Data Processing Agreement
Last updated: December 1, 2025
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Slingshot and you ("Merchant") and governs the processing of personal data.
1. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Processing" means any operation performed on Personal Data.
- "Data Controller" means the Merchant who determines the purposes and means of processing.
- "Data Processor" means Slingshot, who processes data on behalf of the Merchant.
2. Scope of Processing
Slingshot processes Personal Data solely to provide back-in-stock notification services. The categories of data processed include:
- Customer email addresses
- Customer phone numbers (if SMS enabled)
- Product subscription preferences
- Notification delivery and engagement data
3. Processor Obligations
Slingshot agrees to:
- Process Personal Data only on documented instructions from the Merchant
- Ensure persons authorized to process data are bound by confidentiality
- Implement appropriate technical and organizational security measures
- Assist the Merchant in responding to data subject requests
- Delete or return all Personal Data upon termination of services
- Make available all information necessary to demonstrate compliance
4. Sub-processors
Slingshot uses the following sub-processors:
- Resend Inc. (USA) - Email delivery
- Twilio Inc. (USA) - SMS delivery
- Neon Inc. (USA) - Database hosting
- Vercel Inc. (USA) - Application hosting
5. International Transfers
Personal Data may be transferred to the United States. Such transfers are protected by Standard Contractual Clauses approved by the European Commission.
6. Security Measures
Slingshot implements the following security measures:
- Encryption of data in transit (TLS 1.3) and at rest (AES-256)
- Access controls and authentication
- Regular security assessments
- Incident response procedures
7. Data Breach Notification
Slingshot will notify the Merchant of any Personal Data breach without undue delay and within 72 hours of becoming aware of the breach.