SHIP ZONE INC. — DATA PROCESSING AGREEMENT

Effective Date: March 20, 2026

This Data Processing Agreement (“DPA”) forms part of the Ship Zone Inc. Terms of Service or other written agreement governing a customer’s use of Ship Zone’s Services (the “Agreement”). This DPA is entered into between Ship Zone Inc. (“Ship Zone,” “Processor,” “Service Provider,” “we,” “us,” or “our”) and the customer or business accepting the Agreement (“Customer,” “Controller,” “Organization,” “you,” or “your”).

This DPA governs Ship Zone’s Processing of Personal Information on behalf of Customer in connection with the Services. By using Services involving the Processing of Personal Information, Customer agrees that this DPA is incorporated into and forms part of the Agreement.

1. Purpose

Ship Zone provides shipping, logistics-management, parcel, freight, ocean-freight, e-commerce, marketplace-integration, API, fulfillment-support, tracking, label-generation, electronic-invoicing, and related technology Services. In providing these Services, Ship Zone may Process Personal Information supplied or made available by Customer, including for Customers or Shipments connected to jurisdictions with mandatory electronic-invoicing regimes such as Costa Rica. This DPA establishes the parties’ respective responsibilities concerning such Personal Information.

2. Definitions

2.1 “Applicable Data Protection Law” means privacy, data-protection, and information-security laws applicable to the Processing governed by this DPA, including Canada’s Personal Information Protection and Electronic Documents Act (“PIPEDA”), applicable substantially-similar provincial private-sector privacy legislation (for example, Quebec’s Act respecting the protection of personal information in the private sector, as amended by “Law 25”), and, where applicable to specific Processing, other jurisdictions’ privacy laws described in Section 20.
2.2 “Controller” means the person or entity that determines the purposes and means of Processing Personal Information, or the equivalent term under Applicable Data Protection Law.
2.3 “Customer Data” means information, including Personal Information, submitted, transmitted, uploaded, imported, accessed, or otherwise made available to Ship Zone by or on behalf of Customer in connection with the Services.
2.4 “Data Subject” means an identified or identifiable individual to whom Personal Information relates.
2.5 “Personal Information” means information about an identifiable individual, and includes equivalent terms such as “personal data.”
2.6 “Processing” means any operation performed on Personal Information, including collecting, accessing, receiving, organizing, storing, using, transmitting, disclosing, retrieving, modifying, deleting, or destroying such information.
2.7 “Processor” means an entity that Processes Personal Information on behalf of a Controller, or the equivalent role under Applicable Data Protection Law.
2.8 “Security Incident” (referred to under PIPEDA as a “breach of security safeguards”) means a confirmed breach of security resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Customer Personal Information Processed by Ship Zone. A Security Incident does not include unsuccessful attempts or activities that do not compromise Customer Personal Information, such as unsuccessful login attempts, scans, pings, denial-of-service attempts, or attacks blocked by appropriate security controls.
2.9 “Subprocessor” means a third party engaged by Ship Zone to Process Customer Personal Information on behalf of Customer in connection with the Services.
2.10 “Restricted Marketplace Integration” has the meaning given in the Terms of Service: an authorized connection to a third-party marketplace whose own program terms require Ship Zone not to publicly name that marketplace. “Restricted Marketplace Information” means Personal Information and other information Ship Zone receives or Processes through a Restricted Marketplace Integration.

3. Roles of the Parties

To the extent Ship Zone Processes Personal Information solely on behalf of Customer in providing the Services, Customer acts as the Controller (organization, under PIPEDA), and Ship Zone acts as the Processor (service provider). Ship Zone may independently determine the purposes and means of processing certain information for its own legitimate business purposes, including account administration, billing, payment management, fraud prevention, security, legal compliance, tax and accounting, business records, claims and disputes, enforcement of agreements, and operation and improvement of Ship Zone’s Services where permitted by applicable law. Such independent Processing is governed primarily by Ship Zone’s Privacy Policy and applicable law.

4. Customer Instructions

Customer instructs Ship Zone to Process Customer Personal Information as reasonably necessary to provide the Services, create shipments, obtain shipping quotations, purchase transportation services, generate shipping labels, process fulfillment information, provide shipment tracking, arrange parcel and freight transportation, support ocean-freight transactions, facilitate customs documentation and electronic invoicing where applicable, communicate with carriers, operate authorized integrations, provide technical and customer support, prevent fraud, maintain security, comply with applicable legal obligations, and perform other Processing reasonably necessary to provide Services requested by Customer. The Agreement, this DPA, Customer’s configuration of the Services, API requests, integration settings, and other documented instructions collectively constitute Customer’s instructions to Ship Zone.

