TierlaneHome
Contents
About This ListNotification of Changes1Active Sub-processors2How Tierlane Selects and Manages Sub-processors3Specific Notes on Selected Sub-processors4Change History5Questions and Contact
Legal

Sub-processor List

Effective2026-06-01Updated2026-07-05Version1.4

About This List

This page lists the third parties that Tierlane currently engages to help us deliver the Service (each, a "Sub-processor"). It is published in compliance with Article 28(4) of the EU and UK GDPR, California Consumer Privacy Act §1798.140(ag) (service-provider disclosure), Quebec Law 25 (disclosure of transfers outside Quebec), the LGPD (international transfer disclosure), and Tierlane's Data Processing Agreement (DPA) (available on request at legal@tierlane.app; to be linked at tierlane.app/legal/dpa once published).

This list is incorporated by reference into Tierlane's Privacy Policy (tierlane.app/legal/privacy), Terms of Service (tierlane.app/legal/terms), and DPA.

For definitions of "Service", "Merchant", "Buyer", "Customer Data", "Buyer PII", and "Sub-processor", see Section 2 of the Terms of Service.

How Tierlane receives email: Merchants forward wholesale order emails to a dedicated Tierlane address (<handle>@tierlane.email) using a rule or filter in their own mail client. Tierlane does not connect to, or read, a Merchant's mailbox — there is no Gmail or Outlook OAuth mailbox access. Inbound mail is routed by Cloudflare Email Routing into the parsing pipeline.


Notification of Changes

Tierlane will notify Merchants by email at least 30 days before adding a new Sub-processor that processes Personal Data, and will update this page on the same schedule. Each entry below shows the date on which the Sub-processor was added to this list.

Merchants may object to a new Sub-processor during the notification period by emailing legal@tierlane.app. If a reasonable objection cannot be resolved within 30 days, the Merchant may terminate the portion of the Service affected by the new Sub-processor in accordance with the cancellation terms in the Tierlane Terms of Service.

A complete change history is maintained at the bottom of this page (Section 4).


1Active Sub-processors

The following Sub-processors are active as of the effective date.

Sub-processor Purpose / Category Data Processed Processing Location DPA / Privacy Reference In Use Since
Shopify Inc. App platform, OAuth, Billing API, draft-order creation, catalog read, mandatory privacy webhooks (customers/data_request, customers/redact, shop/redact) Merchant account identifiers, Shopify shop ID, billing records, draft order content, catalog metadata Canada (primary), United States, European Union (regional Shopify infrastructure) shopify.com/legal/dpa 2026-06-01
Cloudflare, Inc. Inbound email routing (Cloudflare Email Routing → Worker for *@tierlane.email), DNS, CDN, WAF, DDoS protection, object storage (Cloudflare R2) for raw inbound-email files (EML) and attachments (purged after 90 days per the retention job), and bot protection (Turnstile) on the public privacy-request form Inbound email envelope (sender, recipient, MIME envelope), short-lived in-transit message buffer, edge request metadata, stored raw EML + attachment objects (R2; 90-day purge) United States — Cloudflare global edge network cloudflare.com/cloudflare-customer-dpa/ 2026-06-01
Anthropic, PBC AI parsing (LLM API) — converting Buyer email text and attachment text into structured draft orders Email subject and body, extracted attachment text, Buyer PII embedded in those (name, email, phone, address, order content). 30-day input/output retention; no training on inputs. United States (with EU SCCs) privacy.claude.com — Anthropic DPA 2026-06-01
Neon, Inc. Primary application database (serverless PostgreSQL) All Tierlane application data: Merchant account, settings, OAuth tokens (encrypted), draft orders, parsed Buyer content (90-day content retention), audit logs United States — us-east-1 (N. Virginia). Provisioned via the Vercel Marketplace integration. neon.tech/dpa 2026-06-04
Vercel Inc. Application hosting and serverless compute (the web app, embedded admin app, and worker functions) Application requests, PII-scrubbed logs, request metadata, edge logs United States (primary). Vercel edge nodes worldwide. vercel.com/legal/dpa 2026-06-01
Microsoft Corporation (Microsoft 365 — Tierlane's business email) Tierlane's own business email (support@, privacy@, legal@, security@). Used to communicate with Merchants and to receive privacy and legal correspondence. Email content received and sent from Tierlane staff inboxes; sender and recipient addresses United States, Canada (Microsoft regional infrastructure for Canadian tenants) microsoft.com/en/trust-center 2026-06-01
Resend Inc. Transactional email delivery (welcome, billing receipts, parsing notifications, security alerts, opt-in product updates) Recipient email address, email subject, email body, sender metadata, delivery status United States (with EU SCCs) resend.com/legal/dpa 2026-06-01
Functional Software, Inc. (Sentry) Error monitoring and crash reporting Application error events with PII scrubbed via Tierlane configuration; user identifier limited to pseudonymous shop_id where logged United States. EU data residency available on Sentry Business plan. sentry.io/legal/dpa 2026-06-01
PostHog Inc. (Cloud EU) Product analytics — pseudonymous, IP-discarded event analytics for the embedded admin app and marketing site Pseudonymous event data identified only by Shopify shop_id; no Buyer PII is sent to analytics; IP addresses discarded at ingestion European Union (PostHog Cloud EU region) posthog.com/privacy; PostHog DPA 2026-06-01
Intuit Inc. (QuickBooks Online) — optional Optional accounting sync (Merchant-enabled): mirror approved Shopify orders/invoices to QuickBooks Invoice and customer data for orders the Merchant elects to sync United States intuit.com/privacy; Intuit DPA 2026-06-01

