> ## Documentation Index
> Fetch the complete documentation index at: https://docs.accountcanvas.app/llms.txt
> Use this file to discover all available pages before exploring further.

# Subprocessors

> Third parties that help Account Canvas provide, secure, and support the Service.

**Last updated: September 3, 2026**

This page identifies third parties used by Brandle & Co LLC, doing business as Account
Canvas, to provide and support the Account Canvas Shopify application, website, and
documentation. It should be read with our [Privacy Policy](/privacy) and
[Terms of Use](/terms).

For merchant customer data, "subprocessor" means a provider that processes personal
information on behalf of Account Canvas while Account Canvas acts as the merchant's
processor or service provider. Other providers below may instead act as independent
controllers or as service providers to Account Canvas for its own business operations.

## Core application subprocessors

| Provider                                                           | Purpose                                                                                                        | Information involved                                                                                                                                                                                                           | Processing and transfer notes                                                                                                                                                                                                                        |
| ------------------------------------------------------------------ | -------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| [Railway Corporation](https://railway.com/legal/dpa)               | Application infrastructure, deployment, networking, PostgreSQL database hosting, backups, and operational logs | Merchant configuration; encrypted Shopify session tokens; encrypted workflow submissions; customer, order, and line-item identifiers; plan records; minimized analytics; sanitized operational records                         | Account Canvas uses a selected Railway deployment region. Railway's DPA includes transfer terms and describes encryption, backups, access controls, and its current subprocessors.                                                                   |
| [Plus Five Five, Inc. (Resend)](https://resend.com/legal/dpa)      | Transactional email delivery to merchants                                                                      | Merchant recipient email, shop reference, workflow title, submission reference, delivery and security metadata. Customer answers and customer/order identifiers are intentionally excluded from workflow notification content. | Resend's DPA includes applicable EU Standard Contractual Clauses and subprocessor terms.                                                                                                                                                             |
| [Functional Software, Inc. (Sentry)](https://sentry.io/legal/dpa/) | Error and performance monitoring                                                                               | Sanitized error, trace, browser, route, and operational metadata; a pseudonymous tenant reference when needed for troubleshooting                                                                                              | Account Canvas disables default PII collection, Session Replay, and SDK log forwarding for launch and applies event sanitizers. Processing region and transfers depend on the Account Canvas Sentry account and Sentry's DPA and subprocessor terms. |

## Platform and business-service providers

| Provider                                                                                              | Role and purpose                                                                                                                                                                            | Information involved                                                                                                                                                                                                  |
| ----------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| [Shopify Inc.](https://www.shopify.com/legal/privacy)                                                 | Commerce platform, app distribution and authentication, customer accounts, APIs, billing, and privacy webhooks. Shopify's role is governed by its own agreements and can differ by service. | Shopify merchant, staff, store, product, file, customer, order, store-credit, metafield, subscription, and webhook information used for enabled Account Canvas features.                                              |
| [Mintlify, Inc.](https://www.mintlify.com/legal/privacy)                                              | Public documentation and legal-page hosting                                                                                                                                                 | Documentation visitor IP address, browser/device data, request and security logs, and cookies or similar data used by the hosted documentation service.                                                               |
| [GoDaddy.com, LLC and applicable affiliates](https://www.godaddy.com/legal/agreements/privacy-policy) | Domain, DNS, and current marketing-website hosting                                                                                                                                          | Website visitor IP address, browser/device data, request logs, security data, and website cookies or similar technologies. Domain-registration contact information is handled under the applicable GoDaddy agreement. |
| [Zoho Corporation and applicable affiliates](https://www.zoho.com/privacy.html)                       | Business email used for support, privacy, security, and account communications                                                                                                              | Sender and recipient details, message content, attachments, routing data, and email security metadata.                                                                                                                |

The providers above may use their own subprocessors. Their linked notices and DPAs
describe those providers, locations, safeguards, and change-notification procedures.

## Data-location and transfer approach

Account Canvas is operated from the United States. Providers may process information
in the United States and other countries. Where required, Account Canvas relies on an
applicable adequacy decision, the EU Standard Contractual Clauses, the UK Addendum or
International Data Transfer Agreement, the EU-U.S. Data Privacy Framework and related
extensions where valid and applicable, or another lawful mechanism. The precise
mechanism can depend on the merchant, provider, account region, and data flow.

Merchants with a data-residency or transfer requirement should contact us before using
the Service for affected data.

## Changes and objections

Merchants provide general authorization for the application subprocessors listed on
this page under the [data-processing terms](/terms#15-data-processing-addendum). We will
update this page before a new subprocessor begins materially different processing where
reasonably practicable and provide additional notice when required by contract or law.

A merchant may object to a new subprocessor on reasonable data-protection grounds by
emailing [support@accountcanvas.app](mailto:support@accountcanvas.app) within 15 days
after notice. We will work in good faith to address the concern. If a reasonable
alternative is unavailable, either party may end the affected Service, subject to
charges already incurred.

## Contact

Questions about providers, transfer mechanisms, or a data-processing agreement can be
sent to [support@accountcanvas.app](mailto:support@accountcanvas.app) or mailed to
Brandle & Co LLC, doing business as Account Canvas, 3211 Boulevard Place,
Indianapolis, Indiana 46208, United States. Do not send passwords, access tokens,
payment card information, or unredacted customer records by email.


## Related topics

- [Terms of Use](/terms.md)
- [Welcome to Account Canvas](/index.md)
- [Privacy Policy](/privacy.md)
- [Privacy and data](/privacy-and-data.md)
