You're in an in-app browser. Open Ordinary in your browser to sign in or install — Google sign-in won't work here.

Open in browser
Ordinary
  • Analytics

    • Multi-touch attribution Four models, switchable in one click.
    • Profit and margins Product costs, per-order costs, profit by channel.
    • Customer analytics Lifecycle, cohorts, the Whales filter, Offer Calculator.
    • Meta ad analytics Creative, placements, audiences, cohort LTV per campaign.

    Optimization

    • AI creatives Three image models, BYO keys, push to Meta.
    • Reconciliation & data integrity Match-to-the-cent revenue. Region-aware privacy.
    • Meta Conversions API Recover the 30–40% iOS + ad blockers strip out.
    • AI session replays An AI watches every session and ranks what's costing you orders.
    See all solutions →
  • Sales & Ads

    • Shopify The base — orders, customers, products, refunds, pixel.
    • Meta Ads Spend, performance, creative, server-side CAPI.
    • Google Ads Search, Shopping, YouTube, PMax — joined to your store.
    • Amazon Sales, conversion, fees, inventory, and ad spend.

    Marketing & Analytics

    • Klaviyo Email + SMS campaigns and flows, attributed revenue.
    • Google Analytics 4 GA4 events alongside commerce data.
    • PostHog Product-analytics events and identity.
    See all integrations →
    • Help Center Guides, walkthroughs, and troubleshooting.
    • Getting started Install Ordinary and connect your data.
    • Integration guides Shopify, Meta, Google, Amazon, Klaviyo.
    • Troubleshooting Fix common data and sync issues.
    • See all resources →
  • Blog
  • Pricing
  • About
Sign in Start free Book a demo

Sub-Processors

Last updated: 2026-08-04

Ordinary engages the following third-party service providers (“Sub-Processors”) to process Personal Data on behalf of merchant customers who use the Ordinary Service. This list is maintained as required by Section 6 of Ordinary’s Data Processing Agreement.

Ordinary updates this list when it engages a new Sub-Processor, and notifies merchants in the Ordinary app and by email to organisation administrators. Merchants may object to a new Sub-Processor within 30 days of that notice, per Section 6.2 of the DPA.


Core infrastructure

Sub-ProcessorPurposeData processedLocation
VercelApplication hosting (Next.js)All request/response data in transit; logsUSA (primary), global edge
NeonPrimary Postgres database (managed)All application data at restUSA (AWS us-east-1)
Digital Ocean App PlatformBackground worker (Graphile) hosting for async tasks (webhook processing, backfills)Queue payloads; temporarily holds event data in transitUSA (primary region)
DigitalOcean SpacesFile storage (admin-files, imported data, temporary export bundles)Uploaded files, data export JSONsUSA
CloudflareReceives and stores session replay recordings, and serves the replay player to authorised merchant usersSession replay content (rendered storefront pages with typed input masked before transmission), visitor IP address in transitUSA / global edge

Authentication and user management

Sub-ProcessorPurposeData processedLocation
ClerkUser authentication, session management, MFAAuthorised-user email, name, password (hashed, stored by Clerk), IP address, user agent, session tokensUSA

Communications

Sub-ProcessorPurposeData processedLocation
ResendTransactional email delivery (GDPR data-request bundles, system notifications)Recipient email, subject, body, attachmentsUSA

Source-system integrations (data ingestion)

