Subprocessors

DaDeveloper LLC. Version 2026-09-09. Effective 2026-09-10.

1. What this list is

1.1 A "Subprocessor" is a company we use to host, store, transmit or process data inside the Service on behalf of Shops and their Shoppers. Section 2 lists every Subprocessor as of the version date. Section 2A lists the business tools that receive what you send us directly (email to our mailboxes, demo requests, and signed Order Forms). "Service", "Shop", "Shopper" and "we" have the meanings given on our Legal notices page at daclerk.com/legal.

1.2 The Merchant Terms refer to this page as the Subprocessor List. The Merchant Terms govern our responsibility for Subprocessors and the notice and objection rights summarised in section 4: we choose them, we remain responsible to the Shop for our own obligations, and we are not responsible for a Subprocessor's downtime or for the output of a third-party model beyond what the Merchant Terms say. If this page and the Merchant Terms differ, the Merchant Terms control. Each Subprocessor processes data under its own published terms, or under a data-processing agreement with us where one is in place; we do not publish or warrant those terms, and this page states what the Model Providers' terms say about retention and training.

1.3 The locations and retention periods on this page are the position as of the version date at the top. Some are set by the provider and some by us. Where a provider does not publish a figure for what we use, this page says what we can state rather than an estimate.

1.4 Where this page states how long backup copies are kept, that is the rolling cycle the Merchant Terms refer to in section 15.4.

2. Current Subprocessors

2.1 OpenRouter selects which of its hosting providers serves a model; those providers act under OpenRouter's terms and are covered by the OpenRouter row. We send every request with OpenRouter's no-data-collection instruction, which limits routing to endpoints that do not store prompts for their own purposes; beyond that we do not pin a host. A change of hosting provider inside OpenRouter's pool is not a new Subprocessor under section 4.

SubprocessorWhat it does for the ServiceData it receivesLocation
VercelHosts the storefronts, shop admin, daclerk.com and the API; runs the request proxy and serverless functions; serves the CDNAll web traffic in transit: IP address, request headers, cookies, and request bodies (chat messages, order and customer form entries). Runtime error logs (short error lines; the app logs no prompts or replies)Functions run in San Francisco, US (region sfo1). CDN edge is global. Vercel keeps runtime logs only for the short window its plan limits allow — Vercel publishes 1 hour on Hobby and 1 day on Pro, extended to up to 30 days only where its Observability Plus add-on is bought. We keep no copy of those logs ourselves
Supabase (on Amazon Web Services)Primary database; sign-in by email one-time code or magic link; live order updates to Shop staff devices; daily database backupsCustomer records (email, name, phone, address, verification flag and who set it and when, preferences, and free-text staff notes written or imported by the Shop, which can include the Shop's record of an ID check (date of birth, ID number) and other details the Shop chose to keep); orders and order items; chat transcripts; login accounts; rate-limit keys that include the Shopper's IP address; staff records; shop settings and product catalogue. The daily database backups hold a copy of the same data and are retained for 7 days: Supabase keeps the last 7 days of daily backups on our planAWS us-west-1 (Northern California, US)
Cloudflare (R2 object storage)Stores product images and shop logos: a public bucket served through Cloudflare's CDN, and a private bucket for restricted-product images served only through short-lived signed links. Holds our nightly backup bucketImage files (no personal data). The backup bucket holds a nightly full copy of the database: customer, order, login and chat-transcript data, including the staff notes described in the Supabase row. Backups are kept for 30 days: a lifecycle rule on the backup bucket deletes each nightly dump 30 days after it is writtenCloudflare R2. The backup bucket is in Cloudflare's Western North America region; the two image buckets are in the United States/North America region chosen when they were created
OpenRouterAI gateway. Routes each chat request to the language models belowPer chat request: the shop's facts and its own AI instructions; for a signed-in Shopper, their name, whether a phone is on file (yes or no, never the number), their verification status, their preferences text, and the items on up to three recent orders; the last 10 Shopper messages in the conversation; catalogue search results and cart contents. We do not add the Shopper's email address, phone number, street address, staff notes, IP address or cookies from the Shop's records to any request. Anything a Shopper types into the chat is sent to the model as typed, including any contact details or delivery address the Shopper chooses to giveUnited States. OpenRouter states it does not train on inputs or outputs and does not log prompts by default. Providers that train on paid requests are switched off on our account, and each request is sent with OpenRouter's no-data-collection flag
Google — Gemini 2.5 Flash (primary model, via OpenRouter)Generates the AI clerk's repliesSame as the OpenRouter rowGoogle. OpenRouter lists this model as served by Google through the endpoints it names for it: Google AI Studio (the Gemini Developer API) and Google Vertex AI. The no-data-collection instruction in section 2.1 excludes any endpoint that would retain the request. Where served through the Gemini Developer API, Google's published terms for its paid Gemini API state that prompts and responses are not used to train Google's models and may be kept for up to 55 days for abuse monitoring.
OpenRouter's chosen host — Llama 3.3 70B Instruct (fallback model, via OpenRouter)Generates replies only when the primary model failsSame as the OpenRouter rowOpenRouter selects the host for this model from the providers it lists for it — on the version date: DeepInfra, Nebius, Novita, AkashML, Parasail, Crusoe, Cloudflare, SambaNova, Groq, CoreWeave, Google and Together AI. We do not pin one, so we do not state a single country for it; the no-data-collection instruction in section 2.1 rules out any of them that would retain the request. Meta itself receives no data unless OpenRouter picks Meta as the host
ResendSends our transactional email from daclerk.comSign-in emails: the Shopper's email address and the one-time code or link. Owner PIN-recovery emails: the owner's email, shop name and code. Demo requests from daclerk.com: shop name, contact name, phone, and any email or note givenUnited States: Resend states that its primary processing operations take place in the United States. It keeps email content and metadata, delivery events and logs for 30 days on its standard plans, which is the kind of plan we are on
GitHub (GitHub Actions)Runs the nightly backup job that copies the database to the Cloudflare backup bucketThe full nightly database dump (customer, order, login and chat-transcript data) passes through a GitHub-hosted runner during the jobGitHub-hosted Ubuntu runner. GitHub publishes that these runners run on Microsoft Azure but does not publish a region for the standard runner sizes, so we do not state one. The runner holds the dump only for the minutes the job takes and keeps nothing after it