5. Customer Responsibilities

Customer represents and warrants that: (1) Customer has complied and will comply with Applicable Data Protection Law; (2) Customer has all necessary rights, permissions, notices, and consents required to provide Personal Information to Ship Zone; (3) Customer is authorized to instruct Ship Zone to Process such Personal Information; (4) Customer’s instructions do not violate Applicable Data Protection Law; (5) Customer will not instruct Ship Zone to Process Personal Information for unlawful purposes; (6) Customer is responsible for the accuracy and lawfulness of Customer Data; (7) Customer will provide all legally required privacy notices to its customers, recipients, employees, and other Data Subjects; (8) Customer will maintain appropriate security over its Ship Zone account, users, API credentials, and connected platforms; and (9) Customer will comply with applicable marketplace, carrier, and platform requirements. Customer is solely responsible for determining whether the Services are appropriate for Customer’s legal and regulatory requirements.

6. Categories of Data Subjects

Customer Personal Information may concern Customer’s employees, authorized users, merchants, sellers, senders, purchasers, shipment recipients, consignees, customers of Customer, customer-support contacts, business contacts, and other individuals whose information Customer submits through the Services.

7. Categories of Personal Information

Depending upon Customer’s use of the Services, Ship Zone may Process:

  • Identity Information: first name, last name, business name, account identifiers.
  • Contact Information: email address, telephone number, billing/pickup/delivery/return address.
  • Shipment Information: order numbers, shipment identifiers, tracking numbers, shipment contents, commodity descriptions, package weight/dimensions, declared value, customs information, delivery instructions, fulfillment information.
  • Tax and Invoicing Information: GST/HST/QST registration information, and, where applicable, identification and tax information required to issue a compliant Costa Rican electronic invoice or equivalent regulated invoice.
  • Marketplace Information: where Customer connects an authorized marketplace or e-commerce integration (including a Restricted Marketplace Integration) — marketplace/seller/store identifiers, order information, recipient information, fulfillment information, shipment information, tracking information.
  • Technical Information: IP addresses, login information, API activity, device information, system logs, security information.

8. Purpose and Nature of Processing

Ship Zone Processes Customer Personal Information for shipping, fulfillment, transportation management, shipment documentation, rate calculation, label generation, tracking, carrier communication, customs and electronic-invoicing support, marketplace and e-commerce integration, customer and technical support, fraud prevention, security, and related logistics-management functions. Processing may include collection, retrieval, organization, transmission, storage, use, disclosure to authorized providers, and deletion.

9. Duration of Processing

Ship Zone may Process Customer Personal Information for the duration of the Agreement and thereafter only for as long as necessary to complete authorized Services, permitted by this DPA or applicable platform requirements, or required or permitted by applicable law. Different categories of Personal Information may be subject to different retention requirements.

10. Confidentiality

Ship Zone will take reasonable measures designed to ensure that persons authorized to Process Customer Personal Information are subject to appropriate confidentiality obligations. Access to Customer Personal Information will be limited to personnel and authorized providers with a legitimate need for access in connection with the Services or other permitted purposes.

11. Security

Ship Zone will maintain reasonable and appropriate administrative, organizational, physical, and technical safeguards designed to protect Customer Personal Information against unauthorized access, acquisition, disclosure, alteration, destruction, or loss, proportionate to the sensitivity of the information, as further described in Schedule B. Customer acknowledges that no Internet transmission, computer network, database, software platform, cloud environment, or electronic-storage system can be guaranteed to be completely secure, and Ship Zone does not warrant or guarantee that Security Incidents will never occur. Nothing in this provision reduces Ship Zone’s obligations under Applicable Data Protection Law that cannot lawfully be limited.

12. Restricted Marketplace Integration Processing

Where Customer authorizes Ship Zone to access information through a Restricted Marketplace Integration, additional requirements apply, as further described in Schedule C. Ship Zone will Process Restricted Marketplace Information only for authorized purposes associated with providing Services requested by the applicable Customer, will not sell Restricted Marketplace Information, and will not use Restricted Marketplace Information for purposes prohibited by the applicable marketplace’s program requirements. Ship Zone will apply the applicable marketplace’s security, access, use, sharing, retention, and deletion requirements to Restricted Marketplace Information, and where those requirements are stricter than the general requirements of this DPA, they will govern. Restricted Marketplace credentials, authorization tokens, and related authentication information are treated as confidential security information and are not intentionally exposed publicly; Customer is responsible for protecting any such credentials under Customer’s own control.

