Vendor Due DiligenceEffective: September 6, 2026 • GDPR Art. 28 Compliant
Third-Party Subprocessor Directory
In accordance with GDPR Article 28, UK-GDPR, and CCPA/CPRA requirements, this register details all external service providers and infrastructure partners authorized to process data on behalf of MeritSKU Inc.
Subprocessor Governance & Security Standards
Binding DPAs & SCCs
Every provider is bound by an executed Data Processing Agreement incorporating European Standard Contractual Clauses.
No AI Model Training
Enterprise terms with OpenAI, Anthropic, and Google Vertex AI explicitly mandate Zero Data Retention (ZDR) and zero foundation model training.
30-Day Advance Notice
Enterprise subscribers receive 30 days written notice before onboarding any new subprocessor, with the right to object.
Authorized Subprocessors (6)
● Actively Monitored & Audited| Subprocessor & Entity | Technical Role | Data Elements Processed | Location | Transfer Safeguards |
|---|---|---|---|---|
Google Cloud Platform Google LLC | Primary cloud hosting, virtual compute engines, Cloud Tasks async job orchestration, Cloud Storage object storage, Secret Manager, Cloud Logging | Encrypted application database backups, async task payloads, server execution logs, container metrics | United States (us-central1 / Iowa) | EU SCCs / SOC 1, 2, 3 / ISO 27001 |
Neon Database Neon Database Inc. | Managed serverless PostgreSQL primary database cluster with tenant Row-Level Security (RLS) | Workspace records, user profiles, candidate products, supplier quotations, encrypted Shopify OAuth credentials (AES-256-GCM), immutable audit logs | United States (AWS us-east-1 / Northern Virginia) | DPA with SCCs / SOC 2 Type II |
Stripe Stripe Payments Company | Payment processing gateway, subscription tier billing (Builder, Operator, Enterprise), billing portal, tax calculations, webhook event delivery | Customer billing name, email address, billing address, payment token identifiers, invoice records | United States | PCI-DSS Level 1 / SOC 1, 2 / DPA with SCCs |
Shopify Shopify Inc. / Shopify International Ltd. | E-commerce platform integration, merchant OAuth 2.0 authorization, unpublished draft product creation via Admin GraphQL, inventory reading, webhook delivery | Merchant store domain ({shop}.myshopify.com), draft product titles, feature descriptions, candidate tags, SKU numbers | United States & Canada | Shopify API Agreement / DPA / SOC 2 Type II |
AI Model Providers OpenAI, LLC / Anthropic, PBC / Google Vertex AI | Large Language Model (LLM) providers for unstructured product metadata extraction, evidence synthesis, and marketing feature bullet generation | Publicly available product descriptions, feature claims, customer feedback text snippets. Strictly zero customer PII or financial credentials. | United States | Enterprise DPA with Zero Data Retention & No Model Training |
PostHog PostHog, Inc. | Product analytics, user interaction telemetry, application performance monitoring, and UX health diagnostics | Anonymized user interaction events, browser version, page navigation telemetry (PII masking strictly enabled) | United States & European Union | DPA with SCCs / SOC 2 Type II |