PayWhirl
Home Features Pricing Book A Demo Integrations Partners Support
Login Try it free
PayWhirl
Home Features Pricing Book A Demo Integrations Partners Support
Try it free Login

Data Protection Addendum

Last updated: August 17, 2026
Effective: September 17, 2026

This Data Protection Addendum (“DPA”) forms part of the agreement (“Agreement”) between PayWhirl, Inc., a California corporation located at 9452 Telephone Road #140, Ventura, California 93004 (“PayWhirl”), and the Merchant identified in the Agreement (“Merchant”).

This DPA applies when PayWhirl processes Customer Personal Data for Merchant through PayWhirl's Multi-Platform or Shopify application. Capitalized terms not defined here have the meanings in the Agreement or Applicable Data Protection Law.

1. Definitions

“Applicable Data Protection Law” means a privacy or data-protection law applicable to a party's processing under the Agreement, including, where applicable, the EU GDPR, UK GDPR and Data Protection Act 2018 as amended, Swiss Federal Act on Data Protection, California Consumer Privacy Act (“CCPA”), and other applicable U.S. state privacy laws.

“Controller” includes a “business” or similar entity that determines the purposes and means of processing.

“Customer Personal Data” means Personal Data contained in Customer Data that PayWhirl processes for Merchant to provide the Service. It excludes information PayWhirl processes independently as a Controller, as described in its Privacy Policy.

“Data Subject” means a person to whom Personal Data relates.

“EU SCCs” means the standard contractual clauses in European Commission Implementing Decision (EU) 2021/914, as amended or replaced.

“Personal Data” includes personal data, personal information, and similar regulated information.

“Personal Data Breach” means a breach of security resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.

“Process” and related terms have the meanings under Applicable Data Protection Law.

“Processor” includes a service provider or contractor that processes Personal Data for a Controller.

“Subprocessor” means a Processor PayWhirl engages to process Customer Personal Data.

“UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner's Office, as amended or replaced.

2. Roles and scope

Merchant is the Controller and PayWhirl is the Processor of Customer Personal Data. If Merchant is itself a Processor for another Controller, PayWhirl acts as Merchant's Subprocessor and Merchant represents that it has authority to appoint PayWhirl.

Each party will comply with Applicable Data Protection Law applicable to its own processing. Annex A describes the processing covered by this DPA.

PayWhirl may process Merchant account, billing, relationship, usage, and security information independently for the purposes described in its Privacy Policy. This does not permit PayWhirl to recategorize Customer Personal Data to avoid this DPA.

3. Instructions and restrictions

PayWhirl will process Customer Personal Data only:

  • to provide, secure, support, and maintain the Service;
  • through Merchant's configuration and use of the Service, APIs, MCP connections, integrations, and support channels;
  • under other documented instructions agreed by the parties; or
  • as required by law, after informing Merchant where legally permitted.

PayWhirl will inform Merchant if it reasonably believes an instruction violates Applicable Data Protection Law and may suspend the affected processing while the parties resolve the issue.

PayWhirl will not:

  • sell Customer Personal Data or share it for cross-context behavioral advertising;
  • retain, use, or disclose it outside the direct business relationship or for an unrelated commercial purpose;
  • combine it with data from another source except as legally permitted to provide the Service;
  • use it for unrelated advertising or profiling; or
  • attempt to reidentify lawfully deidentified data except as permitted by law.

Where required by U.S. state law, PayWhirl certifies that it understands and will comply with these restrictions and will notify Merchant if it can no longer meet them. Merchant may take reasonable steps to stop and remediate unauthorized processing.

4. Merchant responsibilities

Merchant will provide lawful instructions, required notices, and a valid legal basis; obtain required consent; respond to Data Subject requests; use available security and deletion controls; and ensure Customer Personal Data is appropriate and limited to the Service.