13. Other Marketplace and E-Commerce Data

Where Customer authorizes Ship Zone to connect to Shopify, Etsy, eBay, WooCommerce, or another marketplace, e-commerce service, or application, Ship Zone may Process information made available through the authorized connection in accordance with Customer’s instructions, applicable platform permissions, applicable contractual requirements, this DPA, and Applicable Data Protection Law. Where a platform imposes stricter requirements on its information, Ship Zone will apply such requirements where applicable.

14. Subprocessors

Customer authorizes Ship Zone to engage Subprocessors reasonably necessary to provide, support, secure, and maintain the Services, including providers of cloud infrastructure, data hosting, cybersecurity, communications, customer support, software infrastructure, analytics, and payment processing. Ship Zone will require applicable Subprocessors that Process Customer Personal Information on Ship Zone’s behalf to maintain data-protection obligations appropriate to the nature of their Processing, consistent with PIPEDA’s requirement that organizations use contractual or other means to provide a comparable level of protection while information is being processed by a third party. Ship Zone will make available, upon written request, a current list of the categories of Subprocessors materially involved in Processing Customer Personal Information, and will provide reasonable advance notice of the addition of a new Subprocessor where required by Applicable Data Protection Law.

15. Carriers and Logistics Providers

Customer specifically authorizes Ship Zone to transmit necessary Personal Information to carriers and logistics providers selected, requested, or otherwise used to perform Customer’s Shipment, including Canadian domestic carriers, cross-border and international carriers, postal operators, couriers, freight carriers, trucking companies, freight forwarders, ocean carriers, airlines, customs brokers, warehouses, and insurance providers. Once an independent carrier or logistics provider receives Personal Information for its own transportation, regulatory, customs, or operational purposes, that provider may act as an independent Controller under applicable law, and Ship Zone does not control that provider’s independent Processing activities.

16. Third-Party Controllers

A third party receiving information from Ship Zone may be an independent Controller rather than a Subprocessor. Where that occurs, the third party’s Processing is governed by its own legal obligations, contractual terms, and privacy practices. To the maximum extent permitted by applicable law, Ship Zone is not responsible for the independent acts, omissions, privacy practices, security practices, or Processing activities of independent third-party Controllers.

17. Cross-Border and International Data Transfers

Customer acknowledges that the Services involve cross-border shipping and technology infrastructure. Customer Personal Information may therefore be transferred to or Processed in countries other than the country where Customer or the Data Subject is located, including the United States, Costa Rica, and other jurisdictions in which Ship Zone, its service providers, carriers, platforms, or logistics providers operate. Consistent with PIPEDA Principle 4.1.3 (accountability for information transferred to third parties, including across borders), Ship Zone remains responsible for Personal Information in its custody or control, including information transferred to a Subprocessor for processing, and will use contractual or other means to provide a comparable level of protection. Where Applicable Data Protection Law of another jurisdiction requires specific safeguards for a transfer for which Ship Zone is responsible, Ship Zone will implement applicable legally required transfer mechanisms.

18. Data Subject Requests

If Ship Zone receives a request from a Data Subject concerning Customer Personal Information that Ship Zone Processes solely on behalf of Customer, Ship Zone may direct the Data Subject to Customer where appropriate. Taking into account the nature of the Processing and where required by Applicable Data Protection Law, Ship Zone will provide reasonable assistance to Customer in responding to qualifying access, correction, and consent-withdrawal requests. Customer remains responsible for determining whether and how a request should be fulfilled where Customer acts as Controller, including receiving privacy requests, verifying identity, determining applicable legal exceptions, and providing required responses within any statutory response period; Ship Zone does not provide legal advice concerning Customer’s obligations to Data Subjects.

19. Security Incidents (Breach of Security Safeguards)

Upon becoming aware of a Security Incident affecting Customer Personal Information that creates a real risk of significant harm to an individual or for which notification to Customer is otherwise required under Applicable Data Protection Law, Ship Zone will notify Customer without undue delay, consistent with PIPEDA’s breach-notification requirements. Such notification will not constitute an acknowledgment or admission of fault or liability by Ship Zone. Where reasonably available and legally required, Ship Zone may provide information concerning the nature of the Security Incident, categories of affected information, remediation measures, and other information reasonably necessary for Customer’s own notification obligations to affected individuals and to the Office of the Privacy Commissioner of Canada or other applicable regulator.

20. Customer Security Incidents

Customer must notify Ship Zone promptly if Customer becomes aware of compromised Ship Zone or API credentials, unauthorized Ship Zone account access, unauthorized marketplace connections, unauthorized access by Customer personnel, or other circumstances that may affect the security of Customer Data within the Services. Ship Zone is not responsible for Security Incidents caused solely by Customer’s systems, personnel, credentials, applications, or failure to follow reasonable security practices, except to the extent responsibility cannot legally be excluded.

