Subprocessors

Subprocessors

Every provider part of your data passes through, what it does with it, and where it operates — with no exceptions.

Last updated: 15.09.2026

1. What a subprocessor is

When we process your customers' data on your behalf (we are the processor, you are the controller), we rely on providers to run the Platform: hosting, a database, AI models, email delivery, and so on. Every provider that receives part of that data is a subprocessor. This page lists all of them and says, for each one, what it does, what it receives, and where it operates.

Two kinds of parties also receive data but are not subprocessors in the strict sense, because they act on your own authorization rather than ours: your store platform (Salla, Zid, Shopify…), which you connected yourself, and the channel providers (Meta, X), where you connect your own accounts and accept their terms. We still list them here for transparency, but your contractual relationship with them is yours.

The contractual basis for all of this is in the Data Processing Agreement, and the privacy details are in the Privacy Policy.

2. Infrastructure

These are the providers the Platform itself runs on. By the nature of their role, everything in the Platform passes through or is stored with them, which is why they are the most important entries on this list.

ProviderPurposeDataLocation
VercelApplication hosting, serverless compute, edge network, and scheduled-job schedulerAll application trafficUSA (global edge network)
NeonManaged PostgreSQL (primary database)All stored dataUSA / EU (cloud-hosted)
Cloudflare R2Object storage: conversation attachments, uploads, and nightly database backupsFiles and backupsCloudflare global network
Upstash (Redis + QStash)Redis for rate limiting, locks, and short-lived cache; QStash as the job queue for campaign sends and syncsJob payloads carry ids, not message bodies; the cache holds widget configurationUSA / EU
GitHub ActionsRuns the nightly backup jobHolds the database URL and R2 credentials as secrets; the backup itself goes to R2USA

Backups run daily at 03:30 UTC and are retained for 30 days, then pruned. Secret columns (API keys, platform and channel tokens) are encrypted with AES-256-GCM before they reach any storage provider. Details are on the Security page.

3. AI model providers

The agent generates its replies through a language model from a provider you choose for your organization (the default is Anthropic). We never send to more than one provider at the same time; if you configure more than one, the next is used only when the first is down.

ProviderPurposeDataLocation
AnthropicLanguage-model inference (default)Conversation context, product and knowledge-base snippetsUSA
OpenAILanguage-model inference (at your choice)Conversation context, product and knowledge-base snippetsUSA
GoogleLanguage-model inference (at your choice)Conversation context, product and knowledge-base snippetsUSA
  • What the provider receives per reply: the agent instructions, the last 12 messages of the conversation, and the minimum context the tools fetch (matching products, knowledge-base answers, an order status). Not the whole database.
  • We use the commercial APIs, whose terms state that inputs and outputs are not used to train their models.
  • With Anthropic we enable prompt caching: the prompt prefix may be cached at the provider for at most 1 hour (WhatsApp) or 5 minutes (widget) to reduce cost.
  • If you store your own API key, the usage relationship is directly between you and the provider, and the provider bills you.

Every detail of AI processing is in the AI Policy.

4. Messaging and email

These are the providers the actual messages between you and your customers pass through. Meta and X operate on your own accounts with them and under your authorization; Resend is used by us to send email from the domains you verify yourself.

ProviderPurposeDataLocation
Meta PlatformsWhatsApp Cloud API, Instagram DMs, and MessengerMessage content and customer identifiers on those channelsUSA / global
X CorpX direct messagesMessage content and handlesUSA
ResendTransactional and marketing email sending, and the inbound support mailboxEmail addresses and contentUSA

The rules of each channel (the 24-hour window, templates, disconnecting and monitoring) are in the Channel Policies. You can disconnect any channel from /dashboard/integrations?tab=channels; disconnecting clears the credentials stored with us.

5. Payments and identity

These handle your data as a merchant (your account and subscription), not your customers' data.

ProviderPurposeDataLocation
StripePayments and subscriptionsBilling identity; card data is held by Stripe only — we store the subscription status, the last 4 digits, and the card brandUSA / EU
Google (Sign-in)OAuth authentication of dashboard usersName, email, profile pictureUSA

6. Error monitoring

ProviderPurposeDataLocation
SentryTechnical error monitoringError metadata and ids; default PII sending is off, and payloads (message text) are not sentUSA / EU

When an error occurs, Sentry receives the kind of error and the ids of the records involved (a conversation id, for example) so we can trace it — not the content of the conversation itself.

