1. Parties, incorporation, and definitions
This Data Processing Addendum (DPA) forms part of the agreement governing a Merchant's use of StoresOmni LLC's Services (Agreement) where StoresOmni processes Merchant Customer Data on that Merchant's behalf. It is effective with the applicable Agreement and does not require a separate signature unless the parties agree otherwise. Merchant identity and contact details are those supplied for its account or order form. StoresOmni's identity, address, and contacts appear below.
Customer Data means Personal Data relating to Merchant customers, visitors, contacts, or other end users that StoresOmni processes for the Merchant to provide its configured Services, also called Merchant Customer Data in the Privacy Policy. Personal Data, processing, controller, processor, personal data breach, service provider, and business have the meanings given by applicable data protection law. Applicable Data Protection Laws means privacy/data protection laws applicable to the processing under the Agreement. Subprocessor means a third-party processor StoresOmni engages to process Customer Data on the Merchant's behalf. A Security Incident means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data; unsuccessful attempts without such compromise are not themselves Security Incidents.
2. Roles and scope
For Customer Data, the Merchant is the controller/business and StoresOmni is the processor/service provider. If the Merchant itself processes for another controller, it must have authority to appoint StoresOmni as its further processor and convey lawful instructions. Annex I describes the subject matter, data, subjects, nature, purposes, and duration of processing. This DPA does not govern data a provider independently controls under its separate duties or data StoresOmni processes as an independent controller as described in the Privacy Policy.
StoresOmni independently maintains platform identities and authentication, Merchant/platform accounts, billing and subscriptions, platform support/communications, security and fraud prevention, service operations and product analytics, legal compliance and claims. A registered StoresOmni identity can hold separate Merchant-specific customer relationships and other roles. One Merchant's instructions do not authorize access to another Merchant's customer relationship or deletion of the platform identity required by other roles. This division does not override legal service-provider restrictions or permit unrelated use of instructed Customer Data.
3. Documented instructions and Merchant duties
StoresOmni will process Customer Data only on documented Merchant instructions to provide the Services, including instructions concerning transfers, unless required by applicable law. Instructions are the Agreement, this DPA, authorized settings, API requests, and authorized use of configured features. Additional instructions must be lawful, within the agreed Services, or separately agreed in writing. Where law requires other processing, StoresOmni will inform the Merchant before processing unless legally prohibited. StoresOmni will promptly inform the Merchant if it considers an instruction to infringe applicable data protection law and may pause the affected processing while the parties address it.
The Merchant is responsible for the lawfulness, accuracy and minimization of data submitted, its legal basis and required notices/consents, its storefront privacy practices, retention instructions, personnel/integration access, and lawful transfer instructions. It must not submit prohibited sensitive data or instruct unlawful processing. It must secure credentials, properly configure commerce and providers, and respond to its data subjects and regulators. AI invocation, analytics, messaging, and media uploads constitute instructions only within authorized features and permissions; they are not unrestricted authority to repurpose Customer Data.
4. Confidentiality and security
StoresOmni will ensure persons authorized to process Customer Data are bound by appropriate contractual or statutory confidentiality obligations and receive access only as needed for authorized duties. StoresOmni will implement and maintain technical and organizational measures appropriate to the processing risks, taking account of the nature, scope, context, purpose, available technology, and implementation costs. Annex II describes the measures for the standard Services. Measures may evolve without materially reducing the overall protection of Customer Data.
Merchants remain responsible for their own devices, accounts, team permissions, exports, and connected services. No provision represents a StoresOmni security certification, dedicated infrastructure, universal field encryption, guaranteed availability, or an incident-free service. The security obligation is risk-appropriate protection, not an absolute guarantee.
5. Authorization, notice, and objections
The Merchant generally authorizes StoresOmni to engage subprocessors for the configured Services. The Subprocessor and Service Provider List identifies relevant providers, functions, conditional use, and role distinctions. A Merchant-authorized integration or independent payment/tax controller is not automatically a StoresOmni subprocessor for all of its activities. StoresOmni will impose written data protection obligations on subprocessors providing protections required by applicable law and substantially equivalent to the relevant obligations of this DPA, and remains responsible for their performance of those obligations, subject to the Agreement and mandatory law.
