# Subprocessor Disclosure on Shopify Apps: Why It Matters and Where to Check It > When you install a Shopify app, you are also trusting every third-party service, or subprocessor, that app uses to handle your customer data, understanding this supply chain is critical for security and compliance. Source: https://arbyn.app/blog/subprocessor-disclosure-on-shopify-apps-why-it-matters-and-where-to-ch Published: 2026-08-26 --- When you install a Shopify app, you are not just hiring one piece of software. You are hiring its entire, often invisible, supply chain. Every app, from the simplest utility to the most complex AI agent, relies on other companies to function, for hosting, for sending emails, for processing payments, and for running analytics. These third-party vendors are called subprocessors, and they represent a critical, frequently overlooked layer of your store's security and compliance posture. In an ecosystem with tens of thousands of applications and growing by hundreds each month, the variety of these dependencies is immense. The shopify app subprocessor disclosure is not a trivial piece of legal boilerplate buried in a privacy policy; it is a direct window into the operational integrity of the app developer and a map of every company that will gain access to your customer’s data, from purchase history to personal identifiers. For store owners navigating this complex digital marketplace, understanding this chain of data custody is no longer optional. It is a core responsibility of modern commerce. The central truth is that you, the store owner, are the "data controller" in the eyes of the law, because you decide the purpose for collecting customer information. The Shopify app you install is a "data processor," acting on your behalf. But when that app uses another company, like Amazon Web Services for hosting or an AI company for language processing, that third company becomes a subprocessor. This creates a chain of responsibility, but the legal and financial liability ultimately rests with you. If a breach occurs anywhere down that chain, regulators and customers will look to your business first, as you own the direct relationship. Ignoring an app's subprocessors is like hiring a general contractor without asking about their team of electricians, plumbers, and foundation experts. You are trusting them with the keys to your house, and by extension, you are trusting every single person they bring onto the job site, whether you have met them or not. If the plumber they hired causes a catastrophic flood, you are the one dealing with the immediate damage and reputational fallout, not the anonymous subcontractor. This is the reality of the modern digital ecosystem, and navigating it requires a new level of diligence to protect your brand and your customers. What Is a Subprocessor and Why Is It Not Just Legal Jargon? The term "subprocessor" can feel like technical jargon, but the concept is straightforward. In the language of privacy regulations like Europe's GDPR, the "data controller" is the entity that decides why and how personal data is processed. For your Shopify store, that is you. You collect customer names, emails, and addresses to fulfill orders. When you install an app to help manage those customers, that app developer becomes a "data processor," handling the data according to your instructions. A subprocessor is simply any third party engaged by that data processor to help fulfill its services. This could include cloud infrastructure providers like Google Cloud or Microsoft Azure, email delivery services like SendGrid, or specialized AI model providers that power an app's intelligence. Modern applications are built like this by necessity; it is more secure and efficient to use a specialized, world-class service for a specific function than for every app developer to build their own server farms and email protocols from scratch. For instance, a reviews app developer can focus on their core product by using a subprocessor like a Content Delivery Network (CDN) to host and quickly serve customer-uploaded images worldwide, rather than building that complex infrastructure themselves. This approach improves performance and security while accelerating the developer's ability to deliver value. This relationship forms a critical chain of accountability. The data controller (you) is accountable for the entire process. The processor (the app) is accountable to you, and the subprocessor is accountable to the processor. While this sounds like a neat hierarchy, the core responsibility never truly leaves your hands. You can delegate the *task* of processing data, but you cannot delegate the ultimate *responsibility* for its protection. This is the fundamental reason why understanding an app's subprocessors is so vital. A Shopify app developer is legally required to have a written contract, often called a Data Processing Agreement (DPA), with each of their subprocessors. This DPA ensures those vendors meet the same data protection standards that the app itself is promising to you, covering areas like data deletion protocols, security audit rights, and specific encryption standards like AES-256 for data at rest and in transit. Transparency about this supply chain is a direct requirement under laws like GDPR, which mandates that controllers must be informed about and have the ability to object to the use of specific subprocessors, giving you a powerful but rarely used right to veto a vendor you do not trust. Ignoring this chain is a significant business risk. If your customer support app uses a subprocessor based in a country with weak data protection laws, or one with a history of security vulnerabilities, your customer data is exposed. The app developer may be the one who chose that vendor, but you are the one who chose the app. Imagine your new marketing automation app uses a little-known analytics subprocessor that suffers a breach, exposing the browsing habits and purchase history of your entire customer base. The negative headlines