Skip to content

Data Processing Addendum

Trust

Last updated September 03, 2026.

Does Crate offer a data processing agreement?

Yes, and the terms are on this page in full rather than behind a sales conversation, so a legal or procurement review can read them at eleven at night and decide. Under the addendum you are the controller of your shoppers' personal data and Crate is your processor, acting only on your documented instructions. Crate is separately the controller of your own account data, which the privacy policy governs. The addendum covers the categories processed, the named subprocessor list, the security measures actually in place including the ones that are not, international transfers, breach notification without undue delay, help answering a data subject request, deletion within ninety days of closure, and your right to audit. Ask us for a countersigned copy.

The four answers a legal review asks for first

At a glance

Each is stated again in full below, with the reason it is true.

  • Who is who

    You are the controller of your buyers' data. Crate is your processor for it. Crate is the controller of your own account data, and only of that.

  • Where processing happens

    The United Kingdom, on OVH infrastructure, with named onward transfers to France, Nigeria and the United States. All five parties are published by name.

  • How long we keep it

    Store data is deleted within ninety days of an account closing. Billing records survive that because tax law requires it. Every period is named below.

  • What you can verify

    This page, the published subprocessor list, the security page including its open items, and a written answer to a questionnaire. Crate has no audit report to send you.

The terms, section by section

The addendum

Written to be read rather than skimmed past. This page is the substance of the document Crate countersigns.

What this page is, and what it is not

This is the addendum Crate offers, set out in plain language at a stable address. It is not itself an executed contract, and reading it does not put one in place. A marketing page presenting itself as a signed agreement is worse than no page, because it invites somebody to rely on terms nobody countersigned.

To put it in force, email [email protected] and ask for the data processing addendum. It comes back countersigned, with the subprocessor list attached and the contracting entity named, usually within the same week. If your own paper is a condition of the purchase, send it and we will read it rather than insisting on ours.

The roles, which is the part most often got wrong

For the personal data inside your store, meaning your buyers' names, addresses, phone numbers, email addresses and order histories, you decide why and how it is processed. You are the controller. Crate processes it on your instructions and is your processor.

For your own account data, meaning your name, your login, your billing details and how you use the dashboard, Crate decides. Crate is the controller for that, and the privacy policy rather than this addendum governs it.

This matters in a way that is not academic. When one of your buyers asks to be deleted, the request belongs to you, not to Crate, and Crate carries it out for you rather than instead of you. A buyer who writes to Crate directly is told to write to the store, and the store is told the request came in.

Read the privacy policy

Scope, and the instruction Crate acts on

Crate processes your buyers' personal data only to provide the service you signed up for, to keep it secure, and where a law that applies to Crate requires something else. Your use of the dashboard and the settings you choose in it are your documented instructions. There is no separate instruction form to keep updated.

Crate does not sell your buyers' data, does not share it for cross-context behavioural advertising, and does not use it to train a model, its own or anybody else's. Those three are stated as prohibitions rather than as intentions, because an intention is not a term.

What is processed, and about whom

Categories of data subject: your customers and prospective customers, the people who visit your storefront, and the staff you invite into your own account.

Categories of personal data: name, business name, email address, phone number, delivery and billing address, order and refund history, the contents of a cart, support messages, and the technical data a web request carries, meaning IP address, device and browser type, and the pages viewed.

Payment data is deliberately narrow. Crate records the card brand, the last four digits, the expiry and the payment provider's own token. There is no card number column in Crate and no card number reaches it. The provider you connect captures the card.

No special category data is processed by design. Crate does not ask for and has no field for information about health, race, religion, sexual orientation, union membership or immigration status, and does not process biometric data or precise geolocation.

Subprocessors, published rather than offered

Crate uses five third parties to run the service. Each one, what it does, the data it can reach and the country it operates in is published on its own page rather than sent when a reviewer asks.

A party is added to that list before it starts processing data, not after. Customers on a signed addendum are notified in advance, so objecting is a real option rather than a formality. If you object on reasonable data protection grounds and we cannot offer an alternative, you may terminate the affected part of the service without penalty.

Read the subprocessor list

Security measures, including the ones Crate does not have

Everything is served over TLS. Stores are isolated from one another: every record belongs to one store and every query is narrowed to that store before it runs, on the dashboard, on the storefront and through the API. Payment gateway secrets, mail credentials, domain signing keys and integration tokens are encrypted at the application layer with AES-256-GCM. Passwords are hashed. Two-factor authentication, per-permission staff roles, session timeouts, rate limiting and session revocation are all in place, and every change inside a store is written to a tamper-evident append-only trail.

Three controls a reviewer commonly expects are not in place, and this addendum names them rather than describing the measures as appropriate and leaving it there. Crate holds no SOC 2 or ISO 27001 certification and has no third party audit report to attach. The production host runs an ordinary unencrypted filesystem, so there is no full-disk encryption. And there is currently no off-site copy of the production database or of uploaded files, which means a total loss of the host would not be recoverable today. The security page carries the full open list with the status of each item.

Naming those here is deliberate. A security schedule that promises measures the vendor does not have is a term the vendor breaches on the day it is signed.

Read the security posture in full

International transfers

The application, the database, the job queue and uploaded files are processed in the United Kingdom. Onward processing happens in France for email delivery, in Nigeria for merchants who connect Paystack, and in the United States for DNS and certificate issuance.

