Subprocessors
Last updated August 16, 2026
This page lists the third parties that Ready for Commerce, Inc. ("Ready for Commerce," "we," "us," or "our") engages to process Personal Data on behalf of our customers in connection with the Services — our authentication service, our account and billing service, the PIM product, and the Repricer product. These third parties are our "Subprocessors."
This page is the current list referred to in Section 6 and Annex III of our Data Processing Addendum (the "DPA") and is incorporated into it. Capitalized terms used here have the meanings given in the DPA. Our processing of personal information for which we are the controller — such as your account and billing information — is described in our Privacy Policy.
Current Subprocessors
Each Subprocessor is engaged under a written contract imposing data-protection and security obligations no less protective than those in our DPA, and each is authorized to process Customer Personal Data only to perform the function described below. Where an entry states that a provider does not receive Customer Personal Data, it is listed for completeness and transparency rather than because Applicable Data Protection Law requires it.
- Supabase (Supabase Pte. Ltd.) — managed database, object storage, and encrypted secret-vault hosting for the platform and both products, and the store behind our centralized authentication. United States (us-east-1).
- Vercel (Vercel Inc.) — application and web hosting for the authentication service, the account and billing service, the PIM, the Repricer, and our marketing website. United States (us-east-1).
- Railway (Railway Corp.) — hosting for the background workers that run catalog synchronization, imports and exports, market-data collection, and automated pricing. United States (US East).
- Stripe (Stripe, Inc.) — payment processing, subscription management, and payment fraud prevention for direct subscriptions. United States and other countries.
- Shopify (Shopify Inc.) — App Store billing for subscriptions acquired through Shopify, the Shopify sales-channel integration, and the Shopify single-sign-on bridge. Canada and the United States.
- Resend (Resend, Inc.) — transactional email delivery, including sign-in codes, security notifications, billing notices, operational alerts, and messages sent through our contact form. United States.
- PostHog (PostHog, Inc.) — product analytics, error tracking, masked session replay, and application and worker logs. United States.
- Google (Google LLC) — Google sign-in and Google One Tap, when a user chooses to authenticate with a Google account. United States and other countries.
- Cloudflare (Cloudflare, Inc.) — bot mitigation on our authentication service (Cloudflare Turnstile) and DNS for our domains. United States and other countries.
- fal.ai (fal — Features & Labels, Inc.) — hosted artificial-intelligence image processing for the PIM's image optimizer: upscaling, background removal, and subject segmentation. It receives the product image a user chooses to transform and the parameters of the requested operation, and returns a transformed image that it hosts for a limited period so the interface can load it. No account, authentication, or billing data is sent. United States.
- OpenAI (OpenAI, L.L.C.) — artificial-intelligence extraction of pricing information from the external web pages a Customer directs the Repricer to monitor, from the page's text or from a screenshot of it, when the free structured-data parsers cannot read the price. It receives the content of those external pages, not Customer account data, and data submitted through its API is not used to train its models. United States.
- IPRoyal (IPRoyal Services FZE LLC) — residential-proxy and web-unblocking infrastructure used to retrieve those same external competitor pages when a direct request is blocked. It receives the addresses of the pages a Customer asked us to monitor and returns their content; no Customer account data is sent. United Arab Emirates, with retrieval infrastructure in many countries.
- Browserless (Browserless) — remote headless-browser rendering, the last-resort transport for the same external pages when a page cannot be read any other way. It receives the addresses of those pages and returns a rendered screenshot; no Customer account data is sent. United States.
- Sanity (Sanity AS) — content management for our public marketing website. It hosts our own published copy and does not receive Customer Personal Data. Norway and the United States.
- ExchangeRate-API — daily foreign-exchange reference rates used to convert amounts between currencies. We request only the published rate table; no Customer Personal Data and no Customer request data are sent. Varies.
Providers that support only part of the platform
Not every Subprocessor touches every product. In particular, the providers that support competitor monitoring — OpenAI, IPRoyal, and Browserless — are used only by the Repricer, and only for the external web pages a Customer has asked us to monitor. They never receive Customer account data, catalog data, or the contents of a Customer's connected channels. Likewise, fal.ai is used only by the PIM, and only when a user runs an artificial-intelligence image operation on a specific image.
Connected sales channels are not Subprocessors
When you connect a sales channel — such as Shopify, Amazon, Walmart, eBay, BigCommerce, Square, or Google Merchant Center — we exchange data with that channel at your direction and on your instructions, in order to provide the Services you asked for. Those channels are not our Subprocessors: they receive your data as your own providers or counterparties, under the account and the agreement you hold with them directly, and they process it under their own privacy practices. Shopify appears in the list above because it separately processes data for us as a billing and single-sign-on provider, which is a different role from its role as a channel you connect.
Notice of changes
We will provide notice of any intended addition or replacement of a Subprocessor at least thirty (30) days before the change takes effect, by updating this page and, where you have subscribed, by email. To subscribe to notifications of changes to this page, write to privacy@readyforcommerce.com with the subject "Subprocessor notifications" and the email address to notify.
If you have a reasonable, data-protection-based objection to a new Subprocessor, you may notify us within that notice period. The parties will work in good faith to resolve the objection, and if we cannot, you may terminate the affected Service as your sole remedy, as described in Section 6 of the DPA.
Where we must engage a Subprocessor on short notice to protect the security, availability, or lawful operation of the Services, we may do so before the notice period elapses and will notify you promptly afterward, together with the reason.
International transfers
Several Subprocessors process Personal Data outside the European Economic Area, the United Kingdom, and Switzerland. Where a Subprocessor is established in a country that has not received an adequacy decision, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another valid transfer mechanism, and we impose the onward-transfer obligations described in Section 11 of the DPA. This applies in particular to IPRoyal, which is established in the United Arab Emirates and contracts on the Standard Contractual Clauses.
Questions
For questions about this list, to request a copy of our DPA, or to raise a data-protection concern, write to privacy@readyforcommerce.com or use our contact page.