Data processing agreement

Version 2026-09-18, in force since 18 September 2026

This agreement under Art. 28 of the General Data Protection Regulation (GDPR) forms part of the terms of service. It applies whenever Stockwyn processes personal data on behalf of a merchant who uses the app, and it is accepted together with the terms.

1. Parties and roles

  • Controller: the merchant who installs the Stockwyn app in their Shopify store.
  • Processor: Marco Lange, c/o Block Services, Stuttgarter Str. 106, 70736 Fellbach, Germany, operating Stockwyn ("Stockwyn"). Contact: hello@stockwyn.com.

2. Instructions

Stockwyn processes personal data only on the merchant's documented instructions. Installing the app, connecting a marketplace account and switching features on in the app are those instructions; further instructions can be given in writing by email. If Stockwyn believes that an instruction infringes data protection law, it tells the merchant.

3. Subject matter, nature and purpose

Stockwyn keeps the quantities of linked marketplace listings in step with the merchant's Shopify stock and, if the merchant switches order import on, creates marketplace orders in the merchant's Shopify store and reports their shipments back to the marketplace. Personal data is processed only as far as this requires: a buyer's name, shipping address and phone number are read from the marketplace order and written into the Shopify order.

4. Duration

For as long as the app is installed in the merchant's store. Deletion after the end follows section 10.

5. Types of personal data and data subjects

  • Buyers of the merchant: name, shipping address and phone number of a marketplace order. Stockwyn passes them from the marketplace into the Shopify order and does not store them in its own database. It stores only the fact that a handover happened (time, order ID, which fields, no values) for 365 days.
  • The merchant and their staff: shop domain, Shopify access token, app settings, admin language.
  • The merchant's marketplace account: marketplace user ID and access tokens (encrypted), IDs, SKUs and titles of linked listings.
  • The merchant's orders: marketplace order ID, Shopify order ID, import status, sale and change dates, sold units per listing and the IDs of reported shipments, without buyer data.

Stockwyn does not ask Shopify for buyers' email addresses and never contacts buyers.

6. Confidentiality

Stockwyn is operated by one person, who is bound to confidentiality. Anyone who is given access to personal data in the future will be bound to confidentiality in writing before they get access.

7. Security of processing

  • Shopify and marketplace access tokens are stored encrypted (AES-256-GCM). The key is kept only in the server's environment, and the app does not start without it.
  • All connections use HTTPS. Notifications from Shopify are rejected without a valid signature.
  • Buyer data is not stored in Stockwyn's database, so it cannot leak from it.
  • The database is backed up daily in encrypted form; the last seven backups are kept.
  • Every handover of buyer data to Shopify is logged, without the data itself.
  • Access to the production system is limited to the operator and protected by two-factor authentication where the providers offer it.
  • Stockwyn keeps a written plan for security incidents.

The backups are kept with the same hosting provider as the database.

8. Sub-processors

The merchant agrees that Stockwyn uses Railway Corporation (USA) to host the app and its database. Stockwyn tells merchants by email before another sub-processor starts, so that they can object; if a merchant objects, both sides can end the contract.

Shopify and the marketplaces the merchant connects (such as eBay) are not sub-processors of Stockwyn. Stockwyn exchanges data with them on the merchant's instruction; the merchant's own terms with them apply.

9. Transfers outside the EU

The app and its database run in the United States. The transfer is based on the EU standard contractual clauses (and, for the UK, the UK addendum) in Railway's data processing addendum.

10. Deletion and return

  • When the merchant uninstalls the app, the Shopify access token is deleted right away.
  • When Shopify sends its shop deletion request, usually 48 hours after uninstalling, all data of that shop is deleted.
  • When the merchant disconnects a marketplace account or connects a different one, the access credentials of the previous connection and the links to its listings are deleted right away.
  • When eBay reports that an eBay account was closed, its access credentials and the links to its listings are deleted.
  • Deleted data can remain in an encrypted backup for up to seven days.
  • The merchant can ask by email for earlier deletion or for a copy of the data Stockwyn holds about their shop.

11. Assistance

  • Requests from data subjects: because buyer data is not stored, Stockwyn holds no data to answer a buyer's request from. Stockwyn answers Shopify's data requests and deletion requests for customers accordingly and supports the merchant with the information it has.
  • Personal data breaches: Stockwyn tells the merchant without undue delay, and aims to do so within 24 hours, after becoming aware of a breach that affects the merchant's data, with the information the merchant needs for its own notifications.
  • Security and impact assessments: Stockwyn provides the information it has about its processing when the merchant needs it for a data protection impact assessment or a consultation with a supervisory authority.

12. Information and audits

On request, Stockwyn provides the information needed to show that it meets this agreement, in writing within 14 days. Stockwyn is a one-person business and does not offer on-site audits; written questions are answered instead.

13. Liability and precedence

Liability follows the terms of service. Where the terms of service and this agreement differ about the processing of personal data, this agreement applies.