Legal
Data Processing Addendum
When your app's End-User data flows through CashSDK, you are the controller and we are your processor. This addendum binds us to process only on your instructions, secure the data, give notice of subprocessor changes, and delete everything when you leave. It applies to every workspace automatically — no signature required.
On this page
1. Introduction and how this DPA applies#
This Data Processing Addendum (“DPA”) forms part of the CashSDK Terms of Service at cashsdk.com/terms (the “Agreement”) between CashSDK (“we”, “us”, the “Processor”) and the customer that holds the workspace (“you”). It applies whenever we process End-User Personal Data on your behalf in providing the Service.
The DPA is effective automatically for every customer — agreeing to the Terms executes it, and no signature is needed. If you need a countersigned copy for your records or your own compliance program, request one at support@cashsdk.com.
Capitalized terms not defined here have the meanings given in the Agreement.
2. Definitions#
- “Data Protection Laws” — all laws that apply to the processing of Personal Data under this DPA, including the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss FADP, and applicable US state privacy laws such as the CCPA/CPRA.
- “Personal Data”, “Controller”, “Processor”, “Data Subject”, “Processing”, and “Supervisory Authority” — as defined in the GDPR, or the nearest equivalent under other Data Protection Laws.
- “End-User Personal Data” — Personal Data contained in Customer Data relating to End Users of your apps that we process on your behalf, as described in Annex 1.
- “Subprocessor” — a third party we engage to process End-User Personal Data on our behalf.
- “SCCs” — the Standard Contractual Clauses approved by European Commission Decision (EU) 2021/914.
- “Security Incident” — a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to End-User Personal Data.
3. Roles and scope of processing#
You are the Controller of End-User Personal Data and we are your Processor. Where you act as a processor for your own clients, you appoint us as a subprocessor; you warrant that the relevant controller has authorized this DPA and the Subprocessors in Annex 3, and references to your instructions include the instructions you pass through from that controller.
The subject matter, duration, nature, and purpose of the processing, and the categories of Personal Data and Data Subjects, are set out in Annex 1. We process End-User Personal Data for as long as the Agreement is in force, plus the deletion window in Section 13.
4. Customer instructions#
We process End-User Personal Data only on your documented instructions, including for international transfers, unless a law we are subject to requires otherwise — in which case we will inform you before processing, unless that law prohibits it. Your documented instructions are: the Agreement, this DPA, your configuration of the Service (workspaces, integrations, API calls, and settings), and any further written instructions we agree to honor.
We will inform you if we believe an instruction violates Data Protection Laws — though we are not obliged to perform legal review of your instructions — and we may pause the affected processing until the issue is resolved.
You are responsible for the lawfulness of the data and the instructions: that you have a legal basis for the processing, have given End Users the required notices, and have obtained the required consents.
5. Confidentiality#
We ensure that every person we authorize to process End-User Personal Data — employees and contractors alike — is bound by contractual or statutory confidentiality obligations, and that access is limited to what each role requires.
6. Security#
We implement and maintain the technical and organizational measures described in Annex 2, designed to protect End-User Personal Data against accidental or unlawful destruction, loss, alteration, and unauthorized disclosure or access, taking into account the state of the art, the costs of implementation, and the nature and risks of the processing.
We may update those measures as technology evolves, provided an update never materially reduces the overall level of protection during your subscription term.
You are responsible for security on your side of the integration: workspace membership, API-key handling, the security of your apps, and the accuracy of what you send.
7. Subprocessors#
You give general written authorization for us to engage the Subprocessors listed in Annex 3, and for our infrastructure providers to use their own vetted providers. We impose data-protection obligations on every Subprocessor that are materially no less protective than this DPA, and we remain fully liable to you for their performance.
We will give at least 30 days' notice before adding or replacing a Subprocessor that touches End-User Personal Data — by email to workspace owners or by a notice in the dashboard. If you object on reasonable data-protection grounds, we will work with you in good faith on an alternative; if none is workable, you may terminate the affected subscription with a pro-rata refund of prepaid, unused fees.
