Mission Control โ Sub-processor List
Provider: SellerSlice LLC (a Washington State, USA limited liability company) Service: Mission Control ("the Service") Document version: 1.0 Effective date: June 1, 2026 Last updated: June 1, 2026
๐ TL;DR โ The short version
Running Mission Control means we rely on a small, carefully chosen set of trusted third-party companies ("sub-processors") to host our software, store your data, send email, process payments, and power our AI features. Here's the honest summary:
- We keep the list short and we publish it. Most of our competitors don't. You can see exactly who touches your data and why, right here.
- We tell you which sub-processors can touch Amazon data. Only our database host (Supabase) and our hosting platform (Vercel) sit squarely in that path; our email provider (Resend) may carry Amazon-sourced metrics inside the body of reports and notifications we email you. Your Amazon data is never pooled across clients and never used for benchmarking against other sellers. We also contractually prohibit our AI vendors from using your data โ including any Amazon-sourced data โ to train or improve their models (see Section 6; per-vendor tier confirmation is reflected in the Section 4 table).
- We don't sell or share your personal information. Full stop.
- We give you advance warning before we change this list. We'll post new sub-processors here at least 30 days before they start processing your data, and you can subscribe to be notified and object during that window.
- Amazon is not our sub-processor. Amazon is the source of the seller data you authorize us to access, and it acts as an independent controller of that data โ not something we hand your data to.
If you only read one thing: we use Supabase, Vercel, Vercel AI Gateway, Resend, Stripe, Anthropic, OpenAI, xAI/Grok, and Google. Amazon is a data source, not a sub-processor. The full table โ purpose, location, and whether each one can touch Amazon data โ is in Section 4.
Table of Contents
- What this document is
- Definitions
- Our roles: controller and processor
- The current sub-processor list
- How Amazon data is handled (and why Amazon is not a sub-processor)
- AI sub-processors and the no-training commitment
- International data transfers
- Jurisdiction-specific disclosures
- Change notice and your right to object
- How to subscribe to changes
- Contact us
- Version history and changelog
1. What this document is
This Sub-processor List names every third-party company that SellerSlice LLC engages to process personal data and Customer Data on our behalf in order to deliver Mission Control, and it explains what each one does, where it operates, and whether it can come into contact with Amazon-sourced data.
We publish this list because transparency about your supply chain is a baseline expectation of modern data-protection law โ GDPR Article 28(2) and (4) require us to authorize sub-processors and give you a way to object to changes, and the EDPB Opinion 22/2024 on the use of processors and sub-processors confirms that controllers are entitled to know the full chain. We also publish it because we think you deserve to know who we trust with your business before you trust us with it.
This list is incorporated by reference into our Data Processing Agreement (DPA) and our Privacy Policy. Where this list and the DPA differ on a sub-processor's authorization status, the DPA governs the contractual relationship and this list governs the published notice.
2. Definitions
- "Customer Data" โ data that you (our business customer) or your authorized users submit to, or that we collect or generate within, the Service on your behalf, including data we retrieve from connected Amazon accounts at your direction.
- "Personal data" / "personal information" โ information relating to an identified or identifiable natural person, as defined under GDPR Art. 4(1), the UK GDPR, the CCPA/CPRA (Cal. Civ. Code ยง 1798.140), Mexico's LFPDPPP, Australia's Privacy Act 1988 (Cth), and Canada's PIPEDA / Quebec Law 25.
- "Sub-processor" โ a third party engaged by SellerSlice LLC (in our role as a processor) to process personal data or Customer Data on our behalf (GDPR Art. 28(4)).
- "Amazon Information" โ any data exposed through the Amazon Selling Partner API (SP-API), the Amazon Advertising API, Amazon Portals, or Amazon's public-facing websites, as defined in the Amazon Data Protection Policy (DPP) ยง4, regardless of whether that data is personal data. This includes catalog, order, sales, settlement, financial, and advertising data and ASINs.
- "DPP / AUP / SPA" โ Amazon's Data Protection Policy, Acceptable Use Policy, and Solution Provider Agreement, respectively (text effective November 25, 2025).
- "Controller" and "Processor" โ as defined under GDPR Art. 4(7)โ(8) and equivalent terms in the other in-scope laws.
