Back to home
Authorised Sub-Processors

Version 1.0 — Effective date: 26 May 2026

This page lists the third-party sub-processors that may process personal data on behalf of VivaShelf as part of delivering the Service, the role each plays, the regions in which processing occurs, and the legal mechanism relied upon for any international transfer. We notify Customers at least 30 days in advance of any change to this list via in-app banner and email; Customers may object on reasonable data-protection grounds.

Sub-processorPurposeRegionTransfer mechanism
Supabase, Inc.Managed PostgreSQL database hostingEU (Frankfurt) primary; US fallbackSCCs (Decision 2021/914) + encryption.
Vercel, Inc.Application hosting, edge network, CDNEU (fra1, cdg1) primary; global edgeSCCs + EU-U.S. Data Privacy Framework.
Resend, Inc.Transactional email deliveryUnited StatesSCCs + DPF.
Google LLCGoogle Identity OAuth (opt-in sign-in)United StatesDPF + SCCs.
Upstash, Inc.Redis rate-limiting and ephemeral cachingEU region preferred; US fallbackSCCs.
Functional Software, Inc. d/b/a SentryError and performance monitoring (no session replay)United StatesSCCs + DPF.
Google / Apple / Mozilla push servicesWeb-push delivery endpoints (encrypted payload only)GlobalContacted only when push is enabled by the user; only encrypted payload + endpoint identifier exchanged.
Cloudflare, Inc.Origin shield, DDoS protection, bot mitigationGlobal anycastSCCs + DPF.

If you wish to object to a sub-processor change, contact [email protected] within 30 days of notification. If we cannot offer a workable alternative, you may terminate the affected service with a pro-rata refund of prepaid fees.

Related: Data Processing Agreement, Privacy Policy.