7. Marketing-site analytics

These run only on the public marketing website (the home page, pricing, blog, these pages), and only after the visitor accepts in the cookie banner. They never run inside the dashboard or inside the chat widget on your store, and your customers' data never reaches them.

ProviderPurposeDataLocation
Google Analytics 4Marketing-website visit statistics and traffic sourcesPseudonymous usage data (no IP address stored)USA
Google Tag ManagerTag-loading container. Advertising measurement tags (Google Ads, Meta Pixel) are added here and to the Cookie Policy before activation — none is active todayCollects nothing by itselfUSA
Microsoft ClarityHeatmaps and session interaction recordings on the marketing websitePseudonymous usage data (text typed into fields is masked)USA

The related cookies and how to control them are in the Cookie Policy.

8. Store platforms you authorize

When you connect your store, we read and write data at your platform within the scope you authorized at connection time (via OAuth, or with credentials you enter). The platform is not our subprocessor — it is your provider, governed by your contract with it. We list it here so you know exactly what is exchanged.

PlatformConnectionData exchanged
Salla, ZidOAuthProducts, prices, inventory, orders and statuses, coupons, customers, abandoned carts
ShopifyOAuthProducts, prices, inventory, orders and statuses, coupons, customers, abandoned carts
WooCommerceCredentials you enterProducts, prices, inventory, orders and statuses, coupons, customers; abandoned carts are derived from unpaid orders
ikas, IdeaSoftOAuthProducts, prices, inventory, orders and statuses, coupons, customers; on ikas, abandoned carts are derived from unpaid orders
Ticimax, T-Soft, PlatinMarketCredentials you enterProducts, prices, inventory, orders and statuses, coupons, customers

Access tokens for these platforms are stored with us encrypted with AES-256-GCM, and are never included in a data export.

9. Locations and international transfers

The providers listed above operate in the USA and/or the EU, as shown in the tables. This means your customers' data — including customers in Saudi Arabia and Turkey — is transferred to those regions for processing.

  • Contractual safeguards: we rely on Standard Contractual Clauses (SCCs) or equivalent provider commitments for transfers outside the country of origin.
  • Least privilege: each provider receives only what its role needs. The job queue carries ids rather than text, and the error monitor carries error kinds rather than payloads.
  • Encryption: always TLS in transit, and secrets encrypted at rest.

If you are under a legal obligation that prevents certain data from leaving your country, contact us before connecting the channel or store in question so we can see whether a suitable arrangement exists.

10. What we check before adding a subprocessor

We add a new provider to this list only after confirming:

  • Security posture: encryption in transit and at rest, access controls, and a credible track record of incident handling.
  • Contractual commitments: a data processing agreement or equivalent commercial terms, including confidentiality and — for model providers — an explicit statement that your data is not used to train their models.
  • Deletion on termination: the ability to delete our data with them when we end the relationship or when we delete a merchant's data.
  • Data minimisation: that its role can be performed with the least data possible, and that we can restrict what it actually receives.

11. Change notification and right to object

  • Before any material addition to this list (a new provider that receives your customers' data), we notify the account owner by email and by an in-dashboard notice before it takes effect.
  • If you have a reasonable ground to object to the new provider, you can object during the notice period. If we cannot offer a suitable alternative, you may terminate your subscription without penalty, and the usual export and deletion rules apply.
  • Replacing a provider with an equivalent one in the same role (for example, changing the hosting provider to one with the same commitments) is published here and announced, but does not count as a material addition.

This page is the current, authoritative list of our subprocessors; the "last updated" date at the top says when it last changed.

12. Contact

For any question about a specific subprocessor, to raise an objection, or to request a copy of the contractual safeguards for data transfers: privacy@capiagent.com or via the contact page. We reply within 5 business days at most.

This page describes the Platform's actual practice and does not constitute legal advice. For any question about subprocessors or data transfers, email us at privacy@capiagent.com.