ROutpost ReturnsLegal center
Sign inOpen app
Current U.S. documentVersion dated August 19, 2026.
← All legal documents

Data Processing Addendum

Privacy, security, subprocessors, and processing terms for customer data.

Status
Current
For
Customers that require processor terms
Version
August 19, 2026

In this document

1. Purpose and incorporation2. Definitions3. Scope, roles, and instructions4. Outpost's Processing obligations5. United States state privacy terms6. Confidentiality and personnel7. Security measures8. Security Incidents9. Data Subject requests10. Assessments, consultations, and legal requests11. Subprocessors12. Compliance information and audits13. Return and deletion14. United States service scope and processing locations15. Liability and order of precedence16. Term and changesSchedule 1 - Processing detailsSchedule 2 - Technical and organizational measuresSchedule 3 - Subprocessors and Customer-Directed IntegrationsSignatures

Version date: August 19, 2026
Provider/Processor: Babaji Central Company LLC, a California limited liability company operating the Outpost Returns service ("Outpost")
Customer/Controller: The customer identified in the Agreement ("Customer")
Outpost contact: benn@boxfortcommerce.com
Outpost address: 1106 2nd Street, #130, Encinitas, California 92024, United States

This is Outpost's current Data Processing Addendum for its United States service. It does not include an international data-transfer addendum or a data-residency commitment.

1. Purpose and incorporation

This Data Processing Addendum, including its Schedules (the "DPA"), forms part of the agreement between Customer and Outpost governing Customer's use of the Outpost returns-processing platform (the "Agreement"). It applies when Outpost Processes Customer Personal Data on behalf of Customer in providing the Services.

If the parties execute this DPA separately, it becomes effective on the date of the last signature. If Customer accepts online terms that incorporate the DPA, this DPA becomes effective when those terms are accepted. Capitalized terms not defined here have the meaning in the Agreement.

2. Definitions

"Applicable Data Protection Law" means United States privacy, data-protection, and data-security law applicable to the Processing of Customer Personal Data under the Agreement, including, as applicable, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA").

"Controller," "Data Subject," "Personal Data," "Personal Information," "Process" or "Processing," "Processor," "Sale," "Share," and "Service Provider" have the meanings given by Applicable Data Protection Law. "Business" and "Contractor" have the meanings given by the CCPA.

"Customer Personal Data" means Personal Data included in Customer Data that Outpost Processes on Customer's behalf to provide the Services. It does not include personal information for which Outpost independently determines the purposes and means of Processing, such as Outpost's own account relationship, billing, security, legal, or sales records, which is governed by the Outpost Privacy Policy.

"Security Incident" means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data in Outpost's possession or control. Security Incident does not include unsuccessful attempts that do not compromise Customer Personal Data, such as blocked probes, pings, denial-of-service attempts, failed login attempts, or scans.

"Subprocessor" means a third party appointed by or for Outpost to Process Customer Personal Data on Customer's behalf. It does not include Customer personnel or a Customer-Directed Integration acting under Customer's independent agreement.

3. Scope, roles, and instructions

Customer is the Controller or Business and Outpost is the Processor or Service Provider for Customer Personal Data, except where Applicable Data Protection Law assigns a different role. Each party will comply with its obligations under Applicable Data Protection Law.

Customer instructs Outpost to Process Customer Personal Data to:

  • host, authenticate, secure, support, and operate Customer's isolated workspace;
  • import and synchronize return, order, item, carrier, facility, and operational records from Customer-authorized sources;
  • receive, grade, document, photograph, route, reconcile, report on, and measure returned items according to Customer's configuration;
  • operate station devices, printing, billing measurements, reports, exports, and Customer-Directed Integrations;
  • provide AI-assisted classification or summarization when enabled by Customer;
  • prevent, detect, investigate, and remediate abuse, fraud, unauthorized access, operational failure, and Security Incidents;
  • provide support and comply with Customer's documented instructions consistent with the Agreement; and
  • delete, return, disclose, or preserve Customer Personal Data as required by this DPA or applicable law.

The Agreement, this DPA, Customer's configuration and feature use, and lawful written instructions constitute Customer's documented instructions. Customer may give additional instructions if they are consistent with the Agreement and Applicable Data Protection Law. If an instruction requires material work or cost outside the Services, the parties will agree on scope, fees, and timing. Outpost will promptly inform Customer if, in Outpost's reasonable opinion, an instruction infringes Applicable Data Protection Law, unless law prohibits notice, and may suspend the affected Processing while the parties resolve the issue.

