Data Processing Agreement

Last updated: August 25, 2026

For shops using Penny. This sets out how Penny handles your customers' personal data on your behalf — you are the controller of that data, and Penny processes it under your instruction.

Document Version: 2026-08-25 Last Updated: August 25, 2026 Effective Date: August 25, 2026

This Data Processing Agreement ("DPA") is entered into by and between Penny Rental LLC, a Colorado limited liability company ("Penny," "Processor," or "Service Provider") and the bike shop or business entity subscribing to the Penny Platform ("Shop," "Merchant," "Controller," or "Business").

This DPA supplements and forms an integral part of the Penny Master Terms of Service (the "Agreement"). This DPA governs the processing of Customer Personal Data in connection with the software services provided by Penny.


1. DEFINITIONS

Capitalized terms used but not defined herein shall have the meanings ascribed to them in the Agreement or in applicable Data Protection Legislation:

1.1 "Applicable Data Protection Legislation" means all worldwide privacy and data protection laws and regulations applicable to the processing of Personal Data under this Agreement, including without limitation the Colorado Privacy Act (C.R.S. § 6-1-1301 et seq.) ("CPA"), the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 ("CCPA/CPRA"), the European Union General Data Protection Regulation 2016/679 ("GDPR"), and the United Kingdom Data Protection Act 2018 ("UK GDPR").

1.2 "Customer Personal Data" means any Personal Data processed by Penny on behalf of the Shop in the course of providing the Services, including renter contact details, booking information, fit specifications, and electronic waiver execution records.

1.3 "Controller," "Processor," "Data Subject," "Personal Data," "Processing," and "Appropriate Technical and Organizational Measures" shall have the meanings given to them under the GDPR or applicable state privacy statutes (e.g., "Business" and "Service Provider" under CCPA/CPA).

1.4 "Personal Data Breach" means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data transmitted, stored, or otherwise processed by Penny.

1.5 "Sub-Processor" means any third-party data processor engaged by Penny who receives or has access to Customer Personal Data in connection with performing the Services.


2. ROLES AND SCOPE OF PROCESSING

2.1 Role of the Parties: The parties acknowledge and agree that with respect to Customer Personal Data processed through the booking widget, kiosk, and admin dashboard, the Shop is the Data Controller (or "Business" under CCPA/CPA) and Penny is the Data Processor (or "Service Provider" under CCPA/CPA).

2.2 Instructions: Penny shall process Customer Personal Data solely in accordance with the documented instructions of the Shop, as set forth in the Agreement, this DPA, and the Shop’s configuration of the Platform (including authorized support and troubleshooting via administrative impersonation), unless required to do so by applicable law to which Penny is subject.

2.3 Details of Processing: The subject matter, nature, purpose, duration of processing, types of personal data, and categories of data subjects are set forth in Annex A to this DPA.


3. PROCESSOR OBLIGATIONS & CONFIDENTIALITY

3.1 Confidentiality: Penny shall ensure that persons authorized to process Customer Personal Data (including employees, contractors, and agents) are committed to confidentiality through written non-disclosure agreements or are under an appropriate statutory obligation of confidentiality.

3.2 Security of Processing: Taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing, Penny shall implement and maintain appropriate Technical and Organizational Measures (as set forth in Annex B) to ensure a level of security appropriate to the risk.

3.3 Reliability of Personnel: Penny shall take commercially reasonable steps to ensure the reliability of any personnel who have access to Customer Personal Data, limiting access to those individuals who require access to perform the Services.


4. SUB-PROCESSORS

4.1 General Authorization: The Shop grants Penny general written authorization to engage Sub-Processors to perform specific processing activities on behalf of Penny in accordance with this Section 4.

4.2 Current Sub-Processors: A complete list of currently approved Sub-Processors engaged by Penny is set forth in Annex C.

4.3 Sub-Processor Requirements: Penny shall:

  • Impose data protection terms on each Sub-Processor that provide at least the same level of protection for Customer Personal Data as those required by this DPA.
  • Remain fully liable to the Shop for the performance of the Sub-Processor’s obligations.

4.4 Notification of Changes: Penny shall provide the Shop with notice of any planned addition or replacement of Sub-Processors (via email notification or dashboard update) at least thirty (30) days prior to authorizing such Sub-Processor to process Customer Personal Data. The Shop may object to such changes on reasonable, documented data protection grounds within fourteen (14) days of notice. If the parties cannot resolve the objection, either party may terminate the affected service without penalty.


5. ASSISTANCE WITH DATA SUBJECT RIGHTS

5.1 Data Subject Requests (DSARs): Taking into account the nature of the processing, Penny shall provide reasonable assistance to the Shop by appropriate technical and organizational measures, insofar as this is possible, to enable the Shop to respond to requests from Data Subjects exercising their rights (such as access, rectification, erasure, data portability, or objection) under Applicable Data Protection Legislation.

