SHIP ZONE LLC
DATA PROCESSING AGREEMENT
Effective Date: March 20, 2026
This Data Processing Agreement (“DPA”) forms part of the Ship Zone LLC Terms of Service or other written agreement governing a customer’s use of Ship Zone’s Services (the “Agreement”).
This DPA is entered into between Ship Zone LLC (“Ship Zone,” “Processor,” “Service Provider,” “we,” “us,” or “our”) and the customer or business accepting the Agreement (“Customer,” “Controller,” “Business,” “you,” or “your”).
This DPA governs Ship Zone’s Processing of Personal Data on behalf of Customer in connection with the Services.
By using Services involving the Processing of Personal Data, Customer agrees that this DPA is incorporated into and forms part of the Agreement.
1. PURPOSE
Ship Zone provides shipping, logistics-management, parcel, freight, ocean-freight, e-commerce, marketplace-integration, API, fulfillment-support, tracking, label-generation, and related technology Services.
In providing these Services, Ship Zone may Process Personal Data supplied or made available by Customer.
This DPA establishes the parties’ respective responsibilities concerning such Personal Data.
2. DEFINITIONS
For purposes of this DPA:
2.1 “Applicable Data Protection Law”
Means privacy, data-protection, and information-security laws applicable to the Processing governed by this DPA.
2.2 “Controller”
Means the person or entity that determines the purposes and means of Processing Personal Data or the equivalent term under Applicable Data Protection Law.
2.3 “Customer Data”
Means information, including Personal Data, submitted, transmitted, uploaded, imported, accessed, or otherwise made available to Ship Zone by or on behalf of Customer in connection with the Services.
2.4 “Data Subject”
Means an identified or identifiable individual to whom Personal Data relates.
2.5 “Personal Data”
Means information relating to an identified or identifiable individual and includes equivalent terms such as “personal information” where applicable.
2.6 “Processing”
Means any operation performed on Personal Data, including collecting, accessing, receiving, organizing, storing, using, transmitting, disclosing, retrieving, modifying, deleting, or destroying such information.
2.7 “Processor”
Means an entity that Processes Personal Data on behalf of a Controller or the equivalent role under Applicable Data Protection Law.
2.8 “Security Incident”
Means a confirmed breach of security resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Customer Personal Data Processed by Ship Zone.
A Security Incident does not include unsuccessful attempts or activities that do not compromise Customer Personal Data, such as unsuccessful login attempts, scans, pings, denial-of-service attempts, or attacks blocked by appropriate security controls.
2.9 “Subprocessor”
Means a third party engaged by Ship Zone to Process Customer Personal Data on behalf of Customer in connection with the Services.
3. ROLES OF THE PARTIES
To the extent Ship Zone Processes Personal Data solely on behalf of Customer in providing the Services:
- Customer acts as the Controller or Business; and
- Ship Zone acts as the Processor or Service Provider.
The parties acknowledge that privacy-law terminology varies between jurisdictions.
Ship Zone may independently act as a Controller or Business for certain information processed for its own legitimate business purposes, including:
- Account administration;
- Billing;
- Payment management;
- Fraud prevention;
- Security;
- Legal compliance;
- Tax and accounting;
- Business records;
- Claims and disputes;
- Enforcement of agreements; and
- Operation and improvement of Ship Zone’s Services where permitted by applicable law.
Such independent Processing is governed primarily by Ship Zone’s Privacy Policy and applicable law.
4. CUSTOMER INSTRUCTIONS
Customer instructs Ship Zone to Process Customer Personal Data as reasonably necessary to:
- Provide the Services;
- Create shipments;
- Obtain shipping quotations;
- Purchase transportation services;
- Generate shipping labels;
- Process fulfillment information;
- Provide shipment tracking;
- Arrange parcel transportation;
- Arrange freight transportation;
- Support ocean-freight transactions;
- Facilitate customs documentation;
- Communicate with carriers;
- Operate authorized integrations;
- Provide technical support;
- Provide customer support;
- Prevent fraud;
- Maintain security;
- Comply with applicable legal obligations; and
- Perform other Processing reasonably necessary to provide Services requested by Customer.
The Agreement, this DPA, Customer’s configuration of the Services, API requests, integration settings, and other documented instructions collectively constitute Customer’s instructions to Ship Zone.
5. CUSTOMER RESPONSIBILITIES
Customer represents and warrants that:
- Customer has complied and will comply with Applicable Data Protection Law;
- Customer has all necessary rights, permissions, notices, consents, and lawful bases required to provide Personal Data to Ship Zone;
- Customer is authorized to instruct Ship Zone to Process such Personal Data;
- Customer’s instructions do not violate Applicable Data Protection Law;
- Customer will not instruct Ship Zone to Process Personal Data for unlawful purposes;
- Customer is responsible for the accuracy and lawfulness of Customer Data;
- Customer will provide all legally required privacy notices to its customers, recipients, employees, and other Data Subjects;
- Customer will maintain appropriate security over its Ship Zone account, users, API credentials, and connected platforms; and
- Customer will comply with applicable marketplace, carrier, and platform requirements.
Customer is solely responsible for determining whether the Services are appropriate for Customer’s legal and regulatory requirements.
6. CATEGORIES OF DATA SUBJECTS
Customer Personal Data may concern:
- Customer’s employees;
- Authorized users;
- Merchants;
- Sellers;
- Senders;
- Purchasers;
- Shipment recipients;
- Consignees;
- Customers of Customer;
- Customer-support contacts;
- Business contacts; and
- Other individuals whose information Customer submits through the Services.
7. CATEGORIES OF PERSONAL DATA
Depending upon Customer’s use of the Services, Ship Zone may Process:
Identity Information
- First name;
- Last name;
- Business name; and
- Account identifiers.
Contact Information
- Email address;
- Telephone number;
- Billing address;
- Pickup address;
- Delivery address; and
- Return address.
Shipment Information
- Order numbers;
- Shipment identifiers;
- Tracking numbers;
- Shipment contents;
- Commodity descriptions;
- Package weight;
- Package dimensions;
- Declared value;
- Customs information;
- Delivery instructions; and
- Fulfillment information.
Marketplace Information
Where Customer connects an authorized marketplace or e-commerce integration:
- Marketplace identifiers;
- Seller identifiers;
- Store identifiers;
- Order information;
- Recipient information;
- Fulfillment information;
- Shipment information; and
- Tracking information.
Technical Information
Where applicable:
- IP addresses;
- Login information;
- API activity;
- Device information;
- System logs; and
- Security information.
8. PURPOSE AND NATURE OF PROCESSING
Ship Zone Processes Customer Personal Data for purposes including:
- Shipping;
- Fulfillment;
- Transportation management;
- Shipment documentation;
- Rate calculation;
- Label generation;
- Tracking;
- Carrier communication;
- Customs support;
- Marketplace integration;
- E-commerce integration;
- Customer support;
- Technical support;
- Fraud prevention;
- Security; and
- Related logistics-management functions.
Processing may include collection, retrieval, organization, transmission, storage, use, disclosure to authorized providers, and deletion.
9. DURATION OF PROCESSING
Ship Zone may Process Customer Personal Data for the duration of the Agreement and thereafter only for as long as:
- Necessary to complete authorized Services;
- Permitted by this DPA;
- Permitted by applicable platform requirements; or
- Required or permitted by applicable law.
Different categories of Personal Data may be subject to different retention requirements.
10. CONFIDENTIALITY
Ship Zone will take reasonable measures designed to ensure that persons authorized to Process Customer Personal Data are subject to appropriate confidentiality obligations.
Access to Customer Personal Data will be limited to personnel and authorized providers with a legitimate need for access in connection with the Services or other permitted purposes.
