Retail Relay Subprocessor List Version: 2026-08-02-private-test Updated: August 2, 2026 Status: Current attended private-test list This page identifies the four core providers currently used to operate the attended private test. No public subprocessor-change email or objection workflow is configured yet. The operator must give enrolled private-test participants direct notice before a materially new provider processes their data, and a durable public notice method is required before broader enrollment. Putnam Development Studios LLC uses the providers below to process information on its behalf in support of the Retail Relay Service. The exact data sent depends on the feature a customer chooses to use. A provider is listed for transparency even when a particular workflow has not been activated for an organization. This list distinguishes Retail Relay-selected providers from a customer-directed Lightspeed connection. Vercel — application hosting Vercel hosts and delivers the Retail Relay web application and server runtime. Depending on the request, Vercel may process request and response content, network and device information, application logs, deployment artifacts, and other technical data needed to deliver and secure the application. - Vercel privacy policy: Vercel’s notice for its own privacy practices. (https://vercel.com/legal/privacy-policy) - Vercel data processing addendum: Vercel’s current customer data-processing terms. (https://vercel.com/legal/dpa) Supabase — database and authentication Supabase provides the managed database and authentication foundation. It processes user and organization records, connected-source normalized data and evidence, OAuth token envelopes, plans, approvals, audit and execution records, billing metadata, security state, and other application data stored by Retail Relay. R-Series OAuth token sets are encrypted independently before database storage. - Supabase privacy policy: Supabase’s notice for its own privacy practices. (https://supabase.com/privacy) - Supabase security: Supabase’s security and compliance information. (https://supabase.com/security) OpenAI — AI model inference OpenAI provides model inference for retail request planning and bounded extraction of procurement evidence from customer-submitted documents. Retail Relay sends selected prompts and supporting context needed for the chosen workflow. The current application sets store to false on both OpenAI API workflows; that application setting does not eliminate provider abuse-monitoring or legally required retention described in OpenAI’s own documentation. - OpenAI API data controls: OpenAI’s endpoint-specific storage and training documentation. (https://platform.openai.com/docs/models/default-usage-policies-by-endpoint) - OpenAI subprocessor list: The providers OpenAI identifies for its own services. (https://openai.com/policies/sub-processor-list/) - OpenAI privacy policy: OpenAI’s notice for its own privacy practices. (https://openai.com/policies/privacy-policy/) Stripe — hosted subscription billing Stripe provides hosted Checkout, Customer Portal sessions, subscription billing, payment processing, and signed billing events. Payment-card and PaymentMethod details are entered into Stripe-hosted interfaces and are not stored by Retail Relay. Retail Relay stores only the Stripe object identifiers, subscription status and lifecycle timestamps, verified billed-account count and amount, and reconciliation metadata needed to administer billing. The application can create a Stripe Customer Portal session, but the external live Stripe account currently has no active Portal configuration. Portal cancellation must not be represented as available until that configuration is created and tested. - Stripe privacy center: Stripe’s notices for its own privacy practices. (https://stripe.com/privacy) - Stripe services agreement: Stripe’s current service terms and linked data-processing terms. (https://stripe.com/legal/ssa) Customer-directed Lightspeed connection Lightspeed Commerce is the third-party source system that a customer independently chooses and authorizes Retail Relay to connect to. Retail Relay reads exact R-Series source records and sends only separately enabled, reviewed, approved, typed operations to the customer’s selected account. Because the customer selects and controls its Lightspeed account and has its own agreement with Lightspeed, this list treats Lightspeed as a customer-directed integration rather than a Retail Relay-selected Subprocessor. Retail Relay is an independent product and is not affiliated with, sponsored by, or endorsed by Lightspeed Commerce Inc. or its affiliates. - Lightspeed privacy policy: Lightspeed’s notice for its own privacy practices. (https://www.lightspeedhq.com/legal/privacy-policy/) Provider changes and questions No production email, customer-support platform, advertising SDK, or behavioral-analytics provider is currently included in this list because none is configured in the audited application. A provider must be added here before it is used to process private-test customer data on Retail Relay’s behalf. During the attended private test, questions and objections use the established direct operator enrollment channel. Configured public legal, privacy, and support emails appear at the end of this page when available. Configured public contacts Legal: not configured Privacy: not configured Support: not configured