Skip to content
Install on Shopify

Transparency

The full list of who touches your data.

Arbyn uses a small number of third-party services to run. They are listed here, by name, with what they process and where. We update this page before adding anyone new.

Total subprocessors
24
Last updated
August 9, 2026
Change notice
30 days before
What is a subprocessor?

A subprocessor is any third-party service Arbyn uses to operate, where that service might touch your data along the way. GDPR Article 28 requires us to disclose them. It’s also just the honest thing to do. This page is the full list. Nobody else.

The list

24 services. Every one we use.

Each row shows what the vendor does, what they process, where they host it, and their security certifications. Every name links to their own privacy or data processing page so you can check them directly.

SubprocessorWhat we use them forWhat they processRegionLegal / trust
Infrastructure
Google Cloud
Google LLC · US
SOC 2 Type 2SOC 3ISO/IEC 27001
Application hosting, database, background jobs. The servers Arbyn runs on: Cloud Run for compute, Cloud SQL for the database.All Arbyn application data at rest and in transit. Encrypted at rest by Google Cloud SQL.US (us-central1)
Council Bluffs, Iowa
Vercel
Vercel Inc. · US
SOC 2 Type 2ISO 27001GDPR / DPF
Hosts and serves the arbyn.app marketing website and its API routes. Distinct from Google Cloud above, which runs the Arbyn app.Website request data in transit, including IP address and user agent, plus anything a visitor submits through a form on the way to storage.US (iad1)
Global edge network
Neon
Neon Inc. · US
SOC 2 Type 2ISO 27001
The Postgres database behind the arbyn.app marketing website: published content, and everything a visitor submits to us.Contact-form submissions, newsletter and subprocessor-notice subscriptions, privacy-request records and cookie-consent records. Website-visitor data, not your store's or your shoppers'.US (AWS us-east-2)
Vercel Blob
Vercel Inc. · US
SOC 2 Type 2ISO 27001
Stores images uploaded through the arbyn.app admin, such as blog and changelog artwork.Published media files only. No customer data and no store data.US
AI / LLM inference
Deep Infra
Deep Infra, Inc. · US
No-training policy
Hosts the open-source AI models Arbyn uses for all reasoning, sales suggestions, and reply drafting.Your customers' message text and order details, sent so the AI can draft a reply. Not stored, not used for training.US
Commerce platform
Shopify
Shopify Inc. · CA
SOC 2 Type 2PCI-DSS
Source of order, customer, catalog, and policy data. Arbyn reads via Shopify API.All commerce data already lives there. Arbyn pulls, doesn't store duplicates long-term.Per store
Set by store owner
Billing & payments
Shopify Billing
via Shopify App charges · CA
PCI-DSS
All Arbyn subscriptions are charged through your Shopify admin. We never see your card.Subscription metadata. No card details ever touch Arbyn.Per Shopify
Transactional email
Resend
Resend, Inc. · US
SOC 2 Type 2
Sends email from the arbyn.app marketing site: contact-form replies, subscription confirmations and notice-list mail.Email addresses and message bodies for transactional sends from the marketing site only. No marketing lists.US
Postmark
ActiveCampaign LLC · US
SOC 2 Type 2HIPAA
Sends and receives email for the Arbyn APP (a different surface from Resend above): inbound support mail, and forwarding to your inbox when a customer conversation is relayed or escalated.Email addresses, message bodies, and conversation context routed through their service. Delivery logs kept per Postmark's policy. Not used for training.US
CDN & DDoS
Cloudflare
Cloudflare, Inc. · US
SOC 2 Type 2ISO 27001
DNS, CDN, and DDoS protection for the Arbyn dashboard and chat widget.HTTPS traffic in transit. Cached static assets only.Global edge
Website analytics
Microsoft Clarity
Microsoft Corporation · US
Consent-gatedText masked
Anonymized session replay and heatmaps on the arbyn.app marketing site. Loads only after the visitor grants the Session recording category.Masked page interactions (clicks, scrolls) on the marketing site. No form or message content, and never on the dashboard or chat.US
Customer.io
Peaberry Software, Inc. (Customer.io) · US
Consent-gatedSOC 2 Type 2GDPR / DPF
Customer engagement on the marketing site: lifecycle email plus on-site behavioural analytics (a CDP). Loads only after the visitor grants the Analytics category, and identifies a visitor only if they give us their email.Email address, name, on-site page views and events, device/browser and coarse location. Marketing-site visitors only, never the dashboard or chat.US
PostHog
PostHog, Inc. · US
Consent-gatedSOC 2 Type 2GDPR
