Data Processing Agreement
Last updated: July 2026
This DPA describes how HyveFlow processes personal data on behalf of a Shop. It applies to any Shop that uses HyveFlow and supplements our Terms of Service and Privacy Policy. Where a Shop's customers are in the EU/UK or California, it also serves as the Shop's data-processing agreement. It is not legal advice — have counsel review it against your obligations.
1. Roles
For personal data a Shop stores in HyveFlow about the Shop's own customers ("Shop Personal Data"), the Shop is the controller and HyveFlow is the processor. HyveFlow processes Shop Personal Data only on the Shop's documented instructions — which include the Shop's configuration and use of the service — except where law requires otherwise (in which case we notify the Shop unless the law prohibits it).
2. Subject matter, duration, nature & purpose
We process Shop Personal Data to provide HyveFlow's order-management service — intake, deposits, proofs, rosters, invoicing, transactional email, and the integrations a Shop enables — for as long as the Shop's account is active, and thereafter as described in Section 8.
3. Categories of data & data subjects
- Data subjects: the Shop's customers and their team members / athletes, and the Shop's own staff who use HyveFlow.
- Categories: names, contact details (email, phone, address), order and roster details (which may include garment sizes, numbers, and similar fulfillment data), proofs, and invoice/payment-status information. We do not store payment card numbers.
- The Shop must not use HyveFlow to process special-category data (health, biometric, etc.) beyond what routine apparel fulfillment requires.
4. HyveFlow's obligations
- Process Shop Personal Data only on the Shop's instructions and only to provide the service.
- Ensure personnel authorized to process the data are bound by confidentiality.
- Implement appropriate technical and organizational security measures (Section 6).
- Assist the Shop, taking into account the nature of processing, with data-subject requests and with security, breach-notification, and impact-assessment obligations.
- Not sell Shop Personal Data or use it for our own purposes, advertising, or profiling.
5. Subprocessors
The Shop authorizes HyveFlow to engage the subprocessors below to provide the service. We impose data-protection obligations on each that are no less protective than this DPA, and we remain responsible for their performance. We will give reasonable notice of any intended new subprocessor so the Shop can object.
| Subprocessor | Purpose |
|---|---|
| Supabase | Database & storage of Shop data |
| Render | Application hosting (API) |
| Netlify | Web hosting (admin & portal) |
| Cloudflare R2 | File storage (proofs, certificates, design files) |
| Resend | Transactional email delivery |
| Clerk | Authentication / login |
| Anthropic | AI features (order intake, drafting) |
| Intuit / QuickBooks | Invoicing & payment tracking (when the Shop connects it) |
| Drive/Sheets sync (when the Shop connects it) |
6. Security measures
We maintain measures appropriate to the risk, including: encryption in transit; encryption of integration tokens at rest; tenant isolation so one Shop cannot access another Shop's data; private file storage served only via short-lived signed links; role-based access controls; row-level security on the database; and rate limiting and logging to detect abuse. We review these measures as the service evolves.
7. Personal data breaches
We will notify the Shop without undue delay after becoming aware of a personal-data breach affecting Shop Personal Data, with the information reasonably available to help the Shop meet its own notification obligations, and we will take reasonable steps to mitigate.
8. Return & deletion
On request during the term, and on termination, the Shop may obtain a full export of Shop Personal Data (self-serve on request via the platform). At the Shop's choice we will delete or return Shop Personal Data and delete existing copies within a reasonable period, except where law requires retention.
9. Audits
We will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and no more than once a year (or as a supervisory authority requires), allow the Shop or its mandated auditor to review that information, subject to confidentiality and without disrupting the service or other Shops' data.
10. International transfers
Where processing involves transferring personal data across borders (for example to a subprocessor), we rely on a lawful transfer mechanism, such as the EU Standard Contractual Clauses or an adequacy decision, where applicable.
11. Term & precedence
This DPA is effective while the Shop uses HyveFlow and, for Shop Personal Data, survives until deletion or return. If this DPA conflicts with the Terms of Service on the processing of Shop Personal Data, this DPA controls for that data.
12. Contact
Requests under this DPA — including subprocessor objections, data-subject assistance, or a countersigned copy — go to support@hyveflow.io.