Data Processing Addendum
Draft for legal review — last updated 2026-09-29.
This addendum is part of the Terms of Service between you, the merchant, and [owner's legal name], doing business as Featherstall, of [mailing address] ("Featherstall"). It applies whenever Featherstall processes your shoppers' personal data for you. Where it conflicts with the Terms of Service, this addendum wins.
Words such as "controller", "processor", "personal data", "processing" and "personal data breach" mean what they mean in the EU GDPR and the UK GDPR.
1. Roles
- You are the controller of your shoppers' personal data ("shopper data"). Featherstall is your processor.
- Featherstall is a separate controller for merchant account data, as its Privacy Policy explains. This addendum doesn't cover that data.
- Payments run on your own Stripe account, under your agreement with Stripe. Stripe's own processing under that agreement is between you and Stripe.
2. Details of the processing
- Data subjects: shoppers who visit your store, fill a cart or complete checkout.
- Personal data: name, email address and shipping address, and a phone number where the order may go abroad; the items, amounts and currency of each order; Stripe's references for the payment; cart contents (store, products and quantities, and the country chosen to ship to), which stay encrypted in the shopper's own browser; and visitors' IP addresses, which are used in memory for rate limits and aren't stored with orders.
- Special categories: none intended.
- Nature and purpose: hosting your store and its cart; sending shoppers to Stripe Checkout on your Stripe account; copying completed checkouts from Stripe into your order records; showing orders to you in the builder; for each paid order, emailing you a notice and emailing the shopper a confirmation in your store's name, with replies going to your contact email; keeping the service secure; and backing up the database.
- Frequency: continuous, for as long as your store exists.
- Retention: until your store is closed, or until you or the shopper ask us to erase the data, subject to section 9.
3. What Featherstall will do
Featherstall will:
- process shopper data only on your documented instructions, unless the law requires otherwise. Your instructions are the Terms of Service, this addendum, and how you set up and use your store. We'll tell you if we think an instruction breaks data protection law.
- make sure everyone authorised to process shopper data is bound by confidentiality.
- keep the security measures in section 5, and use sub-processors only as section 6 allows.
- help you answer shoppers who exercise their rights (section 7).
- help you with security, breach notification, impact assessments and consultation with regulators, taking into account the nature of the processing and the information we have.
- delete shopper data at the end of the service (section 9), and give you what you need to show compliance (section 10).
4. What you will do
- Have a lawful basis for the processing, and give shoppers the information the law requires. Every store's footer links to the Shoppers section of our Privacy Policy, which explains Featherstall's part.
- Make sure your instructions comply with data protection law.
5. Security measures
- All traffic to Featherstall uses HTTPS. Plain HTTP is redirected, and browsers are told to use only HTTPS for a year. Calls from Featherstall to its providers' APIs use HTTPS.
- The cart cookie is encrypted with a server-side key. Session tokens and sign-in links are stored only as hashes.
- Merchants see only the orders of stores they own. The builder checks ownership on every request.
- Card details never reach Featherstall; shoppers enter them on Stripe Checkout.
- Order records are kept in one database in the US, and in its backups. Web servers in other regions hold store catalogs in memory, but not orders.
- Stores run no JavaScript, load nothing from other sites, and send a strict content security policy.
- Checkout and sign-in are rate limited. An hourly job deletes expired sessions and old sign-in links.
- Access to the database is limited to the app and the people who run Featherstall. Keys for providers are kept as secrets on our host or, for the backup, in our code host's encrypted secrets, and limited to what's needed where the provider allows it.
- Our host backs the database up and keeps each backup for 10 days. Each night we also copy it off our host: a read-only database user reads it over an encrypted connection, and the copy is encrypted with a key kept offline before it's stored, for 7 days.
6. Sub-processors
You give Featherstall general authorisation to use sub-processors. These are the current ones:
- Fly.io: hosting, and the Postgres database with its backups. The database is in the US (Fly.io region iad, in Virginia). Web servers run in several regions; today these include the Netherlands and Singapore.
- Stripe: checkout sessions and payment data on your Stripe account, and merchant onboarding. US and global.
- Cloudflare: sending order emails, both your new-order notices and your shoppers' confirmations, which include shopper details; keeping our encrypted copy of the database, which it can't read; and DNS. Global.
- Anthropic: AI drafting for merchants, which receives no shopper data; and the assistant that runs our daily checks and drafts our replies to mail, which reads our error logs (a line can hold a shopper's IP address or an order reference) and shoppers' requests about their data. US.
- Google: our mailbox (Google Workspace), where shoppers' requests about their data arrive. US.
- GitHub: making our nightly copy of the database. It reads the database over an encrypted connection and encrypts the copy before it's stored. US.
Before we add or replace a sub-processor, we'll email you at least 30 days in advance. You may object on reasonable data protection grounds during that time. If we can't resolve your objection, you may close your store. Each sub-processor is bound by data protection obligations at least as protective as these, and we remain responsible to you for its work.
7. Shopper requests
If a shopper asks Featherstall to exercise their rights, we'll pass the request to you without undue delay, or handle it with you. You can see each order in the builder, and erase a shopper's details from all their orders there. To correct an order record, write to privacy@featherstall.com and we'll do it.
8. Personal data breaches
We'll tell you without undue delay, and in any case within 72 hours of becoming aware of a personal data breach that affects your shopper data. We'll tell you what happened, the kinds and rough number of people and records affected, the likely consequences, and what we're doing about it. We'll send more details as we learn them.
9. Deletion at the end
When your store is closed, it goes offline at once, and 30 days later we delete its shopper data, unless the law requires us to keep it; our backups hold it for up to 10 days more. We keep each order's amounts, currency, dates and our fee, without the shopper's details, for our own accounts. Until then you can reopen the store, see every order in the builder and download them as a spreadsheet, and the same payments are in your Stripe account.
10. Audits
We'll answer your reasonable questions about how we protect shopper data, including security questionnaires. If that isn't enough to show compliance, you may audit us, or have an independent auditor do so. Audits are at your cost, on reasonable notice, under confidentiality, and no more than once a year unless a regulator requires it or there has been a breach.
11. International transfers
The database is in the United States, and web servers run in several regions. Where shopper data is transferred to Featherstall from a country whose law requires a transfer mechanism, these clauses apply:
- EU and EEA. The Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914, Module 2 (controller to processor), are incorporated by reference. You are the data exporter and Featherstall is the data importer.
- Clause 7 does not apply.
- Clause 9(a): Option 2 applies, with the notice period in section 6.
- Clause 11(a): the optional wording does not apply.
- Clause 13(a): the supervisory authority is the one this clause determines.
- Clauses 17 and 18: the law and courts of the EU Member State where you are established. If that law doesn't allow third-party beneficiary rights, or you aren't established in the EU, the law and courts of [EU Member State].
- Annex I: the parties are you (contact: the email you sign in with) and Featherstall (contact: privacy@featherstall.com), and the processing is as section 2 describes. Annex II is section 5. Annex III is section 6.
- UK. The International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, issued by the UK Information Commissioner, is incorporated by reference. Tables 1 to 3 are filled in by the details above. For Table 4, either party may end it as its Section 19 allows.
Accepting the Terms of Service counts as signing these clauses. Each sign-in records which version of the Terms you accepted, and when. If the clauses conflict with this addendum or the Terms of Service, the clauses win.
12. Liability and term
Each party's liability under this addendum is subject to the limits in the Terms of Service, except where data protection law or the clauses above don't allow a limit. This addendum lasts as long as Featherstall processes shopper data for you.
Contact: privacy@featherstall.com.