Subprocessors
Last updated: August 12, 2026
Eturns uses the following subprocessors to provide the Services. We disclose them publicly so merchants and customers can review where data is processed before they install Eturns.
Current subprocessors
| Processor | Region | What we send | DPA |
|---|---|---|---|
| Vercel AI Gateway | Global | Decision context (no PII — sentinel IDs and structured fields) | Vercel DPA |
| xAI / OpenAI / Google | Global (via Gateway) | Same as above — routed by Vercel AI Gateway | Routed by Gateway |
| Supabase | EU + US | Full app data under RLS; photo evidence in private buckets | Supabase DPA |
| Render | Singapore | App hosting; Redis counters + session IDs (no PII) | Render DPA |
| Resend | Global | Recipient email + body for the single send call | Resend DPA |
| Sentry | EU + US | Stack traces + scrubbed extras | Sentry DPA |
| PostHog | EU or US | Event properties (PII-scrubbed before send) | PostHog DPA |
| Shopify | Global | Shopify-internal — Admin API, Billing, webhooks | Shopify Partner Agreement |
AI model vendors (routed via Vercel AI Gateway)
Eturns never calls model vendors directly. All model traffic goes through the Vercel AI Gateway. The current registry routes: - Medium/high decisions and vision primary to xAI Grok 4.5 - Low-complexity decisions and triage to OpenAI GPT-5.4 Mini (with GPT-5.4 Nano as first failover) - Vision failover to Google Gemini 3.5 Flash The authoritative model list lives in app/lib/ai/models.ts in the Eturns application and is mirrored in docs/07-AI-ARCHITECTURE.md. If we add or change a model vendor, we update this page.
Changes to this list
We will update this page before activating a new subprocessor that materially changes where data is processed. Merchants can subscribe to changes by watching this page or by emailing support@eturns.app.
Questions about this policy? Email support@eturns.app.