SHIP ZONE INC. — DATA PROCESSING AGREEMENT — CANADA
Effective Date: March 21, 2026
This Data Processing Agreement (“DPA”) forms part of the Ship Zone Inc. Terms of Service or another written agreement governing Customer’s use of Ship Zone’s Services (“Agreement”).
This DPA is entered into between Ship Zone Inc., based in Toronto, Ontario, Canada (“Ship Zone,” “Processor,” “Service Provider,” “we,” or “us”) and the Customer accepting the Agreement (“Customer,” “Controller,” “Business,” “you,” or “your”).
This DPA governs Ship Zone’s Processing of Personal Data on behalf of Customer.
1. DEFINITIONS
- “Applicable Data Protection Law” means applicable Canadian federal or provincial privacy and data-protection law and any other privacy law applicable to the Processing governed by this DPA.
- “Controller” means the organization determining the purposes and means of Processing Personal Data or an equivalent role under applicable law.
- “Customer Data” means information submitted, uploaded, imported, synchronized, transmitted, or otherwise made available by Customer through the Services.
- “Data Subject” means an identifiable individual to whom Personal Data relates.
- “Personal Data” means information about an identifiable individual and equivalent terms under applicable law.
- “Processing” means any operation performed upon Personal Data.
- “Processor” means an organization Processing Personal Data on behalf of another organization.
- “Security Incident” means a confirmed breach involving unauthorized access, acquisition, use, disclosure, alteration, destruction, or loss of Customer Personal Data.
- “Subprocessor” means an authorized provider engaged by Ship Zone to Process Customer Personal Data on Customer’s behalf.
2. ROLES OF THE PARTIES
Where Ship Zone Processes Personal Data solely on Customer’s behalf:
- Customer acts as Controller or equivalent organization; and
- Ship Zone acts as Processor or service provider.
Ship Zone may independently process information for purposes including:
- Account administration;
- Billing;
- Payment collection;
- Fraud prevention;
- Security;
- Tax;
- Accounting;
- Claims;
- Legal compliance; and
- Enforcement.
Such independent Processing is governed by Ship Zone’s Privacy Policy and applicable law.
3. CUSTOMER INSTRUCTIONS
Customer instructs Ship Zone to Process Personal Data as necessary to:
- Provide shipping Services;
- Obtain rates;
- Generate labels;
- Arrange transportation;
- Process fulfillment;
- Provide tracking;
- Operate integrations;
- Support freight;
- Support ocean freight;
- Facilitate customs documentation;
- Communicate with Carriers;
- Provide support;
- Prevent fraud;
- Maintain security; and
- Comply with applicable legal obligations.
4. DOCUMENTED INSTRUCTIONS
The Agreement, this DPA, Customer’s platform settings, API calls, integration configuration, and other documented directions collectively constitute Customer’s instructions.
Ship Zone will not knowingly Process Customer Personal Data contrary to lawful documented instructions except where permitted or required by law.
5. CUSTOMER RESPONSIBILITIES
Customer represents and warrants that:
- Customer has lawful authority to collect Personal Data;
- Customer may lawfully provide Personal Data to Ship Zone;
- Required privacy notices have been provided;
- Required consent or another lawful basis exists;
- Customer’s instructions comply with applicable law;
- Customer Data is not unlawfully obtained;
- Customer maintains reasonable Account security; and
- Customer complies with applicable platform requirements.
6. CATEGORIES OF DATA SUBJECTS
Personal Data may concern:
- Customer employees;
- Authorized users;
- Merchants;
- Sellers;
- Senders;
- Purchasers;
- Shipment recipients;
- Consignees;
- Customer’s customers;
- Business contacts; and
- Other individuals whose information Customer provides.
7. CATEGORIES OF PERSONAL DATA
Personal Data may include:
- Names;
- Business names;
- Addresses;
- Telephone numbers;
- Email addresses;
- Order information;
- Shipment identifiers;
- Tracking information;
- Fulfillment information;
- Customs information;
- Marketplace information;
- Technical information;
- IP addresses; and
- Account information.
8. PURPOSE OF PROCESSING
Processing may occur for:
- Shipping;
- Fulfillment;
- Rate retrieval;
- Label generation;
- Tracking;
- Transportation management;
- Customs support;
- Freight;
- Ocean freight;
- Marketplace integration;
- E-commerce integration;
- API functionality;
- Support;
- Security; and
- Fraud prevention.