Product analytics on the marketing site, with optional masked session recording. Analytics loads only after the visitor grants the Analytics category; session recording runs only if they also grant the Session recording category.On-site page views and events, device/browser and coarse location; masked session recordings only with Session recording consent. Marketing-site visitors only.US
Google Tag Manager
Google LLC · US
Consent Mode v2
Tag container on the arbyn.app marketing site. Delivers the analytics and advertising tags we configure, under Google Consent Mode.Page views and events from marketing-site visitors, plus the consent state that decides which tags may fire. Never on the dashboard or chat.US
Google Analytics
Google LLC · US
Consent-gatedConsent Mode v2
Traffic and conversion analytics for the arbyn.app marketing site, and conversion events (sign-up, purchase) from the Arbyn app. Loads only after the visitor grants the Analytics category.Page views, events, device/browser and coarse location for marketing-site visitors; store-level conversion events including currency and value from the app.US
Website advertising
Meta Pixel
Meta Platforms, Inc. · US
Consent-gated
Measures Arbyn's own ad campaigns and conversions on the marketing site. Loads only after the visitor grants the Marketing category.Hashed email and conversion events for ad measurement, from the browser and the server-side Conversions API. Marketing-site visitors only.US
LinkedIn Insight Tag
LinkedIn Corporation · US
Consent-gated
Measures Arbyn's own LinkedIn ad campaigns on the marketing site. Loads only after the visitor grants the Marketing category.Ad-measurement identifiers for marketing-site visitors. Never on the dashboard or chat.US
Reddit Pixel
Reddit, Inc. · US
Not yet active
Advertising conversion measurement, not yet active: Arbyn lists the Reddit Pixel here ahead of launch. Once enabled, it will measure Arbyn's own Reddit ad campaigns and conversions on the marketing site and will load only after the visitor grants the Marketing category.Hashed email and conversion events for ad measurement, from the browser pixel and the server-side Conversions API. Marketing-site visitors only.US
Support tooling
Intercom
Intercom, Inc. · US
SOC 2 Type 2
The support chat WE use to talk to store owners on arbyn.app, and the store context Arbyn attaches to it so a conversation with our team starts with the facts. Not a channel Arbyn answers your customers on.Store-owner support context sent in a signed token: plan, CSAT, conversation cap, escalations and revenue figures. Store-owner data, not your shoppers' data.US
Product analytics
Mixpanel
Mixpanel, Inc. · US
SOC 2 Type 2
Product analytics for the Arbyn app: installs, plan changes, and conversation events.Store-level event properties: shop id and domain, store name, country, currency, plan and billing status. Separate development and production projects.US
Address validation
Geocodio
Dotsquare LLC (Geocodio) · US
No-training policy
Validates and corrects a shipping address when Arbyn handles an address change on an order.Your customer's shipping address: street, unit, city, state, postcode and country.US
Google Address Validation API
Google LLC · US
Google Cloud DPA
Second address check on an agent-handled address change, returning validation granularity and a formatted address. The same flow also calls Google's Time Zone API.Your customer's shipping address, and the geographic coordinates derived from it when the time zone is looked up.US
Google Places API
Google LLC · US
Google Cloud DPA
Classifies a shipping address as residential, commercial or a known parcel-forwarding service, so Arbyn can flag a risky delivery.Your customer's shipping address, sent as a text query.US
Analytics and attribution
Shoffi
Shoffi
Affiliate and referral attribution when a store installs the Arbyn Shopify appYour shop domain, the Arbyn Shopify app id, and the IP address of the install request. Sent once, when the app is installed. No shopper data, no conversation content, no order data, and nothing at all after the install.Not publicly disclosed by the vendor

If we add a new one, you find out first.

No surprise vendors. No “we updated our DPA, please re-read 38 pages.”

Subscribe to subprocessor change notices and we’ll email you whenever this list changes. Standard 30 days notice. Object in writing and we’ll work it out, or you can cancel and your data is deleted.

Change notices only. This list is separate from anything marketing, and it has its own unsubscribe.

  • 01
    30 days before any new subprocessor is added, we email subscribers and update this page.
  • 02
    Any store owner on the notice list can object. If we can't address your objection, you can cancel.
  • 03
    If you cancel, your data is deleted within 30 days. We keep only the minimum logs the law requires.
Document version
August 9, 2026
This page is the source of truth. Earlier versions available on request.
Questions
privacy@arbyn.app
For privacy questions, data processing agreements, or GDPR requests.