Legal
Sub-processors
Effective date: 4 August 2026 - Last updated: 4 August 2026
A sub-processor is a company we use that can see personal data we process for you. Under Article 28 of the GDPR we have to name them, and under our Data Processing Agreement we have to tell you before the list changes. This page is that list.
1. The 14 day notice commitment
Before we add or replace a sub-processor, we update this page and notify merchants at least 14 days before the change takes effect. Notice goes to the store contact address Shopify gives us.
If you object on reasonable data protection grounds within those 14 days, write to support@primemoq.app. If we cannot resolve it, you may uninstall and terminate without penalty and we will delete your data under section 10 of the DPA. Removing a sub-processor does not require notice, since it only narrows who can see your data.
Each entry is bound by a written contract with data protection obligations no less protective than the ones in our DPA, and we stay liable to you for what they do.
2. Sub-processors for the app
These see data from inside a merchant's Shopify store. Rows marked in the placeholder style are facts about our own infrastructure that we are not willing to state until they are confirmed, rather than assumptions dressed up as answers.
| Sub-processor | Purpose | Data processed | Location | Their terms |
|---|---|---|---|---|
| Shopify Inc. | The platform the app runs on. Shopify hosts the store, delivers the webhooks we act on and runs the checkout function that enforces a rule. | Store and staff account details, order data, customer identifiers and tags. | Canada, with global infrastructure | Shopify DPA |
| {{VERIFY: which company hosts the Prime MOQ application servers, the PostgreSQL database, the MongoDB database and the Redis queue, and in which country}} | Application hosting and the databases behind api.primemoq.app. The deploy pipeline builds a container and releases it to a self-managed Dokku host, so this is not a named platform we can read out of the code. | Everything the app stores: shop and owner contact details, rule configuration, order records including shopper email addresses, and Shopify customer identifiers. | {{VERIFY: country and region of the application and database hosts}} | Not published |
| {{VERIFY: the SMTP provider configured as MAIL_HOST for the app backend}} | Transactional email from the app itself: install and uninstall notices, the weekly digest, and the export sent in response to a customer data request. | Merchant contact email addresses, and the contents of a data request export. | {{VERIFY: processing location of the backend email provider}} | Not published |
| n8n | Receives an internal event when a store installs, uninstalls or changes plan, so the team sees it without polling the database. | Shop name, shop domain, Shopify plan and Prime MOQ plan. No shopper data. | {{VERIFY: whether this is n8n Cloud or a self-hosted instance, and where it runs}} | n8n DPA |
3. Sub-processors for the website
These see data from primemoq.app: waitlist signups, support messages and website analytics. For this processing Aspedan is the controller, not a processor, so these are service providers rather than sub-processors in the Article 28 sense. They are listed here anyway, because a reader wants one page rather than two.
| Sub-processor | Purpose | Data processed | Location | Their terms |
|---|---|---|---|---|
| Cloudflare, Inc. | Hosting, edge delivery and TLS termination for primemoq.app. | Request metadata handled in transit: IP address, user agent, requested URL. Plus anything you type into a form on its way to us. | United States, served from a global edge network | Cloudflare DPA |
| Supabase, Inc. | The database behind the waitlist, the support form, the blog and the help centre, and the authentication for our own admin area. | Waitlist email addresses and the page they signed up from, support messages and the email address that sent them. | {{VERIFY: the region the Supabase project is provisioned in}} | Supabase DPA |
| Resend | Sends the waitlist confirmation and delivers support messages to our inbox. | Email address, and the message you sent us. | United States | Resend DPA |
| Google LLC | Google Analytics 4 (property G-PLL34CRS31), loaded only after you accept analytics cookies, and Google Fonts, which serves the typeface this site is set in. | Analytics: cookie identifier, page views, referrer, approximate location, device and browser. Fonts: IP address and user agent, at the moment the font file is requested. | United States, with global infrastructure | Google Ads Data Processing Terms |
| Lovable | The platform this site is built and published from. It holds the source and runs the deployment. | No visitor data by design. It holds the application source, which contains no personal data. | {{VERIFY: Lovable's processing location and whether a DPA is in place with them}} | Lovable privacy terms |
4. Who is not on this list
Named here so their absence is a statement rather than an oversight:
- GitLab Inc. holds our built container images. Those images contain application code and no personal data, so GitLab is not a sub-processor.
- No advertising, attribution or customer data platform. We run none.
- No support desk, chat widget or session replay tool. Support arrives by email and is answered by email.
- No AI provider. Your data is not sent to any model provider, and it is not used to train anything.
5. Contact
Questions about a sub-processor, or a request for a copy of the terms we hold with one:
Aspedan Inc.
325 Front St West, Suite 300, Toronto, ON M5V 2Y1, Canada
support@primemoq.app
Questions
A person reads every message, on any plan. If something on this page is unclear, or you want to exercise a right described in it, write to us and say so plainly.