21. Return and Deletion of Personal Information

Upon termination of the applicable Services, Ship Zone will delete or return Customer Personal Information where required by Applicable Data Protection Law and according to applicable retention requirements. Ship Zone may retain information where retention is permitted or required for legal obligations, tax records, accounting, customs and electronic-invoicing records, fraud prevention, security, claims, insurance matters, chargebacks, disputes, litigation, contract enforcement, regulatory obligations, or other lawful purposes; where retained under such an exception, the information remains subject to applicable protections until deletion is appropriate. Where an authorized marketplace requires particular information to be deleted sooner than Ship Zone’s standard retention period, Ship Zone will apply that requirement.

22. Audits and Compliance Information

Where required by Applicable Data Protection Law, Ship Zone will make reasonably necessary information available to demonstrate compliance with applicable Processor obligations. Any audit or assessment requested by Customer must be legally required or reasonably justified, protect Ship Zone’s confidential information and that of other customers, avoid unreasonable disruption, comply with reasonable security requirements, and be conducted at Customer’s expense unless applicable law requires otherwise. Ship Zone may satisfy an audit request by providing appropriate third-party certifications, assessment reports, security documentation, questionnaires, or similar materials where legally sufficient. Customer may not obtain access to systems, source code, infrastructure, or records that would compromise the security, confidentiality, or privacy of Ship Zone or other customers.

23. Government Requests

Ship Zone may disclose Customer Personal Information where required by applicable law, subpoena, court order, governmental demand, regulatory requirement, or other lawful process. Where legally permitted and appropriate, Ship Zone may notify Customer of such a request.

24. Aggregated and De-Identified Information

Where permitted by Applicable Data Protection Law, applicable contracts, and applicable platform requirements, Ship Zone may create and use aggregated or de-identified information that cannot reasonably identify Customer or an individual, for purposes including analytics, security, fraud prevention, performance measurement, capacity planning, service improvement, and business intelligence. Ship Zone will not attempt to re-identify de-identified information where prohibited by applicable law.

25. Restricted Processing

Ship Zone will not knowingly sell Customer Personal Information processed solely on behalf of Customer to data brokers; retain, use, or disclose Customer Personal Information for prohibited purposes; use Restricted Marketplace Information for purposes prohibited by the applicable marketplace’s requirements; or combine restricted Customer Personal Information in a manner prohibited by Applicable Data Protection Law. This provision does not prevent Ship Zone from Processing information for permitted security, fraud prevention, legal compliance, billing, operational, or other purposes allowed under applicable law.

26. U.S. and Other State/Provincial Privacy Requirements

To the extent applicable U.S. state privacy legislation treats Ship Zone as a Service Provider, Processor, or Contractor concerning Customer Personal Information (for example, where Customer or Data Subjects are located in the United States), Ship Zone will comply with applicable statutory obligations for that role, will not sell or share such information as those terms are defined under applicable state law, and will not combine it with personal information from another source except as permitted by applicable law. Nothing in this DPA requires Ship Zone to assume obligations under a law that does not apply to Ship Zone or the applicable Processing activity.

27. Costa Rica and Other Jurisdictions

Where Ship Zone Processes Personal Information in connection with Customers or Shipments connected to Costa Rica (including for electronic-invoicing purposes) or another jurisdiction with its own data-protection or tax-identification requirements, Ship Zone will apply the requirements of that jurisdiction’s applicable law to the Processing of that information, in addition to the requirements of this DPA.

28. Customer Indemnification

29. Limitation of Liability

30. Third-Party Liability

To the maximum extent permitted by applicable law, Ship Zone is not responsible under this DPA for a Security Incident, privacy violation, unauthorized Processing, or other act or omission caused exclusively by Customer, Customer’s employees or contractors, Customer’s applications or devices, Customer-controlled credentials, an independent carrier, an independent marketplace, a governmental authority, or another independent third-party Controller, except where Ship Zone is independently responsible under applicable law.

31. Conflicts

If this DPA conflicts with the Agreement concerning the Processing of Customer Personal Information, this DPA will control solely with respect to that conflict. If an applicable mandatory privacy law requires a provision different from this DPA, the mandatory requirement will control to the extent required. If an applicable Restricted Marketplace Integration’s requirements impose stricter obligations concerning its information, that requirement will govern that information.

32. Changes to This DPA

Ship Zone may update this DPA where reasonably necessary to reflect changes to the Services, Applicable Data Protection Law, new privacy or security requirements, new integrations, marketplace requirements, or changes to Ship Zone’s Processing activities. Material changes will be handled in accordance with applicable law and the Agreement.