Optional Sub-processors

Sub-processors marked "optional" only process data if the Merchant has explicitly enabled the relevant integration (e.g., turning on the QuickBooks sync). If a Merchant does not enable an optional integration, no data is sent to that Sub-processor.


2How Tierlane Selects and Manages Sub-processors

Before engaging a Sub-processor, Tierlane:

  • Reviews the Sub-processor's published security and privacy posture (encryption in transit and at rest, access controls, certifications such as SOC 2 / ISO 27001 / ISO 27701, EU-US Data Privacy Framework certification where available, GDPR compliance materials, and breach history).
  • Executes a written Data Processing Agreement that imposes obligations no less protective than those in our DPA with Merchants, including Article 28(3) GDPR / Article 28(3) UK GDPR terms, EU Standard Contractual Clauses or the UK IDTA / Addendum for international transfers, CCPA service-provider terms, LGPD international transfer terms, and Brazilian SCCs for transfers from Brazil to the United States.
  • Documents the legal basis for cross-border transfers and, where required by Quebec Law 25 or the GDPR, completes a Privacy Impact Assessment / Transfer Impact Assessment.
  • Reviews the Sub-processor's security and privacy posture periodically (at least annually for vendors processing Buyer PII; on material change otherwise).

Tierlane remains responsible to Merchants for the acts and omissions of its Sub-processors with respect to Personal Data as required by Article 28(4) GDPR.


3Specific Notes on Selected Sub-processors

3.1 Email ingestion (Cloudflare Email Routing — not mailbox OAuth)

Inbound order emails reach Tierlane only because the Merchant configures a forwarding rule in their own mail client to <handle>@tierlane.email. Cloudflare Email Routing receives that mail and hands it to a Tierlane Worker, which signs and posts it to the parsing pipeline. Tierlane holds no OAuth credential for, and no standing access to, any Merchant mailbox. Cloudflare also provides object storage (R2) for raw inbound-email files and attachments, in the same processing role and subject to the same DPA; these objects are deleted by the 90-day retention job.

3.2 Anthropic, PBC (AI parsing)

  • Anthropic is Tierlane's AI parsing provider. Tierlane uses Anthropic's API and not its consumer products.
  • Anthropic does not train its models on data submitted by API customers.
  • API inputs and outputs are retained by Anthropic for a maximum of 30 days for abuse-monitoring purposes, then deleted, unless the customer has separately requested zero-retention (Tierlane is on the default 30-day retention).
  • Cross-border transfers from the EU/EEA and the UK are covered by the EU Standard Contractual Clauses and UK Addendum / IDTA executed in Anthropic's DPA.
  • For the avoidance of doubt, Tierlane sends Anthropic only what is needed to parse a single email or attachment into a single draft order: the email body and extracted attachment text (or attachment image), together with Tierlane's fixed parsing instructions. The Merchant's product catalog is never sent to Anthropic — the parsing prompt operates without catalog knowledge by design, and matching parsed lines to the Merchant's products happens entirely within Tierlane's own database.

3.3 Shopify Inc.

  • Shopify is both the platform on which Tierlane runs and the billing operator for Tierlane subscriptions (via the Shopify Billing API). Shopify is also the operator of the mandatory privacy webhooks (customers/data_request, customers/redact, shop/redact).
  • The Merchant's primary relationship is with Shopify, not Tierlane, for the underlying e-commerce platform. Shopify's privacy and security commitments to the Merchant are governed by Shopify's own terms and DPA.

