ShopShift .

§ 06 · Legal

Subprocessors.

Last updated · 2026-05-07

ShopShift uses the third-party services below to deliver the platform. Each vendor receives only the data needed for its specific role, under a data-processing agreement that requires confidentiality and security commitments at least as strict as our own.

We will give existing Customers at least thirty (30) days' notice via the dashboard and email before adding a new subprocessor that processes Customer or Visitor data, so you have time to object or terminate before the change takes effect.

Hosting

Hetzner Online GmbH

Germany (EU)

Server hosting — application servers, PostgreSQL database, Redis. All Customer and Visitor data stored at rest is hosted on Hetzner infrastructure in the EU.

CDN

Bunny Network

Slovenia (EU)

Snippet delivery via global CDN with edge caching. Receives request metadata for the snippet bootstrap call but does not process Visitor behavior events.

AI inference

OpenAI, L.L.C.

United States

AI inference — generating experiment proposals, profiling shops, classifying URL parameters, answering Shop Chat queries. Receives only the data needed for the specific call (a page DOM snippet, a profile excerpt, a chat message). Transfers governed by EU Standard Contractual Clauses.

Billing

Stripe, Inc.

Ireland (EU) / United States

Payment processing for Customer subscriptions. Stripe is the controller for payment-card data; ShopShift never sees full card numbers.

Error tracking

Rollbar, Inc.

United States

Error monitoring for the Rails application and the snippet. Receives error stack traces and request context. We strip Visitor and Customer PII from error payloads before transmission where feasible.

Geolocation

MaxMind, Inc.

United States (data file)

GeoLite2 IP-to-country lookup. The MaxMind database file is bundled into our deployment; no Visitor IPs are sent to MaxMind. Listed for completeness of the data-flow disclosure.

International transfers.

Subprocessors located outside the EU/EEA (notably OpenAI and Rollbar) process data under the EU Standard Contractual Clauses or other lawful transfer mechanisms. Where a subprocessor offers EU data residency we use it (Stripe is contracted via its EU entity, Stripe Payments Europe Limited).

Notification of changes.

We update this page whenever a subprocessor is added, removed, or changes scope. The "Last updated" date at the top reflects the most recent change. To receive direct email notice of subprocessor changes, write to privacy@shopshift.io and we will add you to the notification list.

Contact.

Questions about subprocessors, DPA requests, security questionnaires: privacy@shopshift.io . ShopShift is operated by SVEA IT (CVR 36606061), Denmark.