Subprocessors

Last updated: 6 October 2026

ReclaimHQ Ltd uses a small number of third-party service providers (subprocessors) to deliver the service. This page lists each subprocessor, what it does for us, what personal data it receives, and where the data is processed. It forms the authorised subprocessor list referenced by our Data Processing Agreement.

Current subprocessors

  • Supabase

    Purpose
    Database, authentication, and file storage (our primary data store)
    Personal data received
    All application data: account details, Amazon marketplace data, support case content, and uploaded images. Commercially sensitive financial fields are stored as AES-256-GCM ciphertext.
    Region and transfer mechanism
    EU (Frankfurt, Germany: AWS eu-central-1). Provider DPA incorporating UK GDPR safeguards.
  • Vercel

    Purpose
    Application hosting, serverless compute, and edge network
    Personal data received
    Request data in transit, including IP address and derived country.
    Region and transfer mechanism
    US/global. Provider DPA incorporating SCCs and the UK Addendum.
  • Stripe

    Purpose
    Subscription billing and payment processing
    Personal data received
    Name, email address, and subscription state. Card details are entered directly with Stripe; we never see or store card numbers.
    Region and transfer mechanism
    US/global. Provider DPA incorporating SCCs and the UK Addendum.
  • Anthropic

    Purpose
    AI models for the claims assistant (Tarquin), the support assistant (Susi) and the eBay listing tools
    Personal data received
    Claims and support: conversation content plus the case and order context needed to draft a claim, which can include names or addresses quoted inside Amazon case transcripts. eBay listing tools: the photos of the item you are listing (up to 24), the fault notes you type, product details such as the title, brand, part number and catalogue text, and eBay's own notices about your listings. Anthropic's API terms exclude training on customer data.
    Region and transfer mechanism
    US. Provider DPA incorporating SCCs and the UK Addendum.
  • Resend

    Purpose
    Transactional and marketing email delivery
    Personal data received
    Email address, first name, and email content.
    Region and transfer mechanism
    US. Provider DPA incorporating SCCs and the UK Addendum.
  • Upstash

    Purpose
    Rate limiting and abuse protection (Redis)
    Personal data received
    IP addresses, hashed email identifiers, and user IDs used as rate-limit keys.
    Region and transfer mechanism
    US/global. Provider DPA incorporating SCCs and the UK Addendum.
  • Discord

    Purpose
    Customer support channel and notifications
    Personal data received
    Discord user ID, display name, and support conversation content.
    Region and transfer mechanism
    US. Provider DPA incorporating SCCs and the UK Addendum.
  • Trustpilot

    Purpose
    Review invitations
    Personal data received
    Name and email address, sent only to invite a review.
    Region and transfer mechanism
    EU (Denmark) / US. Provider DPA incorporating UK GDPR safeguards.
  • Ship24

    Purpose
    Parcel tracking (delivery estimates for dispatched stock)
    Personal data received
    Tracking numbers and courier codes only. No names or addresses.
    Region and transfer mechanism
    EU (France). Provider terms incorporating UK GDPR safeguards.
  • UPS

    Purpose
    Parcel tracking for UPS parcels
    Personal data received
    Tracking numbers only. No names or addresses.
    Region and transfer mechanism
    US. Provider developer terms incorporating UK GDPR safeguards.
  • Claims specialists engaged by ReclaimHQ

    Purpose
    Managed case management only. Where you have asked us to run your claims for you, a claims specialist engaged by ReclaimHQ prepares and files reimbursement claims on your behalf, using access you grant and can revoke at any time.
    Personal data received
    Your removal order, reimbursement and claim data, and the contents of the Amazon support cases they work on, which can include names and addresses quoted in delivery evidence. You grant their Seller Central access yourself, and the permissions we ask for are listed on our Managed claims page. Where Amazon offers a permission only at its edit level, that is the level they hold. Access is used only to work your claims: specialists never issue refunds, change pricing or listings, or change bank, deposit or payout details, and they are never given permission to add or manage users. Every case is in your own Seller Central case log, each claim worked is recorded in your ReclaimHQ dashboard, and your billing page lists every case behind the fee.
    Region and transfer mechanism
    Pakistan. Transfer made under a UK International Data Transfer Agreement, supported by a transfer risk assessment. Applies only to accounts on the managed service.

Platforms you connect yourself (not our subprocessors)

These platforms act on your own authorisation, under their own terms. We read and write your data there only with the access you grant, and you can remove it yourself.

  • Amazon (Selling Partner API)

    Purpose
    Marketplace integration you connect. Amazon acts on your own authorisation as the data source for your seller account.
    Personal data received
    Report and data requests for your own seller account.
    Region and transfer mechanism
    US/global. Governed by Amazon's terms; you authorise access directly.
  • eBay

    Purpose
    Optional marketplace integration you connect for resale listings. eBay acts on your own authorisation.
    Personal data received
    Listing content and order data for your own eBay account.
    Region and transfer mechanism
    US/global. Governed by eBay's terms; you authorise access directly.
  • Google

    Purpose
    Optional Google Drive invoice sync and Sign in with Google, under your own authorisation.
    Personal data received
    The Drive folder you pick (invoice files) and, for Sign in with Google, your name and email address.
    Region and transfer mechanism
    US/global. Governed by Google's terms; you authorise access directly.

International transfers

Where a subprocessor processes personal data outside the UK, transfers are made under UK GDPR safeguards: the provider's data processing agreement incorporating the EU Standard Contractual Clauses with the UK Addendum, the UK International Data Transfer Agreement (IDTA), or another lawful transfer mechanism recognised under UK GDPR.

Changes to this list

When we plan to add or replace a subprocessor that will process personal data, we will update this page and notify customers by email at least 30 days before the new subprocessor begins processing, giving you the opportunity to raise a reasonable objection. Minor changes that do not involve personal data (for example, a tooling change with no data access) may be made without notice.

Questions about any subprocessor? Email hello@reclaimhq.uk.