33. Termination

This DPA remains effective for as long as Ship Zone Processes Customer Personal Information governed by this DPA. Termination of Customer’s account or Agreement does not terminate provisions that by their nature must survive, including confidentiality, data retention, deletion, liability, indemnification, and legal-compliance obligations.

34. Governing Law; Dispute Resolution

Unless Applicable Data Protection Law requires otherwise, this DPA is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein, and any dispute arising out of or relating to this DPA is subject to the same binding arbitration agreement and class proceeding waiver set out in the Terms of Service.

35. Entire Data Processing Agreement

This DPA, together with the Agreement, Privacy Policy, and any applicable written addendum, constitutes the parties’ agreement concerning Ship Zone’s Processing of Customer Personal Information on Customer’s behalf.

36. Contact Information

Questions concerning this DPA or privacy matters may be directed to:
Ship Zone Inc.
Privacy Officer / Data Protection Contact

For DPA inquiries, use subject line “Data Processing Agreement.” For privacy requests, use subject line “Privacy Request.” For requests concerning a Restricted Marketplace Integration, use subject line “Marketplace Integration Privacy Request.”

SCHEDULE A — DETAILS OF PROCESSING

Subject Matter: Provision of Ship Zone’s shipping, logistics, e-commerce integration, marketplace integration, fulfillment-support, API, label-generation, tracking, electronic-invoicing, parcel, freight, and related Services.
Duration: For the duration of the Services and applicable authorized or legally required retention periods.
Nature of Processing: Collection, receipt, organization, retrieval, use, transmission, storage, disclosure to authorized providers, support, security, and deletion.
Purpose: To provide, support, maintain, secure, and improve the Services requested by Customer and satisfy applicable legal and contractual obligations.
Categories of Data Subjects: Customer users, employees, merchants, sellers, senders, purchasers, shipment recipients, consignees, Customer’s customers, business contacts, and other persons whose information Customer provides.
Categories of Personal Information: Names, business names, addresses, email addresses, telephone numbers, tax/GST-HST-QST identifiers, order identifiers, shipment identifiers, tracking numbers, shipment information, fulfillment information, customs information, electronic-invoicing information, marketplace information, technical information, and other Personal Information Customer submits through authorized Services.
Special Categories / Sensitive Information: Ship Zone’s Services are not designed for Customer to intentionally submit sensitive Personal Information unrelated to legitimate shipping or logistics requirements. Customer should not submit sensitive Personal Information unless necessary, lawful, and expressly supported by the applicable Service.

SCHEDULE B — SECURITY MEASURES

Ship Zone will maintain security measures appropriate to the nature of applicable Personal Information and risks associated with the Processing, which may include, as applicable:

  • Access Control: restricted system access, authentication, user-access management, least-privilege principles, and removal of access when no longer required.
  • Data Protection: appropriate encryption during transmission, appropriate encryption at rest where required, credential protection, and secure storage practices — including tokenized handling of payment-card data through Ship Zone’s payment processor rather than storage of raw card numbers by Ship Zone.
  • Application and Infrastructure Security: security monitoring, logging, vulnerability management, system updates and patching, network protections, and secure software-development practices.
  • Organizational Measures: confidentiality requirements, security policies, access restrictions, incident-response procedures, and appropriate personnel practices.
  • Business Continuity: backup procedures, recovery procedures, and measures designed to maintain or restore availability of applicable systems, where appropriate.

The precise technical and organizational measures may change over time as long as the overall level of protection is not materially reduced in a manner inconsistent with applicable legal or contractual requirements.

SCHEDULE C — RESTRICTED MARKETPLACE INTEGRATION PROCESSING

Where Customer connects a Restricted Marketplace Integration to Ship Zone:

Purpose: Order processing, shipping, fulfillment, rate comparison, label generation, tracking, shipment-status updates, and related authorized seller/merchant functionality.
Potential Information: Seller or merchant identifiers, order identifiers, shipment information, fulfillment information, recipient information where authorized, delivery information where authorized, tracking information, and other information made available through authorized integration operations.
Restrictions: Ship Zone will: use Restricted Marketplace Information only for authorized purposes; not sell Restricted Marketplace Information; restrict access as required by the applicable marketplace’s program requirements; protect applicable Restricted Marketplace personal information; follow applicable marketplace retention and deletion requirements; and comply with applicable marketplace security and data-protection requirements, applying them in place of this DPA’s general requirements wherever they are stricter. Customer remains responsible for its own compliance with the applicable marketplace’s seller and program requirements.

ACCEPTANCE