5.2 Direct Requests to Penny: If a Data Subject submits a request directly to Penny regarding Customer Personal Data, Penny will promptly notify the Shop and advise the Data Subject to submit their request directly to the Shop.


6. PERSONAL DATA BREACH NOTIFICATION

6.1 Notification Timeline: In the event of a confirmed Personal Data Breach impacting Customer Personal Data, Penny shall notify the Shop without undue delay after becoming aware, and in any event no later than seventy-two (72) hours after becoming aware of the Personal Data Breach.

6.2 Breach Information: The notification shall contain, to the extent available:

  • A description of the nature of the breach, including categories and approximate numbers of Data Subjects and records affected.
  • The name and contact details of Penny’s Data Protection contact (Kyle Christian, kyle@penny.bike).
  • A description of the likely consequences of the Personal Data Breach.
  • A description of the measures taken or proposed to be taken by Penny to mitigate its possible adverse effects.

6.3 Cooperation: Penny shall provide reasonable cooperation and assistance to the Shop in fulfilling its legal obligations to notify regulatory authorities and affected Data Subjects.


7. AUDITS, ASSESSMENTS & COMPLIANCE

7.1 Demonstration of Compliance: Penny shall make available to the Shop all information reasonably necessary to demonstrate compliance with the obligations laid down in this DPA and Article 28 of the GDPR / applicable state privacy statutes.

7.2 Audits: Upon reasonable prior written notice (no less than 30 business days) and no more than once per twelve-month period, Penny shall allow for and contribute to audits or inspections conducted by the Shop or an independent certified auditor mandated by the Shop. Any such audit shall occur during normal business hours without disrupting Penny's business operations and subject to standard confidentiality obligations.

7.3 DPIAs and Prior Consultation: Taking into account the nature of processing and information available, Penny shall provide reasonable assistance to the Shop with any data protection impact assessments (DPIAs) and prior consultations with supervisory authorities required under GDPR Articles 35 and 36 or state privacy laws.


8. RETURN AND DELETION OF DATA

8.1 Post-Termination Options: Upon expiration or termination of the Agreement, the Shop may export its customer records and reservation data. Upon written request from the Shop within thirty (30) days following termination, Penny shall securely delete Customer Personal Data from its production databases, unless applicable law or statutory record-keeping requires continued retention.

8.2 Legal Retention & Waivers: Penny and the Shop may retain Customer Personal Data (specifically executed liability waiver records) to the extent required by applicable law, statutory audit requirements, or to preserve defense records for the duration of applicable statutes of limitations, provided that Penny ensures the continued confidentiality and security of such data.


9. US STATE PRIVACY LAWS (COLORADO CPA & CALIFORNIA CCPA/CPRA)

To the extent the CPA or CCPA applies to the processing of Customer Personal Data:

9.1 Service Provider / Processor Certification: Penny certifies that it acts as a "Service Provider" / "Processor" and:

  • Shall not "sell" or "share" (for cross-context behavioral advertising or targeted advertising) Customer Personal Data.
  • Shall not retain, use, or disclose Customer Personal Data for any purpose other than the specific business purposes set forth in the Agreement and this DPA.
  • Shall not retain, use, or disclose Customer Personal Data outside of the direct business relationship between Penny and the Shop.
  • Shall not combine Customer Personal Data received from the Shop with personal information received from or on behalf of another entity, except as permitted under applicable regulations.

9.2 Compliance Monitoring: Penny grants the Shop the right to take reasonable and appropriate steps to ensure that Penny uses Customer Personal Data in a manner consistent with applicable state statutory obligations.


10. INTERNATIONAL DATA TRANSFERS

Where Customer Personal Data originating in the European Economic Area (EEA), the United Kingdom, or Switzerland is transferred to a country not recognized as providing an adequate level of data protection:

  • The parties hereby incorporate by reference the Standard Contractual Clauses (SCCs) (Module Two: Controller-to-Processor) approved by the European Commission Decision (EU) 2021/914.
  • For UK transfers, the parties incorporate the UK International Data Transfer Addendum to the EU SCCs.
  • For the purposes of the SCCs, the Shop is the Data Exporter and Penny is the Data Importer.

11. GENERAL PROVISIONS

11.1 Conflict: In the event of any conflict or inconsistency between the terms of this DPA and the Master Terms of Service, the provisions of this DPA shall prevail with respect to data protection and privacy matters.

11.2 Severability: If any provision of this DPA is determined to be invalid or unenforceable, the remaining provisions shall remain in full force and effect.