Customer is responsible for the lawfulness, accuracy, quality, and minimization of Customer Personal Data; required notices, consents, and legal bases; Data Subject request intake; and the legality of its instructions. Customer will not provide payment-card data, Social Security numbers, government identifiers, biometric templates, health data, or other regulated or highly sensitive data unless the Services expressly support that data and the parties have agreed in writing to additional safeguards.

4. Outpost's Processing obligations

Outpost will:

  • Process Customer Personal Data only on documented instructions, including transfers, unless required by law; if legally permitted, Outpost will inform Customer of that legal requirement before Processing;
  • ensure persons authorized to Process Customer Personal Data are bound by confidentiality obligations and receive appropriate privacy and security instruction;
  • implement and maintain measures described in Schedule 2, as verified and updated in accordance with Section 7;
  • assist Customer as described in this DPA with Data Subject requests, security, breach notifications, data-protection impact assessments, and regulatory consultations;
  • maintain records and information reasonably necessary to demonstrate compliance with this DPA;
  • impose data-protection obligations on each Subprocessor that are no less protective in material respects for the relevant Processing and remain responsible for the Subprocessor's performance to the extent required by law and the Agreement;
  • notify Customer if Outpost determines it can no longer meet applicable CCPA obligations and permit Customer to take reasonable and appropriate steps to stop and remediate unauthorized use; and
  • not materially reduce the overall protection of Customer Personal Data during the term.

5. United States state privacy terms

To the extent the CCPA or a similar United States state privacy law applies, the parties agree that Customer discloses Customer Personal Data to Outpost only for the limited and specific business purposes stated in Section 3 and Schedule 1. Outpost will act as a Service Provider, Contractor, or Processor, as applicable, and will:

  • not Sell or Share Customer Personal Data;
  • not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer or for any purpose, including a commercial purpose, other than the specific business purposes in this DPA or as otherwise permitted by Applicable Data Protection Law;
  • not combine Customer Personal Data with personal information received from or on behalf of another person, or collected from Outpost's own interaction with a consumer, except as expressly permitted for a Service Provider or Contractor by Applicable Data Protection Law;
  • provide the same level of privacy protection required of Customer for the Customer Personal Data to the extent required by law;
  • comply with applicable obligations and provide reasonable assistance with consumer requests, cybersecurity audits, risk assessments, or other legally required activities relevant to the Services;
  • permit Customer, upon reasonable notice, to take reasonable and appropriate steps to verify that Outpost uses Customer Personal Data consistently with Customer's obligations, subject to Section 12;
  • notify Customer if Outpost determines it can no longer meet these obligations; and
  • permit Customer, upon notice, to take reasonable and appropriate steps to stop and remediate unauthorized Processing.

Outpost certifies that it understands and will comply with the restrictions in this Section. If Outpost receives a consumer request directly concerning Customer Personal Data, Outpost will either act on Customer's documented instruction or inform the consumer that the request should be submitted to the relevant Customer, as permitted by law.

6. Confidentiality and personnel

Outpost will limit access to Customer Personal Data to personnel and contractors who need access to provide, secure, support, or administer the Services. Authorized persons will be subject to written confidentiality obligations that survive the end of their engagement. Outpost will provide appropriate security and privacy awareness instruction based on role and will revoke access when it is no longer required.

Customer will treat Outpost security documentation, audit materials, vulnerability information, penetration-test results, architecture, and nonpublic Subprocessor details as Outpost Confidential Information and will not disclose them except to personnel, auditors, insurers, and advisers who need them and are bound by confidentiality.

7. Security measures

Outpost will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data, taking into account the state of the art, implementation cost, nature, scope, context, and purposes of Processing, and the risk to individuals. The baseline measures are described in Schedule 2.

Outpost may update measures as technology and risk evolve, provided the overall level of protection is not materially reduced. The measures in Schedule 2 are limited by their stated qualifiers and distinguish Outpost-controlled safeguards, provider-managed safeguards, and Customer responsibilities. Customer acknowledges that Customer's users, permissions, devices, credentials, configurations, data-minimization practices, and Third-Party Services affect security and that Customer must use the Services in accordance with documentation and the Agreement.

8. Security Incidents

Outpost will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data. Outpost's operational target is to provide an initial notice within 48 hours after confirmation where practicable, but an evolving investigation or incomplete information will not delay an initial notice or cause speculation. Notice will be sent to Customer's designated security contact or account owner.

