Truefold — Sub-processor Register
Version 1.0 — Effective 2026-08-27 · Published at truefold.ai/legal/subprocessors · Forms Annex III to the Truefold Merchant DPA
Last updated: 2026-08-28
Truefold (operated by Auke Vos, Mexico) engages the following sub-processors to provide its service. Merchants receive at least 30 days' notice before a new sub-processor that processes Customer Data is added (DPA § 6). "Customer Data" below means merchant end-customer data as minimised at ingestion (see the Data Use Disclosure): pseudonymised email hash, platform IDs, order/financial data, catalog data, coarse geography, consent flags — no plaintext names, emails, addresses, phone numbers or IPs are stored anywhere in this chain.
Active sub-processors
| Sub-processor | Entity | Service | Data processed | Location / region | Transfer mechanism |
|---|---|---|---|---|---|
| Google Cloud — BigQuery | Google LLC (US) | Data warehouse holding each merchant's isolated dataset | Minimised Customer Data (the persistent store) | United States by default; EU multi-region for EU merchants (per-merchant dataset pinning) | Provider DPA (Google Cloud Data Processing Addendum) incorporating SCCs; Google LLC is EU-US Data Privacy Framework certified |
| Google Cloud — Vertex AI (Gemini) | Google LLC (US) | AI model serving for the chat assistant, dashboard generation and semantic-model drafting | Natural-language questions, schema/metadata, and PII-filtered query results (server-side guardrails block personal-data columns from query output). Not used for model training | United States | Same as above |
| Supabase | Supabase, Inc. (US) | Application database (Postgres), authentication, file storage | Merchant account data (user names, emails, credentials), the semantic data model (metadata), chat and query logs (literal values redacted; results PII-filtered), encrypted connector credentials, future data-subject-export files | United States | Provider DPA incorporating SCCs |
| Railway | Railway Corp. (US) | Backend application hosting (API + sync engine) | Customer Data in transit and in memory during synchronisation — including full raw API responses momentarily, before minimisation is applied at the storage layer. No persistent Customer Data storage | United States | Provider DPA incorporating SCCs |
| Vercel | Vercel Inc. (US) | Web application hosting and delivery | Merchant account/session data; Customer Data query results in transit to the merchant's browser. No persistent Customer Data storage | United States (edge network global) | Provider DPA incorporating SCCs; Vercel is EU-US Data Privacy Framework certified |
Contingent sub-processors (AI fallback)
Truefold's AI engine is provider-agnostic. The following are configured as fallback model providers and are not in active use; if activated, they would receive the same category of data as Vertex AI above (questions, metadata, PII-filtered results — never raw stored records, never for training). Their listing here constitutes advance notice under DPA § 6.
| Sub-processor | Entity | Service | Location | Transfer mechanism |
|---|---|---|---|---|
| Anthropic | Anthropic, PBC (US) | Fallback AI model provider (Claude) | United States | Provider Commercial Terms + DPA incorporating SCCs |
| OpenAI | OpenAI, LLC (US) | Fallback AI model provider | United States | Provider DPA incorporating SCCs |
Upstream platforms (not sub-processors)
Shopify, Meta, Google Ads and Klaviyo are the sources the merchant connects. Each acts under its own direct relationship with the merchant; Truefold accesses them as the merchant's authorised processor using OAuth credentials the merchant grants (encrypted at rest with AES-256-GCM), and they are therefore not sub-processors of Truefold.
Change log
| Date | Change |
|---|---|
| 2026-08-27 | Initial register (v1.0). |
| 2026-08-28 | Removed the transactional-email provider — it processes only merchant-account and aggregate-metric data (no end-customer Customer Data), so it falls outside this register; it is disclosed in the Privacy Policy instead. |