Channekt › Sub-processors
Sub-processors
Every company that touches a merchant's data on our behalf, what each one does, and where it is. This page is the list the data processing agreement refers to, and it changes only with notice.
Last updated 30 August 2026The list
A sub-processor is a company we use to run Channekt that may hold or handle personal data belonging to a merchant or to a merchant's customers. This is all of them.
| Who | What they do for us | Where | Personal data |
|---|---|---|---|
| Google Cloud (Google Ireland Limited) | The application, the database, the queue, the build pipeline and the database backups | europe-west2, London, United Kingdom | Yes. It runs the database, so everything is there |
| Cloudflare | DNS, TLS termination and the edge in front of the application; the picture service at cdn.channekt.com | Terminated at the nearest edge; nothing is stored there | In transit. Every request crosses it |
| Cloudflare R2 | File storage: product pictures, import files, exports, and the PDFs a parcel needs | European Union jurisdiction | Yes, where a merchant's own export or document contains it |
| Google Cloud Vertex AI | On-Model Studio: generating a photograph of a garment worn by one of our model presets | europe-west1, Belgium | No. A product photograph and a preset, nothing else |
| Stripe | Subscriptions and payment for Channekt itself | Ireland and the United States, under standard contractual clauses | The merchant's billing contact. No card data reaches us |
| Anthropic | The in-product assistant, where a merchant's deployment has it switched on | United States, under standard contractual clauses | No. It is never sent an order or a customer |
| Email provider | Invitations, password resets and the alerts we send | European Union | Staff names and email addresses only |
What each one sees
Google Cloud holds the database, so it holds everything the product holds: the catalogue, the order book and the personal data an order carries. It is a processor to us and a sub-processor to a merchant, in London, and the daily backups are in the same account. Channel credentials are sealed with a key held outside the database before they are written, so a copy of the database alone yields no working token.
Cloudflare is not a content delivery network in front of static files. channekt.com resolves to it, so it terminates TLS and every request to the application is in plaintext at that point before the second hop to London. It also serves product pictures from cdn.channekt.com, holding read credentials for the file store at the edge. Nothing is stored there beyond a cached picture, and a picture on a listing is public by the time a shopper sees it.
Cloudflare R2 holds the files. It was chosen for the cost of reading data out, which is what a picture store is charged for, and the honest consequence is stated here rather than buried: R2 offers a European Union jurisdiction, not a United Kingdom one. So the claim for files is the EU. The database, the application and the backups have not left London. Anybody whose requirement is specifically the United Kingdom should read this paragraph rather than the row above it.
Google Cloud Vertex AI is used by one optional feature. On-Model Studio sends a product photograph and one of our own model presets and gets a picture back. The model that does it does not exist in London, which is why that one call runs in Belgium. No customer personal data is involved in a product photograph, the feature is off for a store until it is switched on, and the region is printed beside every result the product produces.
Stripe bills the merchant for Channekt. Card details are entered on Stripe's own hosted checkout and never reach our systems; there is nowhere in the database for them to go.
Anthropic serves the assistant, which is optional and narrow: it answers why a product cannot be published to a channel yet and drafts titles and descriptions. It is never sent customer personal data, and that is a property of what the code sends rather than a promise about a prompt.
Connected shops are not on this list
Shopify, eBay, WooCommerce, Magento and any other channel a merchant connects are not our sub-processors. They are the merchant's own accounts and their own agreements. Data moves between them and Channekt because the merchant asked for it to, and each channel's terms are between the merchant and that channel.
Adding or replacing one
Merchants are told at least 30 days before a new sub-processor starts handling their data, or before an existing one is replaced. The notice names the company, what it will do and where it is.
A merchant may object within those 30 days on reasonable data protection grounds. We will try to offer a way to carry on without the change; if there is none, the merchant may end the agreement for the affected part of the service without penalty and be refunded for what was paid and not used.
This page is versioned with the code, not in a content system, which is why the date at the top is the date something on it actually changed.
What has changed
| When | What |
|---|---|
| 29 August 2026 | File storage moved from Google Cloud Storage to Cloudflare R2, so the claim for files became the European Union rather than the United Kingdom. Cloudflare added for DNS, TLS and the picture service. Google Cloud Vertex AI added for On-Model Studio. |
| 24 August 2026 | Hosting moved to Google Cloud in London. Before that it was a different provider in Frankfurt, and this list said so. |
Channekt has no production merchants yet. The two changes above happened while the product was in development and nobody's live data was involved, and they are listed because the record starts now rather than on the day it first matters.