MintLGS legal

Data Processing Addendum

This addendum defines how MintLGS processes personal information for a store and the responsibilities each party keeps.

Last updated: August 2, 2026

On this page
  1. 1. Application of this addendum
  2. 2. Instructions and permitted purpose
  3. 3. Customer responsibilities
  4. 4. Confidentiality and security
  5. 5. Subprocessors
  6. 6. Requests and assessments
  7. 7. Personal data incidents
  8. 8. Return, deletion, and retention
  9. 9. International transfers
  10. 10. U.S. state privacy terms
  11. 11. Compliance information
  12. 12. Processing details

1.Application of this addendum

This Data Processing Addendum (DPA) forms part of the MintLGS Terms of Service when MintLGS processes personal information in Customer Data for a Customer. Capitalized terms not defined here have the meaning in the Terms.

The Customer is the controller, business, or equivalent decision-maker for this personal information. MintLGS is the processor, service provider, contractor, or equivalent party acting on the Customer's documented instructions. Each party remains responsible for obligations that apply to its separate role.

2.Instructions and permitted purpose

MintLGS will process Customer Personal Data only to provide, secure, maintain, support, and improve the contracted service; follow the Customer's configured workflows and lawful instructions; prevent abuse; and comply with applicable law. The Terms, product configuration, support requests, and use of documented features are the Customer's instructions.

MintLGS will notify the Customer if an instruction appears to violate applicable data-protection law, unless prohibited from doing so. The Customer will not instruct MintLGS to process unlawful, excessive, or specially regulated information outside the service's intended use.

3.Customer responsibilities

The Customer will provide lawful notices, obtain required consent or another lawful basis, limit staff access, configure appropriate retention, respond to Store Customer requests, and use the service consistently with law. The Customer is responsible for custom event questions, merchant notes, uploaded content, email practices, and determining whether information about minors or sensitive information may be collected.

4.Confidentiality and security

MintLGS limits access to people and providers that need it and that are subject to confidentiality duties. MintLGS maintains safeguards appropriate to the nature and risk of the service, including production HTTPS, secure session cookies, password hashing, protected temporary tokens and provider credentials, access controls, tenant scoping, audit logging, rate limits, private export delivery, backups, monitoring, and security maintenance.

The Customer acknowledges that no service can guarantee absolute security and will maintain reasonable account, staff, device, network, and physical safeguards.

5.Subprocessors

The Customer gives general authorization for MintLGS to use subprocessors needed to provide the service. MintLGS remains responsible for their processing to the extent required by applicable law and uses agreements that impose appropriate data-protection duties.

The current list appears at Service Providers and Connected Services. MintLGS may update the list as the service changes. A Customer with a legally required, reasonable objection to a new core subprocessor should contact privacy@mintlgs.com promptly so the parties can work toward a practical solution.

6.Requests and assessments

Taking into account the nature of the processing, MintLGS will reasonably assist the Customer with verified requests for access, correction, deletion, restriction, objection, or portability and with data-protection assessments or regulator inquiries when the relevant information is available to MintLGS. The Customer remains responsible for communicating with the Store Customer or regulator.

If MintLGS receives a request that clearly concerns a Customer's Store Customer, MintLGS may direct the requester to that Customer and will not independently respond on the Customer's behalf unless law requires it.

7.Personal data incidents

MintLGS will notify the affected Customer without undue delay after confirming a personal data breach involving Customer Personal Data when applicable law requires notice. MintLGS will provide available information about the nature of the incident, affected information, likely consequences, and mitigation, and will update the Customer as material facts develop.

Notification does not admit fault or liability. The Customer is responsible for determining its own notice obligations.

8.Return, deletion, and retention

During an active account, the Customer can use available export tools and ordinary product features to access or correct data. Formal offboarding may provide a temporary export window before tenant-controlled operational data is purged.

MintLGS may retain limited records required for billing, referrals, tax, accounting, offboarding, abuse prevention, security, disputes, or law. Deleted active data can remain in time-limited backups until the backup lifecycle expires. Connected providers apply their own retention requirements. The Privacy Policy describes current operational retention in more detail.

9.International transfers

MintLGS and its providers may process information in the United States and other countries. Where applicable law requires a transfer mechanism, the parties will use the applicable standard contractual clauses or another approved safeguard. A legally required transfer addendum can be requested through the privacy contact.

10.U.S. state privacy terms

Where a U.S. state privacy law treats the Customer as a business or controller and MintLGS as a service provider, processor, or contractor, MintLGS will not sell or share Customer Personal Data for cross-context behavioral advertising; retain, use, or disclose it outside the business purposes in the agreement except as permitted by law; or combine it with personal information received from another person except as permitted to provide the service.

MintLGS will provide the same level of privacy protection required by applicable law, will notify the Customer if it can no longer meet a required obligation, and will allow reasonable steps to stop and remediate unauthorized use.

11.Compliance information

On reasonable written request, MintLGS will provide information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality, security, third-party rights, and reasonable limits on frequency and scope. The parties will first use existing documentation and remote review. Any additional audit must be legally required, scheduled in advance, avoid disruption, and be performed by a qualified independent reviewer at the Customer's expense.

12.Processing details

Subject matter and duration: operation of the MintLGS service for the subscription term and applicable retention period.

Nature and purpose: collection, organization, storage, retrieval, display, transmission, calculation, synchronization, support, backup, security, export, and deletion needed for the Customer's configured store operations.

People: Store Customers, prospective customers, staff, event participants, buylist sellers, order recipients, marketplace buyers and sellers, support contacts, and other people whose information the Customer submits.

Information: identity and contact details; addresses; account, order, inventory, buylist, event, loyalty and store-credit records; payment status and limited card descriptors; shipping and tracking; marketplace and provider identifiers; messages and support attachments; staff and audit information; device and security data; and other information entered into configured forms.

Sensitive information: MintLGS is not designed for social security numbers, government identity documents, medical records, biometric templates, raw payment-card data, or similarly sensitive content. A Customer should not place that information in free-text fields or uploads unless MintLGS expressly supports it and the Customer has confirmed a lawful need.