Categories of providers that may process data to operate, secure, support, and extend Shopify and WooCommerce access.
Effective 19 July 2026Last updated 19 July 2026Version 1.0
1. Selection and responsibility
ITLOX assesses providers for the service they perform, access required, security and privacy commitments, location, deletion and return obligations, incident support, and contractual restrictions. Providers may process data only for the authorised service purpose and remain subject to confidentiality and security duties.
Provider or categoryPurposeData and service scopeLocation note
ShopifyCommerce platformInstallation, authentication context, products, orders, billing, privacy webhooks, storefront and app extension workflows.Merchant-selected Shopify regions and processing terms
WordPress and WooCommerceCommerce platform and connectorConnector authentication, products, carts, orders, storefront workflows, and merchant-directed lifecycle events.Merchant-selected WordPress host and WooCommerce processing terms
Amazon Web ServicesCloud infrastructureApplication hosting, databases, object storage, encryption, networking, logs, queues, malware-scanning infrastructure, backup and delivery.Primary authorised production regions with controlled transfers
Transactional communication providersEmail and service noticesMerchant-requested support, operational messages, security notices, and service communications.Configured production provider and region
Support and incident toolingCustomer supportSupport requests, troubleshooting evidence, incident coordination, and authorised account context.Restricted to personnel and vendors required for the request
Optional AI providersAI-assisted draftsOnly when a merchant enables and invokes an AI-assisted feature; prompts and permitted input are sent under the product policy for that feature.Provider and model disclosed in product configuration where required
2. Merchant-selected services
A merchant may separately connect suppliers, fulfilment systems, printers, shipping tools, or other services. Those merchant-selected providers act under the merchant's agreement and instructions unless a written ITLOX agreement says otherwise.
3. International transfers
Where personal data moves across borders, ITLOX uses an applicable transfer mechanism and supplementary safeguards appropriate to the processing, such as recognised contractual clauses, encryption, access restrictions, and data minimisation.
4. Changes and objections
Material additions affecting merchant data will be published here and notified where required by contract or law. A merchant with a legitimate data-protection objection may contact dpo@itlox.com before the stated change takes effect.
5. Questions
For a data-processing agreement, security information, or the final named production-provider list, contact dpo@itlox.com.