Application servers, database and encrypted backups. Receives all store operational data at rest. This is where everything lives.
Everyone who touches your data
This is the complete list. If a company isn't on it, it doesn't receive data from us. We update this page at least 30 days before a new sub-processor begins processing, and email the address on your account — see clause 5 of the DPA for your right to object.
Shopify itself is not listed as our sub-processor. Shopify is your processor, under your own agreement with them; we read from and write to your store on your instruction.
Drafting campaigns from your descriptions. Receives your prompt plus structural store metadata — collection names, tag names, prices where relevant. No customer personal data. Contractually excluded from training on our inputs.
Stack traces and request context when something fails. Store domain and campaign identifiers may appear; personal data is scrubbed before transmission. Retained 30 days.
Account and service notifications — policy changes, campaign expiry warnings, billing failures. Receives your merchant email address only. No customer data.
The inbox behind support@ and privacy@. Receives whatever you choose to send us, including anything you paste into a support email.
DNS, TLS termination and abuse protection for this site and the app. Sees request metadata in transit — IP address, path, user agent. Stores no application data.
Removed sub-processors
We keep the history so you can see what changed rather than only what's current.
Get notified of changes
Merchants on any plan are emailed 30 days before a sub-processor is added. If you need that notice to go to a compliance address instead of your account email, tell us and we'll route it there.
[email protected]