This page is incorporated by reference into our Data Processing Addendumas Annex III. We review the list when we add or remove a vendor; if you'd like at least 30 days advance notice of changes — typically required by enterprise data-protection agreements — email privacy@zillo.appand we'll add you to the change-notice list.
| Sub-processor | Category | Purpose | Region | Documentation | Last reviewed |
|---|---|---|---|---|---|
| Stripe | Payments | Card processing, payouts to merchants, KYC, dispute handling, Connect onboarding, Terminal (POS). | USA / Australia / EEA | DPA | May 2026 |
| Amazon Web Services (AWS) | Cloud infrastructure | