Skip to content

Legal center

Data Processing Agreement

Processor/operator conditions for the data that gifty processes on the Merchant's behalf.

Effective date
July 21, 2026
Version
2026-07-21
Who it applies to
Merchants that transmit personal data for the Service.

In short

  • The Merchant decides the purposes; gifty processes only to provide and protect the Service.
  • We apply security measures, govern the sub-processors and assist with rights and incidents.
  • When the relationship ends we return or delete the data, subject to backups and legal retentions.

1. Parties, scope and precedence

This Data Processing Agreement ("DPA") forms part of the Terms of Service entered into between the Merchant, as controller, and APPS 4 SELLERS CORP ("gifty"), as processor, with respect to the personal data that gifty processes on the Merchant's behalf (the "Merchant Data"). It applies to all processing carried out on behalf of and under the instructions of the Merchant in the framework of the Service. In the event of a conflict between this DPA and the Terms, this DPA prevails in matters of data, and over both the applicable mandatory law prevails, including Argentina's Law 25,326 and Brazil's LGPD as applicable.

2. Instructions and obligations of the parties

Gifty will process the Merchant Data only according to documented instructions of the Merchant, which comprise: these Terms and this DPA, the configuration that the Merchant applies in the Service, the legitimate use of the features and written requests compatible with the agreement. If an instruction appears to us to be contrary to the law, we will report it and may suspend its execution until it is clarified. If a law obliges us to additional processing, we will report it before carrying it out, unless that law prohibits it.

The Merchant warrants that: it has a valid legal basis for the data it uploads or has processed; it published the required privacy notices; it applies minimization and accuracy; it obtained the necessary permissions; and its instructions are lawful. The Merchant is responsible toward the data subjects and the authorities for the compliance with its own obligations as controller.

3. Details of the processing

  • Subject matter: host, organize, issue, deliver, query, synchronize, reconcile, support, protect and delete gift cards and their associated information.
  • Duration: the term of the contractual relationship, plus the periods for return, backup rotation and legal retention.
  • Nature and purpose: storage, structuring, query, communication, reconciliation and deletion operations necessary to provide the Service.
  • Categories of data subjects: buyers, recipients, store customers, contacts and authorized users of the Merchant.
  • Categories of data: identification and contact, order and gift card data (amount, currency, balance, redemption, message, delivery), technical identifiers and support logs.
  • Sensitive data: not contemplated or necessary; the Merchant undertakes not to upload it deliberately.

4. Confidentiality and security

The personnel authorized to process Merchant Data are subject to confidentiality duties and receive adequate training. Gifty implements technical and organizational measures proportionate to the risk, which include: encryption in transit, secure management of secrets, data isolation per tenant, least-privilege access with periodic review, audit logs, monitoring, backups and continuity, vulnerability management, secure development practices, data validation at the boundaries, incident response and provider assessment. The measures may evolve provided that they do not materially reduce the level of protection.

5. Sub-processors

The Merchant generally authorizes the engagement of the sub-processors necessary to provide the Service. Gifty imposes on them by contract data protection obligations no less protective than those of this DPA and is answerable for their compliance under the terms of the applicable law. We will give notice of material changes of sub-processors with reasonable advance notice; the Merchant may object for reasonable grounds within fifteen days, in which case we will seek an alternative or allow the affected functionality to be terminated.

Current categories of sub-processors:

  • Infrastructure, database and storage: Vercel, Neon, Cloudflare.
  • Background task processing: Trigger.dev.
  • Transactional communications: Resend (email), Kapso (WhatsApp).
  • Payments and billing: Mercado Pago, Stripe, Tus Facturas.
  • Observability and product analytics: Sentry, PostHog.
  • Ecommerce platforms and connectors enabled by the Merchant: Tiendanube and equivalents.

6. International transfers

When the processing involves international transfers of Merchant Data, gifty applies a valid mechanism under the pertinent regulations (Law 25,326, LGPD or another applicable): adequacy decision, approved contractual clauses, binding corporate rules or a legal exception, together with a risk assessment and supplementary measures where applicable. Upon the Merchant's reasonable request, we will provide information about the mechanisms used or a redacted copy of the safeguards, protecting confidential information.

7. Data subjects' rights, assessments and authorities

If a data subject directs a request about Merchant Data directly to us, we will forward it without delay and will not respond on the Merchant's behalf, unless instructed by the Merchant or required by legal obligation. Taking into account the nature of the processing, we will reasonably assist the Merchant in responding to requests for access, rectification, portability, objection and deletion, in carrying out impact assessments and prior consultations, and in attending to requirements of supervisory authorities. The Merchant decides the response and verifies the identity of the requester.

8. Security incidents

After confirming a security incident that affects Merchant Data, gifty will notify the Merchant without undue delay, reporting —to the extent the information is available— the nature of the incident, the categories and approximate volume of data and data subjects affected, the likely consequences, the measures adopted or proposed and a point of contact, with updates as the investigation progresses. The notification does not imply an admission of liability. The Merchant decides the notifications to data subjects and authorities that correspond to it as controller, without prejudice to the direct notification duties that the law imposes on gifty.

9. Return, deletion and audit

Upon termination of the provision of the Service, and at the Merchant's reasonable choice, we will return the Merchant Data in a standard format or delete it, unless the law requires keeping it. The data included in backups remains isolated until the rotation is completed and irreversibly anonymized data ceases to be personal.

Gifty will make available to the Merchant the information reasonably necessary to demonstrate compliance with this DPA. Additional audits require justified cause, reasonable prior notice, a proportionate and confidential scope, not interfering with the operation or accessing data of other tenants, and favor remote reports and evidence; the costs are borne by the Merchant unless the audit reveals a material breach by gifty.

10. Liability, term and contact

The parties' liability under this DPA is governed by the limitations of the Terms, except to the extent that applicable law prohibits limiting it. The obligations of this DPA subsist for as long as gifty retains Merchant Data. The annexes and lists of this DPA may be updated without materially reducing the level of protection, with notice of material changes. Contact for data processing matters: hola@crossup.ai — APPS 4 SELLERS CORP, 470 Ansin Blvd, Suite K, Hallandale Beach, FL 33009, United States.