ANNEX A: DETAILS OF PROCESSING

A.1 Subject Matter and Duration of Processing

  • Subject Matter: The provision of bicycle rental fleet management software, online/kiosk booking workflows, electronic liability waiver signing, customer email communications, and POS inventory synchronization services.
  • Duration: The term of the subscription Agreement plus any post-termination retention period permitted or required by law.

A.2 Nature and Purpose of Processing

  • Processing customer bookings, reservations, dates, and equipment allocations.
  • Delivering automated operational confirmation and receipt emails.
  • Presenting, executing, and archiving customer liability waivers.
  • Processing payment transaction metadata via Stripe Connect.
  • Syncing catalog items and work orders with Lightspeed POS under a generic shop account (without transmitting individual customer records).

A.3 Categories of Data Subjects

  • End-user customers, cyclists, and renters booking through the Shop’s widget or kiosk.
  • Authorized shop managers, mechanics, and counter staff.
  • Adult signers executing digital waivers for rental equipment.

A.4 Categories of Personal Data

  • Contact Details: Full name, email address, and mobile phone number. (Phone numbers are collected for kiosk counter lookup and direct shop contact; not shared with third-party aggregators).
  • Rental Parameters: Reservation start/end times, booked bike models, sizes, rental history.
  • Rider Physical Fit Specs: Rider height and weight (used solely for bike sizing and suspension setup).
  • Electronic Waiver Signatures: Signature image (base64 PNG), signed-at timestamp, signer name, and optionally signer email and phone number.
  • Transaction Metadata: Stripe payment intent IDs, charge amounts, discount codes. *(Excludes raw credit card numbers)*.

A.5 Sensitive Data / Special Categories of Data

  • No special category data under GDPR Article 9 is intentionally processed, except for optional rider height/weight metrics provided voluntarily by the customer solely for mechanical equipment fit.

ANNEX B: TECHNICAL AND ORGANIZATIONAL MEASURES (TOMs)

Penny maintains security measures designed to protect Customer Personal Data against unauthorized access, loss, or alteration:

  1. Access Control & Multi-Tenancy:
  • Strict database-level multi-tenant isolation ensuring each Shop’s data is segregated via explicit `shop_id` scoping.
  • Role-based access control (RBAC) ensuring staff only access features permitted by the Shop owner.
  • Multi-factor authentication (MFA) enforced on hosting and production administrative management portals.
  1. Encryption:
  • In Transit: All external and internal API traffic is encrypted using Transport Layer Security (TLS 1.3 / HTTPS).
  • At Rest: Managed database volumes and stored media assets are encrypted at rest using industry-standard AES encryption provided by managed infrastructure providers.
  1. Data Integrity & Backups:
  • Managed database backups provided by PostgreSQL database infrastructure.
  • Continuous uptime and error monitoring via Sentry.
  1. Software Development & Pipeline Security:
  • Automated test and static-lint enforcement on every code change, with containerized deployment pipelines and regular dependency updates.
  1. Incident Response & Breach Management:
  • Documented procedure to assess security incidents and issue notifications to impacted Shops without undue delay and no later than seventy-two (72) hours after confirmed breach discovery.

ANNEX C: AUTHORIZED SUB-PROCESSORS

Sub-Processor NameService ProvidedProcessing LocationData Protection Documentation
Stripe, Inc.Payment processing, Connect merchant onboarding, payment securityUSA / GlobalStripe DPA
Vercel Inc.Web application hosting, serverless compute, edge networkUSA / GlobalVercel DPA
Neon, Inc.Managed PostgreSQL database hosting (customer and reservation records)USANeon Privacy
Google LLC (Firebase)User authentication and staff credentialsUSAFirebase Terms
Resend, Inc.Transactional email delivery (booking receipts, waiver links)USAResend Privacy
Supabase, Inc.Media object storage (shop logos, bike fleet photos)USASupabase DPA
Functional Software, Inc. (Sentry)Application error logging and performance diagnosticsUSASentry DPA
Lightspeed Commerce Inc.Equipment catalog and work-order sync (opt-in; no customer PII transmitted)Canada / USALightspeed Privacy

EXECUTION

This DPA is accepted and agreed to by the Shop upon registering an account, executing an Order Form, or subscribing to the Penny Platform.

PENNY RENTAL LLC (Processor) A Colorado Limited Liability Company By: ___________________________ Name: Kyle Christian Title: Founder / Managing Member Contact: kyle@penny.bike Date: August 25, 2026

BIKE SHOP / MERCHANT (Controller) By: ___________________________ Authorized Signatory Name: ___________________________ Shop Legal Name: ___________________________ Title: ___________________________ Date: ___________________________