Version 1.1, effective September 24, 2026. Version 1.1 only renames EcomBrain to Commerce Spine and updates the web addresses; nothing else changed. Questions: [email protected]
This Data Processing Addendum ("DPA") is between SellerPlex LLC, a Wyoming limited liability company at 1910 Thomes Ave, Cheyenne, WY 82001, USA ("SellerPlex", "we"), and the customer identified in the Commerce Spine account ("Customer", "you").
This DPA is part of, and incorporated into, the Commerce Spine Terms of Service (https://www.commercespine.com/terms/, the "Terms"). It applies whenever we process personal data contained in Customer Data on your behalf. Capitalized terms not defined here have the meanings in the Terms. For how we handle personal data on our own behalf (marketing site visitors, account contacts, billing), see the Privacy Policy (https://www.commercespine.com/privacy/).
For personal data within Customer Data, you are the controller (or business) and we are the processor (or service provider). You are responsible for having a lawful basis to collect and use that data and for the accuracy of your instructions. We are responsible for processing it only as this DPA and the Terms allow.
We process Customer Data for one purpose: to operate the Commerce Spine warehouse and API for your Organization. Concretely, that means syncing your data from Amazon under the authorization you granted, storing it in your Organization's warehouse on Google Cloud Platform, serving it to your Tokens through the read-only API, and maintaining backups and logs needed to run the Service reliably.
We will not:
Annex A describes the processing details (subject matter, duration, nature, categories of data and data subjects).
We process Customer Data only on your documented instructions. The Terms, this DPA, and your use of the Service's settings and features (for example, connecting or disconnecting an Amazon account, issuing or revoking a Token, cancelling your subscription) are your complete instructions. If a law requires us to process differently, we will tell you before we do, unless the law forbids that notice. If we believe an instruction violates data protection law, we will flag it and may pause the affected processing until it is resolved.
We limit access to Customer Data to personnel who need it to operate or support the Service, and we require everyone with access to be bound by confidentiality obligations, whether by contract or professional duty, before they touch it.
We protect Customer Data with appropriate technical and organizational measures. The specifics we commit to today:
We will not materially weaken this overall level of protection during your subscription. We may improve or replace individual measures as the Service and threat landscape evolve.
If a data subject sends us a request about personal data in your Customer Data (access, deletion, correction, and similar rights), we will not respond on your behalf; we will redirect the person to you where identifiable and notify you promptly. Given the nature of the data, we usually cannot identify a data subject inside your warehouse ourselves. Where you cannot fulfill a request through the console or API on your own, we will provide reasonable assistance at your written request.
If we confirm a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Data, we will notify you without undue delay, and in any case within 72 hours of confirming the breach. The notice will describe what happened, the data affected so far as known, and the steps we are taking. We will keep you updated as the investigation progresses and cooperate with your own notification obligations. Notification is not an admission of fault.
Customer Data is hosted in the United States on Google Cloud Platform. If you are subject to GDPR, UK GDPR, or similar laws that restrict transfers to the US, the EU Standard Contractual Clauses (module 2, controller to processor), with the UK Addendum where applicable, are incorporated into this DPA by reference and apply to those transfers. A countersigned copy is available on request via [email protected].
When your subscription ends, we delete your Organization's warehouse data within 30 days. Backups containing your data expire on a rolling basis and are purged within a further 35 days as part of the normal backup rotation. During the 30-day window you may ask us for reasonable help exporting your data. We may retain limited records where the law requires (for example, billing records), protected under this DPA for as long as we hold them.
Given the size and stage of the Service, audits work as follows: on written request, no more than once per year, we will provide a summary of our security measures, relevant certifications or attestations from our infrastructure providers (for example, Google Cloud's SOC 2 and ISO 27001 reports), and written answers to reasonable security questionnaires. This is intended to satisfy audit and information rights. If your regulator requires more, we will discuss reasonable additional steps at your cost.
Liability under this DPA is subject to the limitations and carve-outs in Section 12 of the Terms. This DPA does not create a separate or higher cap.
Current as of September 24, 2026. Changes follow the notice process in Section 8.2.
| Entity | Role | What it processes | Location |
|---|---|---|---|
| Google Cloud Platform (Google LLC) | Subprocessor | Warehouse hosting, storage, and backups for Customer Data | United States |
| Stripe, Inc. | Subprocessor | Payment and billing data for the Customer's subscription (not warehouse data) | United States |
| HighLevel Inc. (GoHighLevel) | Subprocessor | CRM for marketing-side lead and contact data (not warehouse data) | United States |
| Amazon (Amazon.com, Inc. and affiliates) | Data source, not a subprocessor (see Section 8.3) | Provides Customer Data under the Customer's own authorization | Per Amazon's infrastructure |