Legal

Sub-processors

Every third party Mercentia routes personal data through, what they do with it, and where. This page is generated from the platform's own integration registry, so it changes when the software does.

Last updated · August 2026

What this list is

A sub-processor is a company we engage to process personal data on your behalf while providing Mercentia. Each one below is contracted by us, runs on our account, and applies to every merchant on the platform. We hold a data processing agreement with each, and the vendor's own agreement is linked so you can follow the chain one link further.

The list is generated from the same registry the platform uses to configure these integrations. That is deliberate: a hand-written list is the one legal document that goes out of date without anyone touching it.

Hosting and infrastructure

ProviderWhat it doesDataRegion
Railway
Their DPA
Application hosting for the gateway, worker and web surfacesall data in transit through the application
Merchants, Shoppers, Site visitors
EU (West) / US
Neon
Their DPA
Managed PostgreSQL — the primary store for every record belowaccount, contact, address, order, support
Merchants, Shoppers
EU (Frankfurt)
Redis (Railway)Job queues, rate limiting, session and cart cachingcontact, cart contents, session identifiers
Merchants, Shoppers
EU (West)
Cloudflare
Their DPA
CDN, DNS, edge caching and custom-domain certificatesIP address, user agent, request metadata
Merchants, Shoppers, Site visitors
Global edge
Cloudflare R2
Their DPA
Object storage for product images, theme assets and uploadsuploaded media (may contain personal data the merchant uploads)
Merchants, Shoppers
EU / Global
MeilisearchProduct and content search indexing for storefrontssearch queries, catalogue content
Shoppers
EU

Payments

ProviderWhat it doesDataRegion
Stripe
Their DPA
Card processing for shopper checkouts and for Mercentia subscription billing. Card numbers are entered directly into Stripe and never reach our servers.name, email, billing address, payment token
Merchants, Shoppers
US / EU
Razorpay
Their DPA
Card and UPI processing for merchants selling in Indianame, email, phone, payment token
Shoppers
India
PayPal
Their DPA
Wallet and express checkoutname, email, shipping address, payment token
Shoppers
Global

Email, SMS and messaging

ProviderWhat it doesDataRegion
Resend
Their DPA
Transactional and marketing email delivery. Used unless the merchant has connected their own email provider, in which case their provider carries the message instead.email address, name, message content
Merchants, Shoppers
US
Twilio
Their DPA
SMS notifications and WhatsApp messaging where a merchant enables themphone number, message content
Shoppers
US / EU
EmailableEmail deliverability and disposable-address checks during signup and order risk scoringemail address
Merchants, Shoppers
US

AI model providers

ProviderWhat it doesDataRegion
Anthropic
Their DPA
The models behind the store builder, product copy, translation, the buyer assistant and the support agent. Prompts are not used to train the provider’s models.prompt content, catalogue content, buyer-assistant messages
Merchants, Shoppers
US
OpenAI
Their DPA
Fallback and secondary models for the same AI features, used when the primary provider is unavailable or a task routes to it. Prompts are not used to train the provider’s models.prompt content, catalogue content, buyer-assistant messages
Merchants, Shoppers
US

Operations and support

ProviderWhat it doesDataRegion
Sentry
Their DPA
Application error monitoringIP address, user agent, account identifier, error context
Merchants, Shoppers, Site visitors
EU
TaxJarSales-tax calculation for US destinationsshipping address
Shoppers
US
IPinfoCountry lookup for currency display and order risk scoringIP address
Shoppers, Site visitors
US
Slack
Their DPA
Internal operational alerting — platform health, error spikes and escalations reach the on-call channelstore name and identifier in alert text
Merchants
US
TelegramInternal bug-report relay from the in-product support form, where a merchant chooses to send onereport text submitted by the merchant, store identifier
Merchants
Global
Open Exchange RatesDaily currency conversion ratesNo personal dataUS

What is not on this list

Services you connect to your own store are your sub-processors, not ours. When you link Klaviyo, a helpdesk, your own carrier account, your accounting software, an ad platform's conversion API, or a payment provider you hold the keys for — Paystack and Flutterwave work this way — the data goes to your account on that service, on your instruction. We pass it on; we have no contract with them covering your data.

Mercentia detects those automatically from what you have connected and lists them in the privacy policy your storefront generates, under Settings → Legal. If you add a service we do not recognise, you can add it to that list by hand.

Signing in with Google or GitHub is different again: they send us your name and email so we can identify you. They are a source of data, not a recipient of it.

Change notice

We give account owners at least 30 days' notice by email before a new sub-processor begins processing personal data, and you may object under the DPA during that period. To be notified of changes, email [email protected] and we will add you to the notification list.