Home / Data Processing Agreement

Legal

Data Processing Agreement

Last updated: August 26, 2026

Who this DPA applies to. This Data Processing Agreement applies to every Order signed on or after August 26, 2026, and to existing subscriptions beginning with their next renewal. If your signed Order or a separately executed data processing agreement contains different terms, that document controls.

Background

This Data Processing Agreement ("DPA") forms part of the agreement between Grasshopperlabs.io LLC, doing business as Grasshopper Labs, 6416 Rea Rd Ste B7, PO Box 78311, Charlotte, NC 28277 ("Grasshopper") and the Customer identified in the applicable Order, consisting of the Order, the Terms of Service, and this DPA (together, the "Agreement"). Capitalized terms not defined here have the meanings given in the Terms of Service.

This DPA describes how Grasshopper processes Personal Data on Customer's behalf when providing the Services. If this DPA conflicts with the Terms of Service on a matter relating to Personal Data, this DPA controls. If this DPA conflicts with a signed Order, the Order controls.

1. Definitions

  • "Applicable Data Protection Law" means all laws and regulations that apply to the processing of Personal Data under the Agreement, which may include: (a) United States federal law and state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA") and the comprehensive privacy laws of other U.S. states; (b) in Canada, the Personal Information Protection and Electronic Documents Act ("PIPEDA") and substantially similar provincial laws, including Quebec's Act respecting the protection of personal information in the private sector; (c) in Australia, the Privacy Act 1988 (Cth) and the Australian Privacy Principles; and (d) in Latin America, Brazil's Lei Geral de Proteção de Dados ("LGPD"), Colombia's Law 1581 of 2012, Mexico's Federal Law on the Protection of Personal Data Held by Private Parties, and comparable laws of other countries where Customer operates.
  • "Customer Data" has the meaning given in the Terms of Service.
  • "Personal Data" means any information within Customer Data that relates to an identified or identifiable natural person, and includes "personal information" and equivalent terms under Applicable Data Protection Law.
  • "Data Subject" means the individual to whom Personal Data relates, and includes a "consumer" under U.S. state privacy laws.
  • "Controller" means the party that determines the purposes and means of processing Personal Data, and includes a "business" under the CCPA and an "organization" or "APP entity" under Canadian and Australian law. "Processor" means the party that processes Personal Data on behalf of the Controller, and includes a "service provider" or "contractor" under U.S. state privacy laws and an "operator" under the LGPD.
  • "Sub-processor" means a third party engaged by Grasshopper to process Personal Data in connection with the Services.
  • "Security Incident" means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data processed by Grasshopper or its Sub-processors. Unsuccessful attempts such as blocked intrusion attempts, port scans, and denial-of-service attacks that do not result in unauthorized access are not Security Incidents.
  • "Process" and "processing" mean any operation performed on Personal Data, including collection, storage, use, disclosure, transfer, and deletion.

2. Roles of the Parties

As between the parties, Customer is the Controller of Personal Data and Grasshopper is the Processor. Grasshopper processes Personal Data only on behalf of Customer and in accordance with Customer's documented instructions. Where Customer itself acts as a processor for a retailer or other client, Customer represents that its instructions to Grasshopper are consistent with the instructions it has received from that client, and Grasshopper acts as a sub-processor to Customer.

Exhibit A describes the subject matter, nature, purpose, and duration of processing, the categories of Data Subjects, and the types of Personal Data.

3. Grasshopper's Obligations

3.1 Processing on instructions

Grasshopper will process Personal Data only (a) to provide, maintain, secure, and support the Services, (b) as instructed by Customer through its configuration and use of the Services, including through Users' actions in the platform and the API, (c) as otherwise documented in the Agreement, and (d) as required by law, in which case Grasshopper will inform Customer of the legal requirement before processing unless the law prohibits it. Grasshopper will notify Customer if it believes an instruction violates Applicable Data Protection Law, and may suspend the instruction until the matter is resolved.

3.2 U.S. state privacy law terms

Where the CCPA or another U.S. state privacy law applies, Grasshopper (a) will not sell or share Personal Data, (b) will not retain, use, or disclose Personal Data for any purpose other than the business purposes specified in the Agreement, or outside the direct business relationship with Customer, (c) will not combine Personal Data with personal information it receives from other sources, except as permitted for a service provider, (d) will comply with the obligations that apply to service providers and contractors under those laws and provide the same level of privacy protection they require, (e) will notify Customer if it determines it can no longer meet those obligations, and (f) grants Customer the right to take reasonable steps to stop and remediate unauthorized use of Personal Data. Grasshopper certifies that it understands these restrictions. Grasshopper does not receive Personal Data as consideration for the Services.