3. Our roles: controller and processor
SellerSlice LLC wears two hats, and which one applies determines how a sub-processor is engaged:
- We are a processor (acting on your documented instructions) for the Customer Data and Amazon Information your authorized users put into, or connect to, Mission Control's client portal and tools. In this role, as between you and SellerSlice, you are the controller of that data, and the companies in Section 4 are our sub-processors. For Amazon Information specifically, a further layer applies: Amazon remains an independent controller of the source data under its DPP/AUP/SPA, which set additional purpose-and-use constraints on that data that neither you nor we can waive (see Section 5).
- We are a controller for the limited personal data we determine the purposes of on our own account โ our own user accounts, billing and tax records, security and audit logs, and internal operations. In that role, the same companies act as our own processors.
This dual-role mapping is set out in full in our Data Processing Agreement and our Privacy Policy ยง1. It matters here because GDPR Art. 28(2)/(4), the equivalent processor-accountability rule in Australia (APP 8 / s 16C), and Quebec Law 25 ยง17 all attach obligations to the processor chain โ which is exactly what this list documents.
4. The current sub-processor list
The table below is the authoritative, current list of Mission Control sub-processors as of the effective date above.
"Touches Amazon data?" flags whether a sub-processor can come into contact with Amazon Information (see Section 5). A "Yes" does not mean the sub-processor uses, aggregates, or retains that data for its own purposes โ it means the data passes through or rests on that provider's infrastructure in the course of delivering the Service to you.
"Input-retention" states how long, per our contract or the vendor's API tier, that vendor retains the inputs we send it. For AI vendors this is the term that backs our no-training commitment (Section 6); entries marked "Confirmation pending" are those for which the vendor tier is still being confirmed.
| # | Sub-processor | Purpose | Location | Touches Amazon data? | Input-retention | More info |
|---|---|---|---|---|---|---|
| 1 | Supabase | Database, authentication, realtime, file storage | United States | Yes | For the life of the Service relationship; purged on deletion/de-auth per Section 5 | Privacy ยท DPA/SCCs |
| 2 | Vercel | Application hosting, scheduled jobs (cron), Web Analytics + Speed Insights | United States | Yes (hosting) | Transient in compute; no application data at rest beyond logs | Privacy ยท DPA |
| 3 | Vercel AI Gateway | AI inference routing layer (routes prompts to model vendors) | Per Vercel (region confirmation pending) | Transient only (prompts in transit; no at-rest storage) | Transient routing only | DPA |
| 4 | Resend | Transactional email delivery (sender domain mail.sellerslice.com); delivers reports and notifications | United States | Possibly โ message bodies (reports/notifications) may embed Amazon-sourced metrics; processes client contact PII + content | Message metadata/logs per Resend's retention policy; bodies not retained for vendor purposes | Privacy ยท DPA |
| 5 | Stripe | Payment and subscription processing | United States | No | Per Stripe's retention policy as an independent controller of payment data | Privacy ยท DPA |
| 6 | Anthropic | AI copy generation and research (Copywriting, Copy Researcher) | Confirmation pending | Possibly transient (listing content may be sent for inference; no buyer PII) | Confirmation pending โ no-training / short-retention tier to be confirmed | Privacy |
| 7 | OpenAI | AI scoring and embeddings (Marketing-Ready scoring, semantic search) | Confirmation pending | Possibly transient (listing content may be sent for inference; no buyer PII) | Confirmation pending โ no-training / zero-retention tier to be confirmed | Privacy |
| 8 | xAI / Grok | Web/X search for our internal Morning Review / News briefing only โ not a client-data or Amazon-data processor | Confirmation pending | No | Confirmation pending โ data-usage / input-retention terms to be confirmed | Confirmation pending |
| 9 | Calendar / Meet integration (per-user OAuth, two-way sync of meeting data incl. attendee emails) | United States | No | Per Google Cloud DPA; we retain only sync state, not Google's copy | Privacy ยท Cloud DPA |
Not a sub-processor (data source / independent controller)
| Entity | Relationship | Location |
|---|---|---|
| Amazon (Selling Partner API / Advertising API) | Data source, independent controller โ NOT our sub-processor. Amazon is where the seller data you authorize us to read originates; Amazon determines its own purposes for that data as a controller. See Section 5. | United States |
| Stripe (payment data) | For the payment-card and transaction data Stripe collects to process your payments, Stripe acts as an independent controller, not solely our processor. Stripe is also listed at #5 above for the processing it performs on our behalf. Stripe is EU-US Data Privacy Framework (DPF) certified. | United States |
5. How Amazon data is handled (and why Amazon is not a sub-processor)
This section is the most important one for Amazon sellers, so we've put the plain-English version first.