StoresOmni will give notice of intended additions or replacements processing Customer Data at least 14 days before authorizing the new processing, through email or a Service notice directing the Merchant to the updated list. The Merchant may object within 10 days of notice on reasonable, documented data protection grounds. The parties will work in good faith to resolve the issue, including an appropriate alternative where reasonably available. If unresolved within 15 days after objection, the Merchant may terminate the affected Services, or the Agreement if the affected processing is material, without a penalty attributable solely to that objection. Accrued charges remain due; any unused prepaid fees for terminated affected Services will be refunded proportionately.
Where urgently necessary to address an active security threat or prevent serious service interruption, an emergency replacement may begin sooner to the extent legally permissible, with notice as soon as reasonably practicable and continued objection rights. This does not remove mandatory advance authorization or notice requirements. Enabling a previously disclosed optional provider is governed by the Merchant's configuration/instructions; an undisclosed new subprocessor remains subject to this section.
6. Data subject requests and assistance
Taking account of the nature of processing, StoresOmni will assist through appropriate technical/organizational measures and available information so the Merchant can meet applicable data-subject rights obligations. If we receive a request concerning data controlled by the Merchant, we will direct the requester to the Merchant or notify the Merchant where appropriate; we will not independently act on the Merchant's behalf except on verified instructions or as required by law. We handle requests about our independent platform identity/controller processing under our Privacy Policy.
The Merchant should first use available access, correction, export, and deletion controls. Where further assistance is necessary, StoresOmni will provide reasonable help with verified requests. We may charge reasonable, disclosed costs for substantial custom assistance beyond standard features, except where prohibited by law or necessary to remedy our own breach. Assistance must not disclose another tenant's records or weaken access controls.
7. Security Incidents
StoresOmni will notify the affected Merchant without undue delay after becoming aware of a Security Incident involving its Customer Data. Notice will describe reasonably available information about the incident, affected data/subjects where known, likely consequences, mitigation measures, and a contact for follow-up. Information may be supplied in stages as the investigation progresses; notice is not an admission of fault.
StoresOmni will take reasonable steps to contain, investigate, and mitigate the incident and assist the Merchant with legally required regulator or data-subject notifications, taking account of the processing and information available to us. The Merchant remains responsible for its controller notification duties. We will coordinate public or customer communications where practicable, without delaying required notices or disclosing information prohibited by law.
8. Compliance, assessments, and regulatory assistance
Taking account of the nature of processing and information available, StoresOmni will assist the Merchant with applicable security, breach notification, data protection impact assessment, prior consultation, and regulatory obligations. We will make available information reasonably necessary to demonstrate compliance with this DPA. Substantial custom assistance may incur reasonable costs agreed in advance, without restricting mandatory rights or charging for remedying our own breach. We do not promise a certification, assessment, or report that does not exist.
9. International transfers and government requests
Customer Data may be processed in the United States and other jurisdictions where StoresOmni or applicable providers operate. Unless expressly agreed in writing, there is no specific data residency commitment. StoresOmni will not make a transfer subject to legal transfer restrictions without an applicable lawful mechanism. Where required, the parties will cooperate to establish an appropriate transfer arrangement and necessary supporting information, including separate standard contractual clauses or other lawful safeguards, before the restricted transfer. Annex III explains this process; publication or acceptance of this DPA does not by itself execute such an instrument or assert framework certification.
StoresOmni will provide available information reasonably needed for relevant transfer assessments and identify the applicable mechanism on request, subject to lawful confidentiality limits. Changes to processing locations remain subject to legal safeguards and relevant subprocessor notice duties.