will feature your brand's name, not the subprocessor's, just as American Express faced questions in 2024 when a third-party payment processor breach exposed its cardholder data. This is why a clear, public, and easily understandable subprocessor disclosure is a powerful signal. It demonstrates that the app developer takes their role as a data processor seriously and has performed the necessary due diligence on their own supply chain. Conversely, an app that makes it difficult to find this information, or provides a vague and unhelpful list, should be a major red flag. It suggests a lack of maturity and a disregard for the transparency that modern data privacy laws and customers demand. The Regulatory Hammer: GDPR, CCPA, and the Cost of Ignorance The requirement to vet an app's subprocessors is not just a best practice; it is backed by significant legal and financial consequences. Major data privacy regulations, like the General Data Protection Regulation (GDPR) in Europe and the California Consumer Privacy Act (CCPA), place the ultimate liability for data protection squarely on the shoulders of the data controller, the store owner. These laws mandate that you know who is processing your customers' data, where they are processing it, and for what purpose. Under GDPR, the most severe violations can result in penalties of up to €20 million or 4% of a company's global annual revenue, whichever is higher. For a growing brand with $25 million in annual revenue, that could mean a fine of $1 million. These are not theoretical threats; regulators have issued over €7.1 billion in GDPR penalties since the law took effect, demonstrating a clear and sustained enforcement appetite. This global trend includes laws like Brazil's LGPD, with fines up to R$50 million, and Canada's PIPEDA, making subprocessor diligence a worldwide necessity. The logic is simple: "I didn't know" is not a defense. When you choose to use a third-party app, you are responsible for ensuring that app and its entire downstream ecosystem are compliant. If your app vendor uses a subprocessor that suffers a data breach, you are the one who may be legally obligated to notify your customers and regulators. This is a critical and often misunderstood point. The responsibility to notify belongs to the entity that owns the relationship with the customer, regardless of where the technical failure occurred. The financial fallout from such an incident can be crippling. According to IBM's 2025 reporting, the average cost of a data breach in the United States has hit a record $10.22 million, more than double the global average. This figure includes expenses for forensic investigation, legal fees, regulatory penalties, public relations to manage brand damage, and customer compensation, a sum that can be existential for a growing brand. Supply chain breaches are particularly painful, costing more on average ($4.91 million) and taking longer to contain. Both GDPR and CCPA have specific requirements regarding third-party vendors. GDPR, under Article 28, requires processors to get written authorization from the controller before engaging any subprocessor. It also gives the controller the right to object to changes in the subprocessor list, a right you can only exercise if you know who is on the list in the first place. The CCPA, as amended by the CPRA, mandates that contracts with "service providers" (the CCPA's term for processors) must explicitly prohibit them from selling or sharing personal information and restrict them to using the data only for the specific business purposes outlined in the contract. This means you need contractual assurances that flow all the way down the supply chain, governing everything from the subject matter and duration of processing to the types of data involved. Without a clear subprocessor disclosure from your app vendor, it is impossible for you to verify that these legal requirements are being met. You are operating on blind faith, and in the current regulatory environment, that is a gamble that no store owner can afford to take. Beyond Compliance: How Subprocessor Transparency Signals a Quality App While avoiding multi-million dollar fines is a powerful motivator, the importance of subprocessor transparency extends far beyond mere legal compliance. The practice of maintaining and publishing a clear, detailed, and up-to-date list of subprocessors is a strong indicator of an app developer's overall quality, maturity, and trustworthiness. It is a signal that the company understands its role in the data ecosystem and has a disciplined, professional approach to its own operations. A developer who is meticulous about documenting their data flows for compliance is likely also meticulous about their code quality, security threat modeling, and customer support. It is a proxy for operational excellence, much like a chef who keeps their kitchen immaculately clean gives you confidence in the meal to come. When a developer makes their subprocessor list easy to find and understand, they are communicating a message of confidence and transparency, showing they have nothing to hide in their digital supply chain. Think about the alternative. An app developer who hides this information, buries it in dense legal text, or simply does not have a list prepared is sending a very different signal. It could mean several things, none of them good. It might mean they have not performed proper due diligence on their own vendors, perhaps choosing a subprocessor based on the lowest price without performing a security assessment or checking for SOC 2 compliance. It could mean they are using cheap or questionable services they would rather you not know about, like an obscure hosting provider with poor security practices or an analytics service that might be reselling data. In some cases, it may simply indicate a lack of operational maturity, a small, disorganized team that has not considered the broader compliance implications of their own architecture and lacks a response plan for a breach