3.3 Confidentiality of personnel

Grasshopper will ensure that personnel authorized to process Personal Data are bound by written confidentiality obligations, have received appropriate data protection and security training, and access Personal Data only as needed to perform their role.

3.4 Security

Grasshopper will implement and maintain the technical and organizational measures described in Exhibit B, and will not materially reduce the overall level of protection they provide during the Term.

3.5 Assistance

Taking into account the nature of the processing and the information available to it, Grasshopper will provide reasonable assistance to Customer in (a) responding to Data Subject requests, (b) meeting Customer's security, breach notification, and impact assessment obligations, and (c) responding to inquiries from supervisory authorities. Assistance that goes beyond the standard functionality of the Services may be billed at Grasshopper's then-current professional services rates.

3.6 Records

Grasshopper will maintain records of its processing activities as required by Applicable Data Protection Law and make them available to Customer on reasonable request.

4. Customer's Obligations

Customer is responsible for the lawfulness of the Personal Data it provides to Grasshopper and of its instructions. Customer represents and warrants that:

  1. it has provided all notices and obtained all consents required by Applicable Data Protection Law for Grasshopper to process Personal Data as described in this DPA, including notices to drivers regarding location tracking in the Grasshopper mobile application, and notices to and consents from End Consumers regarding delivery messaging, tracking, and proof-of-delivery photographs, as further described in the Terms of Service;
  2. it has assessed the measures in Exhibit B and determined that they are appropriate for the Personal Data it will process through the Services;
  3. it will not provide Grasshopper with Personal Data of children under sixteen (16), health information, payment card numbers, government identification numbers, biometric data, or other special categories of Personal Data, except in a field Grasshopper has designated for that purpose in writing;
  4. it will configure the Services, including user permissions, data sharing with trading partners, and retention settings, in a manner consistent with its own obligations; and
  5. it will respond to Data Subject requests and supervisory authority inquiries directed to it.

5. Sub-processors

5.1 Authorization

Customer authorizes Grasshopper to engage the Sub-processors listed in Exhibit C, and any affiliates of Grasshopper, to process Personal Data in connection with the Services. Grasshopper will impose on each Sub-processor written data protection obligations that are no less protective than those in this DPA, and Grasshopper remains responsible for each Sub-processor's performance.

5.2 Changes

Grasshopper will update Exhibit C and notify Customer at least thirty (30) days before adding or replacing a Sub-processor that will process Personal Data. Notice will be given by email to Customer's billing or administrative contact, or by a notice in the Services. Customer may object in writing within that period on reasonable grounds relating to data protection. If the parties cannot resolve the objection in good faith within thirty (30) days, Customer may terminate the affected Services on written notice without early termination fees, as its sole remedy, and Grasshopper will refund prepaid Fees for the terminated portion of the Term.

6. International Transfers

6.1 Hosting location

Grasshopper hosts and processes Customer Data in the United States. Customers located in Canada, Australia, Latin America, or elsewhere outside the United States instruct Grasshopper to transfer Personal Data to, and process it in, the United States, and represent that they have satisfied any notice, consent, or cross-border transfer requirement under Applicable Data Protection Law for that transfer.

6.2 Transfer safeguards

Where Applicable Data Protection Law requires additional contractual safeguards for a transfer to the United States, the parties will cooperate in good faith to put them in place, including: (a) for Australian Customers, Grasshopper's undertaking in this DPA to handle Personal Data in a manner consistent with the Australian Privacy Principles, so that Customer may rely on it under APP 8; (b) for Canadian Customers, Grasshopper's undertaking to provide a level of protection comparable to that required under PIPEDA and applicable provincial law, and to cooperate with any privacy impact assessment Customer is required to perform; (c) for Brazilian Customers, contractual clauses consistent with the LGPD's requirements for international transfers, including any standard clauses approved by the Brazilian data protection authority; and (d) for Customers in other jurisdictions, an appropriate transfer mechanism recognized under the applicable law. Grasshopper will not transfer Personal Data outside the United States except to a Sub-processor listed in Exhibit C, and any such Sub-processor will be bound by transfer safeguards equivalent to those required of Grasshopper.

7. Data Subject Requests

If Grasshopper receives a request directly from a Data Subject to access, correct, delete, restrict, or port Personal Data, or to opt out of processing, Grasshopper will (to the extent legally permitted) promptly forward the request to Customer and will not respond except to direct the Data Subject to Customer or as required by law. Customer may use the Services' administrative tools, export functions, and API to fulfill most requests directly. Grasshopper will provide reasonable additional assistance on request, which may be billed as described in Section 3.5.

