Skip to content

Shopxare
Are AI Shopxare Mobile Free

Hello World!

  • English
  • Deutsch
  • Português
  • Italiano
  • Español
  • Polski
  • Türkçe
Log in Start free
MessengerThe chat on your website, in your brand. InboxOne shared inbox for the whole team. Are AIAn AI agent that answers only from what you taught it. CopilotDrafts, summaries and translations for your team. Help centerAnswers your customers can find on their own. Tickets and emailEmail becomes tickets, with states and reply targets. AutomationFlows, workflows and messages that run on their own. ReportsResponse times, satisfaction and your team, at a glance. ContactsEveryone you talk to, with context. IntegrationsWordPress, WooCommerce, Shopify, JavaScript and webhooks. CallsVoice, video and screen sharing in the chat. ChannelsMessenger, email and Telegram in one inbox.

Shopxare

Why Shopxare Free Compare Security
DocsStep-by-step guides for every part Developer hubJavaScript API, webhooks, plugins DownloadMac, Windows, iOS and Android apps ChangelogWhat’s new in Shopxare

Company

About us Contact Brand guidelines System status

Compare

Shopxare vs Intercom Shopxare vs Tidio A tawk.to alternative

Product

Messenger Inbox Are AI Copilot Help center Tickets and email Automation Reports Contacts Integrations Calls Channels
Shopxare Mobile Docs Compare Why Shopxare Contact Free Security Download Changelog System status Log in
Start free
All legal documents Terms of Service Data Processing Addendum Service Level Agreement AI Terms Developer Terms App Terms Privacy Policy US State Privacy Notice Cookie Policy Sub-processors Acceptable Use Policy Refund Policy Copyright Policy Security Responsible Disclosure Policy Law Enforcement Guidelines

Data Processing Addendum

Version 3.6 · effective February 9, 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service or other written agreement (the "Agreement") between Shopxare, LLC ("Shopxare", "Processor") and the customer ("Customer", "Controller"). It applies automatically when Shopxare processes Customer Personal Data. Customers who need a signed copy can request one with the DPA request form.

1. Definitions

"Data Protection Laws" means all laws on the processing of personal data that apply to a party, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended ("CCPA"), other US state privacy laws, and Türkiye's Law No. 6698 on the Protection of Personal Data ("KVKK"). "Customer Personal Data" means personal data in Customer Data processed by Shopxare on behalf of Customer. "Controller", "processor", "data subject", "personal data breach", "processing" and "supervisory authority" have the meanings given in the GDPR. "Sub-processor" means a third party engaged by Shopxare to process Customer Personal Data.

2. Roles and scope

2.1 Customer is the controller (or a processor acting for its own controller) and Shopxare is the processor (or sub-processor) of Customer Personal Data.

2.2 Shopxare is an independent controller for account, billing and website data described in the Privacy Policy; this DPA does not apply to that data.

2.3 The subject matter, nature, purpose and duration of processing, the types of personal data and the categories of data subjects are described in Annex I.

3. Customer's obligations

Customer will: (a) give only lawful instructions; (b) have a lawful basis and provide the notices required for the processing, including for Messenger cookies and local storage on its websites; (c) not instruct Shopxare to process special categories of data except as allowed by the Acceptable Use Policy; and (d) be responsible for the accuracy of Customer Personal Data.

4. Shopxare's obligations

Shopxare will:

4.1 process Customer Personal Data only on Customer's documented instructions, which are the Agreement, this DPA and Customer's configuration and use of the Services, unless required otherwise by law (in which case Shopxare will inform Customer unless the law prohibits it); Shopxare will tell Customer if it believes an instruction infringes Data Protection Laws;

4.2 ensure that its personnel authorised to process Customer Personal Data are bound by confidentiality;

4.3 implement the technical and organisational measures in Annex II;

4.4 respect the conditions for engaging Sub-processors in section 6;

4.5 taking into account the nature of the processing, assist Customer by appropriate measures in responding to data subject requests (section 7);

4.6 assist Customer with security, breach notification, data protection impact assessments and prior consultations, taking into account the information available to Shopxare;

4.7 delete or return Customer Personal Data at the end of the Services (section 9); and

4.8 make available the information necessary to demonstrate compliance and allow audits (section 10).

5. Security and confidentiality

Shopxare maintains the measures in Annex II and may update them, provided the overall level of protection is not reduced.

6. Sub-processors

6.1 Customer gives a general authorisation for Shopxare to engage Sub-processors. The current list is on the Sub-processors page (Annex III).

6.2 Shopxare will notify Customer of a new Sub-processor at least 30 days before it starts processing Customer Personal Data, by updating the Sub-processors page and emailing customers who have subscribed to updates there or signed this DPA. Customer may object on reasonable data protection grounds within that period. The parties will discuss the objection in good faith; if it cannot be resolved, Customer may terminate the affected Services and receive a refund of prepaid fees for the remaining term.

6.3 Shopxare will impose data protection obligations on each Sub-processor that are no less protective than this DPA, and remains liable for its Sub-processors' performance.

6.4 Services that Customer chooses to connect (for example Telegram, an AI provider with Customer's own API key, WooCommerce or Shopify) are not Sub-processors of Shopxare; Customer's relationship with them is governed by their terms.

7. Data subject requests

Customer can access, correct, export and delete most Customer Personal Data itself in the Services. If Shopxare receives a request from a data subject relating to Customer Personal Data, it will forward it to Customer without undue delay and not respond itself, except to direct the data subject to Customer or as required by law.

8. Personal data breaches

8.1 Shopxare will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data.

8.2 The notice will describe, as far as known, the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Shopxare will provide further information as it becomes available and take reasonable steps to contain and remedy the breach.

