SHIP ZONE LLC — DATA PROCESSING AGREEMENT

Effective Date: March 20, 2026

This Data Processing Agreement (“DPA”) forms part of the Ship Zone LLC Terms of Service or other written agreement governing a customer’s use of Ship Zone’s Services (the “Agreement”). This DPA is entered into between Ship Zone LLC (“Ship Zone,” “Processor,” “Service Provider,” “we,” “us,” or “our”) and the customer or business accepting the Agreement (“Customer,” “Controller,” “Business,” “you,” or “your”).

This DPA governs Ship Zone’s Processing of Personal Data on behalf of Customer in connection with the Services. By using Services involving the Processing of Personal Data, Customer agrees that this DPA is incorporated into and forms part of the Agreement.

1. Purpose

Ship Zone provides shipping, logistics-management, parcel, freight, ocean-freight, e-commerce, marketplace-integration, API, fulfillment-support, tracking, label-generation, and related technology Services. In providing these Services, Ship Zone may Process Personal Data supplied or made available by Customer. This DPA establishes the parties’ respective responsibilities concerning such Personal Data.

2. Definitions

2.1 “Applicable Data Protection Law” means privacy, data-protection, and information-security laws applicable to the Processing governed by this DPA, including applicable U.S. federal and state privacy laws.
2.2 “Controller” means the person or entity that determines the purposes and means of Processing Personal Data, or the equivalent term (“Business” under U.S. state law) under Applicable Data Protection Law.
2.3 “Customer Data” means information, including Personal Data, submitted, transmitted, uploaded, imported, accessed, or otherwise made available to Ship Zone by or on behalf of Customer in connection with the Services.
2.4 “Data Subject” means an identified or identifiable individual to whom Personal Data relates.
2.5 “Personal Data” means information relating to an identified or identifiable individual, and includes equivalent terms such as “personal information.”
2.6 “Processing” means any operation performed on Personal Data, including collecting, accessing, receiving, organizing, storing, using, transmitting, disclosing, retrieving, modifying, deleting, or destroying such information.
2.7 “Processor” means an entity that Processes Personal Data on behalf of a Controller, or the equivalent role (“Service Provider” or “Contractor” under U.S. state law) under Applicable Data Protection Law.
2.8 “Security Incident” means a confirmed breach of security resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Customer Personal Data Processed by Ship Zone. A Security Incident does not include unsuccessful attempts or activities that do not compromise Customer Personal Data, such as unsuccessful login attempts, scans, pings, denial-of-service attempts, or attacks blocked by appropriate security controls.
2.9 “Subprocessor” means a third party engaged by Ship Zone to Process Customer Personal Data on behalf of Customer in connection with the Services.
2.10 “Restricted Marketplace Integration” has the meaning given in the Terms of Service: an authorized connection to a third-party marketplace whose own program terms require Ship Zone not to publicly name that marketplace. “Restricted Marketplace Information” means Personal Data and other information Ship Zone receives or Processes through a Restricted Marketplace Integration.

3. Roles of the Parties

To the extent Ship Zone Processes Personal Data solely on behalf of Customer in providing the Services, Customer acts as the Controller or Business, and Ship Zone acts as the Processor or Service Provider. Ship Zone may independently act as a Controller or Business for certain information processed for its own legitimate business purposes, including account administration, billing, payment management, fraud prevention, security, legal compliance, tax and accounting, business records, claims and disputes, enforcement of agreements, and operation and improvement of Ship Zone’s Services where permitted by applicable law. Such independent Processing is governed primarily by Ship Zone’s Privacy Policy and applicable law.

4. Customer Instructions

Customer instructs Ship Zone to Process Customer Personal Data as reasonably necessary to provide the Services, create shipments, obtain shipping quotations, purchase transportation services, generate shipping labels, process fulfillment information, provide shipment tracking, arrange parcel and freight transportation, support ocean-freight transactions, facilitate customs documentation, communicate with carriers, operate authorized integrations, provide technical and customer support, prevent fraud, maintain security, comply with applicable legal obligations, and perform other Processing reasonably necessary to provide Services requested by Customer. The Agreement, this DPA, Customer’s configuration of the Services, API requests, integration settings, and other documented instructions collectively constitute Customer’s instructions to Ship Zone.