If a government or law-enforcement authority seeks Customer Data, StoresOmni will notify the Merchant unless prohibited by law, seek to direct the authority to the Merchant where practicable, assess the demand's validity, and disclose only what is legally required. We will use reasonable available legal measures to address unlawful or overbroad demands where appropriate and preserve confidentiality to the extent lawful. These duties do not require breaching law or promising that every government request can be defeated.
10. Information and audit rights
StoresOmni will allow and contribute to audits, including inspections, by the Merchant or its mandated independent auditor as required by applicable law to verify processor obligations. Parties should first use reasonably sufficient documentation and remote verification. If this is insufficient or law/regulator requirements justify further review, they will agree on reasonable scope, timing, and protections. Ordinarily audits occur no more than annually on at least 30 business days' notice, except where an incident, credible compliance concern, regulator, or mandatory law requires otherwise.
Audits must be proportionate, during reasonable business hours, under confidentiality duties, and avoid unreasonable disruption or unauthorized access to other tenants, secrets, or security-sensitive information. Equivalent evidence may be supplied to protect those interests; safeguards may not defeat statutory audit rights. No destructive testing or unsolicited penetration testing is authorized by this section. The Merchant bears ordinary audit costs and reasonable pre-agreed assistance costs, except as otherwise required by law or for substantiated StoresOmni non-compliance. Audit materials are confidential, without preventing required disclosures to advisers or authorities.
11. Return, deletion, and retention
On termination of the relevant Services or a verified lawful instruction, StoresOmni will, at the Merchant's choice, return Customer Data through available export or reasonable agreed means and delete remaining copies, or delete Customer Data, within a reasonable period appropriate to the data and processing, unless applicable law requires retention. Coordinate export before closure where possible. We will provide written information about completed or scheduled deletion on reasonable request; we will not certify erasure from systems outside our control.
Customer relationship closure is separate from full data deletion and from platform identity deletion. The Merchant cannot direct deletion of unrelated store relationships or retained platform capabilities. Data necessary for StoresOmni's distinct lawful controller purposes is governed by the Privacy Policy and applicable law, not continued unrestricted processor retention. Any statutory preservation or legal hold limits deletion only for the relevant lawful purpose; retained data remains protected and is removed when that requirement ends.
Deletion may require background cleanup and removal of related files. Backup/recovery copies, where maintained, may remain until their relevant lifecycle ends, subject to security and restricted use; restored data remains subject to applicable deletion instructions. No fixed backup rotation, immediate log erasure, or universal deletion interval is promised. Independent Merchant-authorized providers may retain records under their own duties; StoresOmni will assist with applicable instructions within its authority.
12. Applicable U.S. service-provider terms
Where applicable U.S. privacy law requires service-provider, contractor, or processor terms, StoresOmni will process Customer Data only for specified purposes of providing the Services and permitted processing under that law; will not sell or share Customer Data for cross-context behavioural advertising; and will not retain, use, disclose, or combine it outside the permitted business purposes or direct business relationship except where legally permitted. Both parties acknowledge and will comply with these restrictions.
The Merchant may take reasonable steps permitted by law to verify compliant use and to stop or remediate unauthorized processing. StoresOmni will notify the Merchant if it determines it can no longer meet these obligations and will cooperate with reasonable remediation. Assistance and verification rights in this DPA apply. These restrictions are not overridden by broad independent-controller language elsewhere in the Agreement.
13. Liability, precedence, and survival
Mandatory applicable law prevails, followed by any separately binding transfer instrument to the extent of its required precedence, then this DPA for Customer Data processing, then other Agreement terms. A separately negotiated agreement may expressly vary this DPA only consistently with mandatory law and a binding transfer instrument. This matches the Terms' precedence rule. Merchant storefront policies do not amend this DPA.
The Agreement's liability exclusions and aggregate cap, governing law, dispute procedure, and notice provisions apply to this DPA, except where mandatory law or a binding transfer instrument requires otherwise. This DPA does not create an additional liability cap or restrict data subjects' or regulators' non-waivable rights. Processing protection, confidentiality, assistance, retention/deletion, and other obligations survive as necessary while relevant data is held. An invalid provision does not invalidate the rest.
