Featherstall.

Data Processing Addendum

Draft for legal review — last updated 2026-09-29.

This addendum is part of the Terms of Service between you, the merchant, and [owner's legal name], doing business as Featherstall, of [mailing address] ("Featherstall"). It applies whenever Featherstall processes your shoppers' personal data for you. Where it conflicts with the Terms of Service, this addendum wins.

Words such as "controller", "processor", "personal data", "processing" and "personal data breach" mean what they mean in the EU GDPR and the UK GDPR.

1. Roles

2. Details of the processing

3. What Featherstall will do

Featherstall will:

4. What you will do

5. Security measures

6. Sub-processors

You give Featherstall general authorisation to use sub-processors. These are the current ones:

Before we add or replace a sub-processor, we'll email you at least 30 days in advance. You may object on reasonable data protection grounds during that time. If we can't resolve your objection, you may close your store. Each sub-processor is bound by data protection obligations at least as protective as these, and we remain responsible to you for its work.

7. Shopper requests

If a shopper asks Featherstall to exercise their rights, we'll pass the request to you without undue delay, or handle it with you. You can see each order in the builder, and erase a shopper's details from all their orders there. To correct an order record, write to privacy@featherstall.com and we'll do it.

8. Personal data breaches

We'll tell you without undue delay, and in any case within 72 hours of becoming aware of a personal data breach that affects your shopper data. We'll tell you what happened, the kinds and rough number of people and records affected, the likely consequences, and what we're doing about it. We'll send more details as we learn them.

9. Deletion at the end

When your store is closed, it goes offline at once, and 30 days later we delete its shopper data, unless the law requires us to keep it; our backups hold it for up to 10 days more. We keep each order's amounts, currency, dates and our fee, without the shopper's details, for our own accounts. Until then you can reopen the store, see every order in the builder and download them as a spreadsheet, and the same payments are in your Stripe account.

10. Audits

We'll answer your reasonable questions about how we protect shopper data, including security questionnaires. If that isn't enough to show compliance, you may audit us, or have an independent auditor do so. Audits are at your cost, on reasonable notice, under confidentiality, and no more than once a year unless a regulator requires it or there has been a breach.

11. International transfers

The database is in the United States, and web servers run in several regions. Where shopper data is transferred to Featherstall from a country whose law requires a transfer mechanism, these clauses apply:

Accepting the Terms of Service counts as signing these clauses. Each sign-in records which version of the Terms you accepted, and when. If the clauses conflict with this addendum or the Terms of Service, the clauses win.

12. Liability and term

Each party's liability under this addendum is subject to the limits in the Terms of Service, except where data protection law or the clauses above don't allow a limit. This addendum lasts as long as Featherstall processes shopper data for you.

Contact: privacy@featherstall.com.