5. Customer Responsibilities

Customer represents and warrants that: (1) Customer has complied and will comply with Applicable Data Protection Law; (2) Customer has all necessary rights, permissions, notices, consents, and lawful bases required to provide Personal Data to Ship Zone; (3) Customer is authorized to instruct Ship Zone to Process such Personal Data; (4) Customer’s instructions do not violate Applicable Data Protection Law; (5) Customer will not instruct Ship Zone to Process Personal Data for unlawful purposes; (6) Customer is responsible for the accuracy and lawfulness of Customer Data; (7) Customer will provide all legally required privacy notices to its customers, recipients, employees, and other Data Subjects; (8) Customer will maintain appropriate security over its Ship Zone account, users, API credentials, and connected platforms; and (9) Customer will comply with applicable marketplace, carrier, and platform requirements. Customer is solely responsible for determining whether the Services are appropriate for Customer’s legal and regulatory requirements.

6. Categories of Data Subjects

Customer Personal Data may concern Customer’s employees, authorized users, merchants, sellers, senders, purchasers, shipment recipients, consignees, customers of Customer, customer-support contacts, business contacts, and other individuals whose information Customer submits through the Services.

7. Categories of Personal Data

Depending upon Customer’s use of the Services, Ship Zone may Process:

  • Identity Information: first name, last name, business name, account identifiers.
  • Contact Information: email address, telephone number, billing/pickup/delivery/return address.
  • Shipment Information: order numbers, shipment identifiers, tracking numbers, shipment contents, commodity descriptions, package weight/dimensions, declared value, customs information, delivery instructions, fulfillment information.
  • Marketplace Information: where Customer connects an authorized marketplace or e-commerce integration (including a Restricted Marketplace Integration) — marketplace/seller/store identifiers, order information, recipient information, fulfillment information, shipment information, tracking information.
  • Technical Information: IP addresses, login information, API activity, device information, system logs, security information.

8. Purpose and Nature of Processing

Ship Zone Processes Customer Personal Data for shipping, fulfillment, transportation management, shipment documentation, rate calculation, label generation, tracking, carrier communication, customs support, marketplace and e-commerce integration, customer and technical support, fraud prevention, security, and related logistics-management functions. Processing may include collection, retrieval, organization, transmission, storage, use, disclosure to authorized providers, and deletion.

9. Duration of Processing

Ship Zone may Process Customer Personal Data for the duration of the Agreement and thereafter only for as long as necessary to complete authorized Services, permitted by this DPA or applicable platform requirements, or required or permitted by applicable law. Different categories of Personal Data may be subject to different retention requirements.

10. Confidentiality

Ship Zone will take reasonable measures designed to ensure that persons authorized to Process Customer Personal Data are subject to appropriate confidentiality obligations. Access to Customer Personal Data will be limited to personnel and authorized providers with a legitimate need for access in connection with the Services or other permitted purposes.

11. Security

Ship Zone will maintain reasonable and appropriate administrative, organizational, physical, and technical safeguards designed to protect Customer Personal Data against unauthorized access, acquisition, disclosure, alteration, destruction, or loss, as further described in Schedule B. Customer acknowledges that no Internet transmission, computer network, database, software platform, cloud environment, or electronic-storage system can be guaranteed to be completely secure, and Ship Zone does not warrant or guarantee that Security Incidents will never occur. Nothing in this provision reduces Ship Zone’s obligations under Applicable Data Protection Law that cannot lawfully be limited.

12. Restricted Marketplace Integration Processing

Where Customer authorizes Ship Zone to access information through a Restricted Marketplace Integration, additional requirements apply, as further described in Schedule C. Ship Zone will Process Restricted Marketplace Information only for authorized purposes associated with providing Services requested by the applicable Customer, will not sell Restricted Marketplace Information, and will not use Restricted Marketplace Information for purposes prohibited by the applicable marketplace’s program requirements. Ship Zone will apply the applicable marketplace’s security, access, use, sharing, retention, and deletion requirements to Restricted Marketplace Information, and where those requirements are stricter than the general requirements of this DPA, they will govern. Restricted Marketplace credentials, authorization tokens, and related authentication information are treated as confidential security information and are not intentionally exposed publicly; Customer is responsible for protecting any such credentials under Customer’s own control.

13. Other Marketplace and E-Commerce Data

Where Customer authorizes Ship Zone to connect to Shopify, Etsy, eBay, WooCommerce, or another marketplace, e-commerce service, or application, Ship Zone may Process information made available through the authorized connection in accordance with Customer’s instructions, applicable platform permissions, applicable contractual requirements, this DPA, and Applicable Data Protection Law. Where a platform imposes stricter requirements on its information, Ship Zone will apply such requirements where applicable.