11. SECURITY
Ship Zone will maintain reasonable and appropriate administrative, organizational, physical, and technical safeguards designed to protect Customer Personal Data against unauthorized access, acquisition, disclosure, alteration, destruction, or loss.
Depending upon the systems and information involved, safeguards may include:
- Access controls;
- Authentication;
- Least-privilege access;
- Encryption;
- Network safeguards;
- Credential protection;
- Logging;
- Monitoring;
- Vulnerability management;
- Backup procedures;
- Incident-response procedures;
- Secure software-development practices; and
- Personnel access restrictions.
Security measures may evolve as technology, threats, legal requirements, and Ship Zone’s Services change.
12. NO ABSOLUTE SECURITY GUARANTEE
Customer acknowledges that no Internet transmission, computer network, database, software platform, cloud environment, or electronic-storage system can be guaranteed to be completely secure.
Ship Zone does not warrant or guarantee that Security Incidents will never occur.
Nothing in this provision reduces Ship Zone’s obligations under Applicable Data Protection Law that cannot lawfully be limited.
13. AMAZON SP-API INFORMATION
Where Customer authorizes Ship Zone to access information through Amazon’s Selling Partner API (“SP-API”), additional requirements apply.
Ship Zone will Process applicable Amazon Information only for authorized purposes associated with providing Services requested by the applicable selling partner.
Ship Zone will not sell Amazon Information.
Ship Zone will not use Amazon Information for purposes prohibited by applicable Amazon requirements.
Ship Zone will apply applicable Amazon security, access, use, sharing, retention, and deletion requirements to Amazon Information.
Where Amazon’s applicable requirements are stricter than the general requirements of this DPA, the applicable Amazon requirements will govern the Processing of Amazon Information.
14. AMAZON PII
Certain Amazon Information may constitute Personally Identifiable Information (“PII”) or other restricted information under Amazon requirements.
Ship Zone will restrict access to such information according to applicable Amazon requirements and legitimate business need.
Amazon PII will be retained only for authorized purposes and for periods permitted by Amazon’s then-current requirements.
Where Amazon requires deletion within a specified period, Ship Zone will apply that requirement unless continued retention is expressly permitted or legally required.
15. AMAZON CREDENTIALS AND TOKENS
Ship Zone will treat applicable:
- SP-API credentials;
- Authorization tokens;
- Security credentials;
- Access credentials; and
- Related authentication information
as confidential security information.
Ship Zone will not intentionally expose such credentials publicly.
Customer is responsible for protecting Amazon credentials and authorization information under Customer’s control.
16. OTHER MARKETPLACE DATA
Where Customer authorizes Ship Zone to connect to Shopify, Etsy, Amazon, or another marketplace, e-commerce service, or application, Ship Zone may Process information made available through the authorized connection.
Ship Zone will Process such information in accordance with:
- Customer’s instructions;
- Applicable platform permissions;
- Applicable contractual requirements;
- This DPA; and
- Applicable Data Protection Law.
Where a platform imposes stricter requirements on its information, Ship Zone will apply such requirements where applicable.
17. SUBPROCESSORS
Customer authorizes Ship Zone to engage Subprocessors reasonably necessary to provide, support, secure, and maintain the Services.
Subprocessors may include providers of:
- Cloud infrastructure;
- Data hosting;
- Cybersecurity;
- Communications;
- Customer support;
- Software infrastructure;
- Analytics;
- Payment processing; and
- Other technology or operational services.
Ship Zone will require applicable Subprocessors that Process Customer Personal Data on Ship Zone’s behalf to maintain data-protection obligations appropriate to the nature of their Processing.
18. CARRIERS AND LOGISTICS PROVIDERS
Customer specifically authorizes Ship Zone to transmit necessary Personal Data to carriers and logistics providers selected, requested, or otherwise used to perform Customer’s Shipment.
