Sub-processor Register

Every third party that touches data on LetBuyy, and what for.

Applies to
Merchants
Clauses
6
Reading time
2 min
Revised
3 August 2026

These policies are published for review and are not yet in force. LetBuyy has not opened to merchants, so no agreement has been formed with anyone. They take effect on the day the platform launches, and the effective date will be stated here. Last revised 3 August 2026.

In short

  • This is the complete list of providers that process data as part of running LetBuyy.
  • Each entry states what it does and whether it can reach personal data.
  • We give notice before adding a sub-processor that handles shopper personal data.

This summary is written to be understood. The clauses below are what actually applies — where the two differ, the clauses govern.

  1. Infrastructure and hosting

    These run the platform itself and necessarily hold the data stored in it.

    • Supabase — primary database, authentication storage, and file storage. Holds merchant and shopper personal data.
    • Cloudflare — edge network, DNS, custom-domain routing, bot protection, and the workers that run the API gateway and background jobs. Sees request metadata and traffic in transit.
    • Vercel — hosting for the web applications. Sees request metadata and server logs.
  2. Payments

    Razorpay — payment processing, settlement to merchant bank accounts, and refunds. Collects payment credentials directly from shoppers; we hold references, not card numbers. Razorpay is a Reserve Bank of India authorised payment aggregator and is a Data Fiduciary in its own right for the payment data it collects.

  3. Communications

    Resend — transactional email delivery: order confirmations, account notices, password resets. Processes recipient email addresses and message content.

  4. Shipping and logistics

    Where a merchant connects a courier, that courier receives the delivery address and contact details needed to complete the shipment. Integrations currently available include Shiprocket and Delhivery.

    These are connected per store by the merchant. A store that does not connect one does not send data to it.

  5. Monitoring and operations

    Sentry — error monitoring. Receives stack traces and request context; configured to scrub credentials and personal data from payloads.

    Cloudflare Turnstile — bot protection at registration and login. Receives a challenge token and IP address, not account contents.

    Cloudflare Analytics Engine — aggregated operational metrics. Designed for counts and timings rather than individual records.

  6. Changes to this register

    We will update this page and notify merchant account holders before a new sub-processor that handles shopper personal data begins processing.

    Removing a sub-processor does not require notice.

    NoteApps a merchant installs from the marketplace are not our sub-processors. They are separate processors the merchant engages directly, and their data handling is disclosed in their own listing.

Questions about this document

Write to support@letbuyy.com and quote the clause number. For a complaint rather than a question, use the grievance process.