14. Subprocessors

Customer authorizes Ship Zone to engage Subprocessors reasonably necessary to provide, support, secure, and maintain the Services, including providers of cloud infrastructure, data hosting, cybersecurity, communications, customer support, software infrastructure, analytics, and payment processing. Ship Zone will require applicable Subprocessors that Process Customer Personal Data on Ship Zone’s behalf to maintain data-protection obligations appropriate to the nature of their Processing. Ship Zone will make available, upon written request, a current list of the categories of Subprocessors materially involved in Processing Customer Personal Data, and will provide reasonable advance notice of the addition of a new Subprocessor where required by Applicable Data Protection Law, so that Customer may object on reasonable data-protection grounds; if the parties cannot resolve the objection, Customer’s remedy is to discontinue the Services affected by that Subprocessor.

15. Carriers and Logistics Providers

Customer specifically authorizes Ship Zone to transmit necessary Personal Data to carriers and logistics providers selected, requested, or otherwise used to perform Customer’s Shipment, including parcel carriers, postal operators, couriers, freight carriers, trucking companies, freight forwarders, ocean carriers, airlines, customs brokers, warehouses, and insurance providers. Once an independent carrier or logistics provider receives Personal Data for its own transportation, regulatory, customs, or operational purposes, that provider may act as an independent Controller under applicable law, and Ship Zone does not control that provider’s independent Processing activities.

16. Third-Party Controllers

A third party receiving information from Ship Zone may be an independent Controller rather than a Subprocessor. Where that occurs, the third party’s Processing is governed by its own legal obligations, contractual terms, and privacy practices. To the maximum extent permitted by applicable law, Ship Zone is not responsible for the independent acts, omissions, privacy practices, security practices, or Processing activities of independent third-party Controllers.

17. International Data Transfers

Customer acknowledges that the Services involve international shipping and technology infrastructure. Customer Personal Data may therefore be transferred to or Processed in countries other than the country where Customer or the Data Subject is located, including the United States, Canada, Costa Rica, and other jurisdictions in which Ship Zone, its service providers, carriers, platforms, or logistics providers operate. Where Applicable Data Protection Law requires specific safeguards for an international transfer for which Ship Zone is responsible, Ship Zone will implement applicable legally required transfer mechanisms (which may include standard contractual clauses or an equivalent recognized mechanism).

18. Data Subject Requests

If Ship Zone receives a request from a Data Subject concerning Customer Personal Data that Ship Zone Processes solely on behalf of Customer, Ship Zone may direct the Data Subject to Customer where appropriate. Taking into account the nature of the Processing and where required by Applicable Data Protection Law, Ship Zone will provide reasonable assistance to Customer in responding to qualifying Data Subject requests. Customer remains responsible for determining whether and how a request should be fulfilled where Customer acts as Controller, including receiving privacy requests, verifying identity, determining applicable legal exceptions, and providing required responses; Ship Zone does not provide legal advice concerning Customer’s obligations to Data Subjects.

19. Security Incidents

Upon becoming aware of a Security Incident affecting Customer Personal Data for which notification to Customer is required under Applicable Data Protection Law, Ship Zone will notify Customer without undue delay as required by applicable law. Such notification will not constitute an acknowledgment or admission of fault or liability by Ship Zone. Where reasonably available and legally required, Ship Zone may provide information concerning the nature of the Security Incident, categories of affected information, remediation measures, and other information reasonably necessary for Customer’s compliance obligations.

20. Customer Security Incidents

Customer must notify Ship Zone promptly if Customer becomes aware of compromised Ship Zone or API credentials, unauthorized Ship Zone account access, unauthorized marketplace connections, unauthorized access by Customer personnel, or other circumstances that may affect the security of Customer Data within the Services. Ship Zone is not responsible for Security Incidents caused solely by Customer’s systems, personnel, credentials, applications, or failure to follow reasonable security practices, except to the extent responsibility cannot legally be excluded.

21. Return and Deletion of Personal Data

Upon termination of the applicable Services, Ship Zone will delete or return Customer Personal Data where required by Applicable Data Protection Law and according to applicable retention requirements. Ship Zone may retain information where retention is permitted or required for legal obligations, tax records, accounting, customs records, fraud prevention, security, claims, insurance matters, chargebacks, disputes, litigation, contract enforcement, regulatory obligations, or other lawful purposes; where retained under such an exception, the information remains subject to applicable protections until deletion is appropriate. Where an authorized marketplace requires particular information to be deleted sooner than Ship Zone’s standard retention period, Ship Zone will apply that requirement.

