Radiant Size Chart
Subprocessors
1. Operator
DAWSEN SA, trading as Ash Spark, operates Radiant Size Chart from Juan María Pérez 2965, CP 11300, Montevideo, Uruguay. This page identifies providers that can process merchant or limited order-linked personal data to deliver the service.
The processing roles and merchant authorization are described in the Data Processing Addendum.
2. Shopify
Purpose: commerce platform, app installation and authentication, Admin and storefront APIs, hosted app pricing and billing, consent signals, order and return references, and privacy request delivery.
Processing location: Shopify and its providers operate globally under Shopify's published privacy, security, and transfer terms. Shopify also has a direct relationship with each Merchant.
3. Vercel, Inc.
Purpose: application hosting, serverless runtime, content delivery, request processing, security controls, deployment, and operational logging.
Processing location: primarily United States and the global locations used by Vercel and its providers. Vercel publishes a data-processing addendum, transfer safeguards, subprocessor list, and encryption controls for data at rest and in transit.
4. Supabase Pte. Ltd.
Purpose: managed PostgreSQL database, connection pooling, database security, monitoring, and provider-managed backups.
Processing location: Radiant's production database is hosted in the United States, East region. Supabase publishes a data-processing addendum, transfer safeguards, subprocessor list, and encryption controls for data and backups.
5. Google Cloud Platform (Pub/Sub)
Purpose: authenticated delivery, queueing, and retry of Shopify app-lifecycle, access-scope, and mandatory privacy webhooks to Radiant, including customer data-access and deletion requests and shop-deletion events. This use does not include the optional support chat.
Processing location and retention: Radiant's production Cloud Billing payments profile is an organization in Mexico. Google's published contracting-entity table identifies Google Cloud México, S. de R.L. de C.V. for Mexico, unless otherwise agreed with Google. The production topics do not set an explicit Pub/Sub message-storage policy, so storage is not pinned to a specific region at the topic level; Google's default location behavior and its data-processing and transfer terms apply. The production source topic retains published messages for up to 7 days, including messages already acknowledged by its subscription. The dead-letter topic retains published dead-letter messages for up to 31 days. The source and dead-letter monitoring subscriptions use those same respective windows and do not add separate acknowledged-message retention.
6. Changes and objections
We update this page when a provider begins materially different processing. Merchants may object on reasonable data-protection grounds by emailing info@ashspark.com. Include the Shopify store domain and the provider concerned, but do not include credentials, payment data, or shopper body details.
Providers used only for optional features are added here before those features process merchant-controlled personal data in production.
