This Data Processing Agreement ("DPA") forms part of the YourTracking Terms of Service. It applies from the moment a business creates a YourTracking account and lasts as long as we process personal data for that business. "You" means that business. "We" and "us" mean Lodestar Ecommerce LLC, the company that runs YourTracking (named in full in our Privacy Policy).
1. Roles
For the personal data of the visitors and buyers of your connected stores that the Service processes ("shopper data"), you are the controller and we are your processor. How we handle your own account data is in our Privacy Policy.
2. Your instructions
We process shopper data only to provide the Service: to recognise the visit and the ad click on your store, match a sale to the ad that produced it, send it to the advertising platforms you connect, and show it on your dashboard. Your instructions are these Terms, this DPA and the settings you choose in the Service: the stores and platforms you connect, your cookie setting and the values you choose to send. We do not use shopper data for any other purpose, we do not sell it, and we never use one client's data for another. If we believe an instruction breaks data protection law, we tell you. If a law requires us to process shopper data in another way, we tell you first, unless that law forbids it.
3. The data and the people
People: the visitors and buyers of your connected stores. Data: contact details (email address, phone number, name, postal address), order details (order identifier, value, products, time), online identifiers (ad click identifiers, browser and visit identifiers, cookie values), device and connection data (IP address, browser) and each visitor's consent state. You must not send us special categories of personal data.
4. Confidentiality
Everyone on our side who can access shopper data is bound to keep it confidential.
5. Security
We keep the security measures listed in section 10 of our Privacy Policy. These include encryption in transit and at rest; hashing of identifiers before they are sent, wherever the platform accepts hashed data; separation of each client's data; secrets held in a managed secret store; and least-privilege access with an access log.
6. Sub-processors
You authorise the sub-processors listed on our Sub-processors page. We bind each of them to data protection terms at least as protective as this DPA, and we remain responsible for them. We email you at least 14 days before we add or replace one. If you object on reasonable data protection grounds and we cannot resolve it, you may close your account, and you owe nothing for the time after the change takes effect. The platforms and services you connect, such as Google Ads, Meta, Shopify and Klaviyo, are not our sub-processors: data reaches them on your instruction, under your own agreement with them (Terms, section 3).
7. Helping you
We help you answer shoppers who use their data protection rights. We also help with security, breach notifications, impact assessments and consultations with a supervisory authority, as far as our part of the processing allows. A shopper who writes to us is referred to you.
8. Personal data breaches
If a personal data breach affects your shopper data, we tell you without undue delay, and within 48 hours of becoming aware of it, with what we know at that moment. We add the details as we learn them.
9. When processing ends
When a store leaves the Service, we delete its shopper data:
- a store you remove: on the date your store settings show, between 7 and 60 days after the removal;
- a store whose YourTracking app is uninstalled: about 48 hours later, unless it is installed again;
- a closed account: 60 days after its tracking stops, or at once if you choose to delete everything.
Your orders also stay in your own Shopify store. If you want a copy of what we hold before the deletion date, ask us at info@yourtracking.ai before that date. We keep only what the law makes us keep, such as invoices and the order counts behind them. These hold no shopper contact details.
10. Audits
We make available the information you need to check that we meet this DPA, and we answer your reasonable written questions about it. If that is not enough, you, or an independent auditor bound to confidentiality, may audit our compliance once a year, on 30 days' written notice, at your own cost.
11. Transfers outside the EEA, the UK and Switzerland
Shopper data is hosted in the European Union (Google Cloud, Belgium). We are a company based in the United States. Where our access to shopper data, or a sub-processor's, is a transfer out of the EEA, the UK or Switzerland, the EU Standard Contractual Clauses (Commission Decision (EU) 2021/914, module two, controller to processor) apply between you and us, with the UK Addendum for UK data and the Swiss adjustments for Swiss data. They form part of this DPA: their annexes are filled in by sections 1 to 6 of this DPA and our Sub-processors page. For the Clauses only, the law and courts are those of the EU member state where you are established, or Ireland if you are not established in the EU.
12. Order of precedence
If this DPA and the rest of the Terms disagree about shopper data, this DPA applies. The Standard Contractual Clauses apply over both.
13. Changes and liability
We email you before a change to this DPA takes effect, with the date it applies. Liability under this DPA follows section 14 of the Terms, except where the law does not allow a limit.