Datacrow Sub-processors
Last updated: June 28, 2026
This page lists the sub-processors that Datacrow engages to provide the service. We notify merchants at least 30 days before adding or replacing a sub-processor, and merchants have the right to object as set out in our Data Processing Agreement.
How to read this list
Sub-processors fall into three groups:
- Destination APIs — third parties that receive event data forwarded at the merchant's direction. Each is only used when the merchant enables the corresponding destination in Datacrow. A merchant who only enables Klaviyo, for example, will not have their data sent to Meta or Google.
- Infrastructure — providers we use to host the application, store data, queue jobs, and ship logs. Used for every merchant.
- Operational — providers we use internally for billing, email, support, and observability. Not all are always engaged.
1. Destination API sub-processors
Engaged only when the corresponding destination is enabled by the merchant.
| Sub-processor | Function | Data shared | Geographic location | Privacy policy |
|---|---|---|---|---|
| Meta Platforms, Inc. | Meta Conversions API destination — forwards conversion events for ads attribution | Hashed email, hashed phone, hashed customer ID, raw IP + user-agent, event metadata, commerce data | United States | https://www.facebook.com/privacy/policy |
| Google LLC | Google Analytics 4 Measurement Protocol — forwards events for analytics reporting | Pseudonymous client ID, hashed customer ID (when present), event metadata, commerce data | United States (with global processing) | https://policies.google.com/privacy |
| Google LLC | Google Ads Enhanced Conversions / Customer Match — forwards conversion data for ads attribution | Hashed email, hashed phone, hashed first/last name, hashed address, gclid, gbraid, wbraid | United States (with global processing) | https://policies.google.com/privacy |
| Klaviyo, Inc. | Klaviyo Events API — forwards events for email/SMS marketing flows | Email, phone, customer ID, event metadata, commerce data (unhashed per Klaviyo's spec — Klaviyo is the customer engagement system and requires plaintext identifiers to match profiles) | United States | https://www.klaviyo.com/legal/privacy-notice |
| TikTok Pte. Ltd. / ByteDance | TikTok Events API — forwards conversion events for ads attribution | Hashed email, hashed phone, raw IP + user-agent, ttclid, event metadata, commerce data | United States and Singapore | https://www.tiktok.com/legal/page/global/privacy-policy/en |
| Pinterest, Inc. | Pinterest Conversions API — forwards conversion events for ads attribution | Hashed email, hashed phone, hashed external ID, raw IP + user-agent, event metadata, commerce data | United States | https://policy.pinterest.com/en/privacy-policy |
2. Infrastructure sub-processors
Used for every merchant.
| Sub-processor | Function | Data stored/processed | Geographic location | Privacy policy |
|---|---|---|---|---|
| Railway Corp. | Application hosting (compute) | All application code and runtime data | United States (US-West, Oregon) | https://railway.app/legal/privacy |
| Railway-managed PostgreSQL | Primary database — stores canonical events, delivery logs, merchant config, encrypted credentials | All data we collect (see Privacy Policy §3–§5) | United States (same region as application) | Same as Railway |
| Railway-managed Redis | Queue + ephemeral cache — BullMQ job state, identity dedup cache, OAuth bridge state | Canonical event payloads in transit (≤7 days), short-lived state tokens | United States (same region as application) | Same as Railway |
| Vercel, Inc. | Marketing + legal website hosting (www.datacrow.app) | Public web pages only; standard request logs (IP, user-agent). No merchant or shopper account data. | United States | https://vercel.com/legal/privacy-policy |
3. Operational sub-processors
Used internally; engagement depends on configuration.
| Sub-processor | Function | Data shared | Geographic location | Privacy policy |
|---|---|---|---|---|
| Shopify Inc. | App distribution + billing (charges merchants on our behalf) | Merchant identifiers, subscription state, billing history (no shopper data) | Canada and United States | https://www.shopify.com/legal/privacy |
| Axiom, Co. | Log aggregation and observability | Operational logs (filtered to exclude shopper PII); contains merchant IDs, error messages, request IDs | United States | https://axiom.co/privacy |
| Resend.com, Inc. | Transactional email delivery (e.g., billing notifications, security alerts to merchants) | Merchant email address, message content | United States | https://resend.com/legal/privacy-policy |
| Google LLC (Google Workspace) | Business email — receives correspondence sent to our support / privacy aliases | Merchant email address + message content | United States | https://policies.google.com/privacy |
| GitHub, Inc. | Source code hosting + CI | No production shopper data; contains code that processes shopper data | United States | https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement |
| Anthropic / OpenAI (if and when engaged) | We do not currently use any AI/LLM provider to process merchant or shopper data. This row is included to commit publicly: if we ever do, it will be opt-in only and disclosed here 30 days in advance. | N/A | N/A | N/A |
Notes on cross-border transfers
For merchants located in the European Economic Area, the United Kingdom, or Switzerland, data is transferred to the United States and processed there. We rely on the EU Standard Contractual Clauses (2021/914) Module 2 (Controller-to-Processor) and the UK International Data Transfer Addendum (IDTA) as the lawful basis for these transfers. These are incorporated by reference into our Data Processing Agreement.
Sub-processors that have certified under the EU-US Data Privacy Framework (DPF) — including Meta and Google — provide an additional transfer mechanism. We do not currently rely on DPF certification ourselves; Datacrow as a US indie operates under the SCCs directly.
Change log
| Date | Change |
|---|---|
| June 26, 2026 | Initial published list |
| June 28, 2026 | Corrected infrastructure list — removed Cloudflare (not used); added Vercel (website hosting) and Google Workspace (business email) |
Last reviewed by Milo on June 28, 2026. Material changes are emailed to active merchants and reflected here within 24 hours.