As information becomes reasonably available, the notice will describe:

  • the nature of the Security Incident, including affected systems and categories of Customer Personal Data and Data Subjects, where known;
  • approximate dates and scope, where known;
  • likely consequences known to Outpost;
  • containment, remediation, and recovery measures taken or planned; and
  • an Outpost contact for coordination.

Outpost will take reasonable steps to contain, investigate, mitigate, and remediate the Security Incident; preserve relevant evidence; provide reasonable updates; and assist Customer with legally required notifications. Outpost's notice or response is not an admission of fault or liability. Customer is responsible for determining whether to notify individuals, regulators, customers, insurers, or others, except where law assigns that obligation to Outpost. The parties will coordinate public statements and notifications relating to the other party and will not identify the other party without prior consultation unless law requires it.

9. Data Subject requests

Taking into account the nature of Processing, Outpost will provide reasonable technical and organizational assistance for Customer to respond to requests to access, know, correct, delete, restrict, object, opt out, or port Customer Personal Data. Available assistance may include role-based access, search, export, correction, deletion, and support processes.

If Outpost receives a request directly from a Data Subject concerning Customer Personal Data, Outpost will not independently respond except on Customer's documented instruction or as required by law. Outpost may direct the requester to Customer. Customer will reimburse reasonable costs for assistance that is unusually burdensome or requires custom development, except where the burden results from Outpost's breach of this DPA.

10. Assessments, consultations, and legal requests

Outpost will provide information reasonably necessary for Customer to conduct a data-protection impact assessment or prior consultation relating to Customer's use of the Services, considering the nature of Processing and information available to Outpost. Customer remains responsible for its assessment and regulatory relationship.

If Outpost receives a subpoena, warrant, court order, or governmental demand for Customer Personal Data, Outpost will, to the extent legally permitted, notify Customer before disclosure, review the request for facial validity, disclose only information legally required, and reasonably support Customer's effort to seek protective treatment. Outpost may seek reimbursement for extraordinary legally compelled assistance where permitted.

11. Subprocessors

Customer gives Outpost general written authorization to use Subprocessors listed in Schedule 3 and on the public DPA page at https://app.outpostreturns.com/legal/dpa#schedule-3-approved-subprocessors. Outpost will provide at least 15 days' prior notice of a new Subprocessor that will Process Customer Personal Data, except an urgent replacement needed to maintain security or availability, for which notice will be provided as soon as practicable.

Customer may object during the notice period on reasonable data-protection grounds, with enough detail for Outpost to evaluate the concern. The parties will work in good faith on a commercially reasonable alternative. If no reasonable alternative is available, Customer may terminate only the affected Service before the new Subprocessor begins Processing and receive a refund of prepaid recurring fees allocable to the unused post-termination period. Customer may not object solely to obtain different commercial terms.

Outpost will enter into a written agreement with each Subprocessor requiring protection of Customer Personal Data consistent with this DPA for the relevant Processing. Outpost remains responsible for its obligations where a Subprocessor performs them on Outpost's behalf, subject to the Agreement's liability limitations.

Customer-Directed Integrations are not Subprocessors when Customer independently contracts with, enables, or instructs Outpost to exchange data with them. Customer authorizes those disclosures and is responsible for evaluating the integration's terms, security, and legal basis.

12. Compliance information and audits

Upon written request no more than once in a 12-month period, Outpost will provide available information reasonably necessary to demonstrate compliance with this DPA, which may include a current third-party audit report, certification, penetration-test summary, security questionnaire, or written control summary. Outpost may redact information that would expose another customer, personal information, privileged material, security-sensitive details, or irrelevant proprietary information.

If the information above is reasonably insufficient, Customer may request an audit. The parties will agree in advance on scope, timing, duration, auditor, confidentiality, and cost. Audits must occur during normal business hours, avoid disruption, use an independent qualified auditor that is not Outpost's competitor, and not require access to another customer's data or production credentials. Customer bears audit costs unless the audit identifies Outpost's material breach, in which case Outpost will reimburse reasonable audit costs. A regulator's legally binding audit right is not limited by this paragraph.

Outpost will address substantiated material findings within a reasonable period based on risk. Customer may exercise CCPA verification rights through the process in this Section, including reasonable annual assessment evidence and incident-triggered evidence where appropriate.