Amazon is not a company we hand your data to โ it's where your data comes from. When you connect a Selling Partner or Advertising account, you authorize Mission Control to read data from Amazon on your behalf. Amazon is the source and an independent controller of that data; it is therefore not a sub-processor in the chain described in Section 4. The contracts that govern what we may do with that data are the Amazon Data Protection Policy (DPP), Acceptable Use Policy (AUP), and Solution Provider Agreement (SPA) (text effective November 25, 2025).
What that means in practice, and how it constrains the sub-processors above:
- No buyer personal information, by design. Mission Control uses no Restricted SP-API roles, so we hold no buyer PII โ no buyer names, addresses, emails, or phone numbers. The Amazon Information our sub-processors can touch is catalog, sales, settlement, financial, and advertising data, not consumer contact data. (Because we hold no buyer PII, the โค30-day Amazon-sourced-PII retention ceiling is moot in practice โ but we state it for completeness.)
- Supabase (storage) and Vercel (hosting) sit in the Amazon-data path; Resend may carry it inside email bodies. Amazon Information rests in our Supabase database and passes through Vercel's hosting infrastructure. In addition, reports and notifications we email through Resend may embed Amazon-sourced metrics in the message body. No other sub-processor receives Amazon Information for its own use. AI vendors (Anthropic, OpenAI) may receive listing content transiently for inference, never buyer PII, and never for training (see Section 6).
- Never pooled, never benchmarked across clients, never disclosed to other clients. Amazon Information is used solely to support the Authorized User whose account it came from. We do not aggregate it across clients, do not use it for cross-client benchmarking, and do not disclose it to other clients โ and this bar survives de-identification and aggregation. (Amazon AUP ยง4.4 / ยง4.6; SPA ยงD-7.1 / ยงD-7.5.)
- Retained only while you're connected, with an 18-month ceiling; deleted โ not anonymized โ when you disconnect. While your authorization is active, we retain per-client listing performance metrics (including before/after change-impact analysis) solely for you, for no longer than 18 months of non-PII Amazon Information. On de-authorization, disconnection, or account closure, your Amazon Information is deleted (destroyed to a NIST 800-88-aligned standard), not anonymized, within 30 days, regardless of the 18-month window. Under the Amazon DPP, anonymization is categorically not an accepted substitute for deletion. Security and audit logs are retained for at least 12 months per the DPP. See our Data Retention page and Privacy Policy ยง12 for the full schedule.
- Security incidents go to Amazon within 24 hours. Any security incident affecting Amazon Information is reported to Amazon's incident channel at security@amazon.com within 24 hours of detection (DPP ยง1.6), via our named Amazon Incident Management Point of Contact (IMPOC), reachable via privacy@sellerslice.com. The 24-hour Amazon clock is only one of several breach-notification obligations that may apply โ GDPR/UK Art. 33 (72 hours to the supervisory authority), Australia's Notifiable Data Breaches scheme, Mexico's de forma inmediata notice to titulares, and Canada's OPC / Quebec CAI duties may run in parallel. The full breach-notification matrix is in our Privacy Policy and DPA; this section is not exhaustive.
Because Amazon Information lives on Supabase and Vercel (and may travel in email bodies via Resend), those sub-processors are contractually bound (via their DPAs, SCCs, and our flow-down terms) to handle it consistently with the Amazon DPP/AUP/SPA constraints above.
6. AI sub-processors and the no-training commitment
Mission Control uses four AI vendors and layers โ Anthropic, OpenAI, xAI/Grok, and the Vercel AI Gateway routing layer (rows 3, 6, 7, and 8 above). They power advisory features only: copywriting and copy research, Marketing-Ready scoring, AI report generation, and the internal Morning Review / News briefing.
Our commitment, which we require of these vendors by contract:
We contractually require that no Customer Data or Amazon-sourced data we send our AI sub-processors is used to train, fine-tune, or otherwise improve any third-party AI model. This prohibition is flowed down to our AI sub-processors. The commitment is only as strong as the vendor tier that backs it, and per-vendor tier confirmation is reflected in the Section 4 table โ until each tier is confirmed, treat this as a contractual requirement we impose rather than a fully-verified vendor guarantee.
