Subprocessors and Connected Services Notice
Version: 2026-08-03
Effective date: 3 August 2026
This Notice distinguishes a subprocessor, which MuthoCommerce appoints to process Merchant Personal Data for the MuthoCommerce Service, from a connected service, which Merchant selects and instructs under that provider's own terms. Calling every integration a MuthoCommerce subprocessor would give merchants the wrong legal and operational picture.
1. Core and conditional subprocessors
The following register reflects the current application architecture. The vendor-management owner must verify and maintain the actual contracting legal entity, enabled product, processing locations, data-protection agreement, retention, security evidence, and deletion route for each production account. A conditional vendor is a subprocessor only when its service is enabled for the affected data; an unverified conditional vendor must remain disabled for Merchant Personal Data.
| Service brand | Status and function | Data categories | Location position |
|---|---|---|---|
| Cloudflare | Core infrastructure: Workers, D1, KV, R2, Queues, Durable Objects, Workers AI, Vectorize, and Analytics Engine as configured | Service requests, account/store content, Merchant Personal Data, files, search/AI context, operational and security events | Global edge processing; persistent-service location and any regional control must match the production Cloudflare contract and configuration |
| Resend | Conditional outbound and inbound email delivery | Recipient/sender address, message content and attachment, delivery and complaint events | Processing locations must be verified from the production account terms before activation |
| Amazon Web Services / SES | Conditional alternative email delivery | Recipient/sender address, message content, delivery and complaint events | Production AWS region and any global email processing must be recorded before activation |
If Google sign-in is offered, Google receives the user's authentication request under Google's own terms and returns authorised identity attributes to MuthoCommerce. The final role classification and production OAuth configuration must be recorded in the vendor register; MuthoCommerce must not describe Google as processing all store data merely because it provides sign-in.
The production provider for MuthoCommerce's own subscription charges has not been verified from repository evidence. It must be selected, contractually reviewed, and added here with its correct processor/independent role before any paid automatic charge is enabled. A Stripe, bKash, SSLCommerz, aamarPay, or PayPal connection chosen by a Merchant for shopper payments is a separate data flow and does not answer that subscription-billing question.
No vendor may be added to this public subprocessor table solely because a package exists in source code. The data flow must be enabled in production and contractually reviewed.
2. Merchant-selected connected services
Depending on configuration, the Service can connect to the categories below. These providers are ordinarily independent providers engaged or authorised by Merchant, not general MuthoCommerce subprocessors for all merchants.
| Category and current connectors | Typical data sent on Merchant instruction | Merchant responsibilities |
|---|---|---|
| Payments: bKash, SSLCommerz, aamarPay, Stripe, PayPal, and manual/COD methods | Order reference, amount, currency, shopper contact or redirect context, payment status, refund request | Contract, fees, onboarding/KYC, lawful payment method, settlement, reserves, refunds, reconciliation, provider privacy notice |
| Couriers: Pathao, RedX, Steadfast | Recipient, phone, address, order/parcel, COD amount, delivery instruction and status | Courier contract, correct address/parcel data, delivery promises, COD reconciliation, cancellation and complaint handling |
| Social and messaging: Meta/Facebook Messenger, comments, WhatsApp and configured channels | Social identifier, message/comment content, attachments, conversation context, template or response | Channel permission and consent, platform terms, template/marketing rules, human escalation, retention and deletion |
| Analytics and advertising: Google Analytics, Meta Pixel, TikTok Pixel | Page/device identifiers, URLs, events, cart/order conversion fields configured by Merchant | Prior consent where required, truthful cookie/privacy notice, purpose and audience control, opt-out, provider terms |
| Domains and DNS | Domain, hostname, certificate and validation records | Domain ownership, registrar terms, lawful name, renewal, DNS authority |
| Merchant-configured email/SMS | Recipient, message, order/account context, delivery status | Lawful audience, sender identity, consent/opt-out, provider account, fees, template content |
| Partner apps, OAuth clients, webhooks, API/MCP agents | Scoped store, order, customer, product, event or action data authorised by Merchant | App due diligence, least privilege, developer terms, monitoring, revocation and downstream deletion |
MuthoCommerce passes only fields needed for the configured action and should show scope before connection. Merchant can disconnect a service, but must also follow that provider's process to revoke credentials or delete data already received.
3. Notice and objection
MuthoCommerce will maintain a dated change history and offer Merchant Owners a subprocessor-change notification. Except for an emergency replacement needed to protect security or continuity, MuthoCommerce will give at least 15 days' advance notice before a new subprocessor begins material processing of Merchant Personal Data. Merchant's objection and remedy rights are in the DPA.
An emergency addition will be disclosed as soon as reasonably practicable with the reason, data scope, safeguards, and whether it is temporary. A vendor name change or corporate reorganisation with no material processing change may be recorded without a new objection period, but a new purpose, data category, or location is material.
4. Required register fields
The non-public vendor register must contain the verified legal entity, service, owner, contract and DPA date, data categories, data subjects, purpose, systems, locations, onward subprocessors, transfer mechanism, retention/deletion, encryption, access method, incident-notice term, assurance evidence, risk rating, review date, exit plan, and deletion confirmation. Conditional services must default to disabled until their review is complete.