22. Audits and Compliance Information

Where required by Applicable Data Protection Law, Ship Zone will make reasonably necessary information available to demonstrate compliance with applicable Processor obligations. Any audit or assessment requested by Customer must be legally required or reasonably justified, protect Ship Zone’s confidential information and that of other customers, avoid unreasonable disruption, comply with reasonable security requirements, and be conducted at Customer’s expense unless applicable law requires otherwise. Ship Zone may satisfy an audit request by providing appropriate third-party certifications, assessment reports, security documentation, questionnaires, or similar materials where legally sufficient. Customer may not obtain access to systems, source code, infrastructure, or records that would compromise the security, confidentiality, or privacy of Ship Zone or other customers.

23. Government Requests

Ship Zone may disclose Customer Personal Data where required by applicable law, subpoena, court order, governmental demand, regulatory requirement, or other lawful process. Where legally permitted and appropriate, Ship Zone may notify Customer of such a request.

24. Aggregated and De-Identified Information

Where permitted by Applicable Data Protection Law, applicable contracts, and applicable platform requirements, Ship Zone may create and use aggregated or de-identified information that cannot reasonably identify Customer or an individual, for purposes including analytics, security, fraud prevention, performance measurement, capacity planning, service improvement, and business intelligence. Ship Zone will not attempt to re-identify de-identified information where prohibited by applicable law.

25. Restricted Processing

Ship Zone will not knowingly sell Customer Personal Data processed solely on behalf of Customer to data brokers; retain, use, or disclose Customer Personal Data for prohibited purposes; use Restricted Marketplace Information for purposes prohibited by the applicable marketplace’s requirements; or combine restricted Customer Personal Data in a manner prohibited by Applicable Data Protection Law. This provision does not prevent Ship Zone from Processing information for permitted security, fraud prevention, legal compliance, billing, operational, or other purposes allowed under applicable law.

26. CCPA and U.S. State Privacy Requirements

To the extent applicable U.S. state privacy legislation treats Ship Zone as a Service Provider, Processor, or Contractor concerning Customer Personal Data, Ship Zone will comply with applicable statutory obligations for that role, including by:

  • Processing Customer Personal Data only for the business purposes specified by Customer and the Agreement and not retaining, using, or disclosing it outside those business purposes, except as otherwise permitted by applicable law;
  • Not selling or sharing Customer Personal Data as those terms are defined under applicable state law;
  • Not combining Customer Personal Data with personal information Ship Zone receives from another source, except as permitted by applicable law; and
  • Providing Customer with the ability to review, correct, or delete Customer Personal Data as required for Customer to respond to verified consumer requests under applicable state law.

Nothing in this DPA requires Ship Zone to assume obligations under a law that does not apply to Ship Zone or the applicable Processing activity.

27. Canadian Privacy Requirements

Where Canadian federal or provincial privacy law (including PIPEDA) applies to the Processing governed by this DPA because Customer or a Data Subject is located in Canada, the parties will comply with applicable requirements for their respective roles. Customer remains responsible for determining the legal basis upon which Customer collects and provides Personal Information to Ship Zone.

28. Customer Indemnification

29. Limitation of Liability

30. Third-Party Liability

To the maximum extent permitted by applicable law, Ship Zone is not responsible under this DPA for a Security Incident, privacy violation, unauthorized Processing, or other act or omission caused exclusively by Customer, Customer’s employees or contractors, Customer’s applications or devices, Customer-controlled credentials, an independent carrier, an independent marketplace, a governmental authority, or another independent third-party Controller, except where Ship Zone is independently responsible under applicable law.

31. Conflicts

If this DPA conflicts with the Agreement concerning the Processing of Customer Personal Data, this DPA will control solely with respect to that conflict. If an applicable mandatory privacy law requires a provision different from this DPA, the mandatory requirement will control to the extent required. If an applicable Restricted Marketplace Integration’s requirements impose stricter obligations concerning its information, that requirement will govern that information.

32. Changes to This DPA

Ship Zone may update this DPA where reasonably necessary to reflect changes to the Services, Applicable Data Protection Law, new privacy or security requirements, new integrations, marketplace requirements, or changes to Ship Zone’s Processing activities. Material changes will be handled in accordance with applicable law and the Agreement.

