Subprocessors
Version 1.0
Last Updated: July 19, 2026
Purpose
This Subprocessors List identifies the third-party service providers that SetRoasFlow uses to operate and deliver the Services.
These providers may process Merchant Customer Data on behalf of SetRoasFlow solely for the purposes described in the Privacy Policy, Terms of Service and Data Processing Addendum.
This document does not include advertising platforms or other Destinations selected by Merchants. Those services receive data only when explicitly configured by the Merchant and are not considered subprocessors of SetRoasFlow.
Infrastructure Subprocessors
| Provider | Purpose | Categories of Data | Region |
|---|---|---|---|
| Cloudflare | Edge processing, Workers, networking, security, D1 database, Durable Objects | Event data, network metadata, operational logs, hashed identifiers where applicable | Global |
| Supabase | Application database, authentication, storage | Merchant account information, configuration, operational data | Region selected by SetRoasFlow |
Payment Providers
At the time of this publication, SetRoasFlow does not actively process subscription payments.
Should payment functionality become available, the relevant payment processor(s) will be added to this list before processing payment information.
Customer Support Providers
At the time of publication, no third-party customer support provider processes Merchant Customer Data on behalf of SetRoasFlow.
If future support tools are introduced, this list will be updated accordingly.
Analytics Providers
SetRoasFlow may use privacy-conscious analytics to understand usage of its own website and dashboard.
Such analytics are limited to SetRoasFlow's own services and are not used to analyze Merchant Customer Data unless expressly described in the Privacy Policy.
Merchant-selected Destinations
The following platforms are not subprocessors of SetRoasFlow.
They receive Merchant Customer Data only when:
- the Merchant enables the integration;
- the Merchant configures the Destination;
- the Merchant instructs SetRoasFlow to transmit data.
Examples include:
Advertising and analytics platforms (receive hashed identifiers only):
- Meta
- Google (Google Ads, Google Analytics 4)
- TikTok
- Snapchat
Marketing and CRM platforms (receive email addresses and telephone numbers in clear text, and only where consent permits):
- Klaviyo
- HubSpot
Merchant-operated data infrastructure (receives raw event records; personal data only where the Merchant explicitly enables it and consent permits):
- Google BigQuery
- Snowflake
- Amazon S3, Cloudflare R2 or other S3-compatible object storage
- An HTTP endpoint operated by the Merchant
The last category is distinct: the Merchant is exporting data to infrastructure the Merchant itself controls and contracts for. SetRoasFlow neither selects nor holds a relationship with those providers.
The Merchant remains responsible for determining the legal basis for transmitting data to these Destinations, for the location and safeguards of any transfer, and for reviewing each Destination's privacy practices.
Warehouse Export Buffer
Where a Merchant enables warehouse export, event records are held briefly by SetRoasFlow on Cloudflare infrastructure (already listed above as an infrastructure subprocessor) before being delivered in batches to the Merchant's destination.
This buffer is operational, not archival: records are deleted three days after delivery. See the Data Retention Policy.
Selection Criteria
Before engaging a subprocessor, SetRoasFlow evaluates factors including:
- security practices;
- reliability;
- privacy commitments;
- contractual safeguards;
- technical capabilities;
- regulatory compliance where applicable.
Changes to Subprocessors
SetRoasFlow may update this list as its infrastructure evolves.
Material additions or replacements of subprocessors that process Merchant Customer Data will be reflected in this document.
Contact
Questions regarding subprocessors may be directed to:
Operator
Matteo De Giuseppe
Italy
Version History
| Version | Date | Description |
|---|---|---|
| 1.0.0 | July 19, 2026 | Initial publication. |
End of Subprocessors List