Who this DPA applies to. This Data Processing Agreement applies to every Order signed on or after August 26, 2026, and to existing subscriptions beginning with their next renewal. If your signed Order or a separately executed data processing agreement contains different terms, that document controls.
This Data Processing Agreement ("DPA") forms part of the agreement between Grasshopperlabs.io LLC, doing business as Grasshopper Labs, 6416 Rea Rd Ste B7, PO Box 78311, Charlotte, NC 28277 ("Grasshopper") and the Customer identified in the applicable Order, consisting of the Order, the Terms of Service, and this DPA (together, the "Agreement"). Capitalized terms not defined here have the meanings given in the Terms of Service.
This DPA describes how Grasshopper processes Personal Data on Customer's behalf when providing the Services. If this DPA conflicts with the Terms of Service on a matter relating to Personal Data, this DPA controls. If this DPA conflicts with a signed Order, the Order controls.
As between the parties, Customer is the Controller of Personal Data and Grasshopper is the Processor. Grasshopper processes Personal Data only on behalf of Customer and in accordance with Customer's documented instructions. Where Customer itself acts as a processor for a retailer or other client, Customer represents that its instructions to Grasshopper are consistent with the instructions it has received from that client, and Grasshopper acts as a sub-processor to Customer.
Exhibit A describes the subject matter, nature, purpose, and duration of processing, the categories of Data Subjects, and the types of Personal Data.
Grasshopper will process Personal Data only (a) to provide, maintain, secure, and support the Services, (b) as instructed by Customer through its configuration and use of the Services, including through Users' actions in the platform and the API, (c) as otherwise documented in the Agreement, and (d) as required by law, in which case Grasshopper will inform Customer of the legal requirement before processing unless the law prohibits it. Grasshopper will notify Customer if it believes an instruction violates Applicable Data Protection Law, and may suspend the instruction until the matter is resolved.
Where the CCPA or another U.S. state privacy law applies, Grasshopper (a) will not sell or share Personal Data, (b) will not retain, use, or disclose Personal Data for any purpose other than the business purposes specified in the Agreement, or outside the direct business relationship with Customer, (c) will not combine Personal Data with personal information it receives from other sources, except as permitted for a service provider, (d) will comply with the obligations that apply to service providers and contractors under those laws and provide the same level of privacy protection they require, (e) will notify Customer if it determines it can no longer meet those obligations, and (f) grants Customer the right to take reasonable steps to stop and remediate unauthorized use of Personal Data. Grasshopper certifies that it understands these restrictions. Grasshopper does not receive Personal Data as consideration for the Services.
Grasshopper will ensure that personnel authorized to process Personal Data are bound by written confidentiality obligations, have received appropriate data protection and security training, and access Personal Data only as needed to perform their role.
Grasshopper will implement and maintain the technical and organizational measures described in Exhibit B, and will not materially reduce the overall level of protection they provide during the Term.
Taking into account the nature of the processing and the information available to it, Grasshopper will provide reasonable assistance to Customer in (a) responding to Data Subject requests, (b) meeting Customer's security, breach notification, and impact assessment obligations, and (c) responding to inquiries from supervisory authorities. Assistance that goes beyond the standard functionality of the Services may be billed at Grasshopper's then-current professional services rates.
Grasshopper will maintain records of its processing activities as required by Applicable Data Protection Law and make them available to Customer on reasonable request.
Customer is responsible for the lawfulness of the Personal Data it provides to Grasshopper and of its instructions. Customer represents and warrants that:
Customer authorizes Grasshopper to engage the Sub-processors listed in Exhibit C, and any affiliates of Grasshopper, to process Personal Data in connection with the Services. Grasshopper will impose on each Sub-processor written data protection obligations that are no less protective than those in this DPA, and Grasshopper remains responsible for each Sub-processor's performance.
Grasshopper will update Exhibit C and notify Customer at least thirty (30) days before adding or replacing a Sub-processor that will process Personal Data. Notice will be given by email to Customer's billing or administrative contact, or by a notice in the Services. Customer may object in writing within that period on reasonable grounds relating to data protection. If the parties cannot resolve the objection in good faith within thirty (30) days, Customer may terminate the affected Services on written notice without early termination fees, as its sole remedy, and Grasshopper will refund prepaid Fees for the terminated portion of the Term.
Grasshopper hosts and processes Customer Data in the United States. Customers located in Canada, Australia, Latin America, or elsewhere outside the United States instruct Grasshopper to transfer Personal Data to, and process it in, the United States, and represent that they have satisfied any notice, consent, or cross-border transfer requirement under Applicable Data Protection Law for that transfer.
Where Applicable Data Protection Law requires additional contractual safeguards for a transfer to the United States, the parties will cooperate in good faith to put them in place, including: (a) for Australian Customers, Grasshopper's undertaking in this DPA to handle Personal Data in a manner consistent with the Australian Privacy Principles, so that Customer may rely on it under APP 8; (b) for Canadian Customers, Grasshopper's undertaking to provide a level of protection comparable to that required under PIPEDA and applicable provincial law, and to cooperate with any privacy impact assessment Customer is required to perform; (c) for Brazilian Customers, contractual clauses consistent with the LGPD's requirements for international transfers, including any standard clauses approved by the Brazilian data protection authority; and (d) for Customers in other jurisdictions, an appropriate transfer mechanism recognized under the applicable law. Grasshopper will not transfer Personal Data outside the United States except to a Sub-processor listed in Exhibit C, and any such Sub-processor will be bound by transfer safeguards equivalent to those required of Grasshopper.
