Home Legal Sub-processors

Sub-processors

Every third party that may handle data on our behalf, what it does and where it sits, plus the 30 days’ notice you get before that list changes at all.

Last updated 11 August 2026 · Applies to the Provenance Shopify app

Every third party that may handle data on our behalf in running Provenance, what it does, and where it does it. This list is part of the Data Processing Addendum, which is where the obligations attached to it are written down.

We give 30 days' notice before adding or replacing anyone on this list. Notice goes to installed merchants by email and appears here with a date in the change log at the foot of this page. If you object on reasonable data protection grounds within that period and we cannot resolve it, you may terminate without penalty.

The list

Sub-processorWhat it doesWhereWhat it may handle
ShopifyThe platform the app runs inside, and the store your register is mirrored intoGlobal, with EU processing availableEverything the app reads and writes
NeonThe Postgres database that is our system of recordFrankfurt, eu-central-1Merchant account, staff accounts, the item register
VercelRuns the app itselfGlobal edge, functions in the EUData in transit while a request is being served
CloudflareServes this website, and DNS for both hostsGlobal edgeTechnical details of a web request to this site
ResendDelivers the messages sent through the contact form on this siteUnited StatesYour name, email address and message, if you use that form

Notes on three of them

Shopify is not really a sub-processor in the usual sense. It is the platform you are already on, you have your own agreement with it, and the copy of your register held as metaobjects lives in your account rather than ours. It is listed because it processes data in the course of the app working, and leaving it out would make this list look tidier than it is.

Neon is where the records actually live. The database is the system of record and the Shopify metaobjects are the mirror, for the reason set out on how it works: metaobjects cannot enforce that an identifier is unique, and uniqueness is the safety property this whole product rests on.

Resend is only involved if you use the contact form on this website. The app sends no email at all, to you or to anybody else. If that changes, this page and the Privacy Policy change with it, on notice.

Who is not on this list

Worth saying, because their absence is a decision rather than an oversight.

  • No analytics provider. This site measures nothing and sets no cookies.
  • No error tracking service. Failures are read from the hosting platform's own logs.
  • No customer support platform. Support is an email address.
  • No advertising, attribution or session recording of any kind.

Change log

Dated, and appended to rather than rewritten. A list of current sub-processors with no history is a list you cannot audit.

11 August 2026. First published, with Shopify, Neon, Vercel, Cloudflare and Resend. No changes to report yet: this is the initial state.