Sub-ProcessorPurposeData processedLocation
ShopifySource of merchant store data (orders, customers, products, webhooks)OAuth token, store data synced per merchant authorisationGlobal (Shopify’s own infrastructure)
Meta (Graph API)Read-only pull of merchant’s own ad campaign performance dataOAuth token, campaign metadata, ad performance metrics (aggregate, no customer data)USA
Google (Analytics Data API, Search Console API, Sheets API)Read-only pull of merchant’s GA4 / GSC / Sheets data (optional per merchant)OAuth token, aggregate session / search / spreadsheet dataUSA
Amazon Ads APIRead-only pull of merchant’s Amazon ad campaign performance (optional per merchant)OAuth token, campaign metadata, ad performance metricsUSA
Amazon Selling Partner API (SP-API)Read-only pull of merchant’s own Amazon Seller account business data — sales & traffic, financials, inventory, orders (optional per merchant)OAuth token, aggregate sales / traffic metrics, financial event amounts (settlements / fees / refunds), inventory levels, order records (product / quantity / price; no end-buyer personal data)USA
PostHogLegacy merchant analytics ingestion for orgs that installed PostHog before Ordinary’s pixelOAuth token, aggregate session dataUSA or EU per merchant’s PostHog region
KlaviyoRead-only pull of merchant’s own email + SMS campaign and flow performance data (optional per merchant)OAuth token, campaign / flow metadata, send metrics (recipients, opens, clicks, unsubscribes, bounces, attributed revenue)USA

Ad-platform forwarding (outbound, at merchant instruction)

These Sub-Processors receive hashed customer identifiers only, forwarded on the merchant’s explicit instruction via an OAuth-authorised connection to the merchant’s own ad account. Merchants can disconnect at any time via Settings → Integrations.

Sub-ProcessorPurposeData processedLocation
Meta Conversions APIServer-side purchase event forwarding to merchant’s own Meta ad accountSHA-256 hashed email / phone / first name / last name; purchase amount, currency, timestamp, event IDUSA
Google Enhanced Conversions (planned)Server-side conversion forwarding to merchant’s own Google Ads accountSHA-256 hashed user data; purchase amount, currency, timestampUSA

Billing and subscriptions

Sub-ProcessorPurposeData processedLocation
StripeSubscription billing for Ordinary’s own fees to merchantsMerchant billing contact, payment method (tokenised), subscription stateUSA

Ordinary’s own product analytics (internal)

Sub-ProcessorPurposeData processedLocation
PostHog (our instance)Product analytics on Ordinary’s own application usage by authorised merchant usersAuthorised-user events (page views, clicks within Ordinary), pseudonymous user IDUSA

Note: this is Ordinary’s own product-analytics instance, separate from any merchant’s PostHog integration. It collects behaviour of merchant administrators inside the Ordinary dashboard, not their customers’ behaviour on their storefronts.


Data transfer mechanisms

For transfers of Personal Data from the EEA / UK / Switzerland to the US or other third countries:

  • Where a Sub-Processor is certified under the EU-US Data Privacy Framework, we rely on that certification.
  • Where it isn’t, we rely on the 2021 Standard Contractual Clauses (SCCs), Module 2 (Controller → Processor) or Module 3 (Processor → Sub-Processor) as applicable.

Merchants subject to EU/UK/Swiss data-protection law may request a signed copy of the SCCs via privacy@tryordinary.com.


Change log

DateChange
2026-04-20Initial launch list published
2026-08-04Listed Cloudflare as a core-infrastructure Sub-Processor. Cloudflare receives and stores Session Replay recordings and serves the replay player to authorised merchant users. Notice issued to merchants in-app and by email; merchants who wish to object under Section 6.2 of the DPA may do so at privacy@tryordinary.com.
2026-06-09Listed the Amazon Selling Partner API (SP-API) as a distinct data-ingestion entry, alongside the existing Amazon Ads API. Same vendor (Amazon) and region (USA); read-only ingest of the merchant’s own Amazon Seller business data (sales & traffic, financials, inventory, orders) with no end-buyer personal data.
Ordinary

Performance clarity for Shopify brands. Built by Rendr.

System status

Product

Solutions Integrations Pricing Blog About Support

Resources

Help Center Getting started Integration guides Troubleshooting

Legal

Privacy Policy Terms of Service Data Processing Agreement Sub-Processors Data Deletion support@tryordinary.com

© 2026 LoudNoises, LLC. All rights reserved.

Operated by Rendr.

A couple of cookies?

We use a few to understand which parts of the site help DTC brand owners. Optional — analytics still work without them, just less precisely.

Privacy policy