33. Termination

This DPA remains effective for as long as Ship Zone Processes Customer Personal Data governed by this DPA. Termination of Customer’s account or Agreement does not terminate provisions that by their nature must survive, including confidentiality, data retention, deletion, liability, indemnification, and legal-compliance obligations.

34. Governing Law; Dispute Resolution

Unless Applicable Data Protection Law requires otherwise, this DPA is governed by the same governing law, and any dispute arising out of or relating to this DPA is subject to the same binding arbitration agreement and class action waiver, set out in the Terms of Service.

35. Entire Data Processing Agreement

This DPA, together with the Agreement, Privacy Policy, and any applicable written addendum, constitutes the parties’ agreement concerning Ship Zone’s Processing of Customer Personal Data on Customer’s behalf.

36. Contact Information

Questions concerning this DPA or privacy matters may be directed to:
Ship Zone LLC
Privacy / Data Protection Contact

For DPA inquiries, use subject line “Data Processing Agreement.” For privacy requests, use subject line “Privacy Request.” For requests concerning a Restricted Marketplace Integration, use subject line “Marketplace Integration Privacy Request.”

SCHEDULE A — DETAILS OF PROCESSING

Subject Matter: Provision of Ship Zone’s shipping, logistics, e-commerce integration, marketplace integration, fulfillment-support, API, label-generation, tracking, parcel, freight, and related Services.
Duration: For the duration of the Services and applicable authorized or legally required retention periods.
Nature of Processing: Collection, receipt, organization, retrieval, use, transmission, storage, disclosure to authorized providers, support, security, and deletion.
Purpose: To provide, support, maintain, secure, and improve the Services requested by Customer and satisfy applicable legal and contractual obligations.
Categories of Data Subjects: Customer users, employees, merchants, sellers, senders, purchasers, shipment recipients, consignees, Customer’s customers, business contacts, and other persons whose information Customer provides.
Categories of Personal Data: Names, business names, addresses, email addresses, telephone numbers, order identifiers, shipment identifiers, tracking numbers, shipment information, fulfillment information, customs information, marketplace information, technical information, and other Personal Data Customer submits through authorized Services.
Special Categories / Sensitive Information: Ship Zone’s Services are not designed for Customer to intentionally submit sensitive Personal Data unrelated to legitimate shipping or logistics requirements. Customer should not submit sensitive Personal Data unless necessary, lawful, and expressly supported by the applicable Service.

SCHEDULE B — SECURITY MEASURES

Ship Zone will maintain security measures appropriate to the nature of applicable Personal Data and risks associated with the Processing, which may include, as applicable:

  • Access Control: restricted system access, authentication, user-access management, least-privilege principles, and removal of access when no longer required.
  • Data Protection: appropriate encryption during transmission, appropriate encryption at rest where required, credential protection, and secure storage practices — including tokenized handling of payment-card data through Ship Zone’s payment processor rather than storage of raw card numbers by Ship Zone.
  • Application and Infrastructure Security: security monitoring, logging, vulnerability management, system updates and patching, network protections, and secure software-development practices.
  • Organizational Measures: confidentiality requirements, security policies, access restrictions, incident-response procedures, and appropriate personnel practices.
  • Business Continuity: backup procedures, recovery procedures, and measures designed to maintain or restore availability of applicable systems, where appropriate.

The precise technical and organizational measures may change over time as long as the overall level of protection is not materially reduced in a manner inconsistent with applicable legal or contractual requirements.

SCHEDULE C — RESTRICTED MARKETPLACE INTEGRATION PROCESSING

Where Customer connects a Restricted Marketplace Integration to Ship Zone:

Purpose: Order processing, shipping, fulfillment, rate comparison, label generation, tracking, shipment-status updates, and related authorized seller/merchant functionality.
Potential Information: Seller or merchant identifiers, order identifiers, shipment information, fulfillment information, recipient information where authorized, delivery information where authorized, tracking information, and other information made available through authorized integration operations.
Restrictions: Ship Zone will: use Restricted Marketplace Information only for authorized purposes; not sell Restricted Marketplace Information; restrict access as required by the applicable marketplace’s program requirements; protect applicable Restricted Marketplace personal information; follow applicable marketplace retention and deletion requirements; and comply with applicable marketplace security and data-protection requirements, applying them in place of this DPA’s general requirements wherever they are stricter. Customer remains responsible for its own compliance with the applicable marketplace’s seller and program requirements.

ACCEPTANCE