Last Updated: 22 August 2026
This page lists the third-party sub-processors that Automated Commerce B.V. uses to deliver the Service. Sub-processors act on our instructions and are bound by data-protection obligations consistent with the GDPR and our Privacy Policy.
We notify Customers of new sub-processors (or replacements) at least 30 days in advance through this page and through in-Service notice or email. If you have signed our Data Processing Agreement, you have the right to object to a new sub-processor on data-protection grounds, as set out in the DPA.
Where a sub-processor is established outside the European Economic Area (EEA), we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented by appropriate technical and organisational safeguards. Transfer Impact Assessments are available on request.
For participating merchant storefronts, Automated Commerce acts as the merchant's processor for consented behavioral analytics and attribution. The merchant remains responsible for the legal basis and the consent message shown on its storefront.
After analytics consent, the storefront may send page views, product and cart interactions, checkout events, campaign parameters, timestamps, page and referrer URLs, and related product, cart, checkout, or order references. Requests use https://collect.automatedcommerce.ai/v1/collect or an exact merchant-owned proxy approved for that storefront. The AC collector and the separately operated Umami tracker remain blocked before consent.
The data can include pseudonymous visitor, session, consent, event, and commerce identifiers. On an approved headless storefront using the exact-origin collector, the collector may set the HttpOnly first-party ac_vid cookie after consent. It expires after at most 400 days. Other storefront modes do not receive ac_vid. Identifiers are used to deduplicate events, connect consented interactions, reconcile Shopify orders and refunds, and calculate descriptive attribution. They are not used to guess a person-level link when the evidence is missing.
Accepted raw envelopes are temporarily stored in Cloudflare R2. Canonical events, permitted identity links, touches, journeys, and attribution outputs are stored in our self-hosted ClickHouse analytics environment on Hetzner infrastructure in Germany. Cloudflare D1 stores bounded consent, delivery, and privacy-workflow evidence. Neon PostgreSQL stores tenant configuration, approvals, and operational references. Destinations for advertising remain off unless separately approved.
Retention is approved per merchant and purpose. Raw events, canonical behavioral events, identity links, journeys and touches, consent state, delivery evidence, privacy receipts, and non-identifying aggregates can therefore have different periods. Personal derived data inherits the earliest applicable source expiry. Automated expiry and bounded cleanup apply across R2, ClickHouse, and D1. We do not present one raw-event period as the retention period for every store.
Withdrawing analytics consent stops later browser telemetry and new analytics identity use. A shopper can also request access or erasure through the merchant, or contact us where Automated Commerce is the controller. Verified erasure covers the applicable R2, ClickHouse, identity, consent, delivery, cache, and pending-job records. Separately permitted operational order records may remain where the merchant has a documented legal or contractual reason.
The processors used for this flow are Cloudflare for edge collection, queues, R2, D1, and secure connectivity; Hetzner for the self-hosted Umami, PostHog, Kafka, PostgreSQL, and ClickHouse analytics stack; and Neon for the main PostgreSQL control records. Umami, PostHog, and ClickHouse are self-hosted software in this flow, not cloud subprocessors that receive the data on their own account. See the current subprocessor list.
Voor deelnemende webwinkels verwerkt Automated Commerce analytics- en attributiegegevens in opdracht van de winkelier. De winkelier blijft verantwoordelijk voor de rechtsgrond en de toestemmingsmelding in de webwinkel.
Na toestemming voor analytics kan de webwinkel paginaweergaven, product- en winkelwageninteracties, checkoutgebeurtenissen, campagneparameters, tijdstippen, pagina- en verwijzende URL's en bijbehorende product-, winkelwagen-, checkout- of orderreferenties versturen. Verzoeken gaan naar https://collect.automatedcommerce.ai/v1/collect of naar een voor die webwinkel goedgekeurde proxy op het eigen domein. De AC-collector en de afzonderlijk werkende Umami-tracker blijven vóór toestemming geblokkeerd.
De gegevens kunnen pseudonieme bezoeker-, sessie-, toestemming-, gebeurtenis- en commerce-identificatoren bevatten. Bij een goedgekeurde headless webwinkel met de collector op hetzelfde domein kan de collector na toestemming de HttpOnly first-party cookie ac_vid plaatsen. Deze verloopt uiterlijk na 400 dagen. In andere storefrontmodi wordt ac_vid niet geplaatst. De identificatoren worden gebruikt om dubbele gebeurtenissen te voorkomen, toegestane interacties te verbinden, Shopify-orders en terugbetalingen te controleren en beschrijvende attributie te berekenen. Bij ontbrekend bewijs raden wij geen persoonskoppeling.
Geaccepteerde ruwe berichten worden tijdelijk opgeslagen in Cloudflare R2. Canonieke gebeurtenissen, toegestane identiteitskoppelingen, touchpoints, klantreizen en attributieresultaten worden opgeslagen in onze zelf beheerde ClickHouse-analyseomgeving op infrastructuur van Hetzner in Duitsland. Cloudflare D1 bevat begrensd bewijs over toestemming, levering en privacyprocessen. Neon PostgreSQL bevat tenantconfiguratie, goedkeuringen en operationele referenties. Advertentiebestemmingen blijven uitgeschakeld zonder afzonderlijke goedkeuring.
