Legal
Data Processing Agreement
Effective 9 August 2026 · Last updated 9 August 2026
This Data Processing Agreement (the “DPA”) applies whenever Zappush LLP (“Zappush”, “we”, “our”, “us”) handles personal information on behalf of a customer (“you”, “your”) while providing the Zappush platform. It forms part of, and is incorporated by reference into, our Terms and Conditions. By accepting those Terms, or by using the platform, you accept this DPA. You do not need to sign anything separately.
This DPA covers information about your shoppers, customers, leads, and other individuals whose data you send us. It does not cover your own account information, which is covered by our Privacy Policy.
If you need a countersigned copy for your records, or a negotiated version, write to [email protected] and we will sort it out.
1. Definitions
- “Your Data” means personal information about your shoppers, customers, leads, or other individuals that you send to us, or that you authorise us to collect through the platform.
- “Process” means anything we do with Your Data, including collecting, receiving, storing, organising, using, transmitting, and deleting it.
- “Sub-processor” means a third party we engage to process Your Data on our behalf.
- “Security Incident” means unauthorised access to, or unauthorised disclosure of, Your Data while it is in our care.
- Terms used here and not defined have the meaning given to them in the Terms and Conditions.
2. Roles and ownership
You decide what Your Data is collected, why it is collected, and where it is sent. You own it. Nothing in this DPA or in the Terms transfers ownership of Your Data to us, and we acquire no rights in it beyond those needed to provide the platform to you.
We process Your Data only to provide the platform to you and only on your instructions. Your instructions are given through the way you configure the platform, through this DPA and the Terms, and through any written request you send us.
3. What we will do
We will:
- Process Your Data only to provide, maintain, secure, and support the platform for you, and as otherwise instructed by you or required by law. If a law requires us to process Your Data in some other way, we will tell you before we do, unless that law forbids us from telling you.
- Never sell Your Data, never share it with anyone for their own marketing, and never use it for any purpose of our own.
- Keep Your Data confidential, and limit access to the personnel who need it to do their jobs, each of whom is under a duty of confidentiality that survives the end of their engagement with us.
- Apply the security measures set out in Annex A, and not materially weaken them for as long as we hold Your Data.
- Keep Your Data logically separated from every other customer's data.
- Tell you without undue delay if we become aware of a Security Incident affecting Your Data, and give you the information you reasonably need in order to respond.
- Help you respond to requests from individuals about their information, and to reasonable questions from a regulator or a platform partner, at no extra charge.
- Delete Your Data as set out in clause 9 and in our Data Retention Policy.
4. What you will do
You will:
- Make sure you have the right to send us Your Data, and that you have given whatever notice and obtained whatever consent applies to the people it is about, wherever you operate.
- Give the platform accurate instructions, including which events are captured, which destinations receive them, and which of your team have access.
- Not send us information we do not need. In particular, do not send government identifiers, payment card numbers, passwords, health records, or similarly sensitive categories of information. The platform is not built for them, we do not want them, and we are not responsible for them if you send them anyway.
- Keep your account credentials secure, and remove access for people who no longer need it.
- Act as the point of contact for your own shoppers. They are your customers, not ours.
5. Sub-processors
You authorise us to engage the sub-processors listed in Annex B. Each one is engaged under written terms that are no less protective of Your Data than this DPA, and we remain responsible to you for what they do.
We may add or replace a sub-processor. When we do, we will update Annex B and give you at least 30 days' notice, by email or in the dashboard, before that sub-processor begins processing Your Data. If within that period you object on reasonable grounds relating to the protection of Your Data, we will work with you in good faith to find an alternative. If no reasonable alternative is available, you may terminate the affected part of the service and we will refund any prepaid fees covering the unused remainder of the term.
6. Where we process Your Data
The platform runs on Google Cloud Platform infrastructure in the United States. Our team accesses it from India. Sub-processors process Your Data in the locations named alongside them in Annex B.
You instruct us, and agree, to process and store Your Data in these locations.
7. Security incidents
If we become aware of a Security Incident, we will notify you without undue delay. The notice will describe what we know, which of Your Data is affected as far as we can tell, and what we are doing about it. We will keep you updated as the picture becomes clearer, and we will not withhold information you need in order to meet your own obligations.
We will take reasonable steps to contain the incident and reduce its effects. Notifying you is not an admission of fault or liability on our part.
8. Requests from individuals
Where an individual contacts us directly about information we hold on your behalf, we will not deal with the substance of it ourselves. We will tell them to contact you, and we will let you know it happened.
