Nextstock Data Processing Agreement

Effective date: 2026-09-24

This is the agreement that covers how Nextstock handles your store data on your behalf. It is written for merchants in the EU, the UK and Switzerland, whose privacy laws require one, for merchants covered by US state privacy laws such as California's, and for any other merchant who asks for it. It is short because Nextstock holds very little data about people, and we would rather you read it than skim it.

The short version. You own your store data. We process it only to tell you when to reorder. We do not hold anything about your individual customers, so most privacy requests about them have a one-line answer: we hold nothing. Your data lives in the United States, protected by Standard Contractual Clauses. We delete it 48 hours after you uninstall. Nightly backups are kept for 27 days, so a deleted store can persist inside a backup copy for up to 30 days after that.

1. Who this agreement is between, and when it applies

You are the merchant that installs Nextstock on its Shopify store (the "controller").

We are BROJAS LLC, an Arizona limited liability company, doing business as Nextstock (the "processor"). Contact for data protection: [email protected]. Our postal address is available on request at [email protected].

This agreement forms part of the Nextstock Terms of Service. It applies automatically if you are established in the European Economic Area, the United Kingdom or Switzerland, or if a US state privacy law treats you as a "business" or "controller" and us as your "service provider" or "processor". It applies to any other merchant who emails [email protected] and asks for it. If this agreement and the Terms of Service disagree about data protection, this agreement wins.

"Data protection law" means the law that applies to you: the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended (CCPA) and similar US state laws, and any similar law that applies to your store.

2. Roles

For your store data (defined in section 3), you are the controller and we are the processor. We act only on your instructions.

For the account details we need to run your account (store name and address, the store contact email Shopify lists, timezone, currency, your settings, and the support emails you send us), we are the controller. That data is covered by our Privacy Policy, not by this agreement.

3. What we process, and why

Subject matter. Sales, catalogue and inventory data from your Shopify store.

Duration. From the moment you install Nextstock until 48 hours after you uninstall it, or sooner if you ask (see section 9).

Nature of the processing. Reading the data from Shopify, storing it, adding it up into daily sales totals per product, running a demand forecast on those totals on our own servers, and showing you a reorder list inside your Shopify admin. The data is read on a schedule, normally once a day, when you first open the app, and when you ask it to retry a failed sync. No outside AI service receives store data, and we do not use it to train or improve models for anyone else.

Purpose. To work out what you are likely to sell and tell you when to reorder. Nothing else. We do not use your data for advertising, we do not sell it, and we do not use it for any purpose of our own.

Categories of data ("store data").

| Category | What it holds | |---|---| | Order lines | Shopify order id, line item id, which product variant, when the order was processed, the shop-local sales date, quantity, quantity returned to stock, and the sales channel | | Catalogue | Products and variants: title, vendor, product type, status, SKU, price, unit cost, inventory policy, and the lead time, minimum order quantity and pack size you enter | | Inventory | Available quantity per variant per location, with the time it was observed | | Locations | Shopify location id, name, whether active | | Shop identity and settings | Your store's Shopify address and id, the permissions you granted, install and uninstall times, sync status, and your forecast settings | | Error reports | When an error happens while we handle a record, a piece of that record (for example a product title, SKU or quantity) can appear in the error report sent to Sentry | | Outputs | Forecasts and reorder suggestions we compute for your store |

What is not in it. We do not store, and do not ask Shopify for, any customer identifiers: no names, no email addresses, no postal addresses, no phone numbers, no IP addresses, no browser or device details, no customer ids. Our queries to Shopify do not select those fields, and our database has no columns for them.

Data subjects. Because of the above, store data does not identify any individual. In the language of data protection law, the only people it could relate to are your customers, and only as counts of what was sold. We think that puts most of it outside "personal data". We still treat it under this agreement, because you may take a different view and because it costs us nothing to do so.

Special categories. None. We do not process any sensitive data.

4. Our obligations as processor

We will:

  1. Follow your instructions only. Your instructions are: the Terms of Service, this agreement, and the settings you choose inside the app. We will not process store data for any other purpose. If a law requires us to do something else, we will tell you first unless the law forbids that. If we think an instruction breaks data protection law, we will tell you.
  2. Keep it confidential. Everyone who works on Nextstock is bound to keep your data confidential. Today, that is the owner of the business. Access to production systems is limited to people who need it to run the service.
  3. Keep it secure. Section 5 lists the measures we actually have in place. We will keep those measures, or replace them with better ones, for as long as we process your data.
  4. Use sub-processors only as section 6 allows.
  5. Help you with data subject requests as described in section 7.
  6. Help you meet your own legal duties, such as security assessments, data protection impact assessments and dealing with a regulator, as far as we reasonably can and given what we hold. Section 10 describes how.
  7. Tell you about a breach as described in section 8.
  8. Delete your data as described in section 9.
  9. Answer your reasonable questions about how we process your data, as described in section 10.