notification from their own vendors. Whatever the reason, the result for you, the store owner, is the same: increased risk and uncertainty. You are left to wonder who is really handling your customer data and whether they can be trusted. This transparency builds a foundation of trust that is essential for a long-term partnership. In a crowded Shopify App Store, where thousands of apps compete for your attention, signals of quality are paramount. A public subprocessor list, complete with details about what each service does and where data is processed, allows you to make an informed risk assessment before you install. It turns a potential liability into a demonstration of the developer's commitment to security and privacy. This is why many of the most respected SaaS companies now feature "Trust Centers" on their websites, which provide a single, public location for all security, privacy, and compliance documentation, including security whitepapers, certifications, and system status. This practice, once confined to enterprise software, turns a legal obligation into a competitive advantage by showing customers that you take their data as seriously as they do. As a store owner evaluating a new tool, this should be one of your key vetting criteria. A Practical Guide: Where to Find the Subprocessor List (and What to Look For) Knowing you need to check an app's subprocessors is the first step. The next is knowing where to look and how to interpret what you find. This information is not always in the same place, but a systematic search can quickly reveal how transparent an app developer truly is. The most common and reputable location for this disclosure is on the app developer's own website, typically linked from the footer. Look for pages titled "Subprocessors," "Trust Center," "Privacy," "Security," or "Legal." A mature developer will often have a dedicated page that does more than just list names; it will explain what each service is used for and might even include a changelog to notify customers of updates. This is the gold standard because it is a living document that can be updated instantly, unlike a static terms of service document that may become outdated. If you have checked the website and legal documents and still cannot find a clear list, this is a significant red flag. Your last resort is to contact the app's support team and directly ask for their list of subprocessors. A quality developer should provide this information promptly and without hesitation; if they are evasive, cannot produce a list, or do not understand the request, you should not trust them with your data. The Shopify App Store listing itself is rarely the source for this information, as it is managed by the developer on their own site. Once you locate the list, your evaluation must scrutinize its content. A truly transparent disclosure will include three key pieces of information for each subprocessor: the company name, the specific purpose of the processing, and the geographic location of data storage. Look for reputable, well-known companies like Amazon Web Services (AWS) or Google Cloud, a purpose that is specific (e.g., "Transactional Email Delivery," not just "To provide services"), and a data location that aligns with your compliance needs, such as "EU (Ireland)" if you serve European customers. This is crucial for navigating complex data transfer rules like the EU-U.S. Data Privacy Framework. By reviewing this information, you can build a mental map of your data's journey. You can assess whether the vendors are reputable, have necessary certifications like ISO 27001 or a SOC 2 Type II report, and whether the data transfers comply with your own legal obligations. For example, if you have a large EU customer base, seeing data processed in the US under the EU-U.S. Data Privacy Framework is an important detail to verify. This is not about becoming a cybersecurity expert overnight; it is about performing basic, essential due diligence to protect your business and your customers. A vague list should be challenged. A list containing unknown or untrustworthy names should be a deal-breaker. The goal is to move from a position of blind faith in the app developer to one of informed consent, where you understand the full supply chain you are integrating into your business. This simple verification step is one of the most powerful risk mitigation actions you can take. The Worked Example: Analyzing a Real Subprocessor Disclosure To make this process concrete, let's analyze a real-world subprocessor list. We will use the public disclosure from Arbyn as our worked example, not because it is the only correct one, but because it provides a clear and instructive format that aligns with best practices. A transparent disclosure serves as a powerful tool for building trust, and walking through its components reveals how much you can learn about an app's architecture and philosophy before you ever click "Install." The Arbyn page immediately clarifies what a subprocessor is and why the list is being provided, citing GDPR requirements and stating it is "just the honest thing to do." This store owner-first framing sets a tone of partnership rather than grudging compliance, shifting the conversation from legal obligation to ethical transparency and mutual respect between business owners. The list itself is organized into a clear table with four columns: Subprocessor, What we use them for, What they process, and Region. This structure directly answers the key questions a store owner should have. For example, under "Infrastructure," it lists "Render" as the subprocessor. The purpose is clearly stated: "Application hosting, database, background jobs. The servers Arbyn runs on." The data processed is defined as "All Arbyn application data at rest and in transit," and the region is specified as "US." This single entry tells you who hosts the core application, what data they hold, and where it is located. This level of detail is a hallmark of a high-quality disclosure and technical maturity. The