Service Providers, Subprocessors, and Connected Platforms
Last reviewed: August 5, 2026
This register identifies external organizations that help deliver eshopOS or that a merchant may choose to connect. It is a transparency register, not an internal infrastructure map.
An organization's role can differ by product, country, and processing activity. Inclusion does not by itself mean that the organization is an affiliate, an eshopOS subprocessor, or an endorsed commercial partner.
Relationship definitions
| Relationship | Meaning in this register |
|---|---|
| Operator or affiliate | A legal entity that operates eshopOS or a related legal entity that participates in delivering the service. Product and brand names are not separate affiliates. |
| Subprocessor | A provider engaged by eshopOS to process personal data on behalf of a merchant for service delivery. |
| Financial provider | A payment, banking, payout, or mobile-money provider whose legal role may include processor, independent controller, regulated provider, or a combination depending on the workflow. |
| Connected platform | An external platform that a merchant deliberately authorizes eshopOS to access. A connected platform does not become an eshopOS subprocessor merely because the merchant connects it. |
| Supporting service provider | A provider that supports platform operations or reference data but does not necessarily process merchant customer data as a subprocessor. |
Operator and affiliated entities
| Organization | Role | Purpose | Data involved | Service region |
|---|---|---|---|---|
| Osarian Solutions | eshopOS operator | Operates the product, contracts for services, administers accounts, and handles support and legal requests | Account, business, support, billing, and operational data | United States / service jurisdictions |
eshopOS is a product operated by Osarian Solutions and is not a separate legal entity. Any separate Osarian-affiliated legal entity that begins processing eshopOS personal data will be added to this register based on the applicable corporate and processing records.
Core and optional subprocessors
| Provider | Purpose | Data that may be processed | Availability | Processing region |
|---|---|---|---|---|
| Contabo GmbH | Production application and database hosting | Platform, merchant, storefront, customer, order, and operational data | Core | European Union |
| Cloudflare, Inc. | DNS, content delivery, edge security, routing, object storage, backups, and configured AI or media features | Network metadata, content, uploaded media, domain configuration, and feature inputs when the relevant service is enabled | Core infrastructure; optional AI features | Global |
| Kinde | Identity, authentication, and account access | Account identifiers, email, authentication events, roles, and session metadata | Core | Global |
| Resend | Transactional and authorized lifecycle email delivery | Recipient details, email content, delivery events, and suppression status | Core | Global |
| Sentry | Error and performance monitoring | Filtered diagnostics, request metadata, release information, and error context | Optional; used only when configured | Global |
| Africa's Talking | Rider authentication and operational SMS delivery | Phone number, message content, delivery metadata, and OTP event metadata | Optional and region dependent | Africa / provider-supported regions |
| Google AI services | AI generation or fallback processing for enabled product and media workflows | Prompts, product context, and media supplied to the enabled feature | Optional; used only when configured | Global |
Cloudflare may appear once in this table even though separate Cloudflare products support different functions. The enabled product and its data path determine the applicable processing role.
Payment and financial providers
| Provider | Purpose | Data that may be processed | Availability | Service region |
|---|---|---|---|---|
| Stripe | Platform billing, supported merchant payments, connected accounts, verification, and payout-related workflows | Business, account, customer, transaction, verification, and payment metadata required by the selected Stripe service | Country and product dependent | Stripe-supported regions |
| Paystack Payments Limited | Platform billing, merchant payments, verification, subaccount, and transfer-related workflows | Business, account, customer, transaction, verification, and settlement metadata | Country and product dependent | Paystack-supported African markets |
| Safaricom PLC / M-Pesa | Mobile-money payment and payout rails where enabled | Mobile number, account reference, transaction, payment, and settlement metadata | Optional and region dependent | Kenya and supported M-Pesa services |
These providers may process some information under their own legal obligations, including payment regulation, identity verification, fraud prevention, dispute handling, and record retention. Their own terms and privacy notices apply to those activities.
Merchant-enabled connected platforms
| Platform | Connection purpose | Data authorized by the current connector | Connection method | Availability |
|---|---|---|---|---|
| Shopify | Merchant-authorized catalog and inventory migration into eshopOS | Products, collections, variants, media, locations, and inventory levels; the current connector does not request Shopify customer data | OAuth | Optional |
| BigCommerce | Merchant-authorized catalog, category, warehouse, and inventory migration | Products, categories, variants, product images, inventory locations, and stock levels; current scope does not import customers or orders | OAuth or merchant-provided store API credentials | Optional |
| Squarespace | Merchant-authorized commerce catalog migration | Products, slugs, descriptions, tags, variants, prices, stock quantities, visibility, and product image URLs; current scope does not import customers or orders | Merchant-provided read-only API key | Optional |
| Meta Platforms / WhatsApp | Merchant-enabled messaging, checkout handoff, and direct-order communication | Merchant and customer contact details, message content, order context, and delivery events when the feature is enabled | Merchant-enabled integration | Optional |
| Shippo | Merchant-enabled carrier rates, labels, tracking, and shipping workflows | Shipment addresses, contacts, package details, carrier selections, labels, and tracking events | OAuth or merchant configuration | Optional |
Connected platforms remain subject to the merchant's authorization, the provider's terms, and the scopes shown during setup. Disconnecting a platform ends future connector access but does not automatically delete records already imported into eshopOS.
Supporting and reference services
| Provider or service | Purpose | Data intended for the service | Availability |
|---|---|---|---|
| GitHub, Inc. | Source control, release workflows, and deployment automation | Source, build, release, and deployment metadata; merchant customer data is not intended for this service | Core operational provider |
| Komoot Photon | Shipping and location search | Search text and optional geographic bias coordinates used to return location candidates | Active location-search dependency |
| Frankfurter, Open ER API, ExchangeRate-API, Currency API reference datasets, FloatRates, and exchangerate.host | Foreign-exchange reference rates and provider failover | Currency codes, requested rate pairs, and technical request metadata; account and customer data is not intended for these requests | Provider rotation and fallback |
Reference-rate results are operational estimates. They are not guaranteed bank, card-network, or settlement rates.
Change notices
eshopOS reviews this register when a provider is added, removed, or materially changes its role. Merchants may request provider-change notices using their account email.
Where a data-processing agreement provides a right to object to a new subprocessor, the applicable agreement and notice period control.
Controlled trust materials
Architecture summaries, data-flow evidence, security questionnaires, continuity materials, audit evidence, and similar due-diligence documents are not published in this register. Eligible organizations can request a trust and security review.
Scope and security boundary
This register does not disclose internal hostnames, network addresses, storage bucket names, deployment runner names, private endpoints, credentials, software versions, security rules, contract values, or private configuration.