Annex I — Details of processing
Parties and subject matter: the Merchant identified in the account/order terms uses StoresOmni LLC for hosted website/storefront and related commerce functions. The Merchant's account contact and StoresOmni privacy@storesomni.com are the processing contacts. Depending on enabled functions, processing supports separate store-customer relationships, products and orders, checkout, payments/tax, shipping/pickup, digital delivery, communications, configured analytics, support, and authorized AI assistance.
Data subjects: Merchant customers, prospective customers, storefront visitors, contacts, recipients of communications, and individuals whose data the Merchant lawfully submits. Merchant/platform identity data independently controlled by StoresOmni is outside this Annex to that extent.
Data categories: names/contact identifiers; store-specific customer profiles and relationship information; orders, carts, product/transaction and payment metadata; addresses, shipping/pickup, tax/location and registration evidence as relevant; returns/refunds/disputes; chats/support and transactional messages; uploaded files/media; device/network/session/consent and configured analytics information; authorized AI prompts/context, attachments, outputs and approvals; integration/webhook and operational records. Special-category data is not required for ordinary Services and must not be submitted unless expressly supported and lawful.
Nature and purpose: collection, recording, organization, hosting/storage, retrieval/display, transmission, configured calculation/analysis, authorized generation and changes, communications, security/reliability handling, export, and deletion to provide the contracted Services according to instructions. Processing is ongoing or event-driven as the Merchant configures and uses the Services, for the relevant term and limited periods thereafter for deletion/return and applicable retention duties. Conditional providers receive only applicable data when the function or integration is enabled.
Annex II — Technical and organizational measures
Access and separation: authenticated access and store/role-scoped authorization, separation of Merchant records, restricted privileged server operations, and private media access controls where appropriate. Administrative and sensitive operations use applicable verification, permissions, and operational records; verification requirements depend on the function and configuration.
Transport, credentials, and integrity: protected public-network transport, underlying cloud storage protections, server-side handling of credentials and encryption of connected-provider secrets where implemented, validated inputs, signed/scoped order access, verified provider events, and idempotent financial workflows where appropriate. These measures do not assert encryption of every individual field or that Merchant-public media is private.
Operations and lifecycle: security/audit and diagnostic evidence, resource and abuse controls, supported expiry/cleanup and account lifecycle functions, incident investigation and mitigation, confidentiality duties and restricted access, and risk-appropriate security maintenance. Recovery or backup arrangements, where configured, follow applicable infrastructure controls rather than a promised universal schedule or recovery target. StoresOmni may update these measures without materially reducing overall protection; additional commitments require a separate agreement.
Annex III — Establishing lawful transfer safeguards
Where a restricted transfer requires an additional instrument, the parties must establish the applicable mechanism and required terms, annex information, competent authority, governing-law/jurisdiction selections, assessments, and supplementary measures as necessary before the transfer. Relevant mechanisms may include an applicable adequacy decision, properly completed EU standard contractual clauses, a UK addendum or international data transfer agreement, Swiss adaptations, or another legally recognized safeguard.
No standard contractual clauses or UK/Swiss instrument are automatically executed by this DPA, and StoresOmni does not assert Data Privacy Framework certification. A provider's own certification or contract is not StoresOmni's certification and does not necessarily cover the Merchant-to-StoresOmni transfer. Contact privacy@storesomni.com to establish required arrangements or request information about mechanisms applicable to the configured Services. Where adequate arrangements cannot be established, the affected restricted processing must not proceed.
Contact StoresOmni
StoresOmni LLC, a New Mexico limited liability company. Legal and notices address: 1209 Mountain Road Pl, STE N, Albuquerque, NM 87110, United States.
Support: support@storesomni.com · Privacy: privacy@storesomni.com · Security: security@storesomni.com · Legal: legal@storesomni.com · Copyright: copyright@storesomni.com
Terms of Service · Privacy Policy · Cookie Policy · Data Processing Addendum · Subprocessors and Service Providers