8.3 Notification is not an acknowledgement of fault.

9. Deletion and return

During the Services, Customer can export Customer Personal Data. Within 30 days after the end of the Services, Shopxare will delete Customer Personal Data from its active systems; copies in backups are deleted within the backup cycle (35 days) and are protected until then. Shopxare may keep data where the law requires, subject to this DPA.

10. Audits

10.1 On request, and no more than once a year (unless a supervisory authority requires it or after a personal data breach), Shopxare will answer a reasonable security questionnaire and provide its current security documentation.

10.2 If that is not enough to demonstrate compliance, Customer may conduct an audit, on at least 30 days' written notice, during business hours, without unreasonably disrupting Shopxare's operations, under a confidentiality agreement and at Customer's cost. Audits of Sub-processors are performed by relying on their reports and certifications.

11. International transfers

11.1 Customer Personal Data is stored on servers in Türkiye and may be processed in the United States and other countries where Shopxare or its Sub-processors operate.

11.2 EEA. To the extent Customer Personal Data subject to the GDPR is transferred to a country without an adequacy decision, the parties incorporate the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 ("SCCs"): Module Two (controller to processor) where Customer is a controller, and Module Three (processor to processor) where Customer is a processor. For the SCCs: clause 7 (docking) applies; under clause 9, option 2 (general authorisation) applies with the notice period in section 6.2; the optional language in clause 11 does not apply; under clauses 17 and 18, the law and courts of Ireland apply; Annexes I to III of the SCCs are completed by Annexes I to III of this DPA.

11.3 UK. For transfers subject to the UK GDPR, the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner applies, with Table 1 completed by Annex I, Table 2 by section 11.2, Table 3 by Annexes I to III, and Table 4 allowing either party to end it.

11.4 Switzerland. For transfers subject to Swiss law, the SCCs apply with the Swiss Federal Data Protection and Information Commissioner as the competent authority and references to the GDPR read as references to Swiss law.

11.5 Türkiye. For transfers subject to the KVKK, the parties will use the standard contract published by the Turkish Personal Data Protection Authority where required, and Customer will make any required notification to the Authority.

11.6 If a transfer mechanism is invalidated, the parties will cooperate to put an alternative in place.

12. US privacy laws

To the extent the CCPA or similar US state laws apply, Shopxare acts as a "service provider" or "processor". Shopxare will not: (a) sell or share Customer Personal Data; (b) retain, use or disclose it for any purpose other than providing the Services, or outside the direct business relationship with Customer; (c) combine it with personal data from other sources, except as allowed by law; and Shopxare will comply with the applicable obligations of those laws, provide the same level of protection they require, and notify Customer if it can no longer meet them. Customer may take reasonable steps to stop and remediate unauthorised use. Shopxare certifies that it understands these restrictions.

13. Liability and precedence

Each party's liability under this DPA is subject to the limitations in the Agreement, except where Data Protection Laws or the SCCs do not allow it. If this DPA conflicts with the Agreement, this DPA prevails for the processing of Customer Personal Data; if it conflicts with the SCCs, the SCCs prevail.


Annex I — Description of the processing

Data exporter: Customer, as identified in the Agreement or its Workspace; contact: the Workspace owner. Role: controller or processor. Activities: use of the Services.

Data importer: Shopxare, LLC, 2318 Garden Rd, Shopxare Park, Monterey, CA 93940, United States; [email protected]. Role: processor. Activities: providing the Services.

Categories of data subjects: Customer's End Users (website visitors, customers, prospects and other people who contact Customer), and Customer's Users (teammates).

Categories of personal data: names, email addresses, phone numbers, user IDs and attributes Customer sends; message content and files; Telegram and email identifiers; page visits, events, device, browser, language and approximate location (derived from IP address); call signalling data (calls are not recorded); conversation ratings; teammate names, photos and job titles.

Special categories: none intended; any special categories arise only if End Users include them in messages, in which case the security measures of Annex II apply.

Frequency: continuous.

Nature and purpose: hosting, storage, transmission, display, search, analysis (including by AI features Customer enables), translation and deletion, to provide the Services to Customer.

Retention: for the duration of the Agreement, then as described in section 9.

Sub-processor transfers: as listed in Annex III, for the purposes stated there.

Competent supervisory authority: the authority determined in accordance with clause 13 of the SCCs.

Annex II — Technical and organisational measures

The measures are described in our Security overview and include: encryption of data in transit (TLS 1.2+); encryption of stored credentials such as integration tokens and API keys; salted password hashing; two-step verification and sign-in approval for teammates; role-based access control and tenant isolation enforced in the application; audit logs; access to production systems restricted to authorised Shopxare personnel; network protection and DDoS mitigation through Cloudflare; rate limiting; signed webhooks; identity verification (HMAC) for Messenger users; daily backups kept for 35 days; monitoring and a public status page; incident response procedures; secure development practices with automated tests before each release; and confidentiality obligations for personnel.

Annex III — Sub-processors

See the Sub-processors page, which forms part of this DPA.

Shopxare

Customer messaging for teams that care about every conversation.

Product

Messenger Inbox Are AI Copilot Help center Tickets and email Automation Reports Contacts Integrations Calls Channels

Company

Why Shopxare About us Contact Brand guidelines Free [email protected]

Resources

Docs Developer hub Download Mobile app Compare Security Changelog System status

Legal

Terms of Service Privacy Policy Cookie Policy Data Processing Addendum Sub-processors Acceptable Use Policy All legal documents

© 2026 Shopxare, LLC

Hello World!

  • English
  • Deutsch
  • Português
  • Italiano
  • Español
  • Polski
  • Türkçe

We use only the cookies the site needs to work, like remembering your language. No tracking or advertising cookies. Cookie policy