13. Return and deletion

During the term, Customer may export Customer Personal Data using available features and may request reasonable export assistance. Upon expiration or termination, and at Customer's choice where required by law, Outpost will return or delete Customer Personal Data following a verified written request or the end of an agreed export period, unless law requires retention. Outpost will confirm the target deletion timeframe after identifying the affected active systems, provider lifecycles, backups, export needs, and any legal hold. No shorter fixed deletion period applies unless it is stated in an Order Form or Outpost's written deletion confirmation.

Deletion from active systems does not require immediate deletion from disaster-recovery or immutable backups where deletion is technically impracticable or legally restricted. Remaining backup data will be isolated from ordinary use, protected under this DPA, and deleted or rendered inaccessible according to the ordinary backup lifecycle. Outpost may retain data required for legal holds, billing, fraud prevention, security evidence, or defense of claims, but will limit use to that purpose and delete it when the requirement ends.

14. United States service scope and processing locations

Customer may use this DPA only for a United States-based business and operations in the United States. Customer must not use the Services to Process data subject to the EU GDPR, UK GDPR, Swiss data-protection law, or another non-U.S. data-protection regime unless Outpost first agrees in writing to appropriate additional terms.

Customer authorizes Outpost and its Subprocessors to Process Customer Personal Data in the United States and in other provider locations described in Schedule 3 or the provider's applicable terms. This DPA does not provide a contractual data-residency commitment or an international transfer mechanism. Any required data-residency term or transfer addendum must be stated in a signed Order Form or addendum.

15. Liability and order of precedence

Each party's liability arising from this DPA is subject to the exclusions, waivers, and limitations in the Agreement, except to the extent Applicable Data Protection Law prohibits a limitation. This DPA does not create a separate liability cap or duplicate recovery.

For Processing matters, the order of precedence is: this DPA; the Agreement; and other incorporated documents. An Order Form controls only if it expressly identifies and modifies a provision of this DPA and the modification is permitted by Applicable Data Protection Law.

16. Term and changes

This DPA continues while Outpost Processes Customer Personal Data. Outpost may update public Subprocessor details, contacts, or measures under the processes in this DPA. A material reduction in protection requires Customer's written agreement unless required by law, a regulator, or an urgent security need, in which case Outpost will provide notice and preserve protection to the extent practicable.

Schedule 1 - Processing details

Subject matter and duration

Processing of Customer Personal Data to provide, secure, support, and administer the Outpost Services for the term of the Agreement, including any agreed export, deletion, backup, legal-hold, or transition period.

Nature and purpose

Collection, receipt, import, hosting, organization, storage, retrieval, consultation, display, classification, summarization, transmission, synchronization, printing, reporting, correction, restriction, export, deletion, backup, restoration, security monitoring, and other operations described in Section 3.

Processing frequency

Continuous or event-driven during Customer's use of the Services, with scheduled synchronization, monitoring, billing, backup, and lifecycle operations where configured.

Categories of Data Subjects

  • Customer account owners, administrators, managers, invited users, and client/brand portal users.
  • Warehouse associates, station users, and other Customer personnel or contractors.
  • Return consumers, purchasers, gift recipients, and shipment contacts whose details appear in Customer-controlled return or order records.
  • Customer's clients, vendors, support contacts, and personnel represented in integration or operational records.
  • Other individuals incidentally depicted in Customer-submitted photographs or notes.

Categories of Customer Personal Data

  • Business contact and account data: name, business email, company, role, profile, invitation, facility or brand assignment, account identifiers, and authentication metadata.
  • Workforce and station data: display name, role, facility assignment, language, four-digit workplace station PIN, device identifiers, activation/revocation records, and action history. Authorized tenant administrators can view and manage station PINs. The PIN is a convenience code for associate attribution inside an already activated, facility-bound station and is not represented as password-grade account authentication. Customer should not store hourly pay data unless necessary and lawfully authorized.
  • Return and order data: customer email, order, RMA and return identifiers, tracking numbers, carrier, product name, SKU, barcode, quantity, return reason, status, timestamps, and source-system identifiers.
  • Condition and evidence data: observations, grading reasons, notes, dispositions, service records, exception information, photographs of packages and items, and authorized user identity associated with an action.
  • Facility and integration data: facility address, warehouse and client mappings, URLs, account identifiers, configuration, synchronization history, printer/computer identifiers, and encrypted or access-restricted credentials.
  • Commercial and operational data: Customer's client-pricing configuration, bills to Customer's clients, usage measurements, exports, and service analytics. Outpost's own billing records are generally processed as an independent Controller.
  • Technical and security data: IP address, device/browser metadata, session, log, error, performance, audit, and security events.
  • AI feature inputs and outputs: limited product names, item images, condition tags, notes, candidate categories, classifications, and return issue summaries when enabled.