9. PROCESSING DURATION
Ship Zone may Process Customer Personal Data for the duration of the Services and thereafter only as permitted or required for:
- Legal obligations;
- Platform-specific requirements;
- Claims;
- Financial records;
- Security; or
- Other lawful purposes.
10. CONFIDENTIALITY
Persons authorized to Process Customer Personal Data will be subject to appropriate confidentiality obligations.
Access will be limited to legitimate business need.
11. SECURITY
Ship Zone will maintain reasonable administrative, organizational, physical, and technical safeguards appropriate to applicable risks.
Measures may include:
- Authentication;
- Access control;
- Least privilege;
- Encryption;
- Credential security;
- Network controls;
- Security logging;
- Monitoring;
- Vulnerability management;
- Backup procedures;
- Secure development;
- Personnel controls; and
- Incident-response procedures.
12. SECURITY RESPONSIBILITIES OF CUSTOMER
Customer is responsible for:
- Customer-controlled systems;
- Customer devices;
- Customer credentials;
- Customer API implementations;
- Authorized users;
- Connected applications; and
- Security of Personal Data before transmission to Ship Zone.
13. SECURITY INCIDENTS
Where required by Applicable Data Protection Law, Ship Zone will notify Customer without undue delay after becoming aware of a qualifying Security Incident affecting Customer Personal Data.
Notice is not an admission of liability.
14. INCIDENT INFORMATION
Where reasonably available and legally required, Ship Zone may provide information concerning:
- The nature of the incident;
- Categories of affected information;
- Known consequences;
- Mitigation;
- Remediations; and
- Other reasonably necessary information.
15. AMAZON SECURITY INCIDENTS
Where a Security Incident involves Amazon Information, Ship Zone will apply applicable Amazon incident-response and notification requirements.
16. SUBPROCESSOR AUTHORIZATION
Customer provides general authorization for Ship Zone to engage Subprocessors reasonably necessary to provide and support the Services.
17. SUBPROCESSOR OBLIGATIONS
Ship Zone will require applicable Subprocessors to maintain privacy and security obligations appropriate to the Processing they perform.
Ship Zone’s responsibilities concerning Subprocessors will be governed by Applicable Data Protection Law and the Agreement.
18. SUBPROCESSOR CHANGES
Where applicable law or a binding agreement requires notice of material Subprocessor changes, Ship Zone will provide an appropriate notice mechanism.
19. CARRIERS ARE GENERALLY NOT SUBPROCESSORS
A Carrier may independently determine purposes and means for:
- Transportation;
- Delivery;
- Customs;
- Regulatory compliance;
- Safety;
- Claims;
- Fraud prevention; and
- Legal obligations.
In such circumstances, the Carrier may act as an independent organization rather than a Ship Zone Subprocessor.
Customer authorizes Ship Zone to transmit necessary Shipment information to the applicable Carrier.
20. OTHER INDEPENDENT PROVIDERS
Independent parties may include:
- Customs brokers;
- Insurers;
- Marketplaces;
- Government authorities; and
- Certain payment providers.
Their independent Processing is governed by their own legal responsibilities.
21. AMAZON SP-API PROCESSING
Where Customer authorizes Amazon SP-API access, Ship Zone will Process Amazon Information only for applicable authorized purposes.
Ship Zone will:
- Not sell Amazon Information;
- Restrict access appropriately;
- Apply applicable security requirements;
- Follow applicable retention requirements;
- Follow applicable deletion requirements; and
- Comply with applicable Amazon data-protection obligations.
22. OTHER MARKETPLACE INFORMATION
Information obtained through other marketplaces will be Processed according to:
- Customer authorization;
- Platform permissions;
- Applicable contracts;
- Applicable law; and
- This DPA.
23. DATA SUBJECT REQUESTS
Taking into account the nature of Processing, Ship Zone will provide reasonable assistance where legally required to enable Customer to respond to qualifying requests involving:
- Access;
- Correction;
- Deletion;
- Withdrawal of consent; or
- Other applicable privacy rights.
24. REQUESTS RECEIVED DIRECTLY BY SHIP ZONE
Where Ship Zone receives a request relating solely to Customer-controlled Personal Data, Ship Zone may:
- Refer the requester to Customer;
- Notify Customer; or
- Respond according to Customer’s instructions,
subject to applicable law.
25. GOVERNMENT REQUESTS
Ship Zone may disclose Personal Data where required by lawful process.
Where legally permitted and appropriate, Ship Zone may notify Customer.