Two further points:
- AI features are advisory / decision-support, with a human in the loop. AI-generated copy, scores, reports, and briefings are reviewed and editable by a human before any action is taken on an Amazon account. They do not produce legally or similarly significant automated decisions, and they are not solely-automated decision-making within the meaning of GDPR Art. 22, Quebec Law 25 art. 12.1, or Australia's forthcoming automated-decision disclosure rule. See our AI Disclosure page.
- The no-training claim is only as good as the vendor tier behind it. The actual contractual tier with each AI vendor (Anthropic, OpenAI, and xAI/Grok) is confirmed before the categorical wording above and in the TL;DR is relied upon for that vendor; where a confirmed tier does not guarantee no-training for a given vendor, that wording is narrowed for that vendor. The per-vendor confirmation status is reflected in the "Input-retention" column of Section 4.
7. International data transfers
Several of our sub-processors are located in the United States, and your data may be transferred there and to the other locations listed in Section 4. We rely on the following transfer mechanisms, by recipient and by your jurisdiction. These are described in detail in our Privacy Policy ยง7 and the cross-border appendix to our DPA.
| Origin | Mechanism | Applies to |
|---|---|---|
| European Union / EEA | EU-US Data Privacy Framework (DPF) where the recipient is certified (Stripe, Vercel), with the 2021 EU Standard Contractual Clauses (SCCs) as fallback; SCCs (Module Two/Three) for non-DPF recipients (Supabase, Resend), supported by a documented Transfer Impact Assessment | All EU/EEA-origin personal data |
| United Kingdom | UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs; UK Extension to the DPF where the recipient is certified | All UK-origin personal data |
| Mexico | Titular consent + contractual equivalence โ each US sub-processor is bound by contract to LFPDPPP-equivalent protections; no EU-style adequacy regime applies. The Mexican Aviso de Privacidad offers an accept/reject choice for these transfers | All Mexico-origin personal data |
| Canada (PIPEDA) | Comparable-protection contractual safeguards under PIPEDA's accountability principle; meaningful-consent notice naming US processors and US storage | All Canada-origin personal data |
| Quebec (Law 25) | A completed Privacy Impact Assessment (s 17) finding adequate protection, plus a written agreement with each US recipient reflecting that PIA, before any Quebec-resident PI is transferred to the US stack | All Quebec-origin personal data |
| Australia | APP 8.1 "reasonable steps" โ enforceable DPAs binding each overseas (US) recipient to APP-equivalent handling; SellerSlice accepts s 16C accountability for acts of its overseas sub-processors | All Australia-origin personal data |
| AI sub-processors (Anthropic, OpenAI, xAI/Grok) + Vercel AI Gateway | Listing content and prompts routed to these vendors may be EU/UK/MX/AU/Quebec-origin personal data. Because their processing region(s) are not yet confirmed (see the region entries marked "Confirmation pending" in Section 4), no in-scope personal data is sent to a vendor until a valid transfer mechanism is in place for that vendor โ i.e., DPF or SCCs (EU), IDTA/Addendum (UK), LFPDPPP consent + contractual equivalence (MX), s 17 PIA + written agreement (Quebec), and APP 8 contractual safeguards (AU). | EU/UK/MX/Quebec/AU-origin personal data routed to AI vendors |
8. Jurisdiction-specific disclosures
This list does double duty as a transparency artifact across all of our launch jurisdictions โ the United States (including CA/CCPA-CPRA and the VA/CO/CT/TX-model state laws), the United Kingdom, the European Union, Canada (including Quebec Law 25), Mexico (LFPDPPP), and Australia (Privacy Act/APPs).
- United States (CCPA/CPRA + state laws). Engaging these companies as service providers / processors under written contract is not a "sale" or "share" of personal information. We do not sell or share your personal information, and we honor the Global Privacy Control (which here binds sale/share, targeted advertising, and analytics โ you may re-enable analytics by affirmative opt-in). See "Your US State Privacy Rights," including the appeal path, in our Privacy Policy ยง6.
- European Union / United Kingdom (GDPR / UK GDPR). This list satisfies the transparency expectation behind Art. 28(2)/(4) and gives you the right to object to new sub-processors (Section 9). Recipients and safeguards are named per Art. 13.