Merchant is responsible for services it selects or authorizes, including Payment Providers, applications, LLMs, AI agents, and MCP clients. Enabling a Merchant-selected service is Merchant's instruction for PayWhirl to disclose Customer Personal Data and process authenticated requests within the permissions granted.

A Merchant-selected AI service is not a PayWhirl Subprocessor merely because it connects to a PayWhirl API or MCP connection. Merchant is responsible for that service's terms, privacy and security, lawful use, actions, and revocation. If PayWhirl selects an AI provider for PayWhirl's service chain, the Subprocessor terms below apply.

5. Confidentiality and security

PayWhirl will ensure that personnel authorized to process Customer Personal Data are subject to confidentiality obligations and receive appropriate privacy and security training. Access will be limited according to role and business need.

Taking into account the processing, risk, state of the art, and implementation cost, PayWhirl will maintain the technical and organizational measures in Annex B designed to protect Customer Personal Data against unauthorized or unlawful processing and accidental loss, destruction, or damage.

PayWhirl may update those measures as technology and risk change, provided it does not materially reduce the overall level of protection during the Agreement.

Merchant is responsible for securely configuring and using the Service, managing users and permissions, protecting credentials and Merchant systems, reviewing integrations and AI agents, and notifying PayWhirl of suspected unauthorized activity.

6. Personal Data Breaches

PayWhirl will notify Merchant without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. Notification may be delivered to Merchant's account security contact and may be provided in phases.

To the extent reasonably available, PayWhirl will describe the incident, affected data and people, likely consequences, response and mitigation, and a contact for follow-up. PayWhirl will take reasonable steps to contain, investigate, mitigate, and remediate the breach and will reasonably assist Merchant with legally required notifications.

Merchant is responsible for notices to its Data Subjects, regulators, customers, and other parties, except for notices PayWhirl must make regarding its own Controller processing.

7. Data Subject requests and compliance assistance

If PayWhirl receives a request concerning Customer Personal Data, it will direct the requester to Merchant or notify Merchant where permitted. PayWhirl will respond independently only on Merchant's instruction or as required by law.

Taking into account the nature of processing and available Service functionality, PayWhirl will reasonably assist Merchant with access, correction, deletion, portability, restriction, objection, opt-out, appeal, and applicable automated-decision requests; breach and security obligations; data-protection assessments and regulator consultation; and information needed to demonstrate compliance.

Merchant should first use available self-service functions. Reasonable fees may apply to extraordinary assistance outside standard functionality where allowed by law and agreed in advance.

8. Subprocessors

Merchant generally authorizes the Subprocessors listed in Annex C. PayWhirl will:

  • enter into written terms requiring each Subprocessor to protect Customer Personal Data consistently with this DPA;
  • remain responsible for Subprocessor performance as required by law; and
  • provide at least 14 days' advance notice of a new or replacement Subprocessor by posting an updated list or using another reasonable notice method, except for an urgent security or legal change.

Merchant may object during the notice period on reasonable data-protection grounds. The parties will work in good faith to resolve the objection. If no reasonable solution is available, PayWhirl may modify or discontinue the affected feature, charge reasonable additional fees for a material accommodation requested by Merchant, or terminate the affected Service.

9. Return, deletion, and retention

Merchant may access and export Customer Personal Data using available Service functions during the Agreement and, subject to the Terms, for up to 30 days after termination.

Upon termination or Merchant's lawful instruction, PayWhirl will return, delete, or deidentify Customer Personal Data unless law requires retention. Deidentification satisfies the deletion obligation only if the resulting information is no longer Personal Data under Applicable Data Protection Law.

Customer Personal Data in backups will be protected from ordinary use and deleted through the normal backup-expiry cycle. PayWhirl may retain limited information for legal obligations, fraud and security records, disputes, and legal holds, subject to continued protection and no unrelated use.

Information held by Merchant's connected Payment Provider or another Merchant-selected service is outside PayWhirl's deletion process. PayWhirl also processes applicable Shopify privacy-compliance requests, unless retention is legally required.