8. Data subject requests#
Taking into account the nature of the processing, we will assist you with appropriate technical and organizational measures in fulfilling your obligation to respond to Data Subject requests — access, rectification, erasure, restriction, portability, and objection. The Service's export and deletion capabilities are the first line of assistance; where they do not cover a request, contact support@cashsdk.com and we will assist directly.
If a Data Subject contacts us about your app, we will not respond on your behalf beyond directing them to you, and we will notify you where we reasonably can. In most cases we could not identify the individual anyway — we hold the identifiers you assign, not names.
9. Personal data breaches#
We will notify you without undue delay, and in any case within 72 hours, after becoming aware of a Security Incident affecting End-User Personal Data. The notice will describe, to the extent then known: the nature of the incident, the categories and approximate volume of data and Data Subjects affected, the likely consequences, the measures taken or proposed, and a contact point. We will keep you informed as the investigation develops and will document incidents as Data Protection Laws require.
Our notification is not an acknowledgment of fault. Notifying authorities and Data Subjects is your responsibility as Controller; we will give you reasonable assistance to do it.
10. Assistance with assessments#
Taking into account the nature of the processing and the information available to us, we will reasonably assist you with data protection impact assessments, prior consultations with Supervisory Authorities, and your own security-compliance obligations, in each case as they relate to our processing of End-User Personal Data. We may charge reasonable fees for assistance that goes materially beyond the standard capabilities of the Service, and we will tell you before any fees apply.
11. International transfers#
We process End-User Personal Data primarily in the United States. For transfers of Personal Data from the EEA to countries without an adequacy decision, the SCCs are incorporated into this DPA: Module Two (controller to processor) where you are a Controller, and Module Three (processor to processor) where you act as a processor. In both cases: Clause 7 (docking) is included; Clause 9 Option 2 (general authorization with 30 days' notice) applies; the optional redress language is excluded; the governing law and forum are those of Ireland; and Annexes I, II, and III of the SCCs are completed by Annexes 1, 2, and 3 of this DPA respectively.
For transfers from the UK, the UK International Data Transfer Addendum to the SCCs applies, with its tables completed by the details above. For transfers from Switzerland, the SCCs apply with the adaptations required by the Swiss FDPIC: references to the GDPR are read as references to the FADP, and Swiss authorities and courts are competent for Swiss Data Subjects.
If a transfer mechanism we rely on is invalidated, we will work with you in good faith to put a lawful alternative in place promptly.
12. Audits and reports#
We will make available the information reasonably necessary to demonstrate compliance with this DPA — including summaries of our technical and organizational measures and, when available, third-party assessments or certifications.
Where Data Protection Laws grant you an audit right that this documentation does not satisfy, you (or an independent auditor bound by confidentiality — not a competitor of ours) may audit our compliance: once in any 12-month period, on at least 30 days' written notice, during business hours, without access to other customers' data or systems, and at your own cost. Audit findings are Confidential Information under the Agreement.
13. Return and deletion of data#
During the term you can export Customer Data, including End-User Personal Data, at any time through the dashboard and APIs — that is the designed return mechanism, and it is available on every plan.
After termination or expiry of the Agreement, export remains available for 30 days. We then delete End-User Personal Data from live systems within 90 days of termination, and residual copies in encrypted backups expire on our rotation schedule no later than 180 days after termination — unless a law we are subject to requires longer retention of specific records, in which case we isolate and protect that data and delete it when the requirement ends. On request, we will confirm deletion in writing.
14. US state privacy laws#
Where the CCPA/CPRA or a similar US state privacy law applies, we act as your “service provider” or “processor”: we process Personal Data only for the business purposes described in the Agreement and Annex 1; we do not sell or share Personal Data; we do not retain, use, or disclose it outside our direct business relationship with you or for any commercial purpose other than providing the Service; and we do not combine it with Personal Data received from others except as the law permits for the services. We will notify you if we determine we can no longer meet these obligations, and you may take the reasonable and appropriate steps the statute allows to stop unauthorized use.
