subprocessors

Subprocessors

The third parties that process data on Loyal's behalf, what each one does, and how we tell you when the list changes.

Last updated 14 August 2026 Applies to loyalapp.com and the Loyal Shopify app

On this page

  1. What a subprocessor is
  2. How we choose and manage subprocessors
  3. Current subprocessors
  4. Who is not a subprocessor
  5. How we notify changes
  6. How to object
  7. Subscribe to updates
  8. Contact

How to read this. This page is the authoritative list referred to in section 9 of the Privacy Policy and section 9 and Annex 3 of the Data Processing Addendum. It tells you every company that can touch merchant or subscriber data on our behalf. If a company is not on this page, it does not process your data for us.

1. What a subprocessor is

A subprocessor is a third party service provider we engage to process personal data on our behalf in order to provide Loyal. That includes the companies that host our servers, store our databases and backups, deliver our email, run our support desk and monitor our systems for errors.

Every subprocessor is bound by a written contract that limits it to the processing we instruct, prohibits it from using data for its own purposes, requires security measures no less protective than ours, and flows down the obligations in our Data Processing Addendum. We remain responsible to you for anything a subprocessor does with your data.

2. How we choose and manage subprocessors

Before we engage a subprocessor we review its security practices, its privacy terms, its certifications, the location where it will process data and the transfer mechanism that will apply. We engage the fewest subprocessors we can, give each one the least data it needs, and review the list at least once a year and whenever we change a vendor.

Where a subprocessor is outside the United Kingdom, European Economic Area or Switzerland and processes data from those places, the transfer relies on an adequacy decision where one exists, and otherwise on the Standard Contractual Clauses and the UK Addendum, as described in section 10 of the Privacy Policy and section 11 of the Data Processing Addendum.

3. Current subprocessors

The table shows each subprocessor, the service it provides to us, the categories of data it may process, and the location of processing.

Data categories used in the table. Merchant Data means information about the merchant, its staff and its account, as defined in section 4.1 of the Privacy Policy. Subscriber Data means personal data about a merchant's subscribers, as defined in sections 4.2 to 4.4 of the Privacy Policy. Website Data means information about visitors to loyalapp.com, as defined in section 4.5.

Subprocessor Service provided Data categories Location of processing
[Cloud hosting provider] Application hosting, compute, networking and object storage for the Loyal app and its backups Merchant Data, Subscriber Data [Region, e.g. United States (us-east-1)]
[Database provider, if separate from hosting] Managed database hosting and encrypted backups Merchant Data, Subscriber Data [Region]
[Transactional email provider] Delivery of service notifications from Loyal to merchants, and subscriber notifications a merchant enables Merchant Data, Subscriber Data (name, email address, subscription details in the notification) [Country]
[Support desk provider] Hosting support conversations and attachments Merchant Data, and any Subscriber Data a merchant includes in a support request [Country]
[Error monitoring provider] Capturing application errors and performance data Merchant Data (store domain, request metadata); Subscriber Data only where it appears in an error payload, which we redact where possible [Country]
[Product analytics provider] Recording feature usage in the app so we can improve it Merchant Data (store domain, staff identifier, actions taken). No Subscriber Data. [Country]
[Website analytics provider] Aggregated analytics for loyalapp.com Website Data [Country]
[Marketing email or CRM provider] Sending business to business marketing to merchants and to people who request information Merchant Data (name, work email, company, engagement). No Subscriber Data. [Country]
[AI model provider, if any feature uses a third party model] Generating suggestions for features described in section 23 of the Privacy Policy Only the input the feature needs, as described in the Privacy Policy. Not used for training. [Country]

Decision needed before publishing. Replace every bracketed row with the real vendor, and delete any row that does not apply. Do not publish a placeholder, and do not publish a vendor that is not actually contracted. The list must match the Data Processing Addendum, the Security page and the Cookie Policy. Three specific points to check: (1) whether error monitoring can receive subscriber fields in stack traces, and if so, whether redaction is switched on; (2) whether any AI feature sends data to a third party model provider, because section 23 of the Privacy Policy makes a commitment about that; (3) whether every listed vendor has signed a data processing agreement and, where it is outside the UK, EEA or Switzerland, whether the transfer mechanism named here is in place. Competitors list between 5 and 12 subprocessors. A short accurate list reads better to a merchant's security reviewer than a long vague one.

4. Who is not a subprocessor

The following organisations may receive data in connection with Loyal but are not our subprocessors, because they process data under their own agreement with the merchant rather than on our instructions.

  • Shopify. The Loyal app runs on and depends on the Shopify platform. Shopify processes merchant and subscriber data under its own privacy policy and its agreement with the merchant, and executes charges against payment mandates it holds.
  • Payment gateways. Where a merchant uses its own gateway, that gateway processes payment data under the merchant's agreement with it.
  • Integrations the merchant connects. Klaviyo, Gorgias, Weglot, Shopify Flow and any other tool a merchant chooses to connect receive data at the merchant's instruction and under the merchant's agreement with that provider.
  • A previous subscription provider. Where a merchant asks us to perform a migration, the export comes from the merchant or its previous provider under the merchant's own agreement with them.
  • Professional advisers and authorities. Lawyers, auditors, accountants, insurers and public authorities who may receive data as described in section 9 of the Privacy Policy are recipients, not subprocessors.

5. How we notify changes

We give at least 30 days notice before we add or replace a subprocessor that will process Subscriber Data. Notice is given by updating this page and by email to the address on your Loyal account. The notice identifies the new subprocessor, the service it will provide, the data it will process and the location of processing.

We may remove a subprocessor at any time without notice, and will update this page when we do.

For subprocessors that process only Merchant Data or Website Data, we update this page and do not send a separate email, unless the change is material.

6. How to object

If you have a reasonable objection to a new subprocessor on data protection grounds, email support@slashcart.com within the 30 day notice period with "Subprocessor objection" in the subject line and explain the grounds. We will work with you in good faith to resolve it. If we cannot resolve it within 30 days of your objection, you may terminate the affected part of the service by uninstalling the app, and we will refund any prepaid fees for the unused period. Section 9.4 of the Data Processing Addendum sets out this process in full.

7. Subscribe to updates

To receive an email whenever this page changes, send a message to support@slashcart.com with "Subscribe to subprocessor updates" in the subject line, from the address you want notified. You can unsubscribe the same way.

Decision needed before publishing. If a mailing list or form is set up for this, replace the paragraph above with the sign up link. If not, keep the email approach, but make sure someone actually maintains the recipient list, because the 30 day notice commitment in section 5 depends on it.

8. Contact

SlashCart Inc. 131 Continental Drive, Suite 305 Newark, DE 19713 United States

All enquiries, including subprocessor questions and objections: support@slashcart.com

This page should be read together with our Privacy Policy, Terms of Service, Data Processing Addendum and Cookie Policy, which together form the agreement governing use of Loyal.