26. CROSS-BORDER PROCESSING
Customer acknowledges that Ship Zone’s international transportation and technology Services may require Personal Data to be Processed outside Canada.
This may include:
- The United States;
- Costa Rica;
- Shipment origin countries;
- Shipment transit countries;
- Shipment destination countries; and
- Jurisdictions where authorized service providers operate.
27. CROSS-BORDER SAFEGUARDS
Where Applicable Data Protection Law requires safeguards for a transfer for which Ship Zone is responsible, Ship Zone will implement appropriate measures required by law.
28. RETENTION
Ship Zone will retain Customer Personal Data only for periods reasonably necessary or permitted for:
- Providing Services;
- Accounting;
- Tax;
- Customs;
- Claims;
- Security;
- Fraud prevention;
- Chargebacks;
- Litigation;
- Contract enforcement; and
- Regulatory obligations.
29. PLATFORM-SPECIFIC RETENTION
Where Amazon or another platform imposes a more restrictive retention requirement, Ship Zone will apply that requirement to information governed by it.
30. RETURN OR DELETION
Upon termination of applicable Services, Ship Zone will delete or return Customer Personal Data where required by applicable law.
Ship Zone may retain information where legally permitted or required.
31. SECURE DELETION
Where deletion is required, Ship Zone will use reasonable methods appropriate to the systems and information involved.
32. BACKUPS
Personal Data may persist temporarily in backup systems after deletion from active systems.
Backup information will remain protected and will be deleted or overwritten according to applicable backup lifecycle procedures, subject to stricter platform requirements where applicable.
33. AUDIT INFORMATION
Where required by applicable law, Ship Zone will provide information reasonably necessary to demonstrate compliance with applicable service-provider obligations.
34. CUSTOMER AUDITS
Any requested audit must:
- Be reasonably justified;
- Protect Ship Zone confidential information;
- Protect other Customers;
- Avoid unreasonable business disruption;
- Follow Ship Zone security procedures; and
- Be conducted at Customer’s expense unless applicable law requires otherwise.
35. AUDIT ALTERNATIVES
Where legally sufficient, Ship Zone may satisfy audit requirements through:
- Security questionnaires;
- Policies;
- Certifications;
- Third-party reports;
- Assessment summaries; or
- Other appropriate documentation.
36. COMPLIANCE ASSISTANCE
Where legally required and taking into account the nature of Processing, Ship Zone will provide reasonable assistance concerning:
- Privacy assessments;
- Data Subject requests;
- Security obligations;
- Breach response; and
- Regulatory inquiries.
37. DE-IDENTIFIED INFORMATION
Where permitted by applicable law and platform requirements, Ship Zone may create aggregated or de-identified information.
Such information may be used for:
- Analytics;
- Security;
- Fraud prevention;
- Service improvement;
- Business intelligence; and
- Capacity planning.
38. RESTRICTED USE OF CUSTOMER DATA
Where Ship Zone acts solely as a service provider, Ship Zone will not knowingly sell Customer Personal Data to data brokers or Process Customer Personal Data for prohibited independent purposes.
This does not prevent lawful Processing for:
- Security;
- Fraud prevention;
- Legal compliance;
- Billing;
- Claims; or
- Other purposes permitted by law.
39. CANADIAN PRIVACY REQUIREMENTS
Each party will comply with privacy obligations applicable to its respective role under relevant Canadian federal and provincial privacy legislation.
40. CUSTOMER INDEMNIFICATION
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW AND SUBJECT TO THE AGREEMENT, CUSTOMER AGREES TO DEFEND, INDEMNIFY, AND HOLD HARMLESS SHIP ZONE INC. AND ITS AFFILIATES, DIRECTORS, OFFICERS, EMPLOYEES, AGENTS, AND REPRESENTATIVES FROM CLAIMS, PENALTIES, DAMAGES, LOSSES, LIABILITIES, COSTS, AND REASONABLE LEGAL FEES ARISING OUT OF OR RELATING TO:
- Customer’s unlawful collection of Personal Data;
- Failure to provide required privacy notices;
- Failure to obtain required authorization;
- Unlawful Processing instructions;
- Customer misuse of Personal Data;
- Customer’s privacy-law violations;
- Customer systems;
- Customer credentials;
- Customer API implementations;
- Customer marketplace violations; or
- Customer’s breach of this DPA.
41. LIMITATION OF LIABILITY
Except where applicable law prohibits such limitation, liability under this DPA is subject to the exclusions and limitations contained in the Agreement.
