Back to home

Legal

Data Processing Agreement

When Vendmint processes your end customers' personal data on your behalf, it does so as a processor under this agreement, which forms part of our Terms of Service.

Last updated: July 16, 2026

On this page

Subject matter and duration

This agreement applies when Vendmint (processor) processes personal data on your behalf (controller) to provide the service. It lasts as long as we process that data under the Terms.

Nature and categories of data

We process the data your end customers submit through your stores, mainly:

  • Data subjects: your end customers and store visitors.
  • Data categories: form submission fields (may include name, email, message, etc.), order and delivery data (including InPost delivery details, when enabled), the sent discount-code registry (the code recipient's email address, when you enable the autoresponder) and technical metadata such as a hashed IP address and user agent.
  • Purpose: storing and forwarding form submissions, handling orders and deliveries (including notifying you of paid orders — also by push notification, if you enable it), keeping visit statistics for your store, and hosting it.
  • Purpose — form automations, when you enable them: sending, on your behalf, a discount-code email to the person signing up via a form (including keeping a registry of sent codes so the same address never receives a code twice) and forwarding submissions to recipients you designate — your webhook or your own account at a mailing provider (MailerLite, Mailchimp, Brevo).

Our obligations as processor

  • We process personal data only on your documented instructions, including per your store configuration.
  • We keep the data confidential and ensure that persons acting under our authority are bound by confidentiality.
  • We implement appropriate technical and organizational measures (Art. 32).

Subprocessors

You give general consent to our use of the subprocessors listed on the Subprocessors page. We inform you of intended changes (additions or replacements) so you can object on justified data-protection grounds.

Technical and organizational measures

  • Encryption of sensitive credentials at rest (AES-256-GCM) and of data in transit (TLS).
  • Hashing of IP addresses from form submissions (SHA-256).
  • Access control and isolation of build processes.

Breach notification

We will notify you without undue delay after becoming aware of a personal data breach affecting data we process for you, with the information you need to meet your own notification obligations.

Assistance with data subject requests

Taking into account the nature of the processing, we help you respond to data subject requests and meet your obligations under Articles 32 to 36.

Audits

We make available the information needed to demonstrate compliance and allow reasonable audits, which can usually be satisfied with documentation and a security summary.

Return and deletion

At the end of the service, and at your choice, we delete or return the personal data we process for you, unless the law requires us to keep it.

International transfers

When a subprocessor processes data outside the European Economic Area, transfers are protected by standard contractual clauses or an equivalent mechanism, as indicated on the Subprocessors page.

Still have a question?

If anything here is unclear, we would rather explain it than leave you guessing.

Contact us