Parties and scope
The merchant is the business that accepted the Terms; Horcrux is the Dropout Studio venture described there. This DPA covers merchant-submitted and storefront-generated personal data processed by Horcrux to provide the service. It does not make Horcrux a party to merchant-shopper sales.
Roles and instructions
The merchant determines the purposes and lawful basis for its shopper, customer, staff and business data. Horcrux processes that data on the merchant’s documented instructions in the Terms, product controls and support requests, except where law requires otherwise. The final Bangladesh controller/processor terminology and any independent Horcrux purposes must match current applicable law.
Processing details
Subject matter: operation of a multi-tenant commerce platform. Duration: the agreement plus documented retention and deletion periods. Nature: collection, recording, organization, storage, retrieval, use, calculation, transmission, display, restriction, export, backup and deletion.
- People: merchant account holders and staff, shoppers, customers, recipients, support contacts and authorized representatives.
- Data: identity and contact details; addresses; catalog and order content; cart, checkout, payment-status and refund evidence; courier and delivery data; support and policy communications; access, permission, security and audit metadata.
- Sensitive data: not intentionally required for ordinary commerce; merchants must not submit it unless lawfully necessary and expressly supported.
Merchant obligations
The merchant will provide lawful, fair and transparent instructions; publish accurate storefront notices; obtain required permissions; configure staff and integrations responsibly; answer shopper requests; and avoid collecting excessive or prohibited information. The merchant remains responsible for product, marketing, consumer and recordkeeping duties.
Confidentiality and personnel
Horcrux restricts access to authorized personnel and service providers who need it for their role and are bound by confidentiality or equivalent duties. Support correspondence never authenticates a person or authorizes a protected mutation.
Security measures
Measures include tenant isolation; per-request membership and permission checks; encrypted credentials and actionable-email URLs; hash-only public tokens; session controls; audit trails; input validation; rate limits; least privilege; isolated preview resources; durable queues and dead-letter handling; logging minimization; backups, recovery tests and deletion propagation; and fail-closed commerce during uncertain recovery.
Subprocessors
Current Horcrux subprocessors are listed below. Horcrux remains responsible for their processing under this DPA to the extent required by applicable law and contract.
- Cloudflare, Inc. and affiliates — hosting, edge security, Workers, D1, KV, R2, Images, Queues and Workflow — processing locations may be international.
- Resend, Inc. — transactional account and merchant email delivery and limited delivery metadata — processing locations may be international.
- Google LLC — optional account authentication only when the merchant or staff member chooses Google sign-in — processing locations may be international.
- PostHog, Inc. — optional consented product analytics only after all privacy and production gates are enabled; currently disabled — configured US project.
Merchant-directed providers
A merchant’s SSLCommerz account, courier accounts, custom-domain provider and other merchant-selected connections are not Horcrux subprocessors merely because the merchant directs Horcrux to transmit data to them. The merchant must assess and contract with those providers. Horcrux sends only data needed for the requested connection.
Subprocessor changes
We will keep the public schedule current and provide reasonable notice of a material new subprocessor through the dashboard or verified Primary Owner email before the change where practicable. The merchant may raise a documented data-protection objection; the parties will seek a proportionate solution without requiring Horcrux to offer an unsupported architecture.
Rights, incidents, and compliance assistance
Taking account of the service and information available, Horcrux will reasonably assist the merchant with verified individual requests, security incidents, required assessments, and regulator inquiries. We will notify affected merchants without undue delay after confirming a personal-data breach requiring notice and provide available facts, containment and remediation updates. Statutory deadlines and roles follow current applicable law.
International transfers
The merchant authorizes international processing needed by the listed providers subject to applicable safeguards. The parties will adopt any additional transfer mechanism required by current Bangladesh law before production checkout.
Return, export, and deletion
Authorized staff can export merchant-owned core records and original media, including during nonpayment disablement. At termination or closure, Horcrux deletes or de-identifies personal data under the documented 30-day recovery, five-year evidence, 90-day security/email, seven-day log, immediate secret-erasure and 30-day backup-propagation schedule, except where law requires retention. Merchant archive restoration is not offered.
Information and audit
Horcrux will provide reasonably available security, subprocessor and compliance information. Any additional audit must be necessary, proportionate, confidential, non-disruptive, avoid other tenants’ data and platform secrets, and use existing independent evidence first. Allocation of exceptional audit cost remains subject to the final commercial agreement and applicable law.
Priority and contact
If this DPA conflicts with the Terms on covered processing, this DPA controls to that extent. Contact horcrux@dropoutstudio.co with the subject “DPA request” and the store reference. Mandatory law controls over both documents.