8. Security Incidents

8.1 Notification

Grasshopper will notify Customer without undue delay, and in any event within forty-eight (48) hours after confirming a Security Incident affecting Customer's Personal Data. Notice will be sent to Customer's designated security or administrative contact and will include, to the extent known, the nature of the incident, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address it. Grasshopper may provide information in phases as its investigation progresses.

8.2 Response

Grasshopper will take reasonable steps to contain, investigate, and remediate the Security Incident, will keep Customer informed of material developments, and will provide reasonable cooperation to help Customer meet its own notification obligations. Grasshopper's notification of a Security Incident is not an acknowledgment of fault or liability. Customer is responsible for any notices to Data Subjects, regulators, or other third parties that Applicable Data Protection Law requires it to make, and will not identify Grasshopper in any such notice without Grasshopper's prior review unless the law requires it.

9. Audits

Grasshopper will make available to Customer, on request and subject to confidentiality obligations, information reasonably necessary to demonstrate compliance with this DPA, including summaries of its security program, policies, and the most recent third-party penetration test summary. If that information is not sufficient to satisfy an obligation Customer has under Applicable Data Protection Law, Customer or an independent auditor bound by confidentiality may conduct an audit of Grasshopper's processing of Personal Data, provided that (a) audits occur no more than once per twelve (12) months, unless required by a supervisory authority or following a Security Incident, (b) Customer gives at least thirty (30) days' written notice and the parties agree on scope, timing, and duration in advance, (c) audits take place during normal business hours and do not unreasonably disrupt Grasshopper's operations, (d) audits do not extend to the facilities or systems of Sub-processors, for which Grasshopper will provide available third-party audit reports instead, and (e) Customer bears the cost of the audit and reimburses Grasshopper for reasonable time spent beyond eight (8) hours at Grasshopper's then-current professional services rates. Customer will share audit results with Grasshopper and treat them as Grasshopper's Confidential Information.

10. Return and Deletion of Personal Data

  1. Export window. For thirty (30) days after expiration or termination of the Agreement, Customer may export Customer Data, including Personal Data, using the platform's export tools and the API.
  2. Deletion from production. Within sixty (60) days after expiration or termination, Grasshopper will delete or de-identify Personal Data in its production systems, unless Applicable Data Protection Law requires retention or Customer has requested in writing an extension of the export window at Grasshopper's then-current rates.
  3. Backups. Personal Data in encrypted backups will be overwritten in the ordinary course of Grasshopper's backup rotation and in any event within ninety (90) days after expiration or termination. Backup copies are not restored except for disaster recovery, and remain subject to this DPA until overwritten.
  4. Certification. On written request, Grasshopper will confirm in writing that deletion has been completed.

During the Term, Customer may delete Personal Data at any time using the Services' administrative tools, subject to the retention settings Customer has configured.

11. Liability

Each party's liability arising out of or relating to this DPA, taken together with its liability under the Terms of Service, is subject to the exclusions and limitations of liability in the Terms of Service, including the data protection super-cap in Section 10.3 of the Terms of Service. Nothing in this DPA limits a party's liability where such limitation is prohibited by Applicable Data Protection Law.

12. Term and Changes

This DPA takes effect when the Agreement takes effect and continues until Grasshopper has deleted all Personal Data in accordance with Section 10. Grasshopper may update this DPA by posting a revised version at grasshopperlabs.io/dpa. Updates that are required by changes in Applicable Data Protection Law or that do not reduce the protections provided to Customer take effect on posting. Other updates apply to Customer's existing Orders beginning with the next Renewal Term. If a supervisory authority requires a copy of this DPA, either party may provide it.

Exhibit A: Details of Processing

ItemDescription
Subject matterProvision of the Grasshopper transportation management, warehouse management, inventory and fulfillment, driver mobile application, consumer tracking and scheduling, API and EDI, and Data Lake services described in the Order, including related support.
DurationThe Term of the Agreement plus the return and deletion period in Section 10.
Nature and purposeHosting, storage, transmission, display, routing, optimization, notification, reporting, and analytics of Customer Data as needed to plan, dispatch, execute, and document deliveries and warehouse operations, and to support Customer's use of the Services.
Categories of Data SubjectsCustomer's employees and contractors who use the Services (administrators, dispatchers, warehouse staff, customer service staff); drivers and delivery crews, whether employed by Customer or by Customer's carriers; End Consumers who receive deliveries or pickups; contacts at Customer's retailers, shippers, carriers, and other trading partners.
Categories of Personal DataUsers and trading partner contacts: name, business email, phone number, role, login credentials (hashed), activity logs, IP address.

