Sub-Processors

Last updated: 2026-06-09

Ordinary engages the following third-party service providers (“Sub-Processors”) to process Personal Data on behalf of merchant customers who use the Ordinary Service. This list is maintained as required by Section 6 of Ordinary’s Data Processing Agreement.

New Sub-Processors will be listed here at least 30 days before they begin processing Personal Data. Merchants may object to a new Sub-Processor within that 30-day window per Section 6.2 of the DPA.


Core infrastructure

Sub-ProcessorPurposeData processedLocation
VercelApplication hosting (Next.js)All request/response data in transit; logsUSA (primary), global edge
NeonPrimary Postgres database (managed)All application data at restUSA (AWS us-east-1)
Digital Ocean App PlatformBackground worker (Graphile) hosting for async tasks (webhook processing, backfills)Queue payloads; temporarily holds event data in transitUSA (primary region)
DigitalOcean SpacesFile storage (admin-files, imported data, temporary export bundles)Uploaded files, data export JSONsUSA

Authentication and user management

Sub-ProcessorPurposeData processedLocation
ClerkUser authentication, session management, MFAAuthorised-user email, name, password (hashed, stored by Clerk), IP address, user agent, session tokensUSA

Communications

Sub-ProcessorPurposeData processedLocation
ResendTransactional email delivery (GDPR data-request bundles, system notifications)Recipient email, subject, body, attachmentsUSA

Source-system integrations (data ingestion)

Sub-ProcessorPurposeData processedLocation
ShopifySource of merchant store data (orders, customers, products, webhooks)OAuth token, store data synced per merchant authorisationGlobal (Shopify’s own infrastructure)
Meta (Graph API)Read-only pull of merchant’s own ad campaign performance dataOAuth token, campaign metadata, ad performance metrics (aggregate, no customer data)USA
Google (Analytics Data API, Search Console API, Sheets API)Read-only pull of merchant’s GA4 / GSC / Sheets data (optional per merchant)OAuth token, aggregate session / search / spreadsheet dataUSA
Amazon Ads APIRead-only pull of merchant’s Amazon ad campaign performance (optional per merchant)OAuth token, campaign metadata, ad performance metricsUSA
Amazon Selling Partner API (SP-API)Read-only pull of merchant’s own Amazon Seller account business data — sales & traffic, financials, inventory, orders (optional per merchant)OAuth token, aggregate sales / traffic metrics, financial event amounts (settlements / fees / refunds), inventory levels, order records (product / quantity / price; no end-buyer personal data)USA
PostHogLegacy merchant analytics ingestion for orgs that installed PostHog before Ordinary’s pixelOAuth token, aggregate session dataUSA or EU per merchant’s PostHog region
KlaviyoRead-only pull of merchant’s own email + SMS campaign and flow performance data (optional per merchant)OAuth token, campaign / flow metadata, send metrics (recipients, opens, clicks, unsubscribes, bounces, attributed revenue)USA

Ad-platform forwarding (outbound, at merchant instruction)

These Sub-Processors receive hashed customer identifiers only, forwarded on the merchant’s explicit instruction via an OAuth-authorised connection to the merchant’s own ad account. Merchants can disconnect at any time via Settings → Integrations.

Sub-ProcessorPurposeData processedLocation
Meta Conversions APIServer-side purchase event forwarding to merchant’s own Meta ad accountSHA-256 hashed email / phone / first name / last name; purchase amount, currency, timestamp, event IDUSA
Google Enhanced Conversions (planned)Server-side conversion forwarding to merchant’s own Google Ads accountSHA-256 hashed user data; purchase amount, currency, timestampUSA

Billing and subscriptions

Sub-ProcessorPurposeData processedLocation
StripeSubscription billing for Ordinary’s own fees to merchantsMerchant billing contact, payment method (tokenised), subscription stateUSA

Ordinary’s own product analytics (internal)

Sub-ProcessorPurposeData processedLocation
PostHog (our instance)Product analytics on Ordinary’s own application usage by authorised merchant usersAuthorised-user events (page views, clicks within Ordinary), pseudonymous user IDUSA

Note: this is Ordinary’s own product-analytics instance, separate from any merchant’s PostHog integration. It collects behaviour of merchant administrators inside the Ordinary dashboard, not their customers’ behaviour on their storefronts.


Data transfer mechanisms

For transfers of Personal Data from the EEA / UK / Switzerland to the US or other third countries:

Merchants subject to EU/UK/Swiss data-protection law may request a signed copy of the SCCs via privacy@tryordinary.com.


Change log

DateChange
2026-04-20Initial launch list published
2026-06-09Listed the Amazon Selling Partner API (SP-API) as a distinct data-ingestion entry, alongside the existing Amazon Ads API. Same vendor (Amazon) and region (USA); read-only ingest of the merchant’s own Amazon Seller business data (sales & traffic, financials, inventory, orders) with no end-buyer personal data.