Merco

Merco · Legal

Provider register

Services integrated with Merco and their intended roles. This inventory needs verification against production accounts and contracts.

PREPARATION DRAFTPrepared for the intended Dutch operator. Incorporation and operational reviews are pending. These drafts are not effective contracts and do not authorise order funding.

Preparation draft · 27 September 2026 · 2026-09-27-draft-2

01Scope and approval

This preparation inventory includes optional and legacy integrations. It is not an approved subprocessor list and does not imply every listed service receives data in production.

Before the DPA becomes effective, the register must specify each enabled service’s contracted legal entity, purpose, role, processing and support locations, transfer safeguard and authorisation. Changes to approved subprocessors follow the DPA notice and objection process. Payment providers, authorities and trading counterparties can have independent-controller roles.

02Vercel

Service. Web hosting and private file storage through Vercel Blob.

Data. Request metadata, account/workspace records processed by the web service, uploaded files.

Role. Proposed processor/subprocessor for the contracted services.

Verification. Live merco-web Blob store verified Private in Frankfurt (fra1) on 27 September 2026. Web compute, support access, contracted entity and transfer safeguards require separate confirmation.

03Neon

Service. PostgreSQL database hosting.

Data. Account, organisation, order, document, Studio and related application records.

Role. Proposed processor/subprocessor.

Verification. Integrated; actual database region, backups, contracted entity and safeguards require confirmation.

04Render

Service. Background job hosting.

Data. Job payloads and records needed for enabled compliance and logistics workflows.

Role. Proposed processor/subprocessor.

Verification. Configured in source; deployed services, region, entity and safeguards require confirmation.

05Redis service — provider to be confirmed

Service. Queues, cache and rate limits. Upstash integrations and Redis connections are present.

Data. Queue payloads, transient records and rate-limit identifiers, depending on the service.

Role. Proposed processor/subprocessor.

Verification. Production Redis/Upstash providers and division of services require confirmation.

06OpenAI

Service. Studio AI, document assistance, image generation and other enabled AI workflows.

Data. Relevant prompts, conversation context, reference images, documents and requested outputs.

Role. Proposed processor/subprocessor for service content; separate provider purposes require contractual assessment.

Verification. API integrated; contracted entity, retention settings, any regional processing and transfer safeguards require confirmation.

07Resend

Service. Transactional email.

Data. Recipient names/addresses and email content.

Role. Proposed processor/subprocessor.

Verification. Integrated; production account, entity, retention and safeguards require confirmation.

08Mapbox

Service. Maps and related geographic services.

Data. Request/device metadata and geographic queries needed by the enabled feature.

Role. Role depends on the service and provider terms; assess processor and independent-controller activities.

Verification. Browser maps require a separate affirmative choice and withdrawal removes SDK telemetry storage. Additional performance metrics are disabled. Production network/storage behaviour, contract and safeguards still require assessment.

09Tavily

Service. Business research and screening searches.

Data. Search queries, potentially including business names and relevant business-contact details.

Role. Proposed processor/subprocessor for submitted queries; verify contract.

Verification. Integrated; live use, entity, query retention and safeguards require confirmation.

10Amazon Web Services — S3

Service. Optional document/object storage.

Data. Files routed to the enabled storage service.

Role. Proposed processor/subprocessor if enabled.

Verification. Optional integration; code defaults do not establish the actual deployed bucket region or provider arrangement.

11Airwallex

Service. Intended business payments, verification and supplier payout services.

Data. Business/identity information, bank beneficiaries, payment and verification records.

Role. Payment-provider roles depend on the contract; independent controller for its own regulated duties where applicable.

Verification. Integration present; approved marketplace model, licensed contracting entity and live capabilities are pending verification.

12Stripe

Service. Legacy/optional billing and payment integrations.

Data. Billing/customer and transaction details only if the relevant flow remains enabled.

Role. Assess the specific processor and independent-controller services.

Verification. Code remains present. Confirm whether any production billing or historical records still use it; it is not the stated current order-funds provider.

13SeaRates / DP World and other shipment-data services

Service. Optional freight rates, container tracking and vessel information. AISstream and carrier lookups may support enabled features.

Data. Shipment/container references, route queries and request metadata; minimise individual contact details.

Role. Assess each enabled service separately; data suppliers are not automatically subprocessors.

Verification. Contracted services, live enabling, legal entities, locations and roles must be confirmed individually.

Your browser choice

Sign-in and security work without optional storage. Choose whether this browser remembers interface preferences and animation state. No advertising tracking.

Cookies & storage notice · Privacy notice