Subprocessors
Every third party that touches your data, what it does, and what it receives. This page forms Annex III of the data processing addendum.
Six providers are involved in running ShellOrbit. Each does one job, each is bound by a written agreement with confidentiality and security obligations, and none may use your data for its own purposes. This page forms Annex III of the data processing addendum.
1. Current subprocessors
| Provider | Purpose | Data it processes | Role |
|---|---|---|---|
| Amazon Web Services | Hosting, compute, event storage, object storage for oversized payloads, queueing, delivery, backups, logs, content delivery for the site and dashboard | Account data and event data, including headers and raw payload bodies | Infrastructure processor |
| WorkOS | Authentication, session issuance, single sign on where you use it | Email address, name where provided, authentication identifiers, session and login metadata, IP address | Processor for account data |
| Zoho Corporation, ZeptoMail | Transactional email: delivery failure alerts, weekly digests, security and billing notices | Recipient email address, message content, delivery metadata. Alert emails reference endpoint names and event identifiers, not payload bodies | Processor for account data |
| Paddle | Payment processing as merchant of record, tax collection and remittance, invoicing, subscription billing including metered usage | Billing name and email, country, payment instrument held by Paddle, transaction and tax records, metered event counts we report for billing | Merchant of record and independent controller for payment data |
| Zoho Corporation, Zoho CRM | Handling enquiries sent through the contact form on shellorbit.com, and the correspondence that follows | First and last name, email address, company, position where given, subject, and the message body you type. Nothing from your webhook payloads | Processor for enquiry data |
| Functional Software, trading as Sentry | Error monitoring and performance tracing for the dashboard, the API, and the delivery workers, so a fault is found before you have to report it | Exception type and stack trace, the request path and method that failed, endpoint and event identifiers, browser and operating system, IP address, and the account id of the person who hit the error | Processor for diagnostic data |
Payload bodies reach only Amazon Web Services. Authentication, email, payment, enquiry, and monitoring providers receive account level data, not the contents of your webhooks.
Sentry deserves a specific statement, because error reporting is the usual way payload data leaks into a third party by accident. Request and response bodies are stripped before an event leaves our systems, headers named for authorization, cookies, or signatures are removed, and the scrubbing runs on our side rather than relying on Sentry’s own filters. What Sentry receives is the shape of a failure: which code path broke, on which endpoint id, for which account. If a payload fragment ever reaches it inside an exception message, that is a bug, and reporting it to security@shellorbit.com is welcome.
The contact form posts directly from your browser to Zoho, so an enquiry does not pass through our own servers before it reaches the CRM. Sending it is your choice: every address on the contact page reaches us by ordinary email instead.
2. What is deliberately absent
- No advertising or marketing analytics platform.
- No session recording or heatmap tool.
- No customer data platform, data broker, or enrichment service.
- No model training on payload content, by us or by anyone else.
- No third party error tracker with access to raw payloads.
3. Notice of change
We give at least 30 days notice before adding or replacing a subprocessor. Notice goes by email to account holders and this page is updated on the same day. To receive notices at a different address, tell us at privacy@shellorbit.com.
Customers may object to a new subprocessor on reasonable data protection grounds within the notice period, under section 6 of the data processing addendum. If we cannot offer an alternative, you may terminate the affected part of the service and receive a pro rata refund of prepaid fees for the unused remainder of the term.
4. Questions
Write to privacy@shellorbit.com for a copy of the transfer mechanisms in place with any provider on this list, or for the audit and certification reports we are permitted to pass through.