3.4 Neon, Inc. (primary database)

  • Neon is Tierlane's primary PostgreSQL database (US us-east-1), provisioned through the Vercel Marketplace integration.
  • Data at rest is encrypted by managed infrastructure; OAuth tokens are additionally encrypted at the application layer (AES-256).
  • Parsed Buyer email content is purged after 90 days by a scheduled job; draft-order records persist for the life of the account plus the soft-delete window.
  • Point-in-Time Recovery (PITR) is provided by Neon's Launch tier with a 7-day window.

3.5 PostHog Inc. (Cloud EU)

  • Tierlane uses PostHog Cloud EU, the European-region instance of PostHog Inc.'s managed analytics platform. Events are sent to PostHog's EU infrastructure (eu.posthog.com).
  • IP addresses are discarded at ingestion. Person profiles are identified only by Shopify shop_id. Autocapture is disabled on the admin app; only explicit, named events are captured.
  • Event data retention: 90 days.
  • Cross-border transfers from the EU/EEA are intra-EU (PostHog Cloud EU is hosted in the European Union). PostHog Inc.'s standard DPA applies (linked in §1).

3.6 Sentry (Functional Software, Inc.)

  • Sentry receives PII-scrubbed error events. Tierlane configures Sentry with sendDefaultPii: false, server-side scrubbing for buyer email/phone/name patterns, and ignoreErrors rules for known PII-containing error categories.
  • Sentry retention: 90 days.

3.7 Microsoft 365 (Tierlane's business email)

  • Tierlane's staff inboxes (support@, privacy@, legal@, security@) are hosted on Microsoft 365.
  • Personal information you send Tierlane by email — for example, a privacy request or a support enquiry — is processed and stored in this environment. We aim to limit the personal information you send us by email to what is necessary to address your request.

4Change History

A record of changes to the Sub-processor list is maintained here so that Merchants can verify when each Sub-processor was added, modified, or removed.

Date Change Notes
2026-06-01 Initial publication of Sub-processor list All entries added on initial publication.
2026-07-05 v1.4 — Anthropic data-scope corrected; EU-residency offer removed Corrected §3.2: the previous text stated the parsing prompt "includes the Merchant's catalog snippets" — it does not and never has. The parsing prompt is deliberately catalog-blind (the model states it is not given the catalog); only email/attachment content plus fixed instructions are sent, and product matching happens in Tierlane's own database. This narrows the described data scope to match the shipped system. Also removed the §5 offer to "request an EU data-residency deployment" — no such deployment is currently offered (see the Privacy Policy's US-processing disclosure); the offer will return if and when it exists. No change to the sub-processor set.
2026-06-23 v1.3 — Anthropic retention corrected Corrected the stated Anthropic Claude API input/output retention to 30 days, matching Anthropic's organization-default retention; the previously stated "7 days" was a documentation error. No change to Tierlane's processing, data categories, or sub-processor set.
2026-06-11 v1.2 — Supabase removed; Cloudflare role expanded Removed Supabase Inc. — file/object storage migrated to Cloudflare R2 on 2026-06-06; Supabase no longer processes any Service data. Expanded Cloudflare, Inc. entry to cover R2 object storage (raw EML + attachments, 90-day purge) and Turnstile bot protection on the privacy-request form. No new sub-processor engaged.
2026-06-04 v1.1 — reconciled to shipped architecture Added Neon, Inc. as the primary application database. Reclassified Supabase Inc. as file/object storage only (the application database moved to Neon). Removed Google LLC (Gmail OAuth) and Microsoft Corporation (Outlook / Microsoft 365 OAuth) mailbox-access entries — Tierlane is forwarding-only and holds no OAuth credentials for Merchant mailboxes. Removed Xero Limited — not currently offered. Clarified Cloudflare's role as the inbound email router. Updated change-notification window from 15 days to 30 days.

When a new Sub-processor is added, this table will be updated and Merchants will receive at least 30 days' prior notice by email.


5Questions and Contact

For questions about this Sub-processor list, to object to a proposed new Sub-processor, or to receive a copy of a Sub-processor's executed DPA or SCCs (subject to redaction of commercially sensitive terms):

  • Privacy inquiries: privacy@tierlane.app
  • Legal inquiries: legal@tierlane.app
  • Security incidents: security@tierlane.app
  • General contact: support@tierlane.app

Published by Tierlane · Ontario, Canada.

Tierlane
Privacy PolicyTerms of ServiceCookie PolicyAcceptable UseSub-processorsPrivacy Choices
© 2026 Tierlaneprivacy@tierlane.app