Legal

Sub-processors

Last updated

ProductBox uses the third-party services below to run the Service. They are split into two tables, and the split matters.

  • Account data — the services in the first table handle your name, email, billing details and IP address. We are the controller of that data; these are its processors.
  • Product data only — the services in the second table receive barcodes, brand and product names, specifications and images. Product information is not personal data, so no personal data is transferred to anyone in that table.

Hosting and the enrichment infrastructure run on EU servers. Product Enrichment LTD is UK-established; UK–EU flows rely on mutual adequacy, so no additional safeguard is required. Transfers to US services are covered by each provider's standard data-processing terms — standard contractual clauses with the UK Addendum, and in most cases EU–US Data Privacy Framework certification.

1. Processors of account data

  • Hetzner Online GmbH (Germany, EU) — application, database and file hosting for every server. All account data at rest. In-region; no transfer.
  • Stripe (EU / US) — payments, merchant of record, invoicing. Name, email, billing address, card metadata.
  • Twilio SendGrid (US) — transactional email. Recipient email, name, message content.
  • Google (US) — sign-in with Google, and advertising measurement through the browser tag if you accept cookies. Email, name, IP address, click identifier.
  • Cloudflare (US) — Turnstile bot check on registration and password reset. IP address and challenge token.
  • Sentry (Germany, EU) — error monitoring. Error diagnostics only: we disable personally identifiable data in Sentry, so request headers and IP addresses are not sent. In-region; no transfer.
  • Healthchecks.io (US) — uptime and backup monitoring. A heartbeat signal carrying no customer data.

2. Processors of product data only

These services receive product information. They do not receive account data, your identity, your prices, your internal codes, or your uploaded files.

  • DeepSeek (China) — product data extraction and description generation. The product query and the product fields extracted from public pages.
  • Google (Gemini) (US) — product image assessment. Product images and product fields.

What actually leaves. Each enrichment request carries a fixed set of six fields, four of which are ours — a row index, our domain blocklist, URLs already visited, and pre-resolved page URLs. Only two are derived from your list: the search query and a match reference of barcode, brand and product name. Your uploaded file, your other columns, your prices and your identity are never sent. We pin this with an automated test that fails our build if a new field is added to it.

Because no personal data reaches these services, there is no restricted transfer of personal data on this path.

3. Notes

  • We are the controller of your account data. For the product lists you upload we act as a processor only to the extent those lists contain personal data — product catalogues normally contain none.
  • We update this page before adding a sub-processor that handles account data.
  • Questions: support@productbox.net.

Questions about this page?

We're happy to explain anything here in plain language — just ask.

Email support@productbox.net

Also read our Terms of Service.