Sensitive or special-category data

The Services are not designed for biometric templates, government identifiers, Social Security numbers, protected health information, complete payment-card data, or other regulated sensitive data outside the categories expressly described in this DPA. Customer must not submit such data unless expressly supported and covered by written additional terms. Account credentials, integration credentials, and limited financial metadata may be sensitive under some United States laws and receive restricted access.

Customer instructions for deletion

As stated in Section 13 and Customer's configuration or written request, subject to the selected deletion period and backup lifecycle.

Schedule 2 - Technical and organizational measures

This Schedule describes the baseline measures Outpost maintains while the DPA is effective. It is not a certification or a promise that every threat can be prevented. Qualifiers such as "where enabled," "where supported," and "where configured" are part of each measure.

Governance and risk management

  • Assigned executive and operational responsibility for security, privacy, incident response, system access, and material vendors.
  • Written security procedures covering access, secure development, vulnerability handling, logging, incident response, continuity, backups, retention, and material vendors, reviewed after material changes.
  • Confidentiality obligations and security/privacy instruction appropriate to the role for personnel with material access.
  • Risk, access-review, vendor-review, incident, and recovery-test evidence retained where created and reasonably needed for operations, security, or legal obligations.

Access control and authentication

  • Unique user accounts for administrative and portal access; managed password authentication; server-side authorization on sensitive actions; and revocation or suspension workflows.
  • Role-, tenant-, brand-, and facility-based access designed according to least privilege. Database row-level security and server validation are used to isolate customer workspaces.
  • Restricted service-role and privileged access. Production secrets and integration credentials are unavailable to ordinary users and accessed only by authorized server-side functions.
  • Shared station devices use revocable, facility-bound activation and separate associate identification. Associates select their identity with a four-digit workplace PIN that authorized tenant administrators can view, assign, suspend, replace, or delete. The activated station and its facility assignment are the primary access boundary; the PIN is a low-assurance convenience and attribution code, not password-grade authentication. Online failures are throttled and logged. Customer is responsible for workplace rules governing PIN sharing or misuse, as well as physical security and device management.
  • Provider-supported controls for privileged administrative accounts, with end-user authentication features described separately in the Services or Documentation.

Encryption and secrets

  • HTTPS/TLS for public application traffic and provider connections, with HSTS on the production application.
  • Provider-managed encryption at rest for production database and object storage, plus verified encryption for independent backup destinations, as supported and configured in the applicable account.
  • Integration credentials stored using environment-secret, restricted service-only, or vault mechanisms; excluded from user-facing responses and routine logs; and omitted from independent logical database exports where designed.
  • Payment credentials handled by Stripe; Outpost does not intentionally store complete card or bank-account credentials.

Application and tenant security

  • Tenant isolation at database, server, and interface layers; permission checks for return, photo, station, billing, export, and integration actions.
  • Server-controlled financial amounts, subscription state, usage metering, access gates, and external write-back authority.
  • Input validation, bounded queries and exports, endpoint-specific throttles for selected password, station, attachment, billing, and integration workflows, secure session and cookie settings, credential-free client responses, and protection against cross-tenant object access. Outpost does not represent that every endpoint is rate-limited.
  • Idempotency or claim controls for material billing and external write-back actions where supported.
  • Baseline browser security headers, including an enforced Content Security Policy. The current static-rendering-compatible policy permits framework inline scripts and application inline styles and is not represented as a strict nonce-based CSP.
  • Version control, automated migration validation, type checking, lint, security and tenant-isolation tests, build checks, dependency locking, and an auditable production release path. Independent reviewer and required-check settings must be evidenced where promised to Customer.

Logging, monitoring, and incident response

  • Audit and security events for material access, station activation, administrative changes, billing, and integration activity where supported.
  • When error/performance monitoring is enabled, default PII collection is disabled, request bodies, cookies, authentication headers, and query values are removed from events, common credentials and contact identifiers are filtered, and browser session replay is disabled unless separately assessed and disclosed.
  • Incident procedures covering triage, severity, containment, investigation, evidence handling, communication, recovery, and post-incident review consistent with Section 8.
  • Provider timestamps and logs sufficient for reasonable investigation, with access and retention recorded in the Control Evidence Register. Outpost does not promise a log-retention period that the adopted standard and provider configuration do not support.