Such providers may include:
- Parcel carriers;
- Postal operators;
- Couriers;
- Freight carriers;
- Trucking companies;
- Freight forwarders;
- Ocean carriers;
- Airlines;
- Customs brokers;
- Warehouses;
- Insurance providers; and
- Other transportation or logistics providers.
Once an independent carrier or logistics provider receives Personal Data for its own transportation, regulatory, customs, or operational purposes, that provider may act as an independent Controller under applicable law.
Ship Zone does not control the independent Processing activities of such providers.
19. THIRD-PARTY CONTROLLERS
A third party receiving information from Ship Zone may be an independent Controller rather than a Subprocessor.
Where that occurs, the third party’s Processing is governed by its own legal obligations, contractual terms, and privacy practices.
To the maximum extent permitted by applicable law, Ship Zone is not responsible for the independent acts, omissions, privacy practices, security practices, or Processing activities of independent third-party Controllers.
20. INTERNATIONAL DATA TRANSFERS
Customer acknowledges that the Services involve international shipping and technology infrastructure.
Customer Personal Data may therefore be transferred to or Processed in countries other than the country where Customer or the Data Subject is located.
Such countries may include:
- United States;
- Canada;
- Costa Rica; and
- Other jurisdictions in which Ship Zone, its service providers, carriers, platforms, or logistics providers operate.
Where Applicable Data Protection Law requires specific safeguards for an international transfer for which Ship Zone is responsible, Ship Zone will implement applicable legally required transfer mechanisms.
21. DATA SUBJECT REQUESTS
If Ship Zone receives a request from a Data Subject concerning Customer Personal Data that Ship Zone Processes solely on behalf of Customer, Ship Zone may direct the Data Subject to Customer where appropriate.
Taking into account the nature of the Processing and where required by Applicable Data Protection Law, Ship Zone will provide reasonable assistance to Customer in responding to qualifying Data Subject requests.
Customer remains responsible for determining whether and how a request should be fulfilled where Customer acts as Controller.
22. CUSTOMER RESPONSIBILITY FOR REQUESTS
Customer is responsible for:
- Receiving privacy requests from its customers;
- Determining whether a requester is entitled to exercise the requested right;
- Verifying identity where required;
- Determining applicable legal exceptions;
- Providing required responses; and
- Providing Ship Zone with lawful instructions where Ship Zone’s assistance is required.
Ship Zone does not provide legal advice concerning Customer’s obligations to Data Subjects.
23. SECURITY INCIDENTS
Upon becoming aware of a Security Incident affecting Customer Personal Data for which notification to Customer is required under Applicable Data Protection Law, Ship Zone will notify Customer without undue delay as required by applicable law.
Such notification will not constitute an acknowledgment or admission of fault or liability by Ship Zone.
Where reasonably available and legally required, Ship Zone may provide information concerning:
- The nature of the Security Incident;
- Categories of affected information;
- Remediation measures; and
- Other information reasonably necessary for Customer’s compliance obligations.
24. CUSTOMER SECURITY INCIDENTS
Customer must notify Ship Zone promptly if Customer becomes aware of:
- Compromised Ship Zone credentials;
- Compromised API credentials;
- Unauthorized Ship Zone account access;
- Unauthorized marketplace connections;
- Unauthorized access by Customer personnel; or
- Other circumstances that may affect the security of Customer Data within the Services.
Ship Zone is not responsible for Security Incidents caused solely by Customer’s systems, personnel, credentials, applications, or failure to follow reasonable security practices, except to the extent responsibility cannot legally be excluded.
25. RETURN AND DELETION OF PERSONAL DATA
Upon termination of the applicable Services, Ship Zone will delete or return Customer Personal Data where required by Applicable Data Protection Law and according to applicable retention requirements.
Ship Zone may retain information where retention is permitted or required for:
- Legal obligations;
- Tax records;
- Accounting;
- Customs records;
- Fraud prevention;
- Security;
- Claims;
- Insurance matters;
- Chargebacks;
- Disputes;
- Litigation;
- Contract enforcement;
- Regulatory obligations; or
- Other lawful purposes.