If you ask us to help find, correct, export, or delete a specific individual's information, we will do it. Where your e-commerce platform sends us a deletion request on a shopper's behalf, we treat that as your instruction and act on it.
9. Deletion, export, and return
While your account is active, we keep Your Data so the platform works.
You may ask us at any time to export or delete any part of Your Data, whether that is one individual, a date range, a connected store, or all of it. Write to [email protected] from an address on your account. There is no charge, and deletion is permanent.
When your account closes, we keep Your Data for 30 days so you can reactivate or take an export, and then we delete it. If you want it gone sooner, ask us and we will do it.
Our Data Retention Policy sets out the full detail, including the limited categories of record we keep for longer and the reasons why.
10. Information and audit
On reasonable written request, and no more than once in any twelve-month period unless a Security Incident or a platform partner requires otherwise, we will give you the information you reasonably need to satisfy yourself that we are meeting this DPA.
We are not obliged to give access to our systems, our premises, our source code, or any information relating to another customer.
11. Liability and precedence
Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms and Conditions.
If this DPA and the Terms conflict on how Your Data is handled, this DPA prevails. If this DPA conflicts with a separate written agreement signed by both of us, that agreement prevails for the engagement it covers.
12. Term
This DPA applies for as long as we hold Your Data. The clauses on confidentiality, deletion, and liability survive its termination.
Annex A: Security measures
These are the measures in place while we hold Your Data. Our Security page describes them in full.
- All data in transit travels over TLS.
- All data at rest is encrypted on the underlying storage.
- Access tokens for your connected platforms, and the other credentials the platform needs, are encrypted with a managed key service. Each token is bound to the record it belongs to, so a token lifted out of its context cannot be decrypted.
- Every read and every write in the platform is scoped to a single workspace. The workspace identifier is a required argument on data access rather than an optional filter, so a query that omits it does not run.
- Access to production systems is limited to the personnel who need it, granted on a least-privilege basis, and reviewed as roles change. Credentials are held in a managed secret store rather than in code or configuration files.
- We maintain an internal register of every field that holds personal information and every store it lands in, together with automated checks that run before any change ships and block personal information from being written to a place the register does not know about.
- Contact details are converted to an unreadable one-way value before they are sent to any advertising platform.
- Privacy mode is available, which converts identifying details to an unreadable one-way value at the moment they arrive, so no readable contact information is ever written to disk.
- Backups are encrypted and expire automatically on a rolling schedule.
Annex B: Sub-processors
The third parties who process Your Data on our behalf, what each of them does, and where each of them does it.
- Google Cloud Platform: hosting, databases, storage, encryption keys, and backups for the entire platform. Processed in: United States.
- Cloudflare: content delivery and DNS in front of our services. Processed in: United States and global edge network.
- IPinfo: resolving an IP address to an approximate location. Processed in: United States.
- IPLocate: resolving an IP address to an approximate location. Processed in: United States.
- Resend: sending transactional email such as sign-in links, alerts, and account notices. Processed in: United States.
- Trigger.dev: running the background jobs behind some of our tools, including anything submitted to those tools. Processed in: United States.
- Mixpanel: measuring how account holders use the dashboard, so we can improve it. This covers our customers' own use of the product, not shoppers on their stores. Processed in: United States.
- Google Analytics, through Google Tag Manager: measuring how our own websites and public tools are used. Processed in: United States.
- Microsoft Clarity: measuring how our own websites and public tools are used. Processed in: United States.
- Google reCAPTCHA: protecting sign-up and public forms from automated abuse. Processed in: United States.
- Razorpay: processing subscription payments. Processed in: India.
- Shopify: processing subscription payments, and supplying store and order data, for customers who install Zappush from the Shopify App Store. Processed in: Canada and United States.
- Google (Gemini): reviewing advertising copy and landing pages for policy compliance, where a customer uses that feature. This processes advertising content, not shopper information. Processed in: United States.
- Groq: reviewing advertising copy and landing pages for policy compliance, where a customer uses that feature. This processes advertising content, not shopper information. Processed in: United States.
Advertising platforms that you choose to connect, such as Meta, are not sub-processors. They receive data on your instruction, as independent recipients, and what they do with it is governed by your agreement with them.
Contact
Questions about this DPA, or a request for a countersigned or negotiated copy:
Zappush LLP Desk No. WSA43, First Floor, B128, B Block, Sector 2, Noida Uttar Pradesh 201301, India Email: [email protected]