← CartFlow
Subprocessor Register
Version 1.0 · Effective 27 June 2026
Third-party providers that may process CartFlow data.
CartFlow uses the following categories of subprocessors. Specific providers may vary by feature and region.
| Provider | Purpose | Data categories | Location |
|---|---|---|---|
| Render Services, Inc. | Application hosting (cart-flow.store) | All platform data at rest and in transit through the app | United States (Oregon region) |
| Render Managed PostgreSQL | Primary database storage | Structured commerce, account, payment, and audit data | United States (Oregon region) |
| Kopo Kopo (K2 Connect) | M-Pesa payments, STK push, and payment webhooks | Phone numbers, payment amounts, transaction references, receipt metadata | Kenya |
| Safaricom Daraja (via platform PSP) | Alternative M-Pesa wallet checkout path | Phone numbers, STK push metadata, payment callbacks | Kenya |
| Meta (WhatsApp Cloud API) | Order and delivery notifications (when enabled) | Phone numbers, message content, delivery status | United States / Ireland (Meta infrastructure) |
| Kit | Marketing and lifecycle email (seller opt-in) | Email, name, campaign and cart lifecycle metadata | United States |
| ClariFi | Commerce sync (seller opt-in) | Orders, payments, wallet signals, vendor performance | Kenya / United States (per ClariFi deployment) |
Changes
Material subprocessor changes will be notified via email or updated on this page.
Contact
support@bizclinic.africa · +254113132508