Legal
Sub-processors
These are the third parties Flokte relies on to run the service and process merchant data. This list is referenced by the Data Processing Agreement.
| Sub-processor | Purpose | Data | Location | Status |
|---|---|---|---|---|
| Google Cloud Platform | Hosts the Flokte application, API, worker, and primary PostgreSQL datastore on Compute Engine. | Encrypted customer identifiers; order, return, score, action, dispute, and audit records — in transit and at rest on the host. | United States | In use |
| Transactional email provider | Will send shopper restriction notices and merchant re-notifications when email delivery goes live. | Recipient email address and notice contents | To be confirmed when a provider is selected | Planned — notices are logged only today; no email is sent yet |
| Stripe | Processes the merchant's own subscription payments for paid Flokte plans (direct billing). | Merchant billing contact and payment method, plan, and charge history. No storefront-customer data. | United States | Planned — direct billing not yet live |
| OpenAI | Optional. Drafts a plain-language brief for a Flokte reviewer working a dispute — advisory only, never part of the scored decision. | Return reason codes and notes, fault attribution, timing, and the shopper's stated reason. No name, email, or address. Sent with retention opt-out. | United States | Optional — used only when enabled; a rules-based fallback runs otherwise |
| Shopify | Source platform (not a sub-processor — the merchant's own platform) | Order, return, and customer data the merchant authorizes | Per Shopify | In use |
Notice of changes
Under the Data Processing Agreement, Flokte gives merchants advance notice before adding a new sub-processor, and imposes data-protection terms on each that are no less protective than the DPA. To be notified of changes to this list, email legal@flokte.com.
Not sub-processors
The merchant's own commerce platform (Shopify) is the source of the data, not a sub-processor engaged by Flokte. The public marketing site host (Vercel) and the Sanity CMS used for homepage copy do not receive storefront customer data from connected stores. Flokte does not use advertising, analytics, or data-broker services on merchant data.