Subprocessor List
Crossdock — Square↔Shopify integration. Last updated 2026-07-09 (v2).
The vendors below process limited categories of merchant data on Crossdock’s behalf under the data-protection clauses of our Data Processing Addendum (DPA). The list is exhaustive for v2; additions trigger a 30-day notice to merchants in the embedded admin AND an updated version of this page, in the same commit.
| Vendor | Purpose | Jurisdiction | Data categories | DPA reference |
|---|---|---|---|---|
| Shopify, Inc. | App platform; merchant authentication; Admin GraphQL | Canada (data centers per Shopify’s own subprocessor disclosure) | Shop domain, merchant email, shop-scoped IDs (products, variants, inventory, orders, customers — IDs only) | https://www.shopify.com/legal/dpa |
| Square, Inc. (Block, Inc.) | POS data API; OAuth tokens; catalog + inventory + order webhooks | United States | Square merchant ID, OAuth access/refresh tokens (encrypted at rest), catalog object IDs, inventory counts, order line-item IDs | https://squareup.com/help/us/en/article/5092-data-processing-addendum |
| Render Services, Inc. | Web service hosting; scheduled jobs; build pipeline | United States | All Crossdock application traffic at rest in container memory + on the request path | https://render.com/security |
| Neon Inc. | Managed PostgreSQL hosting (crossdock-prod and dev branches) | United States | All persisted Crossdock data — see Privacy Policy for the table-by-table data inventory | https://neon.tech/dpa |
| Upstash, Inc. | Managed Redis hosting (BullMQ queues, echo-suppression cache) | United States (region pinned to us-east) | Queue payloads (shop, correlationId, work-tuple IDs — no PII), echo cache keys + content hashes (no PII) | https://upstash.com/static/trust/dpa.pdf |
| Cloudflare, Inc. | DNS for crossdock.app, Cloudflare Tunnel for dev, Cloudflare R2 for off-platform backups, Email Routing for support@ and security@ | United States (R2 is globally distributed; tunnel + DNS + email are at-edge) | DNS query metadata, dev tunnel traffic, encrypted backup ciphertext, support + security inbound email | https://www.cloudflare.com/cloudflare-customer-dpa/ |
| Plus Five Five, Inc. (Resend) | Outbound transactional email delivery for legal notices (terms/DPA amendment and sub-processor change notifications) | United States (operates on Amazon Web Services / Amazon SES in us-east-1) | Merchant shop-owner / notification email address; notice message content | https://resend.com/legal/dpa |
| Functional Software, Inc. (Sentry) | Error + performance telemetry; stack traces | United States | Stack traces, error messages, request IDs, app environment metadata — personal data redacted before error telemetry leaves Crossdock’s systems | https://sentry.io/legal/dpa/ |
| GitHub, Inc. (Microsoft) | Source code hosting; CI workflows; secret-scan validation | United States | Source code (no production secrets); CI build artifacts; Actions logs | https://github.com/customer-terms/github-data-protection-agreement |
| Crisp IM SARL (France) | Merchant-support live chat for crossdock.app — planned, not yet live (pre-listed ahead of the Phase 7.5 chat-widget launch) | European Union (messaging in the Netherlands, plugin data in Germany, on DigitalOcean’s EU subsidiary; vendor states no transfer outside the EU) | Merchant-support chat transcripts and the shop owner’s contact details, plus visitor session identifiers — applicable only once the chat widget is live | https://help.crisp.chat/en/article/where-do-i-find-my-gdpr-data-processing-agreement-dpa-1wfmngo/ |
Crossdock does not engage any subprocessor in the categories of advertising, behavioral analytics, marketing automation, customer data platforms (CDPs), or email marketing service providers (ESPs). The customer-support vendor listed above is pre-listed ahead of a planned live-chat feature and is not yet live; no merchant data is processed by it until that feature ships. Should Crossdock engage a subprocessor in any additional category in the future, it will be added to the table above in the same commit that integrates it, and merchants will be notified per the 30-day notice procedure described in the Privacy Policy.
Related documents
Related documents: Privacy Policy, Cookie Disclosure.
For data-subject access and erasure requests, the Shopify-managed GDPR webhook flow (customers/data_request, customers/redact, shop/redact) is the canonical mechanism. This list is the supporting disclosure of which entities receive that data en route.