What this list is
A sub-processor is a company we engage to process personal data on your behalf while providing Mercentia. Each one below is contracted by us, runs on our account, and applies to every merchant on the platform. We hold a data processing agreement with each, and the vendor's own agreement is linked so you can follow the chain one link further.
The list is generated from the same registry the platform uses to configure these integrations. That is deliberate: a hand-written list is the one legal document that goes out of date without anyone touching it.
Hosting and infrastructure
| Provider | What it does | Data | Region |
|---|
Railway Their DPA | Application hosting for the gateway, worker and web surfaces | all data in transit through the application Merchants, Shoppers, Site visitors | EU (West) / US |
Neon Their DPA | Managed PostgreSQL — the primary store for every record below | account, contact, address, order, support Merchants, Shoppers | EU (Frankfurt) |
| Redis (Railway) | Job queues, rate limiting, session and cart caching | contact, cart contents, session identifiers Merchants, Shoppers | EU (West) |
Cloudflare Their DPA | CDN, DNS, edge caching and custom-domain certificates | IP address, user agent, request metadata Merchants, Shoppers, Site visitors | Global edge |
Cloudflare R2 Their DPA | Object storage for product images, theme assets and uploads | uploaded media (may contain personal data the merchant uploads) Merchants, Shoppers | EU / Global |
| Meilisearch | Product and content search indexing for storefronts | search queries, catalogue content Shoppers | EU |
Payments
| Provider | What it does | Data | Region |
|---|
Stripe Their DPA | Card processing for shopper checkouts and for Mercentia subscription billing. Card numbers are entered directly into Stripe and never reach our servers. | name, email, billing address, payment token Merchants, Shoppers | US / EU |
Razorpay Their DPA | Card and UPI processing for merchants selling in India | name, email, phone, payment token Shoppers | India |
PayPal Their DPA | Wallet and express checkout | name, email, shipping address, payment token Shoppers | Global |
Email, SMS and messaging
| Provider | What it does | Data | Region |
|---|
Resend Their DPA | Transactional and marketing email delivery. Used unless the merchant has connected their own email provider, in which case their provider carries the message instead. | email address, name, message content Merchants, Shoppers | US |
Twilio Their DPA | SMS notifications and WhatsApp messaging where a merchant enables them | phone number, message content Shoppers | US / EU |
| Emailable | Email deliverability and disposable-address checks during signup and order risk scoring | email address Merchants, Shoppers | US |
AI model providers
| Provider | What it does | Data | Region |
|---|
Anthropic Their DPA | The models behind the store builder, product copy, translation, the buyer assistant and the support agent. Prompts are not used to train the provider’s models. | prompt content, catalogue content, buyer-assistant messages Merchants, Shoppers | US |
OpenAI Their DPA | Fallback and secondary models for the same AI features, used when the primary provider is unavailable or a task routes to it. Prompts are not used to train the provider’s models. | prompt content, catalogue content, buyer-assistant messages Merchants, Shoppers | US |
Operations and support
| Provider | What it does | Data | Region |
|---|
Sentry Their DPA | Application error monitoring | IP address, user agent, account identifier, error context Merchants, Shoppers, Site visitors | EU |
| TaxJar | Sales-tax calculation for US destinations | shipping address Shoppers | US |
| IPinfo | Country lookup for currency display and order risk scoring | IP address Shoppers, Site visitors | US |
Slack Their DPA | Internal operational alerting — platform health, error spikes and escalations reach the on-call channel | store name and identifier in alert text Merchants | US |
| Telegram | Internal bug-report relay from the in-product support form, where a merchant chooses to send one | report text submitted by the merchant, store identifier Merchants | Global |
| Open Exchange Rates | Daily currency conversion rates | No personal data | US |
What is not on this list
Services you connect to your own store are your sub-processors, not ours. When you link Klaviyo, a helpdesk, your own carrier account, your accounting software, an ad platform's conversion API, or a payment provider you hold the keys for — Paystack and Flutterwave work this way — the data goes to your account on that service, on your instruction. We pass it on; we have no contract with them covering your data.
Mercentia detects those automatically from what you have connected and lists them in the privacy policy your storefront generates, under Settings → Legal. If you add a service we do not recognise, you can add it to that list by hand.
Signing in with Google or GitHub is different again: they send us your name and email so we can identify you. They are a source of data, not a recipient of it.
Change notice
We give account owners at least 30 days' notice by email before a new sub-processor begins processing personal data, and you may object under the DPA during that period. To be notified of changes, email [email protected] and we will add you to the notification list.