Legal
How Storenode processes personal data on your behalf — the roles, safeguards, and commitments that apply when you use the Service to process data subject to data-protection law.
This Data Processing Addendum ("DPA") forms part of the agreement between you ("Customer") and Storenode ("Storenode"), and governs Storenode's processing of Personal Data on the Customer's behalf in connection with the Service. It applies to the extent that the processing of Personal Data is subject to the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), or other applicable data-protection laws. Capitalized terms not defined here have the meaning given in our Terms of Service and Privacy Policy.
For Personal Data processed in connection with the Service, the Customer is the data controller(or, where the Customer is itself a processor, the controller's processor) and Storenode is the data processor(or sub-processor). Storenode processes Personal Data only on the Customer's documented instructions, including those reflected in the Terms of Service and in the Customer's use of the Service, except where required by law.
Storenode processes Personal Data for the purpose of providing the Service: turning supplier product URLs and uploaded files into publish-ready Shopify product drafts using AI — performing keyword research, writing product copy, generating infographics and images, applying SEO, and writing drafts to the Customer's connected Shopify store. Processing continues for the duration of the agreement and as otherwise described in the Terms of Service.
Categories of Personal Data processed may include:
Categories of data subjects may include:
The Service is designed for business product content and is not intended for the processing of special categories of Personal Data; the Customer should not submit such data.
The Customer authorizes Storenode to engage the following sub-processors to process Personal Data in connection with the Service. Each receives only the data necessary for its function:
| Function | Purpose |
|---|---|
| Cloud hosting & file storage | Website/application hosting and uploaded-file storage |
| Database | Managed database (account, usage, job data) |
| Authentication | Authentication and account management |
| Payments | Payments and billing |
| AI / LLM providers | AI processing of product content and image generation |
| Keyword research | Keyword research data |
| Supplier-page fetching | Fetching the supplier product pages the Customer submits |
| Shopify store | The Customer's connected store, where drafts are written via the Shopify Admin API |
Storenode imposes data-protection obligations on its sub-processors that are no less protective than those in this DPA and remains responsible for their performance. We will provide notice of new sub-processors and update the list above; the Customer may object on reasonable data-protection grounds by contacting us.
Storenode implements appropriate technical and organizational measures to protect Personal Data, including:
Payment data is handled by a PCI-compliant third-party payment processor; Storenode does not store full payment card numbers. See our Security page for more detail.
Storenode and its sub-processors may process Personal Data in countries other than the Customer's, including the United States. Where such transfers are subject to data-protection law, the parties rely on an appropriate transfer mechanism — such as the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable) — to safeguard the data.
Taking into account the nature of the processing, Storenode will provide reasonable assistance to the Customer in responding to requests from data subjects to exercise their rights (such as access, correction, deletion, restriction, objection, and portability). If Storenode receives such a request directly, it will, where permitted by law, refer the data subject to the Customer. The Customer can also use the Service's functionality and contact us at support@storenode.ai for assistance.
Storenode will notify the Customer without undue delay after becoming aware of a Personal Data breach affecting the Customer's Personal Data, and will provide information reasonably available to it to help the Customer meet its own notification obligations. Storenode will take reasonable steps to mitigate and remediate the breach.
On termination or expiry of the agreement, and at the Customer's choice, Storenode will delete or return the Customer's Personal Data, and delete existing copies, within a reasonable period, except to the extent retention is required by applicable law. The Customer may also request deletion of content during the term as described in our Privacy Policy.
Storenode will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and will, on reasonable prior written request and subject to confidentiality, allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor it mandates — no more than once per year except as required by a supervisory authority or following a breach, and conducted so as to minimize disruption to the Service.
This DPA takes effect for as long as Storenode processes Personal Data on the Customer's behalf and remains in force for the duration of the agreement. It supplements, and does not replace, the Terms of Service.
For questions about this DPA or to make a data-processing request, contact us at support@storenode.ai. Storenode is the processor under this DPA.