Trust

Sub-processors

Every third party that processes customer data on our behalf.

Current as at 5 September 2026

A sub-processor is a third party that processes personal data on our behalf. This is all of them. It is short because the backend was deliberately built with few dependencies, and it is specific because a list that says “cloud providers” and “analytics partners” tells a reader nothing they could check.

The list

Sub-processorWhat it does for usWhat it receivesWhere, and on what basis
OTP Mobil Kft. (SimplePay)Card payments: subscriptions, plan changes and advertising top-ups.Name and email supplied at checkout, amount, currency, transaction reference and status. Card details are entered on SimplePay's own page and never reach us.Hungary (EU)
TeyaHosted checkout used by the earlier advertising top-up route, retained while historical orders are settled.Amount, currency, order reference and payment status.European Economic Area
ResendTransactional and inbound email: sign-in links, order and account mail, and the inbox behind the support agent.Recipient address, message content and delivery metadata.United States — Standard Contractual Clauses
CloudflareNetwork delivery in front of our origin: DNS, TLS termination, and protection against hostile traffic.Connection metadata and request content in transit; IP address and user agent.United States, with EU points of presence — Standard Contractual Clauses
OpenAIModel inference. The agents that research products, write store copy and draft campaign material run against this provider's models.The prompt and context sent for a given generation, which can include product, store and campaign content you created.United States — Standard Contractual Clauses

Both payment providers also act as independent controllers for their own regulatory purposes — fraud prevention, anti-money-laundering, and the records a payment institution is required to keep. That part of their processing is governed by their own terms rather than by ours.

Vendors that are not sub-processors

We use other services that never receive personal data, and we leave them off the list above rather than padding it. Hosting is one: the origin runs on hardware we operate ourselves in the European Union, so there is no hosting provider holding your data. Public data sources are another — domain availability and pricing are read from public registry and registrar interfaces, and market listings are read from public pages, in both cases without sending anything about you.

Categories we maintain rather than fix

Two categories exist where the specific vendor can change: the model provider behind the agent, and the payment route for a given currency or market. Where either changes, the table above is the current record and the notice below is how you hear about it before it happens. We would rather revise a published list than publish a vague one.

Notice of changes

We give at least 30 days’ notice before adding or replacing a sub-processor, under clause 5 of the data processing addendum. To receive that notice by email, write to [email protected] with “sub-processor notice” in the subject. Business customers may object on reasonable data protection grounds within the notice period, and that clause says what happens next.

What each of them has agreed to

Every party above is bound by a written data processing agreement meeting Article 28 GDPR, with the obligations published in full at sub-processor terms — including that they process only on our instructions, do not use the data for their own purposes, do not use it to train models, and report a breach to us within 48 hours. We remain fully liable to you for what they do.

For what we hold ourselves and for how long, see data handling and retention; for the rights you hold over it, clause 8 of the privacy policy.