15. Liability#
Each party's liability arising out of or related to this DPA — including the SCCs, to the extent the law allows — is subject to the exclusions and limitations in the Agreement, and this DPA does not create a separate or additional cap.
16. Order of precedence and changes#
For data-protection matters, this DPA prevails over the rest of the Agreement, and the SCCs prevail over this DPA where they conflict. We update this DPA only as needed to reflect changes in Data Protection Laws or approved transfer mechanisms, with notice as described in the Terms; updates will not materially reduce the protections in place during your current term.
17. Contact#
Data-protection questions, countersigned copies, and instructions: support@cashsdk.com with the subject “DPA”. Security reports: security@cashsdk.com.
Annex 1: Details of processing#
- Subject matter — provision of the CashSDK platform: purchase validation, subscription and entitlement management, paywalls, experiments, analytics, webhooks, and related support.
- Duration — the term of the Agreement, plus the export and deletion windows in Section 13.
- Nature and purpose — hosting, storage, transmission, validation against app-store APIs, computation of subscription state and analytics, forwarding to destinations you configure, and display in your dashboard — all to provide the Service as you configure it.
- Categories of Data Subjects — End Users of the apps you connect to the Service.
- Categories of Personal Data — user identifiers you assign or generate (app user IDs and similar), store transaction identifiers and signed receipt or transaction payloads, purchase details (product, price, currency, quantity, timestamps), subscription and entitlement state (trials, renewals, grace periods, refunds), device and platform metadata (OS and app version, SDK version, locale), and IP addresses transiently in service logs.
- Special categories — none. The Service is not designed for special-category data, and the Acceptable Use Policy prohibits sending it.
- Frequency — continuous, for as long as your apps use the Service.
Annex 2: Technical and organizational measures#
- Encryption in transit — TLS for SDK, API, and dashboard traffic.
- Encryption at rest — databases and backups encrypted at rest by our hosting providers; store credentials (App Store Connect keys, Google Play service accounts) additionally envelope-encrypted at the application layer with segregated key material.
- Tenant isolation — customer data is segregated logically per workspace and enforced at the database layer (row-level security).
- Access control — least-privilege, role-based access for personnel; administrative access is limited and logged; production secrets live in managed secret stores, not in code.
- Application security — code review before merge, automated test suites over the purchase path, and routine dependency updates.
- Monitoring — availability monitoring, structured logs, and error tracking configured to scrub secrets and minimize personal data.
- Backups and resilience — automated encrypted backups with scheduled rotation, hosted with providers that maintain physical-security and redundancy controls.
- Incident response — a documented process for triage, containment, customer notification under Section 9, and post-incident review.
- Personnel — confidentiality obligations for all staff and contractors, with security awareness from onboarding.
- Vendor management — Subprocessors are assessed and bound to written data-protection terms before use (see Annex 3).
Annex 3: Subprocessors#
We currently engage the following Subprocessors and infrastructure providers. The last column notes whether a provider can process End-User Personal Data or only workspace, billing, and website data. We give 30 days' notice of changes as described in Section 7.
| Provider | Purpose | Location | End-User Personal Data |
|---|---|---|---|
| Railway | Application hosting, databases, and queues | United States | Yes |
| Cloudflare | DNS, content delivery, and network security | United States (global network) | Yes (in transit) |
| Vercel | Web hosting for our sites and dashboard | United States | Yes (dashboard delivery) |
| Functional Software, Inc. (Sentry) | Error and performance monitoring, scrubbed of secrets | United States | Incidental (diagnostic events) |
| Stripe | Platform billing and payment processing | United States | No |
| Resend | Transactional email (sign-in codes, billing, notices) | United States | No |
| Google (Google Analytics) | Website analytics on the marketing site | United States | No |
Questions about our policies? Contact →