Orchestrapay
Docs
Get started

Sub-processors

Last updated: 15 August 2026

Orchestrapay uses the third-party service providers ("sub-processors") listed below to help provide the payment orchestration platform. Each sub-processor is bound by contractual data-protection and security obligations, and processes personal data only to provide its service to us. This page is referenced by our Privacy Policy and Data Processing Addendum.

We keep this list current and separate from those documents so that adding or removing a sub-processor does not require a change to the policies themselves. The date above reflects the most recent change to this list.

Sub-processorPurposeData involvedRegion(s)
Amazon Web ServicesHosting for the USA region (data residency)All processed dataUnited States
Huawei CloudHosting for the Egypt region (data residency)Payment and transaction dataEgypt
DigitalOceanHosting for the Europe region (data residency)Payment and transaction dataEuropean Union
VercelHosting of checkout and marketing web pagesTechnical/usage data, checkout inputsUnited States / global edge
CloudflareDNS, content delivery, TLS and network securityConnection metadata (including IP)Global edge
ResendTransactional and notification emailRecipient name and email addressUnited States
SentryError tracking and masked session replayError, device and masked session dataUnited States
Neutrino APICard BIN lookup and IP geolocationCard BIN (first digits) and payer IP addressUnited States
Banks and merchants (secure file transfer)Delivery of reconciliation and settlement reports the merchant requestsTransaction and reconciliation dataAs directed by the merchant
Payment gateways & acquirers (Stripe, Adyen, Checkout.com, PayPal, Paymob, Fawry, and other providers), as directed by the merchantExecuting and settling transactions the merchant routes through usCardholder, payment and transaction dataAs directed by the merchant (global, depending on the provider)

Some components we use for logging, monitoring and background job processing are self-hosted on our own infrastructure (which runs on the hosting providers listed above) rather than operated by a third party, so they are not separate sub-processors.

Changes and notifications

We may update this list from time to time as our service evolves. Merchants who have entered into our Data Processing Addendum may request to be notified of new sub-processors in advance and may object on legitimate data-protection grounds, as described in that addendum.

Questions

For questions about our sub-processors, contact privacy@orchestrapay.com.

Orchestrapay
28 Geary St, San Francisco, CA 94108, United States

Coverage

  • Egypt
  • Saudi Arabia
  • UAE
  • Nigeria
  • Kenya

Product

  • Features
  • Docs
  • Sign in

Legal

  • Privacy policy
  • Terms of service
  • Data Processing Addendum
  • Sub-processors
© 2026 Orchestrapay. All rights reserved.PCI✓DSS