What we process, what the processor processes, and how to get their DPA. This page is not a substitute for a signed processor DPA.
The model those companies use
Stripe, Square, and Adyen publish a Data Processing Agreement because they process personal data as a processor for a merchant, and as a controller for their own sales and fraud files. We copy that split — honestly — for our size.
When we are a controller
We are a controller of the data you send us so we can review a statement, quote hardware, answer an inquiry, or run this site: name, company, email, mobile, the PDF or photo you upload, and the ticket trail. Our Privacy Policy governs that. We do not sell it.
When we are not in the card-data chain
We do not store PAN, track data, or CVV on this site. A payment you run on a terminal, a gateway, or a processor-hosted pay link is the processor’s processing. Their DPA, their AOC, their subprocessor list. We can introduce you to that packet. We will not sign a document that pretends we are the processor.
When we handle your file as a service provider
If you are a merchant and we hold your statement or KYC image so we can work the deal, we handle that file only to provide that service, we do not use it to advertise to your customers, and we delete or return it on the schedule in Records. If you need a written addendum for a specific engagement, write privacy@theplacetoshoplocal.com. A lawyer should review anything you sign.
International transfers
The public site is hosted in the United States. We do not operate an EU establishment. If you write us from abroad, you are sending the file to Arizona.