Retail Relay home

Service-provider register

Retail Relay Subprocessor List

Updated August 2, 2026Version 2026-08-02-private-testDownload a copy
Contents
  1. Vercel — application hosting
  2. Supabase — database and authentication
  3. OpenAI — AI model inference
  4. Stripe — hosted subscription billing
  5. Customer-directed Lightspeed connection
  6. Provider changes and questions
Related documentsTermsPrivacyDPASubprocessorsCancellation

Current attended private-test list

This page identifies the four core providers currently used to operate the attended private test. No public subprocessor-change email or objection workflow is configured yet. The operator must give enrolled private-test participants direct notice before a materially new provider processes their data, and a durable public notice method is required before broader enrollment.

Public-launch configuration remains incomplete: public legal-notice email, public privacy email, public support email, approved data-retention schedule, verified Stripe cancellation configuration.

Putnam Development Studios LLC uses the providers below to process information on its behalf in support of the Retail Relay Service. The exact data sent depends on the feature a customer chooses to use.

A provider is listed for transparency even when a particular workflow has not been activated for an organization. This list distinguishes Retail Relay-selected providers from a customer-directed Lightspeed connection.

Vercel — application hosting

Vercel hosts and delivers the Retail Relay web application and server runtime. Depending on the request, Vercel may process request and response content, network and device information, application logs, deployment artifacts, and other technical data needed to deliver and secure the application.

  • Vercel privacy policyVercel’s notice for its own privacy practices.
  • Vercel data processing addendumVercel’s current customer data-processing terms.

Supabase — database and authentication

Supabase provides the managed database and authentication foundation. It processes user and organization records, connected-source normalized data and evidence, OAuth token envelopes, plans, approvals, audit and execution records, billing metadata, security state, and other application data stored by Retail Relay. R-Series OAuth token sets are encrypted independently before database storage.

  • Supabase privacy policySupabase’s notice for its own privacy practices.
  • Supabase securitySupabase’s security and compliance information.

OpenAI — AI model inference

OpenAI provides model inference for retail request planning and bounded extraction of procurement evidence from customer-submitted documents. Retail Relay sends selected prompts and supporting context needed for the chosen workflow. The current application sets store to false on both OpenAI API workflows; that application setting does not eliminate provider abuse-monitoring or legally required retention described in OpenAI’s own documentation.

  • OpenAI API data controlsOpenAI’s endpoint-specific storage and training documentation.
  • OpenAI subprocessor listThe providers OpenAI identifies for its own services.
  • OpenAI privacy policyOpenAI’s notice for its own privacy practices.

Stripe — hosted subscription billing

Stripe provides hosted Checkout, Customer Portal sessions, subscription billing, payment processing, and signed billing events. Payment-card and PaymentMethod details are entered into Stripe-hosted interfaces and are not stored by Retail Relay. Retail Relay stores only the Stripe object identifiers, subscription status and lifecycle timestamps, verified billed-account count and amount, and reconciliation metadata needed to administer billing.

The application can create a Stripe Customer Portal session, but the external live Stripe account currently has no active Portal configuration. Portal cancellation must not be represented as available until that configuration is created and tested.

  • Stripe privacy centerStripe’s notices for its own privacy practices.
  • Stripe services agreementStripe’s current service terms and linked data-processing terms.

Customer-directed Lightspeed connection

Lightspeed Commerce is the third-party source system that a customer independently chooses and authorizes Retail Relay to connect to. Retail Relay reads exact R-Series source records and sends only separately enabled, reviewed, approved, typed operations to the customer’s selected account. Because the customer selects and controls its Lightspeed account and has its own agreement with Lightspeed, this list treats Lightspeed as a customer-directed integration rather than a Retail Relay-selected Subprocessor.

Retail Relay is an independent product and is not affiliated with, sponsored by, or endorsed by Lightspeed Commerce Inc. or its affiliates.

  • Lightspeed privacy policyLightspeed’s notice for its own privacy practices.

Provider changes and questions

No production email, customer-support platform, advertising SDK, or behavioral-analytics provider is currently included in this list because none is configured in the audited application. A provider must be added here before it is used to process private-test customer data on Retail Relay’s behalf.

During the attended private test, questions and objections use the established direct operator enrollment channel. Configured public legal, privacy, and support emails appear at the end of this page when available.

Service provider: Putnam Development Studios LLC, a Maine limited liability company that provides the Service under the Retail Relay brand.

Legal: not yet published for the attended private test

Privacy: not yet published for the attended private test

Support: not yet published for the attended private test