BeautyReply

BeautyReply beta

Subprocessor List

Effective 28 August 2026

Draft template — not legal advice. This document is provided for internal review and must be verified by qualified legal counsel before a public SaaS launch. BeautyReply does not represent that these terms are complete or compliant.

This page lists third-party providers BeautyReply may use to host, operate, or support the platform. The list is maintained in a central registry in the codebase and should be kept aligned with actual integrations.

1. How to use this list

Business customers reviewing BeautyReply for GDPR purposes should use this list together with the Data Processing Agreement (DPA) template and their own privacy notices. Verify each provider's current privacy policy, DPA availability, and processing location before launch.

2. Active subprocessors

ProviderPurposeData categoriesLocationLinksUpdated
BeautyReply Cloud DatabaseAuthentication, PostgreSQL database, file storage, and row-level security for tenant data.
  • Account credentials and session tokens
  • Business workspace data
  • Widget conversations and messages
  • Leads and contact details
  • Imported website and shop catalog data
  • Uploaded widget assets
EU region when configured (verify project region)2026-08-28
VercelApplication hosting, serverless functions, edge delivery, and operational logs.
  • HTTP request metadata
  • Server function logs (must not contain full chat transcripts when logging is configured correctly)
  • Deployment configuration
Global (verify project region settings)2026-08-28
GroqOptional natural-language generation and structured understanding for assistant replies.
  • Customer questions and recent conversation snippets
  • Compact approved business facts (services, policies, catalog excerpts)
  • No payment card data by design
United States (verify current Groq data processing terms)2026-08-28
SerperOptional public web search snippets for limited research questions (not salon pricing or hours).
  • Search queries derived from customer questions
Verify with Serper documentation2026-08-28
hCaptchaBot protection on signup, lead forms, and support feedback.
  • CAPTCHA challenge metadata
  • IP address and browser signals
Verify with hCaptcha documentation2026-08-28
ResendTransactional email for lead notifications, handoff alerts, and support messages when configured.
  • Recipient email addresses
  • Names
  • Message content in notification emails
Verify with Resend documentation2026-08-28
Shopify (merchant storefront)When a salon enables add-to-cart beta, the visitor browser interacts with the merchant Shopify storefront cart API on the merchant domain.
  • Product variant identifiers
  • Cart actions on merchant domain
Merchant Shopify store region2026-08-28
Google Fonts (via Next.js)Dashboard typography delivery.
  • IP address and browser metadata typical of font requests
Google global infrastructure2026-08-28

3. Changes

BeautyReply may update subprocessors as the product evolves. Material changes should be communicated to business customers in accordance with contractual notice periods once final commercial terms are in place. This beta list is provided for transparency during review and is not a contractual notification.

4. Merchant-controlled services

When a salon connects its own Shopify storefront or links its own website, visitors may also interact with services controlled by the salon (for example Shopify cart APIs on the merchant domain). Those providers are chosen by the salon and are not BeautyReply subprocessors for salon-controlled processing.