This page lists the providers SnopDesk AI engages to process personal data on our behalf (our "subprocessors"), and separately identifies related services that are not subprocessors — because they are independent platforms your customers or you interact with directly, or services you personally choose to connect. This page is incorporated by reference into the Data Processing Agreement.
This list was compiled from the current codebase and configuration. It has not yet been cross-checked against signed vendor contracts by counsel — see docs/legal-review-required.md. Exact per-provider onboarding dates are not separately tracked; the effective date above applies to this page as a whole.
SnopDesk subprocessors
Providers SnopDesk engages to process personal data as part of operating the Service:
| Provider | Service / purpose | Data categories | Processing location |
|---|---|---|---|
| OpenAI | AI-assisted reply drafting/generation and voice features, when enabled for a workspace | Message content, conversation context, knowledge-base/catalog excerpts sent as needed to generate a response | United States (per OpenAI's published infrastructure — not independently verified by SnopDesk for this document) |
| Google (Gemini API / Google Cloud AI) | AI-assisted reply drafting, voice transcription, and image understanding, when enabled for a workspace | Message content, voice notes, images, conversation context | United States and other countries where Google's infrastructure operates (not independently verified by SnopDesk for this document) |
| Hosting / infrastructure provider | Runs the SnopDesk web application, API, database, and background services | All data described in the Privacy Policy, as needed to run the Service | Pending confirmation — see note below |
| Object storage provider | Stores uploaded media (for example, product/catalog images) | Uploaded files and associated metadata | Pending confirmation — see note below |
| Email delivery (SMTP) provider | Delivers account, security, and transactional emails | Email address, message content of transactional emails | Pending confirmation — see note below |
Note on hosting, storage, and email rows above: SnopDesk's infrastructure is configurable (self-hosted services behind environment-variable configuration) rather than hardcoded to one named commercial vendor in the codebase, so the specific company names for these three rows are not independently verifiable from the code alone and are flagged in docs/legal-review-required.md for the business owner to confirm and for this page to be updated accordingly before relying on it for enterprise contracting.
SnopDesk does not currently use a separate analytics or error-monitoring subprocessor — no such tool is integrated into the Service as of this document's effective date.
Independent third-party platforms (not SnopDesk subprocessors)
These platforms process data under their own terms once you (or your customer) interact with them directly — SnopDesk does not engage them as a subprocessor:
- Meta / WhatsApp (Meta Platforms, Inc.) — you authorize SnopDesk to access your WhatsApp Business Account through Meta's own Embedded Signup flow; Meta processes messages and account data under the WhatsApp Business Terms and Meta's Privacy Policy as an independent party. See the Privacy Policy §9.
Merchant-directed integrations (your choice, not SnopDesk's)
You independently choose whether to connect these, and can disconnect them at any time:
- Shopify — store/order data, per the permissions you grant when connecting.
- YouCan — store/order data, per the permissions you grant when connecting.
- Delivery carriers you configure (for example, Ameex, Coliaty, ForceLog) — shipping and delivery-status data, per the carrier account you connect.
Payment provider
- Stripe — processes your subscription payment and billing data directly; we store only Stripe-issued identifiers and billing status, not full card numbers. See the Privacy Policy §12.
Data recipients required by law
We may disclose data to courts, regulators, or law-enforcement authorities where required by applicable law, or to professional advisors (for example, accountants or lawyers) under confidentiality obligations.
Updates to this list
We will update this page when we add or remove a subprocessor. SnopDesk does not currently operate an automated advance-notice mechanism (such as an email or in-app alert specifically for subprocessor changes) — we are not committing to individual prior notice beyond updating this page, unless and until such a mechanism is built. If your organization requires advance notice of subprocessor changes under a signed agreement, contact contact@snopdesk.com.