Data Processing Agreement
Last updated: September 5, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between StorePilot ("Processor", "we") and the customer accepting those Terms ("Controller", "you"). It governs our processing of personal data on your behalf under Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and, where applicable, the UK GDPR.
It takes effect when you accept the Terms of Service and remains in force for as long as we process personal data for you. If you require a countersigned copy for your records, write to contact@store-pilot.net.
For processing subject to the California Consumer Privacy Act as amended by the CPRA, see the US Privacy Notice, which sets out our status as a Service Provider and the restrictions that come with it. Those terms are part of this DPA.
1. Roles
| Role | Party | Meaning |
|---|---|---|
| Controller | You | You decide what the Plugin or loader script collects on your website, why, and on what lawful basis. |
| Processor | StorePilot | We process that data only to provide the Service, and only on your instructions. |
| Data subjects | Your website's visitors | And, separately, your own team members who hold dashboard accounts. |
Where we process personal data about your team members — the name, email address and password of a dashboard account — we act as Controller for that limited purpose, and the Privacy Policy governs it. This DPA covers visitor data only.
2. Subject matter, duration, nature and purpose
Subject matter. Provision of error monitoring, session replay, product analytics, heatmaps, lead capture and uptime monitoring for the websites you connect to the Platform.
Duration. For as long as your account is active, plus the retention periods in §7 and any period required by law.
Nature and purpose. Collection, storage, structuring, aggregation, display and erasure of data generated by visitors to your website, for the sole purpose of providing the Service to you. We do not use it to develop or improve our own products, to train models, or for any purpose of our own.
Categories of data subjects. Visitors to your website, including customers, prospective customers and, where you have logged-in areas, your registered users.
Categories of personal data. As enumerated in the Privacy Policy §2.3: online identifiers, IP address, device and browser characteristics, pages viewed, interaction events, session recordings, error diagnostics, survey answers — where you run on-site surveys — chat transcripts, where you connect a chat provider — and, where you enable lead capture, contact details and submitted form fields. Street addresses and postcodes are refused at collection and are never held.
Chat transcripts, inbound only. Where you connect Brevo Conversations, that provider sends the chats from your site TO the Platform on your own configuration. It is YOUR processor, not our sub-processor: we hold no credential for it, we make no request to it, and the Platform never sends anything to it. Where you have embedded that provider's widget on your site, the collector hands the widget two pseudonymous identifiers of ours (the browser and the visit) inside the visitor's own browser, so that a transcript can be matched to the visit it began in; that is the visitor's browser speaking to your processor, on your site, only where tracking is allowed, and it carries nothing else. What we do with what arrives is what this Agreement says about every other category — store it under your instructions, return it on an access request, delete it on an erasure request, and sweep it on your lead retention window.
Cart-recovery messages. Where you enable a cart-recovery sequence, the Platform plans the messages — which lead, which step, at what moment, and whether anything has silenced it — and delivers each planned step to the Client's own automation channel (for example an n8n webhook you configure) and/or to the Client's own email service provider, using an API key the Client supplies (Klaviyo today). What is delivered is an event describing the cart — contact details, the basket and its totals; it carries no identifier we do not already hold for the Client, and never the visitor id, the stored IP address or raw form fields. The message itself is composed and sent through the Client's own sending identity: the Client is the sender and remains the Controller of that communication, and the Platform never emails your customers on your behalf. Such a provider is the Client's processor, chosen and instructed by the Client, and is not a sub-processor of ours under §4.
Special categories. We do not intentionally process special-category data under Article 9. It can nevertheless enter the Service through content you render on your own pages or fields your own forms collect. Use Settings → Privacy → Excluded URLs on any page where that is a possibility; it is your obligation as Controller to identify those pages.
3. Our obligations as Processor (Article 28(3))
(a) Documented instructions. We process personal data only on your documented instructions, which comprise this DPA, the Terms of Service, and your configuration of the Service. If we are required by Union or Member State law to process it otherwise, we will inform you before doing so unless that law forbids the notification.
(b) Confidentiality. Everyone we authorise to process personal data is bound by a duty of confidentiality.
(c) Security. We implement the technical and organisational measures set out in §6.
(d) Sub-processors. As set out in §4.
(e) Assistance with data subject rights. The Service provides the tools described in §8. To the extent a request cannot be answered with them, we will assist you on request.
(f) Assistance with Articles 32–36. We assist you with security, breach notification, data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to us.
(g) Deletion or return. On termination, at your choice, we delete or return all personal data. Absent an instruction, we delete it within 30 days of account closure, except where storage is required by law. Backups age out on the schedule in §7.
