Subprocessors — MatchAudit for Shopify
Effective date: August 27, 2026
This page identifies the subprocessors MatchAudit uses to provide MatchAudit for Shopify where they may process Shop Data on MatchAudit's behalf. A provider is used only for the stated purpose and subject to contractual confidentiality, security, purpose-limitation, and data-protection obligations.
| Subprocessor | Purpose and data | Primary location / transfer position | Use |
|---|---|---|---|
| Fly.io, Inc. | Runs the App web service and background worker. May process encrypted-in-transit Shopify requests, session data, operational logs, and the minimum Shop Data needed to serve a request. | App machines are configured for Frankfurt, Germany. Fly.io and its infrastructure/support subprocessors may process limited data in other countries under its DPA and applicable transfer safeguards. | Required |
| Supabase, Inc. | Dedicated PostgreSQL database and private object storage for encrypted customer identity fields, screening records, decisions, job metadata, evidence records, and private exports. | The MatchAudit Shopify project is configured for an EU region. Supabase subprocessors may provide infrastructure, backup, security, or support under its DPA and applicable transfer safeguards. | Required |
| OpenAI Ireland Ltd. | Optional AI-assisted case explanations. The current payload is designed to exclude Shopify customer names, street addresses, order IDs, and customer IDs; it may contain country, derived match information, and public sanctions-source data. API content is not used for model training by default. Provider abuse-monitoring retention may apply unless MatchAudit's account is approved for stricter retention controls. | EEA contracting/processing entity with international transfers governed by OpenAI's DPA, including Standard Contractual Clauses where applicable. | Conditional — only when an Authorized User requests or uses an AI-assisted feature |
Shopify is the Merchant's commerce platform and the source of the Shop Data and verified staff session. MatchAudit sends fulfillment-hold, tag, Flow, and billing instructions back to Shopify at the Merchant's direction. Shopify is therefore identified as an independent platform recipient rather than a subprocessor appointed by MatchAudit.
MatchAudit does not use a separate authentication provider for the App. Merchant and staff identity is verified using Shopify's session-token and OAuth mechanisms.
Changes and objections
MatchAudit may update this list when a provider changes. MatchAudit will provide reasonable advance notice of a materially new subprocessor through the App, the Merchant's Shopify contact address, or this page. A Merchant may object on documented data-protection grounds as described in the Data Processing Addendum. If no reasonable alternative is available, either party may terminate the affected processor service to the extent required by applicable law.
Transfer safeguards
Where personal data is transferred outside the EEA without an adequacy decision, MatchAudit uses an applicable transfer mechanism, such as the European Commission's Standard Contractual Clauses, and supplementary measures where required. A provider's published region describes primary hosting and does not mean that support, security, routing, or backup access can never occur elsewhere.