In short
- This is the complete list of providers that process data as part of running LetBuyy.
- Each entry states what it does and whether it can reach personal data.
- We give notice before adding a sub-processor that handles shopper personal data.
This summary is written to be understood. The clauses below are what actually applies — where the two differ, the clauses govern.
Infrastructure and hosting
These run the platform itself and necessarily hold the data stored in it.
- Supabase — primary database, authentication storage, and file storage. Holds merchant and shopper personal data.
- Cloudflare — edge network, DNS, custom-domain routing, bot protection, and the workers that run the API gateway and background jobs. Sees request metadata and traffic in transit.
- Vercel — hosting for the web applications. Sees request metadata and server logs.
Payments
Razorpay — payment processing, settlement to merchant bank accounts, and refunds. Collects payment credentials directly from shoppers; we hold references, not card numbers. Razorpay is a Reserve Bank of India authorised payment aggregator and is a Data Fiduciary in its own right for the payment data it collects.
Communications
Resend — transactional email delivery: order confirmations, account notices, password resets. Processes recipient email addresses and message content.
Shipping and logistics
Where a merchant connects a courier, that courier receives the delivery address and contact details needed to complete the shipment. Integrations currently available include Shiprocket and Delhivery.
These are connected per store by the merchant. A store that does not connect one does not send data to it.
Monitoring and operations
Sentry — error monitoring. Receives stack traces and request context; configured to scrub credentials and personal data from payloads.
Cloudflare Turnstile — bot protection at registration and login. Receives a challenge token and IP address, not account contents.
Cloudflare Analytics Engine — aggregated operational metrics. Designed for counts and timings rather than individual records.
Changes to this register
We will update this page and notify merchant account holders before a new sub-processor that handles shopper personal data begins processing.
Removing a sub-processor does not require notice.
NoteApps a merchant installs from the marketplace are not our sub-processors. They are separate processors the merchant engages directly, and their data handling is disclosed in their own listing.
Questions about this document
Write to support@letbuyy.com and quote the clause number. For a complaint rather than a question, use the grievance process.