(h) Information and audits. We make available all information necessary to demonstrate compliance with this Article, and we submit to audits — see §5.
4. Sub-processors
By default, no third party receives your visitors' personal data. The Platform runs on infrastructure we control, in the European Union; there is no third-party analytics, no advertising network, no error-reporting SDK, no CDN in front of the dashboard, and no external object storage engaged by us.
Your own object storage, if you ask for it. If you ask us in writing, we will configure your site so that its session recordings are written to object storage in a cloud account you own and pay for. That is your infrastructure and your choice: it is your processor rather than our sub-processor, on the same footing as the chat provider and the notification channels you connect. We hold the access credentials you give us for the sole purpose of writing and deleting your own recordings there, we use them for no other customer, and we never do this on our own initiative. Deletion — retention and erasure alike — runs against that storage exactly as it runs against ours — and we will refuse a bucket whose own settings would defeat it. Concretely, we do not accept storage with object-lock retention or object versioning switched on, because on such a bucket a delete leaves the recording retrievable and we would be reporting an erasure we had not performed.
You give general written authorisation for us to engage sub-processors. The current list, with each one's role and location, is available on request — write to contact@store-pilot.net — and is named in the countersigned copy of this DPA.
- We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.
- We will give you at least 30 days' notice before adding or replacing a sub-processor, by email to your account address.
- If you reasonably object on data protection grounds within that period, we will work with you to find an alternative. If none is available, you may terminate the affected part of the Service without penalty and receive a pro-rata refund.
Note that several integrations — your SMTP server, Slack, Telegram, an n8n webhook — are chosen and configured by you, not by us. Where you enable one, the recipient is your sub-processor rather than ours, and it belongs in your own record of processing.
The digest's model provider is ours. The prose of the daily and weekly digest, and the summary of a recorded visit, is written by a large language model operated by Anthropic, PBC (United States) — a sub-processor of ours, named in the countersigned list. Anthropic writes the daily and weekly digest's narrative from a statistics sheet the Platform assembles first: counts, revenue totals, page paths, error messages, uptime results and survey scores (never the free text a visitor typed) — and, for session recordings scored as high interest, a per-visit sheet about a single recorded session: pages visited, click and scroll counts, error messages and checkout totals — and, for chats received from your chat provider, a per-conversation sheet: the exchange itself, with email addresses, telephone numbers, card numbers and credentials masked, together with the page it began on and the first name of your own agent — and, for enquiries somebody sent through a form on your site, what they wrote: the message itself, shortened, with email addresses, telephone numbers and card numbers masked, beside the name of the form, the page it was sent from, how long it has been waiting, and whether there is an email or a telephone number to answer on. The address and the telephone number themselves never travel; nor does anything a visitor entered in a field we refuse at collection. The visitor's name, where we hold one, is masked by value; a name a visitor types inside a sentence is not something any pattern can find, which is why this says masked rather than anonymous. Every sheet contains no visitor identifiers, no session identifiers and no contact fields; error messages, page paths and chat transcripts are redacted before they are sent, and a survey answer a visitor typed is counted and never quoted. Every figure you read in a digest is computed by the Platform before the model is called; the model writes sentences about numbers it did not produce.
Separately, and only where you connect one, an AI client of your own — for example Claude, through the Model Context Protocol — reads, on your instruction and under your account's permissions: aggregate statistics, analytics, issues, uptime results, product performance and derived insights; checkout and order records including basket contents, totals, status and dates; the names, email addresses and telephone numbers on those records; chat transcripts; survey answers, including the free text a visitor typed; and a description of a recorded visit — its pages, duration, device, error count and the narrative summary written about it — together with the pseudonymous visitor and session identifiers that link those records to one another. The raw contents of a form ride only where the person who connected the client holds the admin role, exactly as they do in the dashboard's own export.
It never receives a postal address or a postcode. Those are refused at collection: the platform writes a marker in their place rather than the value, so in ordinary operation there is nothing stored for anyone to disclose, and the projection this client reads through refuses them a second time regardless. It never receives an IP address, not even the truncated form we keep. It never receives session-recording footage: a recorded visit is described and linked, never handed over. Access is read-only and is limited to the sites you name when you connect it, re-checked against your live team membership on every request; you can disconnect it at any time from your profile. The provider of that client is your sub-processor rather than ours, and it belongs in your own record of processing.
5. Audits
On reasonable notice and no more than once in any twelve-month period (unless a supervisory authority requires otherwise, or following a personal data breach), we will:
- answer a written security questionnaire; and
- make available our documentation of the measures in §6.
