About this register
This page identifies OppAction's currently authorized subprocessors, their purpose, the general categories of data they may process, and relevant processing or storage locations.
Current subprocessors
| Subprocessor and legal entity | Service and purpose | Data categories | Processing/storage locations | Transfer safeguards | Provider effective date | Relevant documentation |
|---|---|---|---|---|---|---|
| RailwayRailway Corporation | Application hosting, PostgreSQL database hosting, encrypted credential storage, logs, background jobs, backups, and point-in-time recovery (PITR). | Customer Personal Data stored or processed by the application; authentication and operational metadata; logs; encrypted Shopify and connector credentials; and backups. | Primary application and database processing is in Virginia, United States. PITR and archive storage is in California, United States. Global support, monitoring, edge services, and authorized onward subprocessors may involve other locations documented by Railway. PITR remains enabled. | Railway's DPA incorporates the EU Standard Contractual Clauses and UK Addendum. Railway's current authorized subprocessors remain subject to periodic review. | Existing active provider; original onboarding date is not recorded. | |
| OpenAIOpenAI OpCo, LLC / OpenAI Ireland Ltd., as applicable | AI analysis, generation, scoring, and refinement of merchant-directed catalog and listing content. | Catalog and listing text; merchant instructions; listing metadata; eligible Shopify-hosted product-image URLs; and generated output. OppAction does not send general file uploads or merchant support attachments to OpenAI. | OppAction currently uses global project residency. Processing locations depend on the applicable OpenAI contracting entity, service configuration, authorized subprocessors, and documented transfer mechanisms. | OpenAI's DPA includes EU Standard Contractual Clause and UK transfer safeguards. OppAction sends current Responses API requests with store: false, keeps background mode disabled, and does not enable model-training data sharing. Default abuse-monitoring retention may apply for up to 30 days. OppAction does not claim Zero Data Retention. | Existing active provider; original onboarding date is not recorded. | |
| ResendPlus Five Five, Inc. | Transactional, service, privacy, renewal, onboarding, support, and operational email delivery. | Recipient and sender addresses; message subject and content; attachments where applicable; and delivery and diagnostic metadata. | Resend states that certain account data, email metadata, logs, and API records are stored in the United States. Email delivery may use the sending region configured for the applicable domain and Resend's authorized subprocessors. | Resend's DPA incorporates the EU Standard Contractual Clauses and UK Addendum and states that customer data is deleted within 90 days after account termination, subject to stated legal exceptions. OppAction currently disables click tracking and open tracking. | Existing active provider; original onboarding date is not recorded. | |
| Microsoft 365Microsoft Corporation | Hosting and delivery of messages received through OppAction's support, privacy, legal, security, and billing mailboxes. | Sender and recipient details; message content; attachments; and related email and delivery metadata. | Retained tenant evidence shows applicable data-at-rest locations in the United States, subject to Microsoft's displayed workload qualifications. | Processing is governed by the retained Microsoft Products and Services Data Protection Addendum and Microsoft Customer Agreement. | Existing active provider; original onboarding date is not recorded. |
|
| CloudflareCloudflare, Inc. | Proxying, TLS termination and security, traffic delivery, and protection for app.oppaction.com. | IP addresses; request and connection metadata; TLS traffic; and potentially request content passing through the proxy. | Processing uses Cloudflare's global network. Logpush and Data Localization Suite restrictions are not configured. | Processing is governed by Cloudflare's Self-Serve Subscription Agreement and Customer Data Processing Addendum v6.4. | Existing active provider; original onboarding date is not recorded. |
|
Customer-selected platform and data source
Shopify
Shopify stores the source merchant, catalog, order, billing, OAuth, staff-identity, and webhook data. Shopify is selected and directly used by the merchant and is the authoritative platform and source, rather than a subprocessor appointed by OppAction.
Subprocessor changes
OppAction reviews proposed subprocessors before allowing them to receive production customer personal data. The review considers processing purpose, data minimization, security, retention, deletion, processing locations, onward subprocessors, contractual safeguards, and international-transfer requirements.
OppAction maintains its current subprocessor register at https://oppaction.com/subprocessors. OppAction will publish material changes at that location and provide advance notice to the Customer’s contractual or account contact when required by the DPA or applicable law.
OppAction's default is to provide 30 days' advance notice. OppAction may provide 15 days' advance notice when 30 days is not reasonably practicable because of urgent security, availability, contractual, legal, or operational circumstances. Emergency changes may receive shorter or post-effective notice only when necessary, with notice provided as soon as reasonably practicable.
Customers may submit questions or eligible objections through their established OppAction support or contractual contact. Objections must state reasonable, documented data-protection grounds. An objection does not automatically suspend the entire service, but OppAction will evaluate available safeguards, configuration changes, feature suspension, alternative providers, or applicable termination rights.
Change history
| Effective date | Published date | Subprocessor | Type of change | Summary |
|---|---|---|---|---|
| September 1, 2026 | September 1, 2026 | Microsoft 365 and Cloudflare | Documentation correction | Updated the Microsoft 365 and Cloudflare legal entities, documented the applicable retained agreements and current processing-location evidence, clarified that original onboarding dates are not recorded, and replaced the temporary support contact with OppAction's privacy and legal contacts. |
| August 31, 2026 | August 31, 2026 | OppAction register | Register correction | Corrects the register by adding existing active providers Microsoft 365 and Cloudflare, clarifying current provider data flows and safeguards, and describing Shopify separately as the merchant-selected platform and authoritative data source. This correction does not represent a new engagement date for Microsoft 365 or Cloudflare. |
| August 25, 2026 | August 25, 2026 | OppAction register | Initial publication | Initial publication of OppAction's public subprocessor register. |
Contact
Questions or objections about OppAction's subprocessors or data-processing practices may be submitted to privacy@oppaction.com or legal@oppaction.com.