Drivers and crews: name, phone number, email, employee or contractor identifier, device identifiers, device location while signed in and on an active route or manifest, route and stop history, timestamps, photographs and signatures captured in the app, in-app messages, and performance metrics derived from delivery events.

End Consumers: name, delivery address, phone number, email, appointment windows, order contents and item descriptions, delivery instructions and access notes, communication history (SMS, email, voice), tracking page interactions, proof-of-delivery photographs and signatures, survey responses, and notes about delivery exceptions or damage claims.
Special categoriesNone intended. Grasshopper does not require, and Customer agrees not to provide, special categories of Personal Data. Proof-of-delivery photographs taken during in-home deliveries may incidentally capture the interior of a residence or the people in it; Customer is responsible for instructing drivers accordingly, as described in the Terms of Service.
FrequencyContinuous for the duration of the Term.
Processing locationUnited States.

Exhibit B: Technical and Organizational Measures

Grasshopper maintains an information security program with administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of Customer Data. The measures below describe the program as of the date of this DPA. Grasshopper may update specific measures over time provided the overall level of protection is not materially reduced.

1. Hosting and infrastructure

  • The Services are hosted on Amazon Web Services in the United States. Grasshopper relies on AWS physical and environmental controls for its data centers, which are covered by AWS's independent audit reports.
  • Production environments are logically separated from development and test environments. Customer Data is not used in non-production environments except in de-identified form or with Customer's written approval.
  • Customer Data is logically segregated by account, and access controls in the application enforce tenant boundaries.

2. Encryption

  • Customer Data is encrypted at rest using industry-standard encryption (AES-256 or equivalent) at the storage and database layers, including backups.
  • Customer Data is encrypted in transit between users, mobile devices, integrations, and the Services using TLS 1.2 or higher.
  • User passwords are stored only in salted, hashed form.

3. Access control

  • Access to production systems and Customer Data is granted on a least-privilege, role-based basis and limited to personnel whose job function requires it.
  • Production access requires unique credentials for each individual. Shared accounts are not used for administrative access.
  • Access rights are reviewed at least annually, and access is revoked promptly on role change or termination.
  • Administrative access to production infrastructure is logged.

4. Application security and testing

  • Grasshopper engages an independent third party to perform penetration testing of the web application, mobile application, and API at least annually. Findings are prioritized by severity and remediated according to defined timelines. A summary of the most recent test is available to Customer under confidentiality obligations.
  • Changes to production are made through a change management process with code review, testing in a non-production environment, and version control.
  • Third-party dependencies are monitored for known vulnerabilities.

5. Backup and business continuity

  • Customer Data is backed up automatically on a regular schedule. Backups are encrypted and stored redundantly within AWS.
  • Backup restoration is tested periodically. Backups are retained for a defined rotation period and overwritten thereafter, as described in Section 10 of this DPA.
  • Infrastructure is monitored for availability and performance, with alerting to on-call personnel.

6. Incident response

  • Grasshopper maintains an incident response process covering detection, escalation, containment, investigation, remediation, and Customer notification in accordance with Section 8.
  • Security events and system logs are retained to support investigation.

7. Personnel

  • All employees and contractors with access to Customer Data are bound by written confidentiality obligations.
  • Personnel receive security and data protection training on hire and periodically thereafter.
  • Background screening is performed where permitted by law for personnel with access to production systems.

8. Sub-processor management

  • Sub-processors are assessed for security practices before engagement and are bound by written data protection and security obligations.

Exhibit C: Sub-processors

The following Sub-processors process Personal Data in connection with the Services. This list is current as of the "Last updated" date above and will be updated in accordance with Section 5.

Sub-processorPurposeLocation of processing
Amazon Web Services, Inc.Cloud infrastructure: compute, storage, networking, backups, and hosting of the Grasshopper application and the PostgreSQL data lake used for reporting and the Data Lake package.United States
MongoDB, Inc. (MongoDB Atlas)Managed database hosting for the Grasshopper application database (orders, manifests, users, partners, and related operational data).United States
Twilio Inc.SMS, voice, and related messaging to drivers, Users, and End Consumers (appointment scheduling, confirmations, tracking links, notifications).United States

Contact

Support: support@grasshopperlabs.io
Grasshopper Labs, 6416 Rea Rd Ste B7, PO Box 78311, Charlotte, NC 28277