Where that does not satisfy a legal obligation you can identify, we will discuss a proportionate on-site or third-party audit at your cost, conducted under confidentiality and without access to other customers' data.
6. Security measures (Article 32)
| Measure | What is in place |
|---|---|
| Encryption in transit | TLS 1.2 or above on every endpoint; certificates issued and renewed automatically. |
| Encryption of secrets at rest | Notification credentials and integration secrets are encrypted with AES-256-GCM and are never returned by the API once saved. |
| Access control | Per-site API keys, rotatable at any time. Dashboard access behind JWTs with a 15-minute expiry and rotating refresh tokens. Passwords hashed with bcrypt (cost 12). |
| Role separation | Four organisation roles. Destructive and bulk-export operations require elevated roles; erasure requires an administrator. |
| Network isolation | The database and cache are reachable only from the application container. Only the reverse proxy publishes a port. |
| Data minimisation in code | IP truncation, URL scrubbing, credential-field filtering and error-context redaction are applied at ingest, before storage. |
| Segregation | Every record carries a site identifier and every query is scoped to it. |
| Logging | Structured request logging with authorisation headers and API keys redacted. Request bodies are never logged. |
| Resilience | Nightly backups, retained on the schedule in §7. |
Stated honestly: we hold no ISO 27001 or SOC 2 certification, and no third-party penetration test has been carried out. Two-factor authentication is available on dashboard accounts and is optional: anybody may turn it on from their profile, and our own staff accounts cannot sign in without it. We do not maintain an access audit log recording which of your team members viewed or exported personal data. If any of these is a requirement for you, tell us before you rely on the Service; we would rather lose the deal than imply a control we do not have.
7. Retention
Retention periods for each category are published in the Privacy Policy §4 and enforced by an automated nightly job. Backups are retained for 30 days and then overwritten; data deleted from the live system therefore disappears from backups within that window.
8. Data subject rights
The Service provides:
- Access and portability — a visitor's complete record is visible on their detail page in
the dashboard, and the "Export data" button beside the erasure one (or
GET /api/v1/sites/{siteId}/visitors/{visitorId}/export.json) produces a single machine-readable JSON file of everything held about that browser, suitable for an Article 15 or Article 20 answer. Two limits are stated inside the file itself: recording footage is described rather than embedded, and error entries are reduced to the individual's own part of the fault, because the full record is an aggregate over every visitor who hit it. - Erasure —
DELETE /api/v1/sites/{siteId}/visitors/{visitorId}/dataremoves pageviews, recordings, leads, interaction events, session facts and the visitor record, deletes the associated recording files and heatmap images, and strips identity fields from the error records that are kept as aggregates. It is irreversible, and it erases one browser; where the same person has been seen in more than one, the detail page lists the siblings. - Rectification — lead records are editable in the dashboard.
- Restriction and objection — a visitor's Global Privacy Control signal stops collection immediately and without configuration (Do Not Track is not honoured — see the Privacy Policy); Settings → Privacy → Excluded URLs stops it for a page, and the consent gate stops it for everyone who has not agreed.
If a data subject contacts us directly, we will not respond substantively. We will refer them to you as Controller and notify you without undue delay.
9. Personal data breach
We notify you without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting your data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed.
Notifying your supervisory authority under Article 33, and affected individuals under Article 34, remains your responsibility as Controller. We will provide the information you need to do it. The same notification serves any duty we owe you under US state breach-notification statutes — for example Cal. Civ. Code §1798.82(b), which requires whoever maintains data to notify its owner following discovery — and will include what those statutes require you to pass on.
10. International transfers
The Platform operates from servers in the European Union. See Where Your Data Is Processed.
If a future sub-processor were located outside the EEA, we would put an appropriate Chapter V transfer mechanism in place — Standard Contractual Clauses or an adequacy decision — before any transfer, and say so in the §4 notice and in the sub-processor list we provide.
Where you ask us to write your recordings to object storage in your own cloud account (§4), you choose that storage and its region. If you choose a region outside the EEA, that is a transfer you are making as Controller to your own processor, and the Chapter V mechanism for it is yours to hold; we tell you plainly which address we have been given and we write only where you told us to.
11. Liability and term
Liability under this DPA is subject to the limitations in the Terms of Service. This DPA terminates automatically when the Terms terminate, save for provisions which by their nature survive — confidentiality, deletion and audit among them.
12. Changes
We will notify you by email at least 30 days before any change to this DPA that materially reduces your rights or our obligations. Continued use of the Service after that period constitutes acceptance. The date at the top of this page is the date of the last change.
Contact: contact@store-pilot.net