If Grasshopper receives a request directly from a Data Subject to access, correct, delete, restrict, or port Personal Data, or to opt out of processing, Grasshopper will (to the extent legally permitted) promptly forward the request to Customer and will not respond except to direct the Data Subject to Customer or as required by law. Customer may use the Services' administrative tools, export functions, and API to fulfill most requests directly. Grasshopper will provide reasonable additional assistance on request, which may be billed as described in Section 3.5.
Grasshopper will notify Customer without undue delay, and in any event within forty-eight (48) hours after confirming a Security Incident affecting Customer's Personal Data. Notice will be sent to Customer's designated security or administrative contact and will include, to the extent known, the nature of the incident, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address it. Grasshopper may provide information in phases as its investigation progresses.
Grasshopper will take reasonable steps to contain, investigate, and remediate the Security Incident, will keep Customer informed of material developments, and will provide reasonable cooperation to help Customer meet its own notification obligations. Grasshopper's notification of a Security Incident is not an acknowledgment of fault or liability. Customer is responsible for any notices to Data Subjects, regulators, or other third parties that Applicable Data Protection Law requires it to make, and will not identify Grasshopper in any such notice without Grasshopper's prior review unless the law requires it.
Grasshopper will make available to Customer, on request and subject to confidentiality obligations, information reasonably necessary to demonstrate compliance with this DPA, including summaries of its security program, policies, and the most recent third-party penetration test summary. If that information is not sufficient to satisfy an obligation Customer has under Applicable Data Protection Law, Customer or an independent auditor bound by confidentiality may conduct an audit of Grasshopper's processing of Personal Data, provided that (a) audits occur no more than once per twelve (12) months, unless required by a supervisory authority or following a Security Incident, (b) Customer gives at least thirty (30) days' written notice and the parties agree on scope, timing, and duration in advance, (c) audits take place during normal business hours and do not unreasonably disrupt Grasshopper's operations, (d) audits do not extend to the facilities or systems of Sub-processors, for which Grasshopper will provide available third-party audit reports instead, and (e) Customer bears the cost of the audit and reimburses Grasshopper for reasonable time spent beyond eight (8) hours at Grasshopper's then-current professional services rates. Customer will share audit results with Grasshopper and treat them as Grasshopper's Confidential Information.
During the Term, Customer may delete Personal Data at any time using the Services' administrative tools, subject to the retention settings Customer has configured.
Each party's liability arising out of or relating to this DPA, taken together with its liability under the Terms of Service, is subject to the exclusions and limitations of liability in the Terms of Service, including the data protection super-cap in Section 10.3 of the Terms of Service. Nothing in this DPA limits a party's liability where such limitation is prohibited by Applicable Data Protection Law.
This DPA takes effect when the Agreement takes effect and continues until Grasshopper has deleted all Personal Data in accordance with Section 10. Grasshopper may update this DPA by posting a revised version at grasshopperlabs.io/dpa. Updates that are required by changes in Applicable Data Protection Law or that do not reduce the protections provided to Customer take effect on posting. Other updates apply to Customer's existing Orders beginning with the next Renewal Term. If a supervisory authority requires a copy of this DPA, either party may provide it.
| Item | Description |
|---|---|
| Subject matter | Provision of the Grasshopper transportation management, warehouse management, inventory and fulfillment, driver mobile application, consumer tracking and scheduling, API and EDI, and Data Lake services described in the Order, including related support. |
| Duration | The Term of the Agreement plus the return and deletion period in Section 10. |
| Nature and purpose | Hosting, storage, transmission, display, routing, optimization, notification, reporting, and analytics of Customer Data as needed to plan, dispatch, execute, and document deliveries and warehouse operations, and to support Customer's use of the Services. |
| Categories of Data Subjects | Customer's employees and contractors who use the Services (administrators, dispatchers, warehouse staff, customer service staff); drivers and delivery crews, whether employed by Customer or by Customer's carriers; End Consumers who receive deliveries or pickups; contacts at Customer's retailers, shippers, carriers, and other trading partners. |
| Categories of Personal Data | Users and trading partner contacts: name, business email, phone number, role, login credentials (hashed), activity logs, IP address. Drivers and crews: name, phone number, email, employee or contractor identifier, device identifiers, device location while signed in and on an active route or manifest, route and stop history, timestamps, photographs and signatures captured in the app, in-app messages, and performance metrics derived from delivery events. End Consumers: name, delivery address, phone number, email, appointment windows, order contents and item descriptions, delivery instructions and access notes, communication history (SMS, email, voice), tracking page interactions, proof-of-delivery photographs and signatures, survey responses, and notes about delivery exceptions or damage claims. |
| Special categories | None intended. Grasshopper does not require, and Customer agrees not to provide, special categories of Personal Data. Proof-of-delivery photographs taken during in-home deliveries may incidentally capture the interior of a residence or the people in it; Customer is responsible for instructing drivers accordingly, as described in the Terms of Service. |
| Frequency | Continuous for the duration of the Term. |
| Processing location | United States. |
Grasshopper maintains an information security program with administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of Customer Data. The measures below describe the program as of the date of this DPA. Grasshopper may update specific measures over time provided the overall level of protection is not materially reduced.
The following Sub-processors process Personal Data in connection with the Services. This list is current as of the "Last updated" date above and will be updated in accordance with Section 5.
| Sub-processor | Purpose | Location of processing |
|---|---|---|
| Amazon Web Services, Inc. | Cloud infrastructure: compute, storage, networking, backups, and hosting of the Grasshopper application and the PostgreSQL data lake used for reporting and the Data Lake package. | United States |
| MongoDB, Inc. (MongoDB Atlas) | Managed database hosting for the Grasshopper application database (orders, manifests, users, partners, and related operational data). | United States |
| Twilio Inc. | SMS, voice, and related messaging to drivers, Users, and End Consumers (appointment scheduling, confirmations, tracking links, notifications). | United States |