Data Processing Addendum

Last updated: September 10, 2026

This addendum applies where LASI processes business data on behalf of a customer organization using the Service. The customer is the controller of its data; LASI is a processor acting on the customer’s documented instructions — operating the Service as configured by the customer’s administrators.

Scope of processing

Inventory, cost, and sales records the customer’s team enters; order data pulled from platforms the customer connects (TikTok Shop, Shopify), including the limited buyer details those platforms share for fulfillment; team member names, emails, and roles; and uploaded supplier documents. We do not sell customer data or use it for advertising.

Isolation

Every record is scoped to the customer’s organization and enforced by row-level security in the database plus organization checks in the application layer. Files are stored in organization-scoped private storage served by short-lived signed URLs.

Sub-processors

The full, current list lives on the Privacy Policy: Supabase, Vercel, Whop, Resend where invitation email is enabled, Anthropic where the help assistant or invoice scanning is enabled, Expo for mobile push notifications, UPCitemdb and Barcode Lookup for barcode identification, PrintNode where a packing-bench printer is connected (it receives the shipping labels you print, which carry buyer addresses), Shippo where a label account is connected (it receives the buyer’s name, address and phone and your ship-from address to buy a replacement’s label), and GitHub, which hosts our source code and the scheduled-sync trigger but receives no customer data. Platforms the customer connects (TikTok Shop, Shopify, Homebase) are data sources, not sub-processors. We will update that list before adding a sub-processor that handles customer data.

Security

Encryption in transit everywhere; third-party OAuth tokens encrypted at rest with keys held in the hosting provider’s secret store; role-based access inside each organization; an audit trail of destructive administrative actions. Operator access to the platform console is restricted to an allowlist and logged. Details on the Security page.

Assistance and requests

Administrators can export the organization’s data from Settings at any time. We assist with data-subject requests that reach the customer, and refer any request we receive directly to the customer unless legally prevented.

Incidents

We notify affected customers without undue delay after becoming aware of a personal-data breach involving their data, with what we know about scope and mitigation.

Deletion

On termination, the organization’s data is deleted on request (self-service via account deletion, or by contacting us). Primary database records are deleted immediately; provider backups age out within 30 days; audit and billing records we must keep by law (invoices, payment ledger) are retained for 7 years.

Contact

Data processing questions: mshenbaum@gmail.com