ShipLulu
How it WorksPricingIntegrationsCalculatorBlog
Log inGet started free

Data Processing Agreement

Last updated: March 20, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Data Controller", "Seller") and ShipLulu ("Data Processor", "we", "us") pursuant to Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR").

1. Definitions

"Personal Data" means any information relating to an identified or identifiable natural person processed by ShipLulu on behalf of the Seller in connection with the Service. This includes end-customer names, shipping addresses, phone numbers, email addresses, and order details.

"Processing" means any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, erasure, and destruction.

2. Scope & Purpose

ShipLulu processes Personal Data solely for the purpose of providing fulfillment services: receiving orders, picking and packing items, generating shipping labels, transmitting shipment data to carriers, and syncing tracking information back to the Seller's e-commerce platform. We do not process Personal Data for any other purpose, including marketing, profiling, or selling data.

3. Categories of Data Subjects & Data

  • Data subjects: End customers of the Seller who place orders
  • Data categories: Full name, shipping address (street, city, state, postal code, country), phone number, email address (if provided), order contents and quantities

4. Obligations of the Data Processor

4.1 Processing instructions

We process Personal Data only on documented instructions from the Seller, unless required by applicable law. The Seller's instructions are defined by the Service configuration (connected store, order processing rules).

4.2 Confidentiality

All personnel with access to Personal Data are bound by confidentiality obligations. Access is limited to staff who require it for fulfillment operations.

4.3 Security measures

We implement appropriate technical and organizational measures including: encryption of data in transit (TLS 1.2+) and at rest, access controls with role-based permissions, regular security assessments, secure deletion procedures, and physical security at warehouse facilities.

4.4 Sub-processors

We use the following categories of sub-processors:

  • Shipping carriers (DHL, YTO, 4PX, etc.) — receive recipient name and address for delivery
  • Cloud infrastructure provider — hosts our application and database
  • E-commerce platform APIs (Shopify, WooCommerce) — order and tracking sync at Seller's direction

We will inform the Seller of any intended changes to sub-processors with 14 days' notice. The Seller may object; if the objection cannot be resolved, the Seller may terminate the Service.

4.5 Assistance with data subject rights

We will assist the Seller in responding to data subject requests (access, rectification, erasure, portability, restriction, objection) by providing relevant data or deleting data as instructed, within 10 business days.

4.6 Breach notification

In the event of a personal data breach, we will notify the Seller without undue delay and no later than 48 hours after becoming aware of the breach. Notification will include the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken to mitigate.

5. Data Retention & Deletion

We retain end-customer Personal Data for 90 days after order delivery for operational purposes (returns, claims, carrier disputes). After 90 days, Personal Data is anonymized (name and address replaced with hashed identifiers). Upon termination of the Service, we will delete or return all Personal Data within 30 days, unless retention is required by law.

6. International Transfers

Personal Data is processed in China (warehouse operations) and may transit through cloud infrastructure in other regions. For transfers from the EEA to China, we rely on Standard Contractual Clauses (SCCs) as approved by the European Commission (Decision 2021/914). A copy of the executed SCCs is available upon request.

7. Audit Rights

The Seller has the right to audit our compliance with this DPA. Audits may be conducted by the Seller or an independent auditor, with 30 days' written notice, during business hours, and no more than once per year. We will provide reasonable cooperation and access to relevant documentation.

8. Liability

Each party's liability under this DPA is subject to the limitations set out in the Terms of Service.

9. Term

This DPA remains in effect for the duration of the Service and until all Personal Data has been deleted or returned.

10. Contact

Data Protection contact: privacy@shiplulu.com

ShipLulu

E-commerce fulfillment from China.

Product

PricingCalculatorHow it WorksIntegrationsSeller Dashboard

Company

About UsContactBlog

Legal

Privacy PolicyTerms of ServiceDPA
© 2026 ShipLulu. All rights reserved.
PrivacyTerms