Last updated September 29, 2026
This summary is for convenience. The agreement is the text that follows it.
This Data Processing Agreement (“DPA”) has two parts: (1) the Key Terms and Annexes on this page, which are the Cover Page; and (2) the Common Paper DPA Standard Terms Version 1.1 posted at commonpaper.com/standards/data-processing-agreement/1.1 (the “DPA Standard Terms”), which are incorporated by reference. If there is any inconsistency between the parts, this Cover Page controls over the DPA Standard Terms.
Capitalized words have the meanings given on this page, in the DPA Standard Terms, or in the Agreement. If this page omits or does not define a variable used in the DPA Standard Terms, its meaning is “none” or “not applicable” and the related clause does not apply. This DPA is accepted when Customer accepts the Agreement and applies whenever Provider Processes Customer Personal Data.
| Agreement | The Clove Analytics Terms of Service, together with each Engagement Summary accepted under them. |
|---|---|
| Provider | Clove Analytics LLC. |
| Customer | The Customer under the Agreement. |
| Approved Subprocessors | The Subprocessors listed in Annex III on this page. |
| Provider Security Contact | security@cloveanalytics.com |
| Security Policy | Provider will use commercially reasonable efforts to secure the Service from unauthorized access, alteration, or use and other unlawful tampering, and will maintain the measures described in Annex II. |
| DPA Covered Claim | None. |
| DPA Liability Cap | None. The limitations of liability in the Agreement apply. |
| Governing Law and Chosen Courts | As set out in the Agreement. |
| Governing Member State | EEA transfers: Ireland. UK transfers: England and Wales. |
To the extent the California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq. (“CCPA”) applies, the parties acknowledge and agree that Provider is a service provider and is receiving Personal Data from Customer to provide the Service as agreed in the Agreement and detailed in Annex I(B), which constitutes a limited and specified business purpose. Provider will not sell or share any Personal Data provided by Customer under the Agreement. In addition, Provider will not retain, use, or disclose any Personal Data provided by Customer under the Agreement except as necessary for providing the Service for Customer, as stated in the Agreement, or as permitted by Applicable Data Protection Laws. Provider certifies that it understands the restrictions of this paragraph and will comply with all Applicable Data Protection Laws. Provider will notify Customer if it can no longer meet its obligations under the CCPA.
| Data exporter | Customer. Address and contact person: as given in the Engagement Summary or at checkout. Activities relevant to the transfer: see Annex I(B). Role: Controller, or Processor where Customer Processes the Personal Data on behalf of another Controller. |
|---|---|
| Data importer | Clove Analytics LLC, 30 N Gould Street STE R, Sheridan, WY 82801, United States. Contact: the Provider Security Contact. Activities relevant to the transfer: see Annex I(B). Role: Processor. |
| Service | The Services described in an Engagement Summary, including any Hosted Software. |
|---|---|
| Categories of Data Subjects | Customer’s end customers. Customer’s employees and contractors who use the Hosted Software or communicate with Provider. |
| Categories of Personal Data | Name. Contact information such as email address, phone number, or postal address. Transactional information such as orders, refunds, and purchase history. For Hosted Software users, user activity and analysis such as device information and IP address. |
| Special Category Data | None. Customer will not provide Special Category Data to Provider. |
| Frequency of Transfer | Continuous during the SOW Term. |
| Nature and Purpose of Processing | Collection, storage, analysis, and reporting of Customer Personal Data to build and maintain Customer’s unit economics and profit model, and to provide and support the Hosted Software. |
| Duration of Processing | The SOW Term, plus the deletion period below. |
| Retention | Provider deletes Customer Personal Data within 90 days after the end of the SOW Term, or sooner on Customer’s instruction, except where retention is required by Applicable Laws or where data remains in routine backups until those are overwritten, in which case it stays protected under this DPA. |
| Transfers to Subprocessors | As described in Annex III. Customer Personal Data in Provider’s data warehouse is stored in the European Union. |
Provider will give notice of changes to this list as set out in Section 2.7 of the DPA Standard Terms.
| Subprocessor | Country of location | Processing task |
|---|---|---|
| Google Cloud (Google LLC) | United States; data hosted in the EU | Storage and processing of Customer Personal Data |
| Airbyte, Inc. | United States; EU-hosted instance | Extraction of storefront data |
| Windsor Group AG | Switzerland | Extraction of advertising and storefront data |
| Leadsie Ltd | United Kingdom | Management of access grants to Customer platforms |
| Cloudflare, Inc. | United States | Hosting and access control for the Hosted Software |
| Kinde Australia Pty Ltd | Australia; EU-hosted instance | Authentication for Hosted Software users |
| PostHog, Inc. | United States; EU-hosted instance | Product analytics for the Hosted Software |
| GitHub, Inc. | United States | Execution of data pipelines |
| Google Workspace (Google LLC) | United States | Email, documents, and file storage |
| Resend, Inc. | United States | Transactional email to Hosted Software users |
| Anthropic, PBC | United States | AI-assisted analysis of pseudonymized data |
Clove Analytics LLC
30 N Gould Street STE R, Sheridan, WY 82801, United States
security@cloveanalytics.com
This DPA incorporates the Common Paper Data Processing Agreement Standard Terms (Version 1.1), which are licensed under CC BY 4.0.