← Privacy Policy

Legal notice

Data Processing Addendum

Effective and last updated July 17, 2026

This public Addendum establishes baseline privacy and security terms for merchant integrations when CommuterCart acts as a processor or service provider.

1. Scope and roles

This Data Processing Addendum applies when CommuterCart processes personal information for a merchant solely on the merchant’s documented instructions through a POS product, widget, API, dashboard, or white-label service. The merchant is the controller or business and CommuterCart is the processor or service provider for that processing. Each party remains independently responsible for processing it determines for its own delivery, payment, safety, security, fraud-prevention, legal, or recordkeeping purposes.

2. Instructions and permitted processing

CommuterCart processes merchant personal information only to provide, secure, support, and improve the contracted service; create and fulfill authorized delivery requests; provide analytics; comply with documented instructions; and satisfy applicable law. The merchant will submit only necessary information, maintain a lawful basis, provide required notices, honor customer choices, and not instruct CommuterCart to process information unlawfully.

3. Confidentiality and security

CommuterCart limits access to personnel and providers with a need to know and appropriate confidentiality duties. We maintain administrative, technical, and physical safeguards appropriate to the nature and risk of the information, including access controls, authentication, encryption where appropriate, logging, monitoring, secure development, vendor review, and incident response.

4. Subprocessors

The merchant authorizes subprocessors needed for hosting, databases, mapping, payments, identity, communications, analytics, security, support, document storage, and AI services. CommuterCart requires subprocessors to protect merchant personal information through written obligations appropriate to their services and remains responsible for their processing to the extent required by law and contract.

CommuterCart will make a current subprocessor list or equivalent information available on reasonable request. When a signed agreement requires advance notice of a new material subprocessor, CommuterCart will provide that notice and a reasonable opportunity to raise a documented data-protection objection. The parties will work in good faith on a commercially reasonable solution; an objection does not require CommuterCart to disclose another customer's confidential information or operate without a provider necessary to deliver the service.

5. Rights, incidents, and compliance assistance

Taking into account the nature of processing, CommuterCart provides reasonable assistance with verified privacy requests, security incidents, legally required assessments, regulator inquiries, and information reasonably needed to demonstrate compliance. Unless law prohibits notice, CommuterCart will notify the merchant of a confirmed incident affecting merchant personal information without undue delay after confirmation and provide available information concerning the nature, affected information, likely consequences, containment, remediation, and contact point needed for the merchant's legal obligations. Notice is not an admission of fault or liability.

CommuterCart will not independently respond to a verified request concerning merchant-controlled information except on documented instruction or where law requires. The merchant remains responsible for determining the response, communicating with the requester, and ensuring its instructions are lawful.

6. Retention, return, and deletion

During the service, CommuterCart retains information under the Privacy Policy and the applicable order form. At termination or documented request, CommuterCart deletes, returns, de-identifies, or securely isolates merchant personal information unless continued retention is required or permitted for transactions, taxes, claims, fraud prevention, safety, legal holds, backups, or law.

Upon reasonable written request after required deletion is complete, CommuterCart will provide available confirmation of deletion or describe the lawful exception and applicable isolation. Routine backups may persist until overwritten under the ordinary backup cycle and remain protected and unavailable for ordinary use.

7. U.S. privacy-law restrictions

Where CommuterCart acts as a service provider, contractor, or processor under an applicable U.S. privacy law, it will not sell or share merchant personal information; retain, use, or disclose it outside the specified business purposes and direct relationship except as permitted by law; combine it with personal information from another source except as legally permitted; or use it for cross-context behavioral advertising. CommuterCart will notify the merchant if it determines it can no longer meet an applicable restriction and will permit reasonable steps to stop and remediate unauthorized use.

8. Transfers and audits

CommuterCart uses legally required safeguards for cross-border transfers. If a legally required transfer mechanism, including applicable standard contractual clauses, is necessary for the contracted processing, the parties will incorporate the current mechanism and required annex information through the order form or a written addendum.

Upon reasonable request, CommuterCart provides available security and compliance information. Any audit must protect other customers, security, confidential information, and trade secrets and will ordinarily rely first on current independent reports, questionnaires, and documentation. A further audit must be legally required or supported by a material unresolved concern, use an independent qualified reviewer, avoid disruption, and comply with reasonable security and confidentiality controls.

9. Processing details

The subject matter is the merchant service and authorized delivery activity; duration is the service term plus documented retention; nature includes collection, hosting, organization, transmission, retrieval, analysis, support, security, deletion, and other processing needed to provide the service; purposes are stated in the agreement and documented instructions. Data subjects may include customers, Recipients, pickup contacts, merchant personnel, Drivers, suppliers, and support contacts. Information may include identifiers, contact and address data, orders, products, delivery instructions, transaction status, communications, device and usage data, proof records, and other categories stated in the order form. Sensitive information may be submitted only through an expressly approved workflow.

10. Agreement and contact

This Addendum supplements the Merchant Platform Terms at /merchant-terms and applicable order form. A signed order form or negotiated data-processing agreement controls if it expressly conflicts with this public Addendum. Merchant support and contractual notices may be submitted through /support. Privacy rights requests must use /privacy-request, or mailed to CommuterCart, 186 Main Street, Farmington, ME 04938, United States.