Skip to main content

Legal

Sub-processors

Every third party that receives any data through SupershopOS, what they get, and why. This is the list the Privacy Policy refers to.

What a sub-processor is

A sub-processor is a company that processes data on our behalf so a feature can work — sending an SMS, taking a payment, delivering an email. They act on our instructions only, for the purpose named in the table, and they may not use the data for their own purposes. Each is bound by contract to protect it to the standard our Privacy Policy sets.

The list

WhoWhat forWhat they receiveProcessed inWhen
Cloudflare, Inc.Application hosting, database, file storage, edge caching, and the bot challenge shown on sign-in and sign-up forms.All service data, processed on our behalf. The bot challenge additionally processes your IP address and browser signals; it does not profile you across other sites.Global edge networkAlways — this is our infrastructure
ResendDelivering transactional email: address verification, sign-in links, receipts, and account notices.Recipient email address and the contents of that message.United StatesWhen we send you email
SSL WirelessDelivering transactional SMS: one-time codes and the alerts your account has switched on.Recipient mobile number and the text of that message.BangladeshWhen an SMS is actually sent to you or to a customer who consented
bKash · Nagad · SSLCommerzCollecting a payment you or your customer chose to make.The amount, a transaction reference, and the payer details the provider needs to complete the charge (for example the mobile-wallet number). We receive the result of the transaction, not your full card number.BangladeshOnly when your account enables that payment method
OpenAIAnswering the questions you put to the optional ChatGPT assistant. Once you connect it, ChatGPT signs in as you and reads the records an answer needs — stock, sales, purchasing, expenses, an invoice you name, or a customer you name.Whatever the question you asked requires. That is business data in most cases — products, stock, purchases, sales and expense figures. Ask about one invoice and it receives that invoice line by line: every item on it, the quantity and unit, the prices, and the name and phone number of the customer it was rung up to. Ask about a named customer and it receives their contact details, what they owe and the items they usually buy. The answer is delivered inside your own ChatGPT account, so what happens to that conversation afterwards — including whether OpenAI may use it to improve their models — is governed by OpenAI's terms and by your own ChatGPT data controls, not by us. We send OpenAI nothing on our own initiative.United States and globallyOnly if you connect the optional ChatGPT assistant yourself. Disconnecting it in Settings → Connected apps ends the connection — normally within seconds, and in every case once the access token already issued expires, at most an hour later
AnthropicAnswering the questions you put to the optional Claude assistant. Once you connect it, Claude signs in as you and reads the records an answer needs — stock, sales, purchasing, expenses, an invoice you name, or a customer you name.Whatever the question you asked requires. That is business data in most cases — products, stock, purchases, sales and expense figures. Ask about one invoice and it receives that invoice line by line: every item on it, the quantity and unit, the prices, and the name and phone number of the customer it was rung up to. Ask about a named customer and it receives their contact details, what they owe and the items they usually buy. The answer is delivered inside your own Claude account, so what happens to that conversation afterwards — including whether Anthropic may use it to improve their models — is governed by Anthropic's terms and by your own Claude data controls, not by us. We send Anthropic nothing on our own initiative.United States and globallyOnly if you connect the optional Claude assistant yourself. Disconnecting it in Settings → Connected apps ends the connection — normally within seconds, and in every case once the access token already issued expires, at most an hour later
Mistral AIReading a photographed supplier invoice into a draft goods receipt, when the first attempt on our own infrastructure could not read it.The photograph of that one supplier invoice, and nothing else. That image contains the supplier's name and the invoice's own contents — the products, quantities, batch numbers and the trade prices your shop pays. No customer data, no stock levels, no other records. Extraction normally runs on Cloudflare, our own infrastructure, and never reaches Mistral at all; this happens only for an invoice that path could not read.European UnionOnly if you turn on external AI invoice reading in Settings, and only for an invoice photo our own infrastructure could not read. It is off unless you switch it on
TelegramSending the owner alerts and support replies you asked to receive on Telegram instead of by SMS.The chat identifier you link, and the text of the alert or support message.Outside BangladeshOnly if you link a Telegram chat yourself
GoogleTwo separate, optional features: signing in with a Google account, and playing the in-app help videos, which are hosted on YouTube.For sign-in: your Google account identifier and email. For a help video: your IP address, device and playback information reach Google as they would on any page with an embedded YouTube player. We send no account, business, or customer data to either feature.GlobalOnly if you choose Google sign-in, or open a help video
AppleSigning in with an Apple account.Your Apple account identifier, and the email address — or the private relay address — you choose to share.GlobalOnly if you choose Sign in with Apple

The two assistant rows above are the only optional ones you switch on yourself. What the assistant can read, what it can change, and what it will never do are documented in full: How the Claude connector works

Categories we deliberately have none of

The absence of a row matters as much as the presence of one, so we state it plainly:

  • No advertising network, ad SDK, or ad identifier — the apps contain none.
  • No third-party analytics or product-telemetry vendor. Usage counts are computed by our own server from your own data.
  • No third-party crash-reporting service. Crash diagnostics are stored in our own database on our own infrastructure.
  • No data broker, no marketing list, and no sale of personal data — under any circumstance.

How we choose and review them

  • We add a sub-processor only when a feature cannot work without it, and only for that feature.
  • The optional ones stay off until you switch them on. If you never enable payments, no payment provider ever sees your data.
  • We review the list whenever we ship a change that adds an outbound integration — the same change adds the row, or it does not merge.
  • We do not use sub-processors for advertising, analytics, or crash reporting; those run on our own infrastructure or not at all.

Changes to this list

We will update this page before a new sub-processor starts receiving data, and tell account owners by email when the change affects a feature they use. If you object to a new sub-processor, reply to that email — for optional features you can simply leave them switched off. Questions: privacy@supershop.work.

Back to the Privacy Policy