list continues with other critical functions. For "AI / LLM inference," it lists the specialized service used to host the open-source AI models for reply drafting. Critically, it notes that customer message text and order details are sent for processing but are "Not stored, not used for training," directly addressing a primary privacy concern for anyone using modern AI tools. For billing, it lists "Shopify Billing," clarifying that Arbyn never sees or handles your credit card details. This is an important security distinction, as it deliberately reduces the app's attack surface by applying the principle of least privilege; the developer cannot lose data they never touch in the first place. The list also includes services for transactional email ("Resend" and "Postmark") and performance/security ("Cloudflare"), each with a clear purpose and scope. By reviewing this list, a store owner can gain a high degree of confidence. They know exactly who is in the supply chain, why they are there, and what security and privacy assurances are in place. This level of detail transforms the subprocessor list from a legal formality into a genuinely useful decision-making tool. This transparency is part of a broader philosophy. Just as Arbyn's pricing is a simple flat rate to eliminate the surprise bills common with per-ticket pricing models, the subprocessor list is designed to eliminate surprises in data handling. The common thread is the reduction of uncertainty for the store owner, both financial uncertainty from unpredictable bills and security uncertainty from a hidden data supply chain. A developer who commits to clarity in both areas demonstrates a consistent, store owner-focused philosophy that respects your business as much as you do. The next time you evaluate an app, hold it to this standard. Ask for a list this clear. If the developer cannot provide one, it is worth asking yourself what they might be hiding, and whether that is a risk you are willing to take with your customers' data. When you are ready for a support and sales agent that is as transparent about its data as it is about its pricing, you can install Arbyn from the Shopify App Store. --- ## Pricing - **Arbyn Starter** - $0/month, permanently free. 150 conversations / month. Resets 1st of each month. - **Arbyn Growth** - $59/month flat. 500 conversations / month. Resets 1st of each month. Or $600/year (just under two months free, saves $108, 15% off). - **Arbyn Agent** - $99/month flat. Unlimited conversations. Or $990/year (two months free, saves $198, 17% off). - **There is no trial.** Billing starts immediately on any paid plan. The free Arbyn Starter plan is permanent. - The conversation cap is the only difference between plans. There is no feature gating. ## Channels Live today: **support email** and **on-site live chat**. That is the complete list. SMS, Instagram DMs, Facebook Messenger, WhatsApp and Voice are on the roadmap and are NOT live. Arbyn does not edit orders or change line items. Money-moving actions (cancel, refund, discount, gift card, reship, return) require the store owner's approval, and then Arbyn performs them. Running them fully autonomously is a beta authorization and is in development. Shipping address changes are already autonomous. ## What Arbyn does on a Shopify order - **Change the shipping address**: Live. Arbyn does this on its own. Arbyn updates the shipping address on the Shopify order itself, inside the conversation, and writes the change to the order timeline. - **Cancel an order**: Live. You approve it, then Arbyn cancels the order. Anything that moves money waits for the store owner's approval. That is a deliberate control, not a missing feature. Once you approve, Arbyn fires Shopify's order cancellation itself and confirms it to the customer. - **Issue a refund**: Live. You approve it, then Arbyn issues the refund. Arbyn prepares the refund against the original payment method and sends it to you. On approval it files the refund in Shopify. You can cap the value it is allowed to prepare, per channel. - **Apply a discount**: Live. Arbyn creates a real Shopify discount and applies it to the cart, handing the shopper a checkout with the code already on it. It can also issue a discount code on an order once you approve it. - **Send a gift card, or reship an order**: Live. You approve it, then Arbyn does it. Arbyn creates the gift card, or raises the replacement order, in Shopify once you approve. - **Start a return**: Live. You approve it, then Arbyn opens the return. Arbyn opens the return in Shopify on your approval. - **Look up a gift card or store-credit balance**: Live. Arbyn does this on its own. "Do I have store credit left?" is a question most support tools answer with a human. Arbyn reads the balance itself, for a verified customer or from the code they give you, and reports the masked card, the balance and the expiry. If there is no card, it says so rather than guessing. - **Handle a subscription question**: Live. You choose what it does. Arbyn knows which of your products are sold as a subscription, shows that on the product card in the conversation, and sends a subscriber to their subscription management page to pause, skip or cancel. It answers how your subscriptions work from your own knowledge, but it does not read an individual customer's contract, so it will not state their renewal date or status. Most cancels are a customer with product piling up, and the fix is getting them to the page where they can slow the cadence down. Reading the contract itself is on the roadmap. - **Answer support email and live chat**: Live. Arbyn reads every inbound support email and every chat, works out the intent, pulls the live Shopify context, and replies in your brand voice. Money-moving actions (cancel, refund, discount, gift card, reship, return) require the store owner's approval, and then Arbyn performs them. Running them fully autonomously is a beta authorization and is in development. Shipping address changes are already autonomous.