy@tringify.com for questions, requests, subprocessors and transfer documentation. The Store Agreement’s general terms continue to apply to the extent they do not conflict with this addendum or mandatory law.