CartFlow

Subprocessor Register

Version 1.0 · Effective 27 June 2026

Third-party providers that may process CartFlow data.

CartFlow uses the following categories of subprocessors. Specific providers may vary by feature and region.

ProviderPurposeData categoriesLocation
Render Services, Inc.Application hosting (cart-flow.store)All platform data at rest and in transit through the appUnited States (Oregon region)
Render Managed PostgreSQLPrimary database storageStructured commerce, account, payment, and audit dataUnited States (Oregon region)
Kopo Kopo (K2 Connect)M-Pesa payments, STK push, and payment webhooksPhone numbers, payment amounts, transaction references, receipt metadataKenya
Safaricom Daraja (via platform PSP)Alternative M-Pesa wallet checkout pathPhone numbers, STK push metadata, payment callbacksKenya
Meta (WhatsApp Cloud API)Order and delivery notifications (when enabled)Phone numbers, message content, delivery statusUnited States / Ireland (Meta infrastructure)
KitMarketing and lifecycle email (seller opt-in)Email, name, campaign and cart lifecycle metadataUnited States
ClariFiCommerce sync (seller opt-in)Orders, payments, wallet signals, vendor performanceKenya / United States (per ClariFi deployment)

Changes

Material subprocessor changes will be notified via email or updated on this page.

Contact

support@bizclinic.africa · +254113132508