- Mexico (LFPDPPP). Our Spanish-language
Aviso de Privacidadidentifies the US recipients of your personal information โ Supabase, Vercel, Stripe, Resend, and Google โ together with the AI vendors (Anthropic, OpenAI, xAI) and the Vercel AI Gateway, and offers thetitularan accept/reject choice for these transfers. Each recipient is contractually bound to LFPDPPP-equivalent terms. - Australia (Privacy Act / APPs). Consistent with APP 5 and APP 1.4(f)/APP 8, we disclose that personal information is disclosed to overseas recipients in the United States โ Supabase, Vercel, Stripe, Resend, and Google โ and to the AI providers (Anthropic, OpenAI, xAI, via the Vercel AI Gateway) and Amazon. Under s 16C, an act of an overseas recipient that breaches the APPs is deemed our act, and we accept that accountability.
- Canada (PIPEDA + Quebec Law 25). We name US processors and US storage so that consent is meaningful (PIPEDA's four key elements). For Quebec residents, transfers proceed only after the s 17 PIA + written agreement described in Section 7. Quebec's published Person in charge of the protection of personal information is: Jordache Perozzo, President (privacy@sellerslice.com).
Consistency note: Every US recipient of personal information named in the Section 4 table โ Supabase, Vercel, Stripe, Resend, and Google, plus the AI vendors and the Vercel AI Gateway โ is named in the Mexico and Australia overseas-recipient disclosures above. If a sub-processor is added to or removed from Section 4, these lists must be updated in lockstep.
9. Change notice and your right to object
We will keep this list current. When we intend to engage a new sub-processor, or materially change the role of an existing one:
- We will update this page and post the change at least 30 days before the new sub-processor begins processing your data.
- You may object during that 30-day window if you have reasonable, documented data-protection grounds. To object, contact us at privacy@sellerslice.com with the subject line "Sub-processor objection."
- If we cannot resolve your objection (for example, by offering a commercially reasonable alternative), you may terminate the affected Service in accordance with the sub-processor objection-remedy provision of our DPA and our Terms of Service. On such a termination you receive a pro-rata refund of any prepaid, unused fees for the terminated Service, with no early-termination penalty, and this termination right is your sole and exclusive remedy for an unresolved good-faith objection. We will not penalize a good-faith objection.
This advance-notice and objection right is the published counterpart to the sub-processor terms in our DPA (GDPR Art. 28(2)). Emergency changes required to maintain security or legal compliance may take effect immediately, with notice posted as soon as practicable.
A dated record of every change to this list is kept in Section 12.
10. How to subscribe to changes
To be notified whenever this list changes, email privacy@sellerslice.com with the subject line "Subscribe โ Sub-processor updates," including the email address you'd like notices sent to. We'll add you to the change-notice list and you can unsubscribe at any time.
11. Contact us
| Topic | |
|---|---|
| Privacy, sub-processor objections, data-subject requests | privacy@sellerslice.com |
| Legal / contracts | legal@sellerslice.com |
| General help / support | help@sellerslice.com |
| Billing | billing@sellerslice.com |
| Amazon security incidents (Amazon's channel) | security@amazon.com |
Controller: SellerSlice LLC, a Washington State (USA) limited liability company. EU Article 27 Representative: Published in the Privacy Policy once appointed. UK Representative: Published in the Privacy Policy once appointed. Quebec Law 25 Person in charge of personal information protection: Jordache Perozzo, President (privacy@sellerslice.com) Amazon Incident Management Point of Contact (IMPOC): Reachable via privacy@sellerslice.com.
12. Version history and changelog
| Version | Effective date | Summary of changes |
|---|---|---|
| 1.0 | 2026-06-01 | Initial publication. Establishes the full sub-processor list (Supabase, Vercel, Vercel AI Gateway, Resend, Stripe, Anthropic, OpenAI, xAI/Grok, Google), the Amazon "source, not sub-processor" position, the AI no-training commitment, per-jurisdiction transfer mechanisms (including AI vendors), an 18-month non-PII Amazon retention ceiling, and a 30-day change-notice + objection window. |
Changelog policy: Each future change to the sub-processor table will be added as a new row here with its own effective date and a one-line summary, and prior versions will be archived. A material change (such as adding a sub-processor that touches Amazon data) triggers the 30-day advance notice in Section 9. The canonical version string for this document is maintained in our central legal-versions registry so that the displayed text and our consent/notice records cannot drift apart.