Trust

Sub-processors

Current as of: June 20, 2026

To deliver the HundredFold service, we engage a small number of trusted third parties ("sub-processors") to perform functions on our behalf — such as hosting our application, storing data, sending transactional email, and powering AI analysis. We share with each sub-processor only the data necessary for it to perform its function.

Before engaging a sub-processor, we perform due diligence appropriate to the data it will handle, and we put in place contractual terms that require it to protect that data and use it only to provide services to us.

We will notify customers in advance of material changes to this list — including the addition of a new sub-processor — so that they have an opportunity to review the change. To receive these notifications, email admin@gohundredfold.com to be added to our notification list.

How to read this list

HundredFold acts in two capacities:

The sub-processors below may handle one or both categories, as noted in the "Data processed" column. Where a sub-processor receives only business aggregates (and no personal data at all), we say so.

Infrastructure sub-processors

Sub-processorPurposeData processedRegion
SupabaseManaged PostgreSQL database and authentication. Stores all HundredFold application data, including merchant account-user emails and the minimal end-customer data (order email + ship city/state/country) synced from connected stores.Merchant account-user data (email, role, internal user id); end-customer email + ship city/state/country; all other app data.United States
VercelApplication hosting and scheduled background jobs (cron) that run the data syncs.Hosting and request processing for the application; no separate data store of its own (data at rest lives in Supabase).United States
AnthropicAI analysis powering the daily briefing, AI analyst, and ad/email copy generation (Claude).Business aggregates only — KPIs (revenue/ROAS/AOV), inventory summaries, top-ad metrics, customer-health rates (e.g. repeat/refund %), email metrics, replenishment plan, plus the merchant's own written business-context notes. No end-customer PII; no API keys, tokens, or secrets.United States
HiggsfieldAI image generation for ad creative.Merchant product images + text prompts only. No customer or personal data. Served via a single HundredFold company account across all tenants.United States
ResendTransactional email delivery — sends warehouse notices (packing lists / FBA labels) to a merchant-configured warehouse email.Warehouse-operations email content addressed to a merchant-configured recipient. No end-customer PII.United States
KlaviyoEmail-marketing platform — receives draft templates and draft campaigns the merchant reviews and sends, and receives customer emails to build win-back audience lists.Draft template/campaign content; end-customer email addresses (from orders) exported to build win-back lists.United States

Supabase and Vercel each maintain SOC 2 Type II reports.

Merchant-connected platforms

Separately from the infrastructure sub-processors above, HundredFold connects to platforms that the merchant authorizes as data sources. These are services the merchant already uses and grants HundredFold access to (for example, via OAuth or an API key). They are governed by the merchant's own agreements with those platforms — they are not HundredFold infrastructure sub-processors, because HundredFold does not engage them to provide the HundredFold service; the merchant brings them.

PlatformRole in HundredFoldAccess
ShopifySource of store data: products, variants, inventory, orders (including the customer email + ship city/state/country we store), locations, and fulfillments.Read-only.
Meta (Facebook / Instagram)Source of ad performance data; optional creation of paused draft ads for the merchant to review (never published live).Reads aggregate ad metrics; optional write limited to paused drafts.
GoogleSource of organic, analytics, and ads performance data (Search Console, Google Analytics 4, Google Ads).Read-only aggregates.
Amazon (Selling Partner API)Source of FBA inventory and a sales-and-traffic report (revenue/order counts) plus inbound-shipment operations.Read-only. No customer PII.

This list is current as of June 20, 2026. Questions about our sub-processors can be directed to admin@gohundredfold.com.