Core application subprocessors
Platform and business-service providers
The providers above may use their own subprocessors. Their linked notices and DPAs
describe those providers, locations, safeguards, and change-notification procedures.
Documentation Index
Fetch the complete documentation index at: /llms.txt
Use this file to discover all available pages before exploring further.
Third parties that help Account Canvas provide, secure, and support the Service.
| Provider | Purpose | Information involved | Processing and transfer notes |
|---|---|---|---|
| Railway Corporation | Application infrastructure, deployment, networking, PostgreSQL database hosting, backups, and operational logs | Merchant configuration; encrypted Shopify session tokens; encrypted workflow submissions; customer, order, and line-item identifiers; plan records; minimized analytics; sanitized operational records | Account Canvas uses a selected Railway deployment region. Railway’s DPA includes transfer terms and describes encryption, backups, access controls, and its current subprocessors. |
| Plus Five Five, Inc. (Resend) | Transactional email delivery to merchants | Merchant recipient email, shop reference, workflow title, submission reference, delivery and security metadata. Customer answers and customer/order identifiers are intentionally excluded from workflow notification content. | Resend’s DPA includes applicable EU Standard Contractual Clauses and subprocessor terms. |
| Functional Software, Inc. (Sentry) | Error and performance monitoring | Sanitized error, trace, browser, route, and operational metadata; a pseudonymous tenant reference when needed for troubleshooting | Account Canvas disables default PII collection, Session Replay, and SDK log forwarding for launch and applies event sanitizers. Processing region and transfers depend on the Account Canvas Sentry account and Sentry’s DPA and subprocessor terms. |
| Provider | Role and purpose | Information involved |
|---|---|---|
| Shopify Inc. | Commerce platform, app distribution and authentication, customer accounts, APIs, billing, and privacy webhooks. Shopify’s role is governed by its own agreements and can differ by service. | Shopify merchant, staff, store, product, file, customer, order, store-credit, metafield, subscription, and webhook information used for enabled Account Canvas features. |
| Mintlify, Inc. | Public documentation and legal-page hosting | Documentation visitor IP address, browser/device data, request and security logs, and cookies or similar data used by the hosted documentation service. |
| GoDaddy.com, LLC and applicable affiliates | Domain, DNS, and current marketing-website hosting | Website visitor IP address, browser/device data, request logs, security data, and website cookies or similar technologies. Domain-registration contact information is handled under the applicable GoDaddy agreement. |
| Zoho Corporation and applicable affiliates | Business email used for support, privacy, security, and account communications | Sender and recipient details, message content, attachments, routing data, and email security metadata. |