OmniStore Subprocessors
OmniStore Subprocessors
Effective Date: June 1, 2026 Last Updated: May 24, 2026 Version: 1.0.0
A subprocessor is a third-party service provider that processes personal data on OmniStore’s behalf or on behalf of OmniStore’s merchant customers. This page lists every subprocessor we currently use, the data each one processes, and the legal mechanism we rely on for international data transfers.
We commit to giving merchant account holders at least 30 days’ notice before adding or replacing a subprocessor. The notice is sent by email to the email address on file for each affected OWNER and the entry is added to this page with a future effective_at date.
If a controller (you, the merchant) objects to a proposed new subprocessor within the 30-day notice window, we will work with you to find an alternative arrangement. If no alternative can be found and you do not wish to continue with the new subprocessor in place, you may terminate your subscription without penalty and we will refund any prepaid fees for the unused portion of the current billing period.
1. Current subprocessors
| # | Subprocessor | Purpose | Personal-data categories processed | Location of processing | Transfer mechanism |
|---|---|---|---|---|---|
| 1 | Cloudflare, Inc. (R2 object storage, CDN, DNS) | Storage and global delivery of product images, store logos, hero images. DNS resolution + WAF for useomnistore.com and all *.useomnistore.com subdomains. Cloudflare Image Resizing transforms images on the fly. | Image files uploaded by merchants. The images themselves may incidentally contain personal data (e.g. a merchant photographs a product with a customer in the background) but are not indexed or searched by Cloudflare on a per-person basis. DNS query IPs. | United States, European Union, global edge locations | EU Standard Contractual Clauses (Commission Decision 2021/914) incorporated by reference into Cloudflare’s data-processing addendum |
| 2 | Amazon Web Services, Inc. (SES - Simple Email Service) | Transactional email delivery: registration verification, password reset, billing receipts, dunning notices, member invitations, change-notification emails. | Email address and full name of the recipient; the contents of the email; sender IP for the delivery infrastructure. | United States (region us-east-1) | EU Standard Contractual Clauses (Commission Decision 2021/914) incorporated by reference into the AWS Data Processing Addendum |
| 3 | Stripe Payments Europe Ltd. / Stripe, Inc. (card payments) | Subscription billing for the Stripe-supported card rail (planned, not yet active). | Card metadata tokens, billing address, email, name. Full PAN (card number) is collected by Stripe’s hosted fields and never reaches OmniStore servers. | Ireland (EU customers), United States (rest of world) | EU Standard Contractual Clauses (Commission Decision 2021/914) for EU-to-US transfers; intra-EU data stays in Ireland |
| 4 | Campay Cameroon SA (Cameroon mobile-money) | Subscription billing via Cameroonian mobile-money operators (MTN Mobile Money, Orange Money) for merchants in the FRONTIER pricing band. | Phone number of the payer, transaction amount, transaction reference, transaction status. | Cameroon | No international transfer (controller and processor both in Cameroon) |
| 5 | Monetbil SAS (Cameroon mobile-money alternative rail) | Subscription billing via Cameroonian mobile-money operators (MTN Mobile Money, Orange Money) - alternative to Campay for redundancy. | Phone number of the payer, transaction amount, transaction reference, transaction status. | Cameroon | No international transfer |
| 6 | [Hosting provider - Harold to fill in based on actual VPS provider] | Virtual private server hosting the OmniStore backend, PostgreSQL database, Memurai (Redis-compatible cache), and nginx reverse proxy. | All personal data described in the Privacy Policy passes through this host in the course of being stored, retrieved, or served. | [TBD: provider’s data-center country] | [TBD: SCC if outside Cameroon, none if in Cameroon] |
| 7 | Functional Software, Inc. (Sentry - error monitoring) | Backend exception and frontend error capture, for diagnosing bugs. Optional and not currently enabled. When enabled, the Sentry DSN is set per environment. | Stack traces, breadcrumb trails (recent user actions leading up to an error), browser metadata, IP address, user ID (UUID) of the affected user. We configure Sentry to scrub email addresses, names, and any field tagged sensitive before transmission. | United States, European Union (region depends on Sentry project configuration) | EU Standard Contractual Clauses (Commission Decision 2021/914) incorporated by reference into Sentry’s data-processing addendum |
2. What “subprocessor” means and what it doesn’t
A subprocessor is a party that has access to personal data we process. The above list covers exactly those parties.
The following parties are not subprocessors because they do not have access to OmniStore-controlled or merchant-controlled personal data:
- Domain registrar for
useomnistore.com(no access to platform data; only the WHOIS record). - GitHub / source-code hosting (source code only; no production data).
- Local-machine development tools used by Harold (IDE, package managers).
- Tax-filing / accounting software Harold uses for his own business records (only metadata about merchants, not their data).
- Payment processors that we evaluate but never integrate with (e.g. Flutterwave, Paystack - listed as future possibilities in the subscription strategy but not currently active).
3. Transfer mechanisms in plain English
When personal data leaves the European Economic Area, GDPR requires a legal basis for the transfer (Art. 44 onward). The two mechanisms relevant to OmniStore are:
- Standard Contractual Clauses (SCCs) - a template contract published by the European Commission (Decision 2021/914) that binds the recipient to GDPR-equivalent protections. We rely on this for all transfers to subprocessors located in the US or in jurisdictions without an EU adequacy decision.
- EU adequacy decision - for transfers to jurisdictions the European Commission has formally declared to provide adequate protection (e.g. Canada, Israel, UK, Japan). We don’t currently rely on adequacy decisions as the primary mechanism for any subprocessor; SCCs are the safer default.
A copy of the executed SCCs for any specific subprocessor is available on request to legal@useomnistore.com.
For transfers FROM Cameroon (where the controller - Harold - is located) to subprocessors elsewhere, Loi N° 2010/012 requires the controller to ensure adequate protection. The SCC mechanism above serves that purpose for the same reason; the contract obligation binds the recipient regardless of which originating law mandated it.
4. Older / removed subprocessors
When we remove a subprocessor (because we stop using their service, or migrate to a replacement), we record the removal here. The removal date matters for data-subject requests asking “who held my data on date X?”
| Subprocessor | Used from | Removed on | Reason |
|---|
(No removals yet - this is the v1.0.0 list.)
5. Updating this list
This list is updated whenever a subprocessor is added or removed. Each version of this document is a snapshot at a point in time. Changes go through the same workflow as every other legal document at OmniStore: markdown edit → version bump → CHANGELOG entry → 30-day email notice to merchants → effective date.
A continuous-integration check in the OmniStore build pipeline confirms that every external-vendor reference in application.yml is matched by an entry in this list. If they fall out of sync the build fails.
6. Contact
For questions about who processes your data on our behalf, or to request a copy of an SCC, email legal@useomnistore.com.