Subprocessors
Last updated: 10 September 2026
A subprocessor is a third party we use to run Sichta. This page lists every one, what it receives, and where. The short version: Sichta processes your store's catalogue and configuration data — never a shopper's personal data. Hosting and storage stay in the EU; the subprocessors below marked US run there under Standard Contractual Clauses.
| Subprocessor | Purpose | Data it receives | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | Hosting, database, storage — the app itself. | All app data: your scans, settings, generated files, and merchant contact email. | EU — eu-central-1 (Frankfurt) |
| Resend, Inc. | Transactional email for the alert and change-notification emails you enable. | Your merchant contact email and the notification text. | US — Standard Contractual Clauses |
| OpenAI | AI-snapshots inference (all plans) — opt-in only. | Your public store name, domain, and a generic shopping question. No customer or account data. | US — api.openai.com (Standard Contractual Clauses) |
| Google (Gemini API) | AI-snapshots inference on paid plans (Gemini) — opt-in only. | Your public store name, domain, and a generic shopping question. No customer or account data. | US — generativelanguage.googleapis.com (Standard Contractual Clauses) |
| Anthropic | AI-snapshots inference on paid plans (Claude, with web search) — opt-in only. | Your public store name, domain, and a generic shopping question. No customer or account data. | US — api.anthropic.com |
Shopify
Sichta runs inside Shopify and reads your store through Shopify's APIs. Shopify is your platform and your own processor under your agreement with Shopify — not a Sichta subprocessor — but it is where the data originates and returns.
Changes
We update this page before adding or replacing a subprocessor, and note material changes in the app. See the Data Processing Agreement for your right to object.
Contact
Questions: hello@gigliotti.software.