Current subprocessors
Adherely uses the providers below only for the stated operational purposes. They are subject to contractual and legal data-protection obligations appropriate to their roles.
| Provider | Purpose | Data involved |
|---|---|---|
| Vercel | Application hosting, delivery, and operational request logs | Merchant and consumer service data processed by the hosted application; limited request and device metadata |
| Supabase | Managed PostgreSQL database and scheduled database operations | Merchant configuration, minimized commerce records, participant, consent, message, check-in, progress, and reward data |
| Clerk | Merchant account authentication and session security | Merchant account identifiers, authentication factors, and login or session metadata |
| Twilio | Consumer phone verification and requested SMS delivery | Phone numbers, verification and delivery metadata, SMS content, replies, and opt-out events |
Customer-directed integrations
Shopify is a merchant-authorized commerce integration rather than an Adherely-selected infrastructure subprocessor. A merchant directs the connection to its own Shopify store, and Shopify's separate terms govern that merchant account. Adherely minimizes order data before storing it and uses the connection only for merchant-requested program, attribution, and eligible reward actions.
Changes and objections
Before a material new subprocessor begins processing merchant customer data, Adherely will notify affected merchants through their account contact email or dashboard. Under the Data Processing Addendum, a merchant may raise a reasonable data-protection objection within 15 days after notice.
Questions about a provider or its role can be sent to privacy@adherely.co.