5. Security measures (Annex II)

These are the measures in place today. We list what exists, not what we plan.

What we do not have yet, stated plainly.

6. Sub-processors

You give us general permission to use the sub-processors listed here. This is the full list today.

| Provider | What it does | Where | Store data it can see | |---|---|---|---| | Railway Corporation | Runs our application servers and our database | United States (San Francisco region) | All store data, at rest and in use | | Cloudflare, Inc. | Runs our domain name and TLS, carries traffic between your browser, Shopify and our servers, and stores our nightly database backups (R2, bucket set to North America) | United States company, global network | Store data in transit, encrypted; nightly backup copies at rest, encrypted, kept 30 days | | Functional Software, Inc. (Sentry) | Receives error reports and a job heartbeat from our software so we can fix failures | United States | Technical details and store IDs; sometimes a piece of the record that caused an error, such as a product title, SKU or quantity; no customer data | | Plus Five Five, Inc. (Resend) | Delivers operational emails from our system to our own operators | United States | Counts and store IDs in operational emails; no store data otherwise. Sends no email to you today | | Google LLC (Gmail) | Hosts our email inbox (privacy@ and support@ nextstock.app) | United States | Only what you choose to email us, such as a support question or export files |

Two other providers are named for completeness, because merchants ask:

Resend carries only our own operational emails (counts and store IDs). The app sends no order, catalogue or inventory data through any email service. Google holds only what you send us by email yourself.

Changes. If we want to add or replace a sub-processor that will handle store data, we will name it in our Privacy Policy and email your store's contact email at least 30 days before it handles anything. The table above is Annex III. If you object on reasonable data protection grounds and we cannot resolve the objection, you may end the Terms of Service by uninstalling the app before the change takes effect, and we will delete your data as in section 9. Each sub-processor is bound by a written contract that imposes data protection obligations at least as protective as this agreement, and we remain responsible to you for what they do.

7. Helping with data subject requests

Requests about your customers. Because we hold nothing about any individual customer, the answer to almost every request will be: we hold nothing about that person, so there is nothing to give, correct or erase. Specifically:

Requests about your own store. You can ask for a copy of all the store data we hold, a correction, or deletion, at any time. Email [email protected] from your store's contact email with your store's Shopify address. We reply within 30 days, usually much faster.

8. Breach notification

If we become aware of a personal data breach that affects your store data, we will email your store's contact email without undue delay, and in any case within 72 hours of becoming aware. The first email will say what we know: what happened, when, what data was affected, what we have done so far, and what we suggest you do. We will keep you updated as we learn more, and we will give you what you need to notify your regulator or your customers if you decide you must.

We will not tell your customers or a regulator on your behalf unless you ask us to in writing or the law requires it of us directly. Where a US state breach law applies to data we hold for you, such as Arizona's (A.R.S. 18-552), this notice to you is how we tell the data's owner.

9. Deletion and return

On uninstall. The moment you uninstall, we erase the keys that give us access to your store. About 48 hours after you uninstall, an automatic job deletes your store record, your settings, and all order line, catalogue, inventory, forecast and suggestion data we hold for your store. Shopify also sends us a deletion request around the same time; whichever arrives first wins. If you reinstall before the deletion runs, your history stays where it is.

On request. If you want your data gone sooner, email [email protected] and we will delete it. If you want a copy first, ask before you uninstall, or within the 48 hours.

If the law says we must keep something. If a law requires us to keep any store data after deletion is due, we will tell you what and why, keep it only for that purpose, and delete it when the duty ends.

What survives. Two small proof records outlast the deletion: the notice from Shopify that you uninstalled, and Shopify's deletion request if one arrived. Each holds your store's Shopify address, the kind of notice and the time, nothing else. We keep them so we can show that the deletion happened.

Backups. Deleted rows can remain inside the nightly backup copies described in section 5 for up to 27 days after deletion, after which the copies holding them are gone. We do not restore a deleted store's data from a backup except as part of recovering the whole database from a failure, and if that ever happened after your deletion date we would delete your store's rows again as part of the recovery.

