Data Processing Addendum
Part of the Resale Station Terms of Service · EaseTrade LLC · Version 2026-09-13
This Addendum forms part of the Terms of Service between EaseTrade LLC ("Company", the processor or service provider) and the business that uses Resale Station ("Customer", the controller or business). It governs the personal information Company processes on Customer's behalf ("Customer Personal Data") and controls over the Terms where they conflict on that subject.
1. Scope and roles
Customer decides what Customer Personal Data enters the Service and for what purposes; Company processes it only on Customer's documented instructions, which are the Terms, this Addendum, Customer's settings and its authorized users' actions in the Service. Company acts for itself, not for Customer, for its own account, billing, security and website records, as the Privacy Policy describes.
2. Details of the processing
| Subject matter | Running Customer's resale business: listings, orders, offers, shows, picking, packing, shipping, inventory, crew scheduling and time keeping. |
|---|---|
| Duration | The subscription term and the export period after it (Terms §10). |
| Data subjects | Customer's owners and staff; Customer's buyers as the marketplaces supply them. |
| Categories | Names, work emails, roles, schedules, time-clock punches and (if enabled) photographs, opted-in mobile numbers; buyers' usernames, names, shipping addresses, order and message details; connection tokens. |
| Sensitive data | None is required. Customer must not load health, biometric, government-identifier or payment-card data into free-text fields. |
3. Company's obligations
- Instructions. Process Customer Personal Data only as instructed, and tell Customer if an instruction appears to break the law.
- Confidentiality. Limit access to named staff bound by confidentiality, with logged, purpose-limited access.
- Security. Maintain the measures described in the Privacy Policy: encryption in transit, per-company row-level isolation enforced in the database, hashed credentials, tokens never exposed to users, tested backups, and pre-release tenancy tests.
- Subprocessors. Use only the providers listed at /subprocessors, under written terms no less protective than this Addendum. Company gives company owners at least 15 days' notice by email before adding one that will process Customer Personal Data; Customer may object on reasonable grounds, and if the objection cannot be resolved may terminate the affected subscription and receive a refund of unused prepaid fees.
- Incidents. Notify Customer without undue delay after becoming aware of a breach of security affecting Customer Personal Data, with the information Company has, and cooperate with Customer's own notification duties. This does not replace any statutory duty of either party.
- Assistance. Help Customer answer requests from individuals (access, correction, deletion, portability) using the Service's own tools, and route to Customer any request Company receives directly.
- Return and deletion. At the end of the subscription, provide export for 30 days, then delete Customer Personal Data as the Privacy Policy describes, except what law requires Company to keep.
- Audit. On written request no more than once a year, provide the information reasonably necessary to demonstrate compliance with this Addendum, and allow a reasonable review of it at Customer's expense.
4. Customer's obligations
Customer is responsible for the lawfulness of the data it loads, for the notices it owes its staff and buyers, for its instructions and settings, for the people it authorizes and their use, and for keeping its marketplace and QuickBooks grants within those services' terms.
5. Particular laws
- California. Where the CCPA applies, Company is a service provider: it will not sell or share Customer Personal Data, retain, use or disclose it outside the direct business relationship or for any purpose other than the services, or combine it with data from other sources except as the law permits, and will notify Customer if it can no longer meet its obligations. Customer may take reasonable steps to stop and remediate unauthorized use.
- EU, EEA and UK. The Service is offered from and hosted in the United States. If Customer establishes that European or UK data-protection law applies to its use, the parties will put in place the required transfer mechanism (the EU Standard Contractual Clauses, module two, and the UK Addendum) and this Addendum will be read to include the Article 28 terms; contact Company to arrange it before loading such data.
- Other laws. Where another law requires particular terms between the parties, they are deemed included to the extent required.
6. Liability
Each party's liability under this Addendum is subject to the limits in the Terms, except where the law does not allow.