Skip to main content

Service Providers, Subprocessors, and Connected Platforms

Last reviewed: August 5, 2026

This register identifies external organizations that help deliver eshopOS or that a merchant may choose to connect. It is a transparency register, not an internal infrastructure map.

An organization's role can differ by product, country, and processing activity. Inclusion does not by itself mean that the organization is an affiliate, an eshopOS subprocessor, or an endorsed commercial partner.

Relationship definitions

RelationshipMeaning in this register
Operator or affiliateA legal entity that operates eshopOS or a related legal entity that participates in delivering the service. Product and brand names are not separate affiliates.
SubprocessorA provider engaged by eshopOS to process personal data on behalf of a merchant for service delivery.
Financial providerA payment, banking, payout, or mobile-money provider whose legal role may include processor, independent controller, regulated provider, or a combination depending on the workflow.
Connected platformAn external platform that a merchant deliberately authorizes eshopOS to access. A connected platform does not become an eshopOS subprocessor merely because the merchant connects it.
Supporting service providerA provider that supports platform operations or reference data but does not necessarily process merchant customer data as a subprocessor.

Operator and affiliated entities

OrganizationRolePurposeData involvedService region
Osarian SolutionseshopOS operatorOperates the product, contracts for services, administers accounts, and handles support and legal requestsAccount, business, support, billing, and operational dataUnited States / service jurisdictions

eshopOS is a product operated by Osarian Solutions and is not a separate legal entity. Any separate Osarian-affiliated legal entity that begins processing eshopOS personal data will be added to this register based on the applicable corporate and processing records.

Core and optional subprocessors

ProviderPurposeData that may be processedAvailabilityProcessing region
Contabo GmbHProduction application and database hostingPlatform, merchant, storefront, customer, order, and operational dataCoreEuropean Union
Cloudflare, Inc.DNS, content delivery, edge security, routing, object storage, backups, and configured AI or media featuresNetwork metadata, content, uploaded media, domain configuration, and feature inputs when the relevant service is enabledCore infrastructure; optional AI featuresGlobal
KindeIdentity, authentication, and account accessAccount identifiers, email, authentication events, roles, and session metadataCoreGlobal
ResendTransactional and authorized lifecycle email deliveryRecipient details, email content, delivery events, and suppression statusCoreGlobal
SentryError and performance monitoringFiltered diagnostics, request metadata, release information, and error contextOptional; used only when configuredGlobal
Africa's TalkingRider authentication and operational SMS deliveryPhone number, message content, delivery metadata, and OTP event metadataOptional and region dependentAfrica / provider-supported regions
Google AI servicesAI generation or fallback processing for enabled product and media workflowsPrompts, product context, and media supplied to the enabled featureOptional; used only when configuredGlobal

Cloudflare may appear once in this table even though separate Cloudflare products support different functions. The enabled product and its data path determine the applicable processing role.

Payment and financial providers

ProviderPurposeData that may be processedAvailabilityService region
StripePlatform billing, supported merchant payments, connected accounts, verification, and payout-related workflowsBusiness, account, customer, transaction, verification, and payment metadata required by the selected Stripe serviceCountry and product dependentStripe-supported regions
Paystack Payments LimitedPlatform billing, merchant payments, verification, subaccount, and transfer-related workflowsBusiness, account, customer, transaction, verification, and settlement metadataCountry and product dependentPaystack-supported African markets
Safaricom PLC / M-PesaMobile-money payment and payout rails where enabledMobile number, account reference, transaction, payment, and settlement metadataOptional and region dependentKenya and supported M-Pesa services

These providers may process some information under their own legal obligations, including payment regulation, identity verification, fraud prevention, dispute handling, and record retention. Their own terms and privacy notices apply to those activities.

Merchant-enabled connected platforms

PlatformConnection purposeData authorized by the current connectorConnection methodAvailability
ShopifyMerchant-authorized catalog and inventory migration into eshopOSProducts, collections, variants, media, locations, and inventory levels; the current connector does not request Shopify customer dataOAuthOptional
BigCommerceMerchant-authorized catalog, category, warehouse, and inventory migrationProducts, categories, variants, product images, inventory locations, and stock levels; current scope does not import customers or ordersOAuth or merchant-provided store API credentialsOptional
SquarespaceMerchant-authorized commerce catalog migrationProducts, slugs, descriptions, tags, variants, prices, stock quantities, visibility, and product image URLs; current scope does not import customers or ordersMerchant-provided read-only API keyOptional
Meta Platforms / WhatsAppMerchant-enabled messaging, checkout handoff, and direct-order communicationMerchant and customer contact details, message content, order context, and delivery events when the feature is enabledMerchant-enabled integrationOptional
ShippoMerchant-enabled carrier rates, labels, tracking, and shipping workflowsShipment addresses, contacts, package details, carrier selections, labels, and tracking eventsOAuth or merchant configurationOptional

Connected platforms remain subject to the merchant's authorization, the provider's terms, and the scopes shown during setup. Disconnecting a platform ends future connector access but does not automatically delete records already imported into eshopOS.

Supporting and reference services

Provider or servicePurposeData intended for the serviceAvailability
GitHub, Inc.Source control, release workflows, and deployment automationSource, build, release, and deployment metadata; merchant customer data is not intended for this serviceCore operational provider
Komoot PhotonShipping and location searchSearch text and optional geographic bias coordinates used to return location candidatesActive location-search dependency
Frankfurter, Open ER API, ExchangeRate-API, Currency API reference datasets, FloatRates, and exchangerate.hostForeign-exchange reference rates and provider failoverCurrency codes, requested rate pairs, and technical request metadata; account and customer data is not intended for these requestsProvider rotation and fallback

Reference-rate results are operational estimates. They are not guaranteed bank, card-network, or settlement rates.

Change notices

eshopOS reviews this register when a provider is added, removed, or materially changes its role. Merchants may request provider-change notices using their account email.

Where a data-processing agreement provides a right to object to a new subprocessor, the applicable agreement and notice period control.

Controlled trust materials

Architecture summaries, data-flow evidence, security questionnaires, continuity materials, audit evidence, and similar due-diligence documents are not published in this register. Eligible organizations can request a trust and security review.

Scope and security boundary

This register does not disclose internal hostnames, network addresses, storage bucket names, deployment runner names, private endpoints, credentials, software versions, security rules, contract values, or private configuration.