Data Processing Addendum
Last updated: 2 October 2026
Contents
1. Parties and scope
This Addendum applies between Gecko Checkout ("Gecko", processor) and the merchant using the Service ("Merchant", controller) where Gecko processes personal data on the Merchant's behalf, mainly shopper and customer data. It forms part of the Terms of Service and reflects Article 28 of the UK GDPR and EU GDPR.
2. Processing details (Annex 1)
- Subject matter: hosting checkouts and processing orders, subscriptions and analytics for the Merchant.
- Duration: while the Merchant uses the Service, plus the deletion period in section 10.
- Nature and purpose: rendering checkouts, recording orders, verifying payment status from the Merchant's payment provider, syncing orders to Shopify, subscription records, Live View and analytics, and support.
- Data subjects: the Merchant's shoppers and customers.
- Data categories: name, email, shipping address, order items and totals, currency, subscription status, payment status and identifiers, IP-derived coarse location and device data. No full card numbers or CVV codes.
- Special category data: not intended to be processed.
3. Instructions
Gecko processes personal data only on the Merchant's documented instructions (including configuration of the Service) unless the law requires otherwise, and will tell the Merchant if it believes an instruction breaks data-protection law.
4. Confidentiality
People authorised to process the data are bound by confidentiality.
5. Security (Annex 2)
Gecko currently applies these measures:
- encryption in transit (HTTPS/TLS)
- authenticated access with per-merchant row-level access controls in the database
- payment-provider and integration credentials kept server-side and never sent to browsers
- signature verification of incoming payment webhooks
- role-based restriction of administrative access
- separation of demonstration data from real commerce data
6. Subprocessors
The Merchant authorises the subprocessors listed on our Subprocessors page. Gecko will update that page before adding or replacing a subprocessor so the Merchant can object on reasonable grounds, and will impose equivalent data-protection obligations on each subprocessor.
7. Data subject requests
Gecko will help the Merchant respond to shopper rights requests, taking into account the nature of the processing, and will pass on any request it receives directly.
8. Security incidents
Gecko will notify the Merchant without undue delay after becoming aware of a personal-data breach affecting Merchant data, and provide the information reasonably available to help the Merchant meet its obligations.
9. Assistance
Gecko will provide reasonable help with data protection impact assessments and regulator consultations relating to the Service.
10. Return and deletion
When the Merchant stops using the Service, Gecko will on request delete or return Merchant personal data, unless the law requires Gecko to keep it. Requests: support@geckocheckout.com.
11. Audits
Gecko will make available information reasonably needed to demonstrate compliance with this Addendum and allow reasonable audits on reasonable notice, at the Merchant's cost and subject to confidentiality.
12. International transfers
Where data is transferred outside the UK or EEA, Gecko relies on adequacy regulations or appropriate safeguards such as the UK International Data Transfer Addendum or EU Standard Contractual Clauses.
13. Merchant obligations
The Merchant is responsible for having a lawful basis for processing, giving shoppers appropriate privacy notices, obtaining any consent required for tracking technologies it enables (such as its own Meta Pixel), and the accuracy of its instructions.
Contact us
Gecko Checkout
1 Bestwick Close, Ilkeston, DE7 4QZ, United Kingdom
support@geckocheckout.com