Skip to main content
Vendor Due DiligenceEffective: September 6, 2026 • GDPR Art. 28 Compliant

Third-Party Subprocessor Directory

In accordance with GDPR Article 28, UK-GDPR, and CCPA/CPRA requirements, this register details all external service providers and infrastructure partners authorized to process data on behalf of MeritSKU Inc.

Subprocessor Governance & Security Standards

Binding DPAs & SCCs

Every provider is bound by an executed Data Processing Agreement incorporating European Standard Contractual Clauses.

No AI Model Training

Enterprise terms with OpenAI, Anthropic, and Google Vertex AI explicitly mandate Zero Data Retention (ZDR) and zero foundation model training.

30-Day Advance Notice

Enterprise subscribers receive 30 days written notice before onboarding any new subprocessor, with the right to object.

Authorized Subprocessors (6)

● Actively Monitored & Audited
Subprocessor & EntityTechnical RoleData Elements ProcessedLocationTransfer Safeguards
Google Cloud Platform
Google LLC
Primary cloud hosting, virtual compute engines, Cloud Tasks async job orchestration, Cloud Storage object storage, Secret Manager, Cloud LoggingEncrypted application database backups, async task payloads, server execution logs, container metricsUnited States (us-central1 / Iowa)EU SCCs / SOC 1, 2, 3 / ISO 27001
Neon Database
Neon Database Inc.
Managed serverless PostgreSQL primary database cluster with tenant Row-Level Security (RLS)Workspace records, user profiles, candidate products, supplier quotations, encrypted Shopify OAuth credentials (AES-256-GCM), immutable audit logsUnited States (AWS us-east-1 / Northern Virginia)DPA with SCCs / SOC 2 Type II
Stripe
Stripe Payments Company
Payment processing gateway, subscription tier billing (Builder, Operator, Enterprise), billing portal, tax calculations, webhook event deliveryCustomer billing name, email address, billing address, payment token identifiers, invoice recordsUnited StatesPCI-DSS Level 1 / SOC 1, 2 / DPA with SCCs
Shopify
Shopify Inc. / Shopify International Ltd.
E-commerce platform integration, merchant OAuth 2.0 authorization, unpublished draft product creation via Admin GraphQL, inventory reading, webhook deliveryMerchant store domain ({shop}.myshopify.com), draft product titles, feature descriptions, candidate tags, SKU numbersUnited States & CanadaShopify API Agreement / DPA / SOC 2 Type II
AI Model Providers
OpenAI, LLC / Anthropic, PBC / Google Vertex AI
Large Language Model (LLM) providers for unstructured product metadata extraction, evidence synthesis, and marketing feature bullet generationPublicly available product descriptions, feature claims, customer feedback text snippets. Strictly zero customer PII or financial credentials.United StatesEnterprise DPA with Zero Data Retention & No Model Training
PostHog
PostHog, Inc.
Product analytics, user interaction telemetry, application performance monitoring, and UX health diagnosticsAnonymized user interaction events, browser version, page navigation telemetry (PII masking strictly enabled)United States & European UnionDPA with SCCs / SOC 2 Type II