10. Audits

On reasonable written request, PayWhirl will provide information reasonably necessary to demonstrate compliance, which may include audit reports, certifications, security summaries, or questionnaires, subject to confidentiality and security restrictions.

If that information does not resolve a material compliance concern, Merchant may request a proportionate audit by a qualified independent auditor. Unless a regulator requires otherwise, an audit may occur no more than once annually, on at least 30 days' notice, during normal business hours, without unreasonable disruption or access to other customers' data, privileged material, or sensitive security information. Merchant bears its costs unless the audit identifies a material PayWhirl breach.

11. International transfers

Customer Personal Data may be processed in the United States and other countries where PayWhirl and its Subprocessors operate. PayWhirl will use an appropriate safeguard for a transfer that requires one.

For a transfer subject to EU GDPR:

  • EU SCC Module Two applies where Merchant is a Controller and PayWhirl is a Processor;
  • Module Three applies where Merchant is a Processor and PayWhirl is a Subprocessor;
  • Clause 7 applies; Clause 9(a) Option 2 applies with the notice period in Section 8; optional Clause 11 does not apply;
  • Irish law governs under Clause 17 and Irish courts apply under Clause 18;
  • Annexes A and B of this DPA complete Annexes I and II of the EU SCCs; and
  • the Subprocessor List completes Annex III.

For UK transfers, the EU SCCs as completed above are supplemented by the UK Addendum. For Swiss transfers, the EU SCCs apply with changes required by the Swiss Federal Act on Data Protection. Mandatory transfer terms control over conflicting Agreement terms.

Unless prohibited by law, PayWhirl will notify Merchant of a binding government request for Customer Personal Data, review the request, reasonably challenge unlawful or disproportionate demands, and disclose only what is legally required.

12. Liability, term, and general terms

The Agreement's liability provisions apply to this DPA, except where limitation is prohibited by law or mandatory transfer terms.

This DPA begins when PayWhirl first processes Customer Personal Data and continues while it retains that data. If this DPA conflicts with the Agreement regarding Customer Personal Data, this DPA controls; mandatory transfer terms control where required.

PayWhirl may update this DPA on at least 30 days' notice of a material change. An update will not materially reduce Customer Personal Data protection during a committed term unless required by law. Subprocessor changes follow Section 8.

Annex A — Processing details

Parties

Data exporter: Merchant identified in the Agreement; Controller or Processor as applicable.
Data importer: PayWhirl, Inc., 9452 Telephone Road #140, Ventura, California 93004, USA; Processor or Subprocessor as applicable.
Privacy and security contact: team@paywhirl.com.

Acceptance of the Agreement and DPA constitutes execution of the applicable transfer terms.

Data Subjects

  • Subscribers and prospective Subscribers;
  • Merchant account users, personnel, contractors, and contacts; and
  • other people whose Personal Data Merchant submits to the Service.

Data categories

  • identifiers and contact, billing, and shipping information;
  • account, authentication, role, and preference information;
  • subscription, order, product, pricing, discount, tax, fulfillment, cancellation, and consent records;
  • Payment Provider and token identifiers, payment type, last four digits, expiration information where available, transaction amounts and status, declines, refunds, disputes, and chargebacks, but not full bank-account or routing numbers;
  • communications, support content, custom fields, and Merchant-provided content;
  • device, IP address, activity, security, diagnostic, and log information; and
  • other data Merchant configures the Service or an integration to process.

The Service is not intended for special-category, criminal-conviction, protected-health, biometric-identification, government-ID, authentication-secret, full-card-credential, or specially regulated children's data unless expressly approved in writing.

Processing

Subject matter and purpose: providing subscription, recurring-billing, order, payment-connection, communication, support, reporting, security, API, MCP, and related functions selected by Merchant.

Nature and frequency: collection, recording, organization, storage, retrieval, consultation, configuration, authorized transmission, authenticated API/MCP access, support, security, export, restriction, and deletion, continuously or as initiated by Merchant.

