Skip to content

Data Processing Addendum

Last updated: April 1, 2026

This page summarizes Queeble's standard data processing commitments for merchants and partners evaluating the platform for customer-data workflows.

1. Scope

  • This Data Processing Addendum applies when Queeble processes personal data on behalf of a merchant or business customer in connection with the Queeble services.
  • For that customer data, the merchant is the controller or business and Queeble acts as a processor or service provider except where applicable law states otherwise.

2. Processing Instructions

  • Queeble processes personal data only on documented instructions from the merchant, including instructions reflected in the product configuration, support requests, and applicable service documentation.
  • Queeble will not process merchant customer data for unrelated advertising or for sale to third parties.

3. Categories of Data

  • Depending on enabled features, Queeble may process names, email addresses, phone numbers, shipping or billing addresses, order records, support conversation content, store data, channel metadata, and associated operational records.
  • The categories of data subjects may include merchant staff, store customers, leads, prospects, and end users interacting with enabled channels.

4. Security Measures

  • Queeble maintains technical and organizational safeguards designed to protect personal data, including access controls, authentication controls, encryption for sensitive data flows and secrets, audit logging, and service monitoring.
  • Access to production data is limited to authorized personnel with a legitimate business need.

5. Subprocessors

  • Queeble may use subprocessors for hosting, cloud infrastructure, communication delivery, analytics, support, security, and payment operations.
  • Queeble requires subprocessors to protect personal data through written obligations appropriate to the services they provide.

6. Data Subject Requests

  • Queeble provides features and reasonable assistance to help merchants respond to access, deletion, correction, export, or restriction requests where required by law.
  • If Queeble receives a request directly about merchant-controlled data, Queeble may direct the requester to the relevant merchant unless legally required to respond otherwise.

7. Incident Notification

  • If Queeble confirms a security incident affecting merchant customer data, Queeble will investigate, contain, and remediate the issue and notify the affected merchant without undue delay, subject to legal and operational constraints.
  • Notifications may include the nature of the incident, affected data categories, known impact, and available remediation steps.

8. International Transfers

  • Where cross-border transfers occur, Queeble applies safeguards available under applicable law, including contractual protections where appropriate.

9. Return and Deletion

  • Upon termination or deletion of the services, Queeble will delete or return personal data in accordance with the service terms, retention schedule, merchant instructions, and legal obligations.
  • Backup, security, billing, and compliance records may be retained for limited periods where required for legitimate business or legal purposes.

10. Contact

  • For DPA execution requests or vendor reviews, contact legal@queeble.com.
  • For privacy requests, contact privacy@queeble.com.
  • For security reviews, contact security@queeble.com.