Sub-processors
Orchestrapay uses the third-party service providers ("sub-processors") listed below to help provide the payment orchestration platform. Each sub-processor is bound by contractual data-protection and security obligations, and processes personal data only to provide its service to us. This page is referenced by our Privacy Policy and Data Processing Addendum.
We keep this list current and separate from those documents so that adding or removing a sub-processor does not require a change to the policies themselves. The date above reflects the most recent change to this list.
| Sub-processor | Purpose | Data involved | Region(s) |
|---|---|---|---|
| Amazon Web Services | Hosting for the USA region (data residency) | All processed data | United States |
| Huawei Cloud | Hosting for the Egypt region (data residency) | Payment and transaction data | Egypt |
| DigitalOcean | Hosting for the Europe region (data residency) | Payment and transaction data | European Union |
| Vercel | Hosting of checkout and marketing web pages | Technical/usage data, checkout inputs | United States / global edge |
| Cloudflare | DNS, content delivery, TLS and network security | Connection metadata (including IP) | Global edge |
| Resend | Transactional and notification email | Recipient name and email address | United States |
| Sentry | Error tracking and masked session replay | Error, device and masked session data | United States |
| Neutrino API | Card BIN lookup and IP geolocation | Card BIN (first digits) and payer IP address | United States |
| Banks and merchants (secure file transfer) | Delivery of reconciliation and settlement reports the merchant requests | Transaction and reconciliation data | As directed by the merchant |
| Payment gateways & acquirers (Stripe, Adyen, Checkout.com, PayPal, Paymob, Fawry, and other providers), as directed by the merchant | Executing and settling transactions the merchant routes through us | Cardholder, payment and transaction data | As directed by the merchant (global, depending on the provider) |
Some components we use for logging, monitoring and background job processing are self-hosted on our own infrastructure (which runs on the hosting providers listed above) rather than operated by a third party, so they are not separate sub-processors.
Changes and notifications
We may update this list from time to time as our service evolves. Merchants who have entered into our Data Processing Addendum may request to be notified of new sub-processors in advance and may object on legitimate data-protection grounds, as described in that addendum.
Questions
For questions about our sub-processors, contact privacy@orchestrapay.com.