Duration: the Agreement term plus the return/deletion period in Section 9.

Competent authority: determined under EU SCC Clause 13 based on the data exporter's establishment, representative, or affected Data Subjects.

Annex B — Technical and organizational measures

PayWhirl maintains measures appropriate to the Service and risk, including:

  • written security responsibilities, policies, risk review, and personnel training;
  • unique identities, role-based and least-privilege access, required multi-factor authentication for PayWhirl personnel, optional multi-factor authentication for Service users, access review, and prompt offboarding;
  • encryption of Customer Personal Data in transit and encryption at rest for production databases and backups containing Customer Personal Data;
  • controlled secrets, keys, credentials, and production/support access;
  • logical customer separation and separation of production and nonproduction environments;
  • software-development, testing, change-management, and vulnerability-management controls;
  • logging and monitoring of important security events, a documented incident-response process, backups, restoration, and continuity procedures;
  • provider diligence, written protection obligations, monitoring, and secure offboarding;
  • retention, deletion, legal-hold, and rights-request procedures; and
  • MCP authorization, tenant and permission enforcement, token protection, request/action validation, logging, revocation, rate limits, and safeguards appropriate to the actions made available.

For Multi-Platform, Payment Provider-hosted fields/components and tokenization are designed to transmit full card credentials directly from the Subscriber's browser to PCI DSS-validated providers. Shopify controls checkout for the Shopify application. PayWhirl does not receive full bank-account or routing numbers, does not store card verification codes, and maintains PCI-related controls appropriate to its role and system scope.

Annex C — Subprocessors

PayWhirl may use the following Subprocessors to provide and support the Service. A provider processes Customer Personal Data only to the extent relevant to the services it provides to PayWhirl.

Provider Service provided
Amazon Web Services Cloud hosting, storage, backups, and infrastructure
Cloudflare Security, traffic delivery, performance, and availability
Intercom Customer support and communications
Metabase Reporting and business analytics
Rollbar Application error monitoring
Papertrail / SolarWinds Log management and monitoring
Memetria / Stovepipe Studios Database and technical services
Mailgun Transactional email delivery
Fireflies.ai Meeting recording, transcription, and notes
Slack Internal collaboration and support operations
Notion Documentation, collaboration, and knowledge management
Atlassian / Trello Work management and support operations
Spreedly Payment connectivity, secure fields, and tokenization
OpenAI Artificial-intelligence software services
Anthropic Artificial-intelligence software services
Anysphere / Cursor Artificial-intelligence software-development services

Mailchimp, Google Analytics, Meta, and similar marketing or website-analytics providers may process Personal Data for PayWhirl's own Controller purposes but are not listed here unless they process Customer Personal Data on PayWhirl's behalf. Merchant-selected Payment Providers, commerce platforms, applications, and AI services are not PayWhirl Subprocessors merely because they connect to the Service.

PayWhirl

Recurring payments, subscription billing, customer portals, invoices, integrations, and support from PayWhirl.

team@paywhirl.com

PayWhirl

  • Features
  • Pricing
  • Book A Demo
  • Integrations
  • Partners

Apps

  • Shopify App
  • BigCommerce App
  • Glow Loyalty
  • Upsell Wizard

Resources

  • Case Studies
  • Support portal
  • PayWhirl status
  • API Docs

Use cases

  • Subscription Boxes
  • Coffee & Tea
  • Food & Pantry
  • Beauty & Personal Care
  • Health & Wellness
  • Pet Subscriptions
  • Fashion & Apparel
  • Home & Cleaning
  • Books & Print
  • Courses & Coaching

Company

  • Terms of Use
  • Privacy Policy
  • Data Protection
  • YouTube
  • LinkedIn
Copyright © 2026 PayWhirl Inc. Terms of Use • Privacy Policy • Data Protection • Cookie Preferences