Nothing in this DPA expands Ship Zone’s liability beyond the Agreement unless applicable law requires otherwise.
42. THIRD-PARTY EVENTS
To the maximum extent permitted by law, Ship Zone is not responsible under this DPA for an event caused exclusively by:
- Customer;
- Customer personnel;
- Customer credentials;
- Customer applications;
- An independent Carrier;
- An independent marketplace;
- A governmental authority; or
- Another independent organization,
except where Ship Zone is independently responsible under applicable law.
43. CONFLICTS
If this DPA conflicts with the Agreement regarding Processing of Customer Personal Data, this DPA controls solely concerning that conflict.
Mandatory applicable law will control where required.
Applicable Amazon requirements control Amazon Information to the extent they impose stricter requirements.
44. CHANGES
Ship Zone may update this DPA where reasonably necessary to reflect:
- Legal changes;
- Service changes;
- Security changes;
- Processing changes;
- Marketplace requirements; or
- Platform changes.
Material changes will be handled according to applicable law and the Agreement.
45. TERMINATION
This DPA remains effective while Ship Zone Processes Customer Personal Data governed by it.
Confidentiality, retention, deletion, indemnification, liability, and legal-compliance obligations survive where applicable.
46. GOVERNING LAW
Unless applicable privacy law requires otherwise, this DPA is governed by the laws of Ontario and the federal laws of Canada applicable therein and the dispute provisions contained in the Agreement.
47. CONTACT
Ship Zone Inc.
Toronto, Ontario, Canada
Email: info@shipzone.ca
Website: www.shipzone.ca
For DPA matters: Subject: Data Processing Agreement
SCHEDULE A — PROCESSING DETAILS
Subject Matter: Provision of Ship Zone’s shipping, parcel, freight, ocean-freight, marketplace, e-commerce, API, label-generation, tracking, fulfillment-support, and logistics Services.
Duration: For the duration of the Services plus permitted or legally required retention periods.
Nature: Collection, access, organization, storage, retrieval, use, transmission, disclosure to authorized providers, support, security, and deletion.
Purpose: Providing, supporting, securing, administering, and maintaining Services requested by Customer.
Data Subjects: May include: Customer users; Employees; Merchants; Sellers; Senders; Purchasers; Shipment recipients; Consignees; Customer’s customers; and Business contacts.
Personal Data: May include: Names; Addresses; Telephone numbers; Email addresses; Order information; Shipment information; Tracking information; Fulfillment information; Customs information; Marketplace information; IP addresses; and Technical information.
SCHEDULE B — TECHNICAL AND ORGANIZATIONAL MEASURES
Ship Zone will maintain measures appropriate to the applicable risk.
Measures may include:
- Access Management: Authentication; Individual access controls; Least-privilege access; Access review; Removal of access when no longer required.
- Data Security: Encryption during transmission; Encryption at rest where appropriate or required; Credential security; Appropriate key-management controls.
- Infrastructure Security: Network protections; Logging; Monitoring; Vulnerability management; Patch management.
- Software Security: Secure-development practices; Testing; Change management; Vulnerability assessment.
- Personnel: Confidentiality requirements; Access restrictions; Security awareness.
- Incident Response: Identification; Containment; Investigation; Escalation; Remediation; Required notification.
- Availability: Where appropriate: Backups; Recovery processes; Continuity measures.
SCHEDULE C — AMAZON SP-API
Where Customer authorizes Amazon SP-API access:
Purpose: Order retrieval; Shipping; Fulfillment; Rate comparison; Label generation; Tracking; Shipment-status updates; and Related authorized functionality.
Potential Information: Seller identifiers; Order identifiers; Shipment information; Fulfillment information; Recipient information where authorized; Delivery information where authorized; and Tracking information.
Ship Zone Obligations: Ship Zone will: Use Amazon Information only for authorized purposes; Not sell Amazon Information; Restrict access appropriately; Follow applicable Amazon security requirements; Follow applicable retention requirements; Follow applicable deletion requirements; and Follow applicable Amazon data-protection requirements.
Customer Obligations: Customer remains responsible for: Its Amazon seller obligations; Valid authorization; Account security; and Compliance with marketplace rules.
ACCEPTANCE
By accepting an Agreement incorporating this DPA and using Services involving Processing of Customer Personal Data, Customer agrees that this DPA forms part of the Agreement.
Where Ship Zone and Customer execute a separately signed DPA that expressly supersedes this online DPA, that signed DPA will control to the extent stated.

