Sub-processors
Who helps us run the service, where they are, and the terms we hold them to.
Last updated 2026
1. Sub-processors we use for everyone
| Provider | Purpose | Region | Transfer safeguard | DPA / SCCs |
|---|---|---|---|---|
| [HOSTING PROVIDER] | Servers that host the platform and every site | [HOSTING COUNTRY] | Adequacy or SCCs where outside the EEA | [HOSTING PROVIDER DPA URL] |
| [OFFSITE BACKUP STORAGE PROVIDER] | Encrypted offsite backups (the provider cannot read them) | [BACKUP REGION] | SCCs where outside the EEA | [BACKUP PROVIDER DPA URL] |
| Stripe, Inc. / Stripe Payments Europe, Ltd. | Platform subscription billing; card payments on storefronts that connect Stripe | Ireland / USA | EU-US Data Privacy Framework; SCCs | DPA |
| NameSilo, LLC | Domain registration and renewal (registrant details are required by ICANN) | USA | SCCs; ICANN registration-data rules | [NAMESILO REGISTRATION AGREEMENT / DPA URL] |
| Cloudflare, Inc. | Bot protection on forms (Turnstile) and DNS for connected domains | Global network / USA | EU-US Data Privacy Framework; SCCs | DPA |
| Google LLC / Google Ireland Ltd. | Optional Google sign-in, Calendar and Maps features | Ireland / USA | EU-US Data Privacy Framework; SCCs | DPA |
| Telegram FZ-LLC | Operational alerts to our on-call staff | UAE / global | Not a transfer of personal data | Not needed: no personal data is sent (https://telegram.org/privacy) |
| Unsplash Inc. | Stock-photo attribution: when a site shows or publishes an Unsplash photo from our library, our server reports that download to Unsplash (their API terms require it). The photos themselves are served from our own image host, not from Unsplash | USA | Not a transfer of personal data | Not needed: no personal data is sent (https://unsplash.com/privacy) |
| [ERROR MONITORING PROVIDER, OR "self-hosted"] | Error monitoring (ERROR_WEBHOOK_URL) | [REGION] | SCCs where outside the EEA | [ERROR MONITORING DPA URL] |
2. Used only when you turn a feature on
| Provider | Purpose | Region | Transfer safeguard | DPA / SCCs |
|---|---|---|---|---|
| Apple Inc. | Optional "Sign in with Apple" | USA / Ireland | EU-US Data Privacy Framework; SCCs | DPA |
| Microsoft Corporation | Optional Microsoft sign-in and Outlook calendar connection | USA / Ireland | EU-US Data Privacy Framework; SCCs | DPA |
| Twilio Inc. | SMS and phone verification, when a site enables it | USA | EU-US Data Privacy Framework; SCCs | DPA |
| GitHub, Inc. | Optional publishing of a site's export to the owner's own GitHub repository | USA | EU-US Data Privacy Framework; SCCs | DPA |
3. Providers a site owner connects
These act under the site owner's own contract with them, not as our sub-processors.
| Provider | Purpose | Region | Transfer safeguard | DPA / SCCs |
|---|---|---|---|---|
| Payment providers the owner connects | Taking payment on the owner's storefront: PayPal, Adyen, Checkout.com, Mollie, Razorpay, Paystack, Flutterwave, Mercado Pago, Midtrans, Xendit, Omise, Iyzico, Paymob, PayTabs, Tap, Thawani, Khalti, SSLCommerz, PayHere, Wompi, Toss Payments, YooKassa, CloudPayments, Tinkoff | Per provider | Under the owner's contract with the provider | Each provider's own terms (your contract with them) |
| Shipping carriers and label services the owner connects | Rates, labels and tracking: EasyPost, Shippo, ShipEngine, DHL, Aramex, CDEK, Envia, Melhor Envio, Shiprocket, Biteship | Per provider | Under the owner's contract with the provider | Each provider's own terms (your contract with them) |
| Sales channels and marketplaces the owner connects | Listing products and importing orders: Amazon, eBay, Etsy, Walmart, Mercado Libre, TikTok Shop, Meta (Facebook/Instagram shops and Conversions API), LinkedIn | Per provider | Under the owner's contract with the provider | Each provider's own terms (your contract with them) |
| Business tools the owner connects | Accounting, tax, CRM, email marketing and travel booking: Xero, FreshBooks, TaxJar, HubSpot, ConvertKit (Kit), Duffel | Per provider | Under the owner's contract with the provider | Each provider's own terms (your contract with them) |
4. Get 30 days' notice of changes
We give at least 30 days' notice before we add or replace a sub-processor (see the DPA, section 6). Account holders are told by email. Anyone else can sign up here:
We use this address only to send sub-processor change notices. Each notice has an unsubscribe link.
