Digitdeck uses the following providers to operate the Service. Processing depends on enabled features and configuration; a provider does not necessarily receive every category for every store.
| Provider | Purpose | Potential data | Location/transfer note |
|---|---|---|---|
| Shopify | Platform APIs, authentication, billing, webhooks, storefront extensions | Store, catalog, order, customer, billing and app data | Shopify-selected infrastructure and terms |
| Render Services, Inc. | Application and worker hosting, runtime logs | Encrypted application traffic, identifiers, operational logs | Configured production region; cross-border safeguards as required |
| Neon, Inc. | Managed PostgreSQL database | Tenant configuration and module records, encrypted tokens, customer-linked records | Configured cloud region; cross-border safeguards as required |
| Upstash, Inc. | Redis, queues, rate limiting, job coordination | Job payload identifiers, limited module events, rate-limit keys | Configured database region; cross-border safeguards as required |
| Resend, Inc. | Transactional email delivery | Recipient email, sender, subject/template content, delivery events | United States/global delivery infrastructure |
| OpenAI, L.L.C. | Optional merchant-initiated AI generation | Prompt, brand context, selected store context, generated output, usage | United States and provider infrastructure; only when AI is used |
| Google LLC | Business email and support collaboration | Support correspondence and user-supplied attachments | Global infrastructure under Google Workspace/consumer account terms |
| GitHub, Inc. | Source control and deployment workflow | Application source and CI metadata; no intended Merchant production data | United States/global infrastructure |
Changes and objections
Digitdeck will update this list before a new provider materially processes Customer Data and will provide reasonable notice through the app, email, or this page. A Merchant may object on documented data-protection grounds within fifteen days under the DPA.
Provider requirements
Subprocessors must process data only to provide contracted services, maintain confidentiality and security, notify Digitdeck of relevant incidents, assist with rights and deletion, and comply with applicable transfer requirements. Provider-specific certifications and privacy terms are available from the provider or upon reasonable request.