ZipOrder

Subprocessors

ZipOrder uses the following third-party services to deliver the product. We maintain this list for transparency under KVKK Article 8 and GDPR Article 28. The "Last updated" line in our Terms of Service is bumped whenever this list changes.

Data location: Primary application data (accounts, catalogs, orders) is processed inside the EU. AI extraction (Gemini) may run from any Google Cloud region; payload is held only for the duration of the request. US-hosted services operate under Standard Contractual Clauses (SCCs).

ServiceVendorRegionDataContract
AuthenticationSupabase, Inc.EU (Ireland — eu-west-1)Email, session tokens, hashed password (when set)Supabase DPA
Application database + hostingRailway Corp.EUAll application data: users, catalogs, items, orders, notifications, subscription stateRailway DPA
Object storage (R2)Cloudflare, Inc.EUUploaded source documents (flyers, PDFs, spreadsheets) and derived item imagesCloudflare DPA
AI extraction (Gemini)Google LLCGlobal (Google Cloud regions)Source document content sent for processing (transient — not stored beyond the request)Google AI Studio Terms
Push notificationsExpo (650 Industries, Inc.)United StatesDevice push tokens, message payloads (notification text)Expo Privacy Policy
Mobile + web product analyticsGoogle LLC (Firebase Analytics, Google Analytics 4)Global (Google Cloud)Anonymous usage events (screen views, button taps, error counts). Sent only after the user grants the on-device analytics opt-in (mobile) or accepts the cookie banner (web)Google Analytics Terms
Subscription billingRevenueCat, Inc.United StatesApp user id, platform receipt, subscription stateRevenueCat DPA
Phone verification (OTP)Twilio Inc.United StatesSupplier phone number (E.164), one-time codes, delivery status. Used only when the supplier opts into IBAN payments, PSP setup, or other OTP-gated security flows.Twilio DPA
Web frontend hosting + CDNVercel Inc.Global (edge — closest region to the visitor)Static assets, server-rendered HTML for public catalog / profile / order pages, edge request logs (IP, user agent). No application data is stored on Vercel; the backend (Railway) is the source of truth.Vercel DPA
Transactional emailResend, Inc.EU + United StatesRecipient email, message content (subject + body)Resend DPA
Error monitoringFunctional Software, Inc. (Sentry)EU + United StatesError stack traces (PII redacted), runtime metadata (no message bodies)Sentry DPA
Customer payments (when supplier opts in)iyzi Ödeme ve Elektronik Para Hiz. A.Ş. (Iyzico)TürkiyeOrder id, amount, currency, payment status events. Card details NEVER reach ZipOrder — entered directly on Iyzico's hosted checkout page.Iyzico Merchant Agreement (supplier-side)
Customer payments — global (when supplier opts in)Stripe, Inc. / Stripe Payments Europe Ltd.EU + United StatesOrder id, amount, currency, Checkout Session id, payment status events. Card details NEVER reach ZipOrder — entered directly on Stripe's hosted checkout page (PCI-DSS Level 1 compliant).Stripe Services Agreement (supplier-side)

Contact: Questions about this list? Write to legal@ziporder.io.