De bewaartermijn wordt per winkelier en doel goedgekeurd. Ruwe gebeurtenissen, canonieke gedragsgebeurtenissen, identiteitskoppelingen, klantreizen en touchpoints, toestemmingsstatus, leveringsbewijs, privacybewijzen en niet-identificerende aggregaten kunnen daarom verschillende termijnen hebben. Afgeleide persoonsgegevens erven de vroegste toepasselijke vervaldatum van de bron. Automatische verwijdering en begrensde opschoning gelden voor R2, ClickHouse en D1. Eén termijn voor ruwe gebeurtenissen wordt niet voorgesteld als bewaartermijn voor alle opslag.
Na intrekking van analytics-toestemming stopt latere browsertelemetrie en nieuw gebruik van de analytics-identiteit. Een bezoeker kan ook via de winkelier om inzage of verwijdering vragen, of rechtstreeks contact met ons opnemen wanneer Automated Commerce verwerkingsverantwoordelijke is. Geverifieerde verwijdering omvat de toepasselijke gegevens in R2, ClickHouse, identiteit, toestemming, levering, caches en wachtende taken. Afzonderlijk toegestane operationele ordergegevens kunnen blijven bestaan wanneer de winkelier daarvoor een vastgelegde wettelijke of contractuele grond heeft.
Voor deze gegevensstroom gebruiken wij Cloudflare voor edge-collectie, wachtrijen, R2, D1 en beveiligde verbindingen; Hetzner voor de zelf beheerde Umami-, PostHog-, Kafka-, PostgreSQL- en ClickHouse-analysestack; en Neon voor de belangrijkste PostgreSQL-controledata. Umami, PostHog en ClickHouse zijn in deze stroom zelf beheerde software en geen cloudsubverwerkers die de gegevens voor eigen rekening ontvangen. Bekijk de actuele lijst met subverwerkers.
| Sub-processor | Purpose | Region | Data categories |
|---|---|---|---|
| Cloudflare, Inc. (US, EU subsidiary) | Workers, R2 object storage, Queues, D1, Hyperdrive, KV, and secure tunnels | Globally distributed edge; EU edges available | Customer Content and accepted analytics events in transit and at rest; consent, delivery, privacy-workflow, and service-usage records |
| Neon Inc. (managed PostgreSQL on AWS) | Primary application database | AWS eu-central-1 (Frankfurt, Germany) | Account data, billing records, Customer Content, tenant analytics configuration, approvals, and audit logs |
| Hetzner Online GmbH | Dedicated infrastructure for our self-hosted Umami, PostHog, Kafka, PostgreSQL, Redis, and ClickHouse analytics stack | Germany (EEA) | Consented storefront events, pseudonymous identifiers, order and refund references, channel and campaign data, and derived analytics outputs |
| Vercel Inc. | Frontend hosting (Next.js apps), edge functions | Global edge network with EU regions | Service usage logs, request data |
Some AI providers may, under their default terms, retain or use the data we send them — including Customer Content — for the improvement and training of their own models. Where a provider offers a no-training option we use it where commercially reasonable. See Section 5 of our Privacy Policy for detail.
| Sub-processor | Purpose | Region | Data categories |
|---|---|---|---|
| FAL AI | Image-related AI generation (e.g. studio shots, edits) | Outside EEA — SCCs in place | Image URLs and prompts derived from Customer Content |
| OpenRouter, Inc. | Text-generation routing across underlying language models | Outside EEA — SCCs in place | Product titles, descriptions, prompt context |
| PhotoRoom | Studio-shot image generation and background removal | Outside EEA — SCCs in place | Image URLs derived from Customer Content |
| Tripo AI | 3D model generation | Outside EEA — SCCs in place | Image URLs and prompts derived from Customer Content |
| Sub-processor | Purpose | Region | Data categories |
|---|---|---|---|
| Mollie B.V. | Subscription payment processing | Netherlands (EEA) | Billing data, payment metadata (no full card numbers) |
| Moneybird B.V. | Accounting and invoicing | Netherlands (EEA) | Account and contact data, invoice records |
| Trigger.dev | Background-job orchestration | EEA-aligned cloud regions | Customer Content during job execution; job metadata |
| Resend Inc. | Transactional and notification email delivery | Outside EEA — SCCs in place | Email addresses, message content for service emails |
| Twenty (Twenty CRM) | Customer relationship management — sales pipeline, lead and account tracking, customer-success operations | Self-hosted on EEA infrastructure | Account contact data, sales prospect data, customer-success interaction notes |
| Apify Technologies s.r.o. | Public-web data extraction in import flows | EEA | Public-web URLs supplied by Customer; extracted public data |
| Sanity.io | Content management for the marketing site | EEA / US — SCCs where applicable | Marketing-site content (no Customer Content) |
| Vercel Web Analytics | Cookieless marketing-site analytics | Global edge network with EU regions | Aggregated request data; no cookies, no cross-site identifiers |
When a Customer connects a third-party platform to the Service (Shopify, Google Ads, Meta, Pinterest, marketplaces, and similar), those platforms remain independent controllers in respect of any data they collect on their own account. They are not our sub-processors. Customer's use of those platforms is governed by the respective platforms' terms.
Questions about this list, or requests for our DPA, Transfer Impact Assessments, or further information can be sent to business@automatedcommerce.ai.
Recevez les dernières analyses de l'industrie de l'IA et les mises à jour sur les nouvelles fonctionnalités de la plateforme