Return. Shopify keeps the original of everything we read, so you never lose data by uninstalling. If you still want a copy of what we held, ask under section 7.

10. Showing you we comply

We are a very small operator, so audits are scaled to fit.

11. International transfers

We are based in the United States and our servers and database are in the United States. If you are in the EEA, the UK or Switzerland, giving us your store data is an international transfer. We rely on the following safeguards, which are incorporated into this agreement by reference:

EU. The Standard Contractual Clauses adopted by the European Commission in Decision (EU) 2021/914, Module Two (controller to processor), with you as data exporter and us as data importer. If you are yourself a processor for someone else (for example an agency running a store for a client), Module Three (processor to processor) applies instead, with the same options. Options: Clause 7 (docking) included; Clause 9(a) option 2, general authorisation, with the 30-day notice in section 6; Clause 11 optional redress not included; Clause 13 the supervisory authority of the EU member state where you are established; Clause 17 the law of Ireland; Clause 18 the courts of Ireland. Annex I.A (the parties) is section 1 of this agreement, with your details as they appear in Shopify. Annex I.B (the transfer) is section 3; the transfer is continuous for as long as the Terms of Service last. Annex I.C (the competent authority) follows Clause 13 as set out here. Annex II is section 5. Annex III is section 6.

UK. The same clauses, as amended by the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Information Commissioner under s.119A of the Data Protection Act 2018 (version B1.0, in force 21 March 2022). Table 1 is section 1, Tables 2 and 3 are as set out above, and in Table 4 either party may end the Addendum when the Information Commissioner changes it.

Switzerland. The same clauses, read with the changes the Federal Data Protection and Information Commissioner requires: "member state" includes Switzerland, the FDPIC is the competent authority for Swiss data, and Swiss law governs where the data exporter is in Switzerland.

Onward transfer. Our sub-processor Railway is also in the United States, so there is no further international transfer once your data reaches us. Cloudflare carries encrypted traffic across its global network and holds our nightly backup copies in a bucket set to North America.

Executed copy. Email [email protected] if you want a signed copy of the clauses with the annexes filled in, and we will send one.

If the safeguards above stop being valid, we will work with you in good faith to put a replacement in place, and if none is available you may end the Terms of Service by uninstalling.

12. US state privacy laws

Where the CCPA or a similar US state law applies, we are your "service provider" (or "processor"), and we:

  1. process store data only for the business purpose in section 3, which is providing Nextstock to you;
  2. do not sell or share it (as those words are defined in the CCPA), and do not use it for advertising;
  3. do not keep, use or disclose it for any other purpose, including any commercial purpose of our own, or outside our direct business relationship with you;
  4. do not combine it with personal information we get from anyone else, except where the law allows a service provider to do so;
  5. give it the same level of privacy protection the law requires of you, and tell you if we decide we can no longer meet these duties;
  6. let you take reasonable steps to check that we use it as this agreement says (section 10), and to stop and fix any use that is not allowed;
  7. help you answer consumer requests as in section 7.

We understand these limits and will follow them.

13. Liability

Each party's liability under this agreement is subject to the limitation of liability in section 13 of the Terms of Service, and counts toward the cap there. Nothing in this section limits either party's liability to a data subject or a regulator where data protection law does not allow it to be limited. If the Standard Contractual Clauses apply and do not allow a limit (for example under their Clause 12), the limit does not apply to that liability.

14. Term and changes

This agreement lasts as long as the Terms of Service, and after that until we have deleted your store data under section 9.

We may update this agreement to reflect changes in the law, in our sub-processors, or in our security measures. We will post the new version at https://nextstock.app/dpa, update the effective date, and email your store's contact email at least 30 days before a material change takes effect. Changes that make our obligations stronger, such as adding backups or a certification, may take effect on posting.

15. Governing law

This agreement is governed by the laws of the State of Arizona, United States, the same as the Terms of Service, except that the Standard Contractual Clauses and the UK Addendum are governed by the law stated in section 11.

16. Signing

This agreement applies to you automatically from the moment you install Nextstock, if section 1 says it applies. If you want a signed copy, email [email protected] with your legal entity name, address and signatory, and we will return one signed by us.

| | Merchant (controller) | Nextstock (processor) | |---|---|---| | Legal name | | BROJAS LLC | | Address | | Available on request at [email protected] | | Signed by | | | | Title | | | | Date | | |