Subprocessors
Last updated September 03, 2026.
Which third parties can reach data held in Crate?
Crate uses five third parties to run the service. OVH hosts the application, the database and uploaded files in the United Kingdom. Cloudflare runs authoritative DNS and is the destination object storage is being moved to. Brevo delivers transactional and marketing email. Paystack processes card and bank payments for merchants who connect it. Let's Encrypt issues the TLS certificates. Crate loads no third party analytics, advertising or session recording script on the marketing site, the dashboard or a merchant's storefront. Anything a merchant connects themselves, such as their own payment provider or delivery partner, is their own processor and appears in their dashboard rather than here.
Who touches what, and where
Published in full. Customers on a signed data processing addendum are notified before a party is added, so there is a real opportunity to object.
| Party | What it does for Crate | Data it can reach | Country |
|---|---|---|---|
| OVH SAS | Hosting for the application, the database, the job queue and uploaded files. | All merchant and buyer data held in Crate, as the underlying infrastructure. | United Kingdom |
| Cloudflare, Inc. | Authoritative DNS for Crate's domains, and the DNS challenge used to issue certificates. Also the destination Crate's object storage is being moved to. | No personal data today. Uploaded product and media files once the storage move completes, at which point this row is amended before the change rather than after it. | United States, operating a global network |
| Brevo, Sendinblue SAS | Delivery of transactional and marketing email, meaning order confirmations, password resets, staff invitations and merchant newsletters. | Recipient name and email address, and the contents of the message being sent. | France |
| Paystack Payments Limited | Card and bank payment processing for merchants who connect it. Card details are captured by Paystack and never reach Crate. | Cardholder and payment details, the order amount, and the buyer contact details a payment requires. | Nigeria |
| Internet Security Research Group, Let's Encrypt | Issuing the TLS certificates that secure Crate and merchant custom domains. | Domain names only. No personal data. | United States |
Parties Crate deliberately does not use
-
No third party analytics
Crate loads no analytics, advertising, heatmap or session recording script on the marketing site, the dashboard or a hosted storefront. A merchant may add their own tag to their own storefront, and when they do it is their processor and their disclosure to make.
-
No error or performance monitoring vendor
Application logs stay on Crate's own infrastructure. No exception tracking service receives them, which also means no stack trace carrying customer data leaves the host.
-
No model training on your data
Merchant and buyer personal data is not sent to any third party for model training, and Crate does not train on it either.
How this list changes
A party is added here before it starts processing data, not after. Customers on a signed data processing addendum are notified in advance, so objecting is a real option rather than a formality.
Two changes are already known and are written into the rows above rather than kept quiet. Object storage is moving from the application host to Cloudflare R2, and this page names Cloudflare now so that the move is not a surprise when it lands. A merchant's own connected payment provider or delivery partner is their processor rather than Crate's, and appears in their dashboard rather than on this page.
Ask [email protected] for a countersigned data processing addendum with this list attached, naming the contracting entity and the country it is registered in.
SecurityQuestions about this list
Short answers, and none of them hedge. If yours is not here, ask us on the contact page.
Will you tell me before you add a subprocessor?
Yes. Customers on a signed data processing addendum are notified before a party is added, so there is a real opportunity to object rather than a notice after the fact.
Is my data processed outside the United Kingdom?
The application, the database and uploaded files are processed in the United Kingdom. Email delivery is processed in France, payment processing in Nigeria for merchants who connect Paystack, and DNS and certificate issuance involve parties operating global networks.
Do you use my store's data to train models?
No. Merchant and buyer personal data is not sent to any third party for model training, and Crate does not train on it.
What about the payment provider or courier I connected myself?
That is your processor rather than Crate's. It appears in your own dashboard, under the integration you connected, and your own privacy policy is what covers it for your buyers.
Trust and legal
Every document a security or procurement review asks for, in one place.
Need this attached to a signed agreement?
Ask for the data processing addendum and this list comes with it, countersigned, usually the same week.
14-day free trial · No card required