Subprocessors and Data Locations

Current standard-service providers and customer-directed recipients

Tomorrowfy GmbH · Version 1.3 · Effective 21 August 2026

About this list

This document describes providers that may process Customer Data for Tomorrowfy’s standard services. A provider is used only where the relevant feature or workflow requires it. Processing location includes remote support access and provider subprocessors where applicable, not only the location of the primary database.

Core and optional subprocessors

Google Cloud

Subprocessor

Purpose
Cloud Run compute, Firestore, BigQuery, Pub/Sub, Cloud Tasks, logging, monitoring, secret management, deployment infrastructure, and optional Vertex AI.
Data
Customer account, Shopify, subscription, order, contact, address, configuration, credentials, analytics, logs, support, and AI prompt/query-result data as required by enabled functions.
Locations
Primary Firestore, BigQuery, and backend compute: europe-west3 (Frankfurt, Germany). Google support and subprocessors may access data globally. Vertex AI currently uses a global endpoint for Gemini 3 and may process requests outside the EEA; other configured models may use us-central1.
Safeguard and notes
Google Cloud Data Processing Addendum; 2021 EU Standard Contractual Clauses and supplementary measures for restricted transfers. Google states that Vertex AI customer data is not used to train or fine-tune models without permission, subject to its terms and configured retention controls.

Vercel, Inc.

Subprocessor

Purpose
Hosting and global delivery of the EverSubs frontend, server-side Next.js API routes, deployment, runtime logs, and performance telemetry.
Data
Application requests, merchant and end-customer identifiers, session and request metadata, data passed through API routes, deployment data, and performance data.
Locations
Current production server functions: iad1 (Washington, D.C., USA). Static and edge delivery: global. Vercel and its subprocessors may process data in the United States and other locations under its DPA.
Safeguard and notes
Vercel DPA with 2021 EU Standard Contractual Clauses and listed supplementary measures. The production execution region is disclosed as currently configured, and this document will be updated if that configuration changes.

Twilio SendGrid

Optional subprocessor — only when Tomorrowfy-managed email delivery is enabled

Purpose
Sending transactional subscription, billing, payment-action, and delivery emails for Customers that enable Tomorrowfy-managed email delivery.
Data
Recipient and sender email addresses, first name, product/order/subscription details, relevant dates, template variables, message identifiers, delivery status, and links required for the message.
Locations
United States and Twilio/SendGrid infrastructure and subprocessors in North America and the EU. SendGrid email-activity data is stored in the United States unless a supported regional configuration applies.
Safeguard and notes
Twilio Data Protection Addendum; 2021 EU Standard Contractual Clauses for SendGrid restricted transfers. Twilio states that it does not retain email body content as part of standard sending, while email delivery metadata and activity may be retained under service settings, commonly up to 30 days. SendGrid is not used merely because a Customer enables Klaviyo or another customer-directed integration.

DeepL SE

Conditional subprocessor

Purpose
On-demand translation of text submitted by an authorized merchant user.
Data
Text submitted for translation and language settings. Personal data should be avoided unless needed and lawfully submitted.
Locations
DeepL operates hybrid infrastructure in Europe and AWS regions in Europe, the United States, and Asia-Pacific. By default, content may be processed in different regions unless a data-residency option is purchased and configured.
Safeguard and notes
DeepL Pro/API Pro data-protection terms; SCCs and EU–US Data Privacy Framework where applicable to AWS. DeepL states that paid-service translation text is processed to return the translation, is not used for model training outside the account, and is not stored after processing unless a saving feature is used.

Slack Technologies Limited / Salesforce

Conditional subprocessor

Purpose
Selected operational alerts, including billing exceptions and manual privacy/redaction workflows.
Data
Shop domain, customer or subscription identifier, links, billing-challenge status, and — where a privacy request is received — customer email or request details.
Locations
Global, including the United States.
Safeguard and notes
Slack/Salesforce data-protection terms and 2021 EU Standard Contractual Clauses; EU–US Data Privacy Framework where applicable. Tomorrowfy should minimize alert content and avoid copying unnecessary personal data into Slack.

Google Workspace

Subprocessor for business communications and administration

Purpose
Customer support, privacy and security communications, document collaboration, and account administration.
Data
Business contact details, support correspondence, security/privacy request details, and documents users choose to send.
Locations
According to Tomorrowfy's Workspace edition and configured data-region policy. Covered data may be stored in Europe if the eligible policy is enabled; Google support and subprocessors may operate globally.
Safeguard and notes
Google Cloud Data Processing Addendum and applicable 2021 EU Standard Contractual Clauses. Customers should avoid sending passwords, full payment data, or unnecessary special-category data by email.

Independent recipient

Google Maps Platform

Independent controller under Google's applicable Maps terms — not a Tomorrowfy subprocessor

Purpose
Geocoding delivery addresses to determine coordinates or an eligible fulfillment location when the delivery-location feature is used.
Data
Address line, city, state/province, postal code, and country; Google may also receive request and network metadata.
Locations
Global Google infrastructure.
Safeguard and notes
The Customer instructs the disclosure by enabling or using the feature. Google's Controller-Controller Data Protection Terms apply. Tomorrowfy limits the submitted address fields to those required for geocoding.

Customer-directed services

The following destinations are not Tomorrowfy-appointed subprocessors. They are selected, configured, and controlled by the Customer. The Customer is responsible for its contract, privacy notice, legal basis, and transfer mechanism for the destination.

  • Shopify — the Customer's commerce platform and primary source and destination for store, customer, order, subscription, payment-status, and product data;
  • Klaviyo — commonly used optional customer-directed integration. When enabled, Tomorrowfy uses Customer-provided Klaviyo credentials to send the selected event categories to the Customer's Klaviyo account. Depending on the enabled events, this may include the customer's email address; customer, subscription, and order identifiers; subscription status and dates; billing or payment-action information; cancellation information; and related event metadata. Klaviyo is contracted and controlled by the Customer and is not a Tomorrowfy-appointed subprocessor;
  • Emarsys — optional customer-configured marketing and customer-status integration;
  • Customer-owned BigQuery project — optional export destination selected by the Customer; and
  • Custom HTTP webhooks — endpoints and payloads configured by the Customer.

Operational vendor not intended to receive production Customer Data

GitHub, Inc. / GitHub B.V.

Development and CI/CD vendor — not used as a production Customer Data store

Purpose
Private source-code hosting, pull requests, issue tracking, and automated deployment workflows.
Data
Source code, configuration without production secrets, developer identities, commit metadata, and CI/CD metadata. Production Customer Data is not intended to be placed in GitHub.
Locations
United States and other GitHub/subprocessor locations.
Safeguard and notes
GitHub data-protection terms and transfer mechanisms apply to organization data. Personnel must not place production Customer Data, secrets, or support exports in repositories or issue content.

Change notice and objections

Tomorrowfy provides notice of a new subprocessor under the DPA, normally by email to the Customer’s contract or privacy contact at least 30 days before processing begins. Customers may send a reasonable data-protection objection to privacy@tomorrowfy.com within 14 days of notice. Urgent security or continuity replacements may be notified without undue delay after appointment.

Contacts