Sub-processors
Last updated: 2026-07-20
SkuVitals uses a small number of service providers ("sub-processors") to operate the App. We limit the data shared with each to what is necessary, and we do not share your customers' personal data — because we do not store any.
Current sub-processors
| Sub-processor | Purpose | Data involved |
|---|---|---|
| Shopify | The platform the App runs on: Admin API access to your catalog/inventory/order aggregates, and subscription billing via the Shopify Billing API | Store, catalog, inventory, and order-aggregate data; billing is handled entirely by Shopify — we never receive card details |
Laravel Forge |
Application hosting and the PostgreSQL database where store and catalog data is held | All store data described in our Privacy Policy(/legal/privacy-policy) |
| Resend | Transactional email delivery: the daily inventory-health digest, stock alerts, scheduled reports, and login verification codes | The recipient's email address (a store owner/staff address) and the message content, which is your own inventory-health aggregate data — no customer personal data |
| Lognitor | Error and reliability telemetry (only when enabled) | Exception details and technical context, with access tokens and any personal data scrubbed before sending; user identification is disabled |
| Google Analytics | Aggregate traffic analytics for the public marketing website only (never the embedded App), and loaded only after the visitor consents | Website-visitor usage data — pages viewed, device/browser, and approximate location (IP anonymised); no store, catalog, or customer data |
Not used
- No separate file-storage sub-processor. Generated export files are stored on the App's own server filesystem and deleted after their download window; we do not use a third-party object store for them.
- No advertising or cross-site tracking sub-processors. The embedded App uses no analytics at all; the public marketing website uses only Google Analytics (listed above), and only with your consent — see our Cookie Notice(/legal/cookies).
Data protection
We can provide a Data Processing Addendum (DPA) on request at hellogrenz@gmail.com. Consistent with Shopify's
requirements, we practise data minimisation, encrypt access tokens at rest, and maintain records of processing
activities.
Changes
We will update this page before adding or changing a sub-processor. Where a change is material, we will post the updated list here before it takes effect, so you can review the current sub-processors at any time or contact us with questions.
SkuVitals