Where personal data leaves the United Kingdom or the European Economic Area, the transfer relies on the standard contractual clauses, with the United Kingdom addendum to them where the United Kingdom is the exporter. The clauses are incorporated into the addendum Crate countersigns rather than referenced from it.

Object storage is being moved to Cloudflare R2, which operates a global network. That change is written into the subprocessor list before it happens rather than after, so a review done today is not invalidated by it next month.

The clauses are used with the module the transfer actually needs. Module Two governs the transfer from you to Crate, because you are the controller of your buyers' data and Crate is your processor for it. Module Three governs the hop from Crate to one of the subprocessors named above, because both ends of that hop are processors. A transfer impact assessment is available on request and is meant to sit beside the clauses rather than in place of them.

For a transfer out of the United Kingdom, Crate will sign the International Data Transfer Agreement or the United Kingdom Addendum to the European clauses, whichever your counsel prefers, rather than insisting on one. The Swiss Addendum is available for a buyer who needs it. Where a recipient in the United States is certified under the Data Privacy Framework or its United Kingdom extension, Crate relies on that certification only after checking it against the live list for that specific entity, never as a blanket answer for transfers to the United States.

Breach notification

If Crate becomes aware of a personal data breach affecting data it processes for you, Crate tells you without undue delay and in any case within seventy-two hours of becoming aware, so that you can meet your own regulator deadline, which is what that clock is actually for.

The notice describes what happened, the categories and approximate number of people and records involved, the likely consequences, and what Crate has done and is doing about it. Where the full picture is not known within seventy-two hours you get what is known then and the rest as it arrives, rather than silence until the investigation closes.

Crate notifies you. Crate does not notify your buyers on your behalf, because that is a controller's decision about a controller's customers, and Crate will give you what you need to make it.

Helping you answer a data subject request

When one of your buyers asks for access, correction, deletion or a portable copy, the request is yours to answer and Crate gives you the tools to do it. Buyer records can be read, corrected, exported and deleted from the dashboard without asking Crate for anything.

Where the request cannot be satisfied from the dashboard, ask [email protected] and Crate helps within the time your own deadline needs rather than within a period of its own choosing. Crate answers requests about its own controller data within thirty days, everywhere, which is shorter than any of the laws that apply require.

Deletion and return

When your account closes, the store data you created, meaning your products, orders, customers and content, is deleted within ninety days. Server and security logs are kept for ninety days. Support conversations are kept for two years so a later problem can be traced back. Marketing consent records are kept for as long as the consent stands plus two years, because a consent nobody can evidence is a consent that did not happen.

Billing and invoice records are kept for as long as tax law requires, which is commonly six or seven years, and that is the one period Crate cannot shorten for you.

You can export your data at any time while the account is open, and you should, because a copy you hold is worth more than a promise about a copy Crate holds. That is doubly true while there is no off-site backup on Crate's side.

Audit and information rights

You may ask Crate for the information needed to show that this addendum is being met, and Crate answers in writing. In practice that is a completed security questionnaire, this page, the published subprocessor list, and the security page including its open items.

Crate has no independent audit report, no penetration test report and no certification to send you instead, and says so here rather than pointing at a trust portal that turns out to be empty. Where a written answer genuinely will not do, an audit can be arranged on reasonable notice, no more than once a year unless a regulator or a breach requires otherwise, at your cost and without access to another customer's data.

Term, and what happens on a conflict

The addendum runs for as long as Crate processes personal data for you, and the parts of it that are meant to survive termination, meaning confidentiality, deletion and the transfer safeguards, do survive it.

Where the addendum and the terms of service disagree about the processing of personal data, the addendum wins. Everything else stays with the terms of service.

Read the terms of service

Questions a legal review asks

Short answers, and none of them hedge. If yours is not here, ask us on the contact page.

Will you sign our own DPA rather than yours?

Send it and we will read it. Crate is a small company and reviewing your paper is usually faster than arguing about whose template is standard. Where a clause commits Crate to a control it does not have, we will tell you which one and why rather than signing and hoping.

Are the standard contractual clauses included?

Yes. They are incorporated into the document Crate countersigns, with the United Kingdom addendum where the United Kingdom is the exporter, rather than referenced from a page you cannot see.

How quickly do you tell us about a breach?

Without undue delay and in any case within seventy-two hours of becoming aware, which is what your own regulator deadline needs. If the full picture is not known by then you get what is known, and the rest as it arrives.

Do you use our buyers' data to train models?

No. It is not sent to any third party for training and Crate does not train on it. That is a term of the addendum rather than a statement of intent.

What happens to our data if we leave?

Store data is deleted within ninety days of the account closing. Billing records are kept for as long as tax law requires. Export what you need before you close the account, and do it while the account is open rather than after.

Can we audit you?

Yes, on reasonable notice, once a year unless a regulator or a breach requires otherwise, at your cost and without access to another customer's data. Most reviews are satisfied faster by a written questionnaire, which Crate fills in itself including the rows where the answer is no.

Ask for the countersigned copy

Tell us the contracting entity and where it is registered, and the addendum comes back signed with the subprocessor list attached.

14-day free trial · No card required