Sub-processors

Last updated: 2026-07-20

SkuVitals uses a small number of service providers ("sub-processors") to operate the App. We limit the data shared with each to what is necessary, and we do not share your customers' personal data — because we do not store any.

Current sub-processors

Sub-processor Purpose Data involved
Shopify The platform the App runs on: Admin API access to your catalog/inventory/order aggregates, and subscription billing via the Shopify Billing API Store, catalog, inventory, and order-aggregate data; billing is handled entirely by Shopify — we never receive card details
Laravel Forge Application hosting and the PostgreSQL database where store and catalog data is held All store data described in our Privacy Policy(/legal/privacy-policy)
Resend Transactional email delivery: the daily inventory-health digest, stock alerts, scheduled reports, and login verification codes The recipient's email address (a store owner/staff address) and the message content, which is your own inventory-health aggregate data — no customer personal data
Lognitor Error and reliability telemetry (only when enabled) Exception details and technical context, with access tokens and any personal data scrubbed before sending; user identification is disabled
Google Analytics Aggregate traffic analytics for the public marketing website only (never the embedded App), and loaded only after the visitor consents Website-visitor usage data — pages viewed, device/browser, and approximate location (IP anonymised); no store, catalog, or customer data

Not used

  • No separate file-storage sub-processor. Generated export files are stored on the App's own server filesystem and deleted after their download window; we do not use a third-party object store for them.
  • No advertising or cross-site tracking sub-processors. The embedded App uses no analytics at all; the public marketing website uses only Google Analytics (listed above), and only with your consent — see our Cookie Notice(/legal/cookies).

Data protection

We can provide a Data Processing Addendum (DPA) on request at hellogrenz@gmail.com. Consistent with Shopify's requirements, we practise data minimisation, encrypt access tokens at rest, and maintain records of processing activities.

Changes

We will update this page before adding or changing a sub-processor. Where a change is material, we will post the updated list here before it takes effect, so you can review the current sub-processors at any time or contact us with questions.