TMV Go terms

TMV Go Data Processing Addendum

Effective September 10, 2026. Adopted by SSY Media, LLC with owner approval.

1. Parties and scope

This addendum forms part of the TMV Go service agreement between SSY Media, LLC (TMV Go) and the merchant identified in the account. For store-visitor data, the merchant is the controller, or a processor acting with its controller's authority, and TMV Go acts as processor or subprocessor. Each party's independent account, payment and legal-compliance processing is governed by its applicable privacy notice.

The addendum applies during the service and while TMV Go retains merchant personal data. If it conflicts with the service terms concerning this processing, this addendum controls. Mandatory applicable data-protection law remains controlling.

2. Processing instructions and scope

TMV Go processes personal data only on documented merchant instructions to provide configured session replay, heatmaps, visitor analytics, checkout milestones, requested AI analysis, support, sharing/export and deletion, or where law requires otherwise. Configuration choices and authorized service requests are instructions. TMV Go will notify the merchant of a legal processing requirement where permitted and flag an instruction it believes infringes applicable data-protection law.

Processing includes collection, transmission, storage, organization, analysis, retrieval, display and deletion. Data subjects are store visitors and customers. Data can include browser/device information, approximate IP-derived location, referral information, page content and structure, interactions, navigation, conversion events and merchant-configured identifiers. Configured replay may include ordinary customer information appearing on the page. Merchant masking settings and explicit exclusions determine what is suppressed before upload.

The service is not intended for payment-card information, passwords, authentication secrets or intentionally collected special-category personal data. Merchants must exclude confidential content and choose suitable masking before recording. TMV Go does not sell recorded visitor data or use it for advertising targeting. AI summaries describe activity and must not be used to make legally significant decisions about individuals.

3. Merchant responsibilities

The merchant determines lawful purposes and legal bases, provides appropriate notices, obtains required consent and configures collection, masking and retention. It must have authority to instruct TMV Go and authorize its users. It must not instruct collection prohibited by law or by the service agreement. TMV Go respects supported consent withdrawal and opt-out signals; previously collected data follows deletion and retention instructions.

4. Confidentiality and security

Access is limited to authorized persons with a need to know who are bound by confidentiality obligations. TMV Go maintains measures appropriate to the processing, including encrypted transport; encrypted operational database and recording storage; encrypted backups; account/site access controls; strong password requirements; application access logs and database connection/table-access logs; and documented incident response and recovery procedures.

Application access logs retain records for 180 days. Database metadata logs rotate by size. Logs exclude replay contents and raw query values and are not represented as immutable against infrastructure administrators. Security measures may evolve without materially reducing the agreed protection. No certification or uninterrupted-service guarantee is implied.

5. Assistance and incidents

TMV Go will provide reasonable assistance, considering the nature of processing and information available, with data-subject requests, security obligations, impact assessments and regulatory consultations. Requests concerning merchant visitor data will be referred to the merchant unless a direct response is legally required.

TMV Go will notify the merchant without undue delay after becoming aware of a personal-data breach affecting its data. Initial notice may be supplemented as facts become available and will describe the incident, known effects, mitigation and a contact. TMV Go will cooperate in containment and remediation. The merchant remains responsible for its own legally required notifications. Contact: support@tmvgo.com. Incident owner: Yasir Mehmood.

6. Subprocessors

The merchant generally authorizes the providers listed below for the stated purposes. TMV Go will require applicable data-protection obligations from subprocessors and remains responsible for their performance as required by applicable law. TMV Go will give at least 30 days' notice of a new subprocessor or material replacement through the account contact, except an urgent security or service-continuity replacement, for which notice will follow promptly.

The merchant may object on reasonable data-protection grounds during that period. The parties will work toward a reasonable alternative. If no alternative is available, the merchant may stop the affected feature or terminate the affected service before the new processing begins, with a proportionate refund of prepaid unused affected service.

ProviderPurposeProcessing location information
InMotion Hosting, Inc.Application/database hosting and service mail infrastructureUnited States infrastructure; provider's current subprocessor terms apply
Backblaze, Inc.Recording object storage and encrypted backup storageRecording bucket configured in US East; provider support and subprocessor locations follow its terms
OpenAI, under the applicable API account agreementEnabled AI narration and insights from selected captured activityNo regional-residency or zero-retention commitment is represented; applicable API processing terms govern

AI inputs are limited by the feature's extraction and masking, but page labels can contain merchant-provided personal information. API requests use store=false. This is not a promise of zero retention: the provider may retain abuse-monitoring information under its applicable terms. Merchant users should not submit confidential information in prompts.

7. International transfers

The service operates from the United States and may involve international processing by authorized providers. Where applicable law requires a transfer safeguard, the parties must establish an applicable adequacy basis or appropriate contractual safeguard, including required annexes and supplementary measures, before the restricted transfer. This addendum does not by itself execute standard contractual clauses or certify participation in a privacy framework. TMV Go will provide available information reasonably needed to assess the applicable safeguards and will not represent an unverified transfer mechanism as established.

8. Retention, return and deletion

Ordinary recording retention is 2 months (60 days) for Starter, 90 for Growth and 180 for Business. Trial recordings remain available for seven days after the fourteen-day capture trial ends. Merchant-directed deletion and background expiry remove associated operational recording data through the service's deletion process. The merchant may export available recordings before deletion or termination.

Encrypted recovery backups follow seven daily and four weekly retained snapshots. Snapshot selection and exceptional recovery/legal-preservation copies mean this is not an unconditional fixed-day erasure guarantee. Exceptional copies must remain restricted, be reviewed for necessity and be deleted when their purpose expires. Backup copies are not used for ordinary service processing; relevant deletion requests must be reapplied before a restored copy is returned to service. Data required by law may be retained only for that requirement with continuing protections. Copies exported or shared by the merchant are outside TMV Go's control.

9. Compliance information and audits

TMV Go will make available information reasonably necessary to demonstrate its processor obligations and allow and contribute to audits required by applicable law. Audits will use reasonable notice, confidentiality and proportionate arrangements that protect other customers and service security. Existing reports and documentation may be used where adequate; these arrangements do not remove mandatory regulatory or controller rights.

10. Contact

SSY Media, LLC, operating TMV Go. Data-protection and incident inquiries: support@tmvgo.com. The merchant's contact is the current account contact.