2A. Business tools that receive what you send us

These are not part of the Service; they receive only what you send to us directly.

ToolWhat it doesData it receivesLocation
Zoho (Zoho Mail)Hosts our business mailboxes: legal@, privacy@, dmca@, support@ and info@daclerk.comWhatever you send to those mailboxes, including privacy requests and legal noticesUnited States: our Zoho organisation is on Zoho's US data centre (zoho.com)
Zoho (Zoho Sign)E-signature of Order Forms with ShopsThe Shop's legal entity and address, the signer's name, email and IP address, and the signed documentUnited States: the same Zoho organisation and data centre as the row above
Google (Gmail)Receives demo requests from daclerk.com until they are moved to a daclerk.com mailboxShop name, contact name, phone, and any email or note given in a demo requestGoogle LLC, United States. Google does not publish which data centre holds a given mailbox, so we state only that the provider and the account are United States-based

3. What we do not use

3.1 No analytics, advertising, session-replay or error-monitoring scripts load on daclerk.com or on any store. No ad pixels. We do not track Shoppers across other websites.

3.2 Google Maps appears only as a link built from the Shop's own address; nothing is sent to Google Maps unless a Shopper taps it. Fonts are served from our own hosting.

3.3 A Google Sheets order feed exists in the software but is not enabled in production and receives no data. If a Shop asks us to enable it, Google will be added to this list first, with notice under section 4.

3.4 We do not sell or share Shop or Shopper data with anyone for advertising, and we do not use it to train AI models.

4. Changes to this list

Section 4 summarises the Merchant Terms' subprocessor-change clause (section 16.2). The Merchant Terms control.

4.1 We update this page before we add or replace a Subprocessor. Shops receive at least 30 days' notice by email to the notice address stated in the Shop's Order Form, or to a replacement address the Shop has given us in writing, before a new Subprocessor that will hold Shop or Shopper data receives any of it.

4.2 If a Shop has a reasonable data-protection objection, it should tell us at legal@daclerk.com within the notice period. If we cannot resolve the objection, the Shop may terminate before the change takes effect, with no notice period, as the Merchant Terms provide.

4.3 If a Subprocessor fails, is compromised, or stops offering its service, we may replace it sooner than 30 days to keep the Service running and secure. We give notice as soon as practicable, and the objection right in 4.2 still applies.

4.4 Removing a Subprocessor, or reducing the data a Subprocessor receives, needs no notice; this page is updated when it happens.

5. Change log

DateChange
2026-09-09First published list.

Questions about this list: privacy@daclerk.com.

Book a demo

Leave your number and we will call you.