Availability, backup, and recovery

  • Managed database resilience and point-in-time recovery where purchased, enabled, and shown in current provider or restoration evidence.
  • Monitored database and photo backup procedures, including logically separate or immutable copies where deployed, restricted access, checksum/integrity verification, and dated restoration exercises.
  • Recovery runbooks, critical-dependency inventory, exercise records, and approved recovery objectives for database, media, warehouse, billing, credential, and integration functions.
  • The executed Order Form or security schedule must use only the frequency, region, retention, immutability, restoration cadence, and recovery objectives supported by current evidence; repository design is insufficient.

Data lifecycle and minimization

  • Collection limited to fields needed for configured return operations, account administration, billing, security, and support.
  • Customer controls and documented support procedures for export, correction, photo deletion, user revocation, credential revocation, and account termination, to the extent supported by the Services and applicable plan.
  • Documented deletion handling aligned with the Privacy Policy and Section 13, including active systems, provider lifecycles, backup expiration, export needs, and legal holds. Outpost does not promise a fixed deletion period unless confirmed in writing for the affected systems.
  • Deidentified analytics maintained without reasonable reidentification and not disclosed in a manner identifying Customer or an individual.

Vendor and physical security

  • Documented due diligence and written data-protection/security terms for material Subprocessors, with access limited to contracted purposes and reviews appropriate to criticality.
  • Production hosting and physical safeguards inherited from audited cloud providers; Outpost personnel do not operate their physical data centers.
  • Vendor incident, availability, and change monitoring proportionate to the dependency.

Schedule 3 - Subprocessors and Customer-Directed Integrations

The list below identifies services used by Outpost or available for the stated feature. A feature-dependent provider Processes Customer Personal Data only when the related feature is configured or used. Provider infrastructure, support, and diagnostic locations may change under the provider's applicable terms; no data-residency commitment applies unless Outpost signs one in writing.

Current and feature-dependent Subprocessors

  • Supabase, Inc. - managed PostgreSQL database, authentication, API, storage, and platform functions; Customer Personal Data categories broadly described in Schedule 1; the current production project reports the AWS US West (Northern California) region (us-west-1).
  • Railway Corp. - application and background-worker hosting; application traffic, limited Customer Personal Data, diagnostics, and service configuration; processing locations described by Railway's applicable terms and Outpost account configuration.
  • Amazon Web Services, Inc. - protected object backup storage if the independent backup services are enabled; database exports and return/operational media excluding designated credential tables; the region selected in the applicable Outpost backup configuration.
  • Stripe, Inc. - Outpost subscription checkout, payment method, tax, invoicing, and payment status; account owner and billing details; processing locations described by Stripe. Stripe may act independently for some payment compliance purposes.
  • Resend, Inc. - transactional account, password-recovery, invitation, and billing email; recipient email, template data, and delivery metadata; processing locations described by Resend's applicable terms.
  • Functional Software, Inc. (Sentry) - error and performance monitoring when configured; device/request diagnostics and limited event context; processing locations described by Sentry's applicable terms and Outpost account configuration; session replay currently disabled.
  • OpenAI, L.L.C. - AI-assisted product classification and return issue summarization when enabled; limited product names, item images, condition tags, warehouse notes, and generated output; processing and retention governed by Outpost's API organization configuration and OpenAI's applicable terms.

Conditional operational vendors

  • PrintNode - customer-authorized printer connection and print jobs; printer/computer identifiers, label content, and job status. PrintNode may instead be a Customer-Directed Integration where Customer contracts with it directly.
  • Labelary - label preview rendering if used; ZPL label content submitted for preview.
  • EasyPost - shipment tracking when enabled; tracking number, carrier, and tracking status. EasyPost may instead be a Customer-Directed Integration where Customer contracts with it directly.

Customer-Directed Integrations

ShipHero, Mirakl, and any other warehouse management system, marketplace, carrier, printer, or service independently selected, contracted, or credentialed by Customer are treated as Customer-Directed Integrations unless Outpost's contractual role makes them a Subprocessor. Customer instructs Outpost to exchange the fields needed for the enabled workflow.

Signatures

The parties may execute this DPA through the Agreement, electronic acceptance, or the signatures below.

OUTPOST: Babaji Central Company LLC
By: ______________________________
Name: ____________________________
Title: _____________________________
Date: ______________________________

CUSTOMER: [CUSTOMER LEGAL NAME]
By: ______________________________
Name: ____________________________
Title: _____________________________
Date: ______________________________

Outpost Returns · Legal center
PrivacyTermsRefundsMSA