Where retained under such an exception, the information will remain subject to applicable protections until deletion is appropriate.
26. PLATFORM-SPECIFIC DELETION REQUIREMENTS
Where Amazon or another authorized platform requires particular information to be deleted sooner than Ship Zone’s standard retention period, Ship Zone will apply the applicable platform requirement to information governed by that requirement.
Customer acknowledges that deletion requirements may therefore vary by information source and Service.
27. AUDITS AND COMPLIANCE INFORMATION
Where required by Applicable Data Protection Law, Ship Zone will make reasonably necessary information available to demonstrate compliance with applicable Processor obligations.
Any audit or assessment requested by Customer must:
- Be legally required or reasonably justified;
- Protect Ship Zone’s confidential information;
- Protect information concerning other customers;
- Avoid unreasonable disruption;
- Comply with reasonable security requirements; and
- Be conducted at Customer’s expense unless applicable law requires otherwise.
Ship Zone may satisfy an audit request by providing appropriate third-party certifications, assessment reports, security documentation, questionnaires, or similar materials where legally sufficient.
Customer may not obtain access to systems, information, source code, infrastructure, or records that would compromise the security, confidentiality, or privacy of Ship Zone or other customers.
28. GOVERNMENT REQUESTS
Ship Zone may disclose Customer Personal Data where required by applicable law, subpoena, court order, governmental demand, regulatory requirement, or other lawful process.
Where legally permitted and appropriate, Ship Zone may notify Customer of such a request.
29. AGGREGATED AND DE-IDENTIFIED INFORMATION
Where permitted by Applicable Data Protection Law, applicable contracts, and applicable platform requirements, Ship Zone may create and use aggregated or de-identified information that cannot reasonably identify Customer or an individual.
Such information may be used for:
- Analytics;
- Security;
- Fraud prevention;
- Performance measurement;
- Capacity planning;
- Service improvement; and
- Business intelligence.
Ship Zone will not attempt to re-identify de-identified information where prohibited by applicable law.
30. RESTRICTED PROCESSING
Ship Zone will not knowingly:
- Sell Customer Personal Data processed solely on behalf of Customer to data brokers;
- Retain, use, or disclose Customer Personal Data for prohibited purposes;
- Use Amazon Information for purposes prohibited by Amazon requirements; or
- Combine restricted Customer Personal Data in a manner prohibited by Applicable Data Protection Law.
This provision does not prevent Ship Zone from Processing information for permitted security, fraud prevention, legal compliance, billing, operational, or other purposes allowed under applicable law.
31. CCPA AND U.S. STATE PRIVACY REQUIREMENTS
To the extent applicable U.S. state privacy legislation treats Ship Zone as a Service Provider, Processor, or Contractor concerning Customer Personal Data, Ship Zone will comply with applicable statutory obligations for that role.
Where required, Ship Zone will not retain, use, or disclose applicable Personal Data outside the permitted business purposes specified by Customer and the Agreement except as otherwise permitted by applicable law.
Nothing in this DPA requires Ship Zone to assume obligations under a law that does not apply to Ship Zone or the applicable Processing activity.
32. CANADIAN PRIVACY REQUIREMENTS
Where Canadian privacy law applies to the Processing governed by this DPA, the parties will comply with applicable federal and provincial requirements applicable to their respective roles.
Customer remains responsible for determining the legal basis upon which Customer collects and provides Personal Information to Ship Zone.
33. CUSTOMER INDEMNIFICATION
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, CUSTOMER WILL DEFEND, INDEMNIFY, AND HOLD HARMLESS SHIP ZONE, ITS AFFILIATES, OWNERS, MEMBERS, DIRECTORS, OFFICERS, EMPLOYEES, CONTRACTORS, REPRESENTATIVES, AGENTS, SUCCESSORS, AND ASSIGNS FROM CLAIMS, DAMAGES, LIABILITIES, PENALTIES, FINES, COSTS, AND REASONABLE LEGAL FEES ARISING OUT OF OR RELATING TO:
- Customer’s unlawful collection of Personal Data;
- Customer’s failure to provide legally required privacy notices;
- Customer’s failure to obtain required consent or another lawful basis;
- Customer’s unlawful instructions to Ship Zone;
- Customer’s misuse of Personal Data;
- Customer’s violation of Applicable Data Protection Law;
- Customer’s breach of this DPA;
- Customer’s systems or applications;
- Customer’s failure to secure credentials;
- Unauthorized actions of Customer’s users;
- Customer’s violation of marketplace requirements; or
- Claims resulting from information Customer did not have authority to provide to Ship Zone.
This provision applies only to the extent permitted by applicable law and the underlying Agreement.
34. LIMITATION OF LIABILITY
Except to the extent a limitation is prohibited by Applicable Data Protection Law, each party’s liability arising under this DPA will be subject to the applicable exclusions and limitations of liability contained in the Agreement.
Nothing in this DPA expands Ship Zone’s liability beyond the liability Ship Zone has agreed to under the Agreement unless such limitation is prohibited by applicable law.
To the maximum extent permitted by law, Ship Zone will not be liable under this DPA for indirect, incidental, special, exemplary, punitive, or consequential damages, including lost profits, lost revenue, lost business, loss of goodwill, or business interruption.
35. THIRD-PARTY LIABILITY
To the maximum extent permitted by applicable law, Ship Zone is not responsible under this DPA for a Security Incident, privacy violation, unauthorized Processing, or other act or omission caused exclusively by:
- Customer;
- Customer’s employees;
- Customer’s contractors;
- Customer’s applications;
- Customer’s devices;
- Customer-controlled credentials;
- An independent carrier;
- An independent marketplace;
- A governmental authority; or
- Another independent third-party Controller,
except where Ship Zone is independently responsible under applicable law.
36. CONFLICTS
If this DPA conflicts with the Agreement concerning the Processing of Customer Personal Data, this DPA will control solely with respect to that conflict.
If an applicable mandatory privacy law requires a provision different from this DPA, the mandatory requirement will control to the extent required.
If an applicable Amazon requirement imposes stricter obligations concerning Amazon Information, that requirement will govern the applicable Amazon Information.
37. CHANGES TO THIS DPA
Ship Zone may update this DPA where reasonably necessary to reflect:
- Changes to the Services;
- Changes to Applicable Data Protection Law;
- New privacy requirements;
- Security developments;
- New integrations;
- Marketplace requirements; or
- Changes to Ship Zone’s Processing activities.
Material changes will be handled in accordance with applicable law and the Agreement.
38. TERMINATION
This DPA remains effective for as long as Ship Zone Processes Customer Personal Data governed by this DPA.
Termination of Customer’s account or Agreement does not terminate provisions that by their nature must survive, including:
- Confidentiality;
- Data retention;
- Deletion;
- Liability;
- Indemnification; and
- Legal-compliance obligations.
39. GOVERNING LAW
Unless Applicable Data Protection Law requires otherwise, this DPA is governed by the same governing law and dispute-resolution provisions applicable to the Agreement.
40. ENTIRE DATA PROCESSING AGREEMENT
This DPA, together with the Agreement, Privacy Policy, and any applicable written addendum, constitutes the parties’ agreement concerning Ship Zone’s Processing of Customer Personal Data on Customer’s behalf.
41. CONTACT INFORMATION
Questions concerning this DPA or privacy matters may be directed to:
Ship Zone LLC
Privacy / Data Protection Contact
Email: info@shipzones.com
Website: www.shipzones.com
For DPA inquiries:
Subject: Data Processing Agreement
For privacy requests:
Subject: Privacy Request
For Amazon-related privacy inquiries:
Subject: Amazon SP-API Privacy Request
SCHEDULE A: DETAILS OF PROCESSING
Subject Matter: Provision of Ship Zone’s shipping, logistics, e-commerce integration, marketplace integration, fulfillment-support, API, label-generation, tracking, parcel, freight, and related Services.
Duration: For the duration of the Services and applicable authorized or legally required retention periods.
Nature of Processing: Collection, receipt, organization, retrieval, use, transmission, storage, disclosure to authorized providers, support, security, and deletion.
Purpose: To provide, support, maintain, secure, and improve the Services requested by Customer and satisfy applicable legal and contractual obligations.
Categories of Data Subjects:
- Customer users;
- Employees;
- Merchants;
- Sellers;
- Senders;
- Purchasers;
- Shipment recipients;
- Consignees;
- Customer’s customers;
- Business contacts; and
- Other persons whose information Customer provides.
Categories of Personal Data:
- Names;
- Business names;
- Addresses;
- Email addresses;
- Telephone numbers;
- Order identifiers;
- Shipment identifiers;
- Tracking numbers;
- Shipment information;
- Fulfillment information;
- Customs information;
- Marketplace information;
- Technical information; and
- Other Personal Data Customer submits through authorized Services.
Special Categories / Sensitive Information:
Ship Zone’s Services are not designed for Customer to intentionally submit sensitive Personal Data unrelated to legitimate shipping or logistics requirements.
Customer should not submit sensitive Personal Data unless necessary, lawful, and expressly supported by the applicable Service.
SCHEDULE B: SECURITY MEASURES
Ship Zone will maintain security measures appropriate to the nature of applicable Personal Data and risks associated with the Processing.
Measures may include, as applicable:
Access Control
- Restricted system access;
- Authentication;
- User-access management;
- Least-privilege principles; and
- Removal of access when no longer required.
Data Protection
- Appropriate encryption during transmission;
- Appropriate encryption at rest where required;
- Credential protection; and
- Secure storage practices.
Application and Infrastructure Security
- Security monitoring;
- Logging;
- Vulnerability management;
- System updates and patching;
- Network protections; and
- Secure software-development practices.
Organizational Measures
- Confidentiality requirements;
- Security policies;
- Access restrictions;
- Incident-response procedures; and
- Appropriate personnel practices.
Business Continuity
Where appropriate:
- Backup procedures;
- Recovery procedures; and
- Measures designed to maintain or restore availability of applicable systems.
The precise technical and organizational measures may change over time as long as the overall level of protection is not materially reduced in a manner inconsistent with applicable legal or contractual requirements.
SCHEDULE C: AMAZON SP-API PROCESSING
Where Customer connects Amazon to Ship Zone:
Data Source: Amazon Selling Partner API.
Purpose:
- Order processing;
- Shipping;
- Fulfillment;
- Rate comparison;
- Label generation;
- Tracking;
- Shipment-status updates; and
- Related authorized seller functionality.
Potential Information:
- Seller identifiers;
- Order identifiers;
- Shipment information;
- Fulfillment information;
- Recipient information where authorized;
- Delivery information where authorized;
- Tracking information; and
- Other information made available through authorized SP-API operations.
Restrictions:
Ship Zone will:
- Use Amazon Information only for authorized purposes;
- Not sell Amazon Information;
- Restrict access as required;
- Protect applicable Amazon PII;
- Follow applicable Amazon retention requirements;
- Follow applicable Amazon deletion requirements; and
- Comply with applicable Amazon security and data-protection requirements.
Customer remains responsible for its own compliance with Amazon seller and marketplace requirements.
ACCEPTANCE
By accepting Ship Zone’s Terms of Service or another agreement incorporating this DPA and using Services involving the Processing of Customer Personal Data, Customer acknowledges and agrees that this DPA forms part of the parties’ Agreement.

