Data Processing Agreement

Last updated: July 1, 2026

1. Introduction

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between CartGain (“Processor,” “we,” “us”) and the merchant (“Controller,” “you”) using the CartGain platform. This DPA sets out the terms relating to the processing of personal data by CartGain on behalf of the merchant, to facilitate compliance with the General Data Protection Regulation (GDPR), India's Digital Personal Data Protection Act (DPDP Act, 2023), and other applicable data protection laws.

2. Definitions

  • Controller: The merchant who determines the purposes and means of processing personal data.
  • Processor: CartGain, which processes personal data on behalf of the Controller.
  • Personal Data: Any information relating to an identified or identifiable natural person (customer).
  • Processing: Any operation performed on personal data, including collection, storage, use, and transmission.
  • Sub-processor: A third party engaged by CartGain to process personal data on behalf of the Controller.
  • Data Subject: The customer whose personal data is being processed.

3. Details of Data Processing

Categories of Data Subjects:

Customers of the Controller who abandon their shopping carts on the Controller's e-commerce store.

Categories of Personal Data:

  • Customer name, email address, and phone number
  • Shipping address and billing information
  • Cart contents, product details, and order values
  • Communication preferences and opt-in/opt-out status
  • Message delivery status and engagement metrics

Nature and Purpose of Processing:

Automated sending of cart recovery notifications via email, WhatsApp, and push-style web alerts to encourage customers to complete their purchases.

Duration of Processing:

For the duration of the Controller's active subscription. Upon uninstall or termination, store-scoped data is purged and the data subject's personal data is procedurally deleted or anonymized within a reasonable window. Residual copies that may remain in hosting-provider backups are purged in line with the provider's own backup retention schedule.

4. Processor Obligations

CartGain shall:

  • Process personal data only on documented instructions from the Controller, unless required by law to do otherwise.
  • Ensure that persons authorized to process the data are bound by confidentiality obligations.
  • Implement appropriate technical and organizational security measures.
  • Not disclose personal data to third parties except as instructed or as required by law.
  • Assist the Controller in fulfilling their obligations to respond to data subject rights requests.
  • Notify the Controller of any personal data breaches without undue delay.
  • Delete or return all personal data at the end of the service term, as directed by the Controller.
  • Maintain records of all processing activities.

5. Controller Obligations

The Controller shall:

  • Ensure they have a lawful basis for processing customer data (e.g., consent, legitimate interest).
  • Provide clear privacy notices to customers about how their data is used.
  • Obtain necessary consents for WhatsApp and email messaging as required by applicable laws.
  • Ensure the accuracy and relevance of personal data provided to CartGain.
  • Respond to data subject requests and notify CartGain of any such requests.
  • Cooperate with CartGain in the event of a data breach investigation.

6. Sub-processors

The Controller authorizes CartGain to engage the following sub-processors:

Sub-processorServiceData Location
Supabase (PostgreSQL)Database hostingData region as selected in the Supabase project dashboard
VercelApplication hosting & CDNGlobal (multi-region) edge
ResendEmail deliveryUS / EU (Resend processing)
Meta (WhatsApp Cloud API)WhatsApp message deliveryGlobal (Meta processing)
RazorpayPayment processingIndia (Razorpay processing)
OpenAIAI-powered message generation (GPT-4o / GPT-4o-mini)US (OpenAI processing)
GroqAI fallback inference (gpt-oss-120b)US (Groq processing)
Upstash (Redis)Job queue & cachingData region as selected in the Upstash project dashboard

CartGain will notify the Controller of any changes to sub-processors and the Controller may object within 14 days.

7. Security Measures

CartGain implements the following technical and organizational security measures:

Encryption

Data encrypted in transit via TLS. API keys and sensitive tokens stored encrypted in the database (AES-256-GCM). Customer passwords hashed with bcrypt (cost 12).

Access Control

Principle of least privilege, OAuth-based access to store data, access tokens stored encrypted, and audit logging of sensitive data access.

Monitoring

Application logging, Shopify webhook signature verification, and audit logging for access to sensitive personal data.

Backups

Backups are managed by the hosting provider; the provider retention window applies to stored backups.

Employee Access

Personnel with access to personal data are bound by confidentiality obligations. [DETAIL PER INTERNAL POLICY]

Incident Response

Documented incident response plan with a 72-hour merchant notification commitment (see CartGain Incident Response Policy).

8. Data Breach Notification

In the event of a personal data breach, CartGain will:

  • Notify the Controller within 72 hours of becoming aware of a personal data breach (as committed in CartGain's Incident Response Policy).
  • Provide details of the nature, scope, and potential impact of the breach.
  • Identify affected categories of data and approximate number of data subjects.
  • Outline measures taken to address the breach and prevent recurrence.
  • Cooperate with the Controller in notifying regulatory authorities and data subjects as required by law.

9. Data Subject Rights

CartGain shall assist the Controller in responding to data subject requests, including:

  • Right of Access: Providing a copy of personal data held about a data subject.
  • Right to Rectification: Correcting inaccurate or incomplete data.
  • Right to Erasure: Deleting personal data upon request (“right to be forgotten”).
  • Right to Restriction: Limiting the processing of personal data.
  • Right to Data Portability: Exporting data in a structured, machine-readable format.
  • Right to Object: Objecting to certain types of processing, including direct marketing.

Controllers can exercise these rights by contacting support@cart-gain.com. We will respond within 30 days.

10. Data Retention & Deletion

  • Personal data is processed for the duration of the Controller's active subscription.
  • Upon uninstall or account deletion, store-scoped personal data is purged from the application database (see CartGain's data-deletion procedures).
  • Controllers may request earlier deletion by contacting support.
  • Copies that may remain in hosting-provider backups are purged in line with the provider's own backup retention schedule.

11. Audit & Compliance

  • CartGain maintains records of all processing activities as required by Article 30 of the GDPR.
  • Upon reasonable notice (minimum 30 days), CartGain will provide access to relevant records for audit purposes.
  • Audits shall be conducted in a manner that does not disrupt CartGain's operations.
  • Audit reports and findings shall be treated as confidential.

12. Governing Law

This DPA is governed by the laws of India. Any disputes arising from this DPA shall be resolved in accordance with the dispute resolution provisions in the Terms of Service. In the event of any conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to data processing matters.

13. Contact Information

Data Protection / Privacy: support@cart-gain.com

Legal / DPA Inquiries: support@cart-gain.com

Grievance Officer: support@cart-gain.com

Address: Street No. 3, Line Par, Shanker Garden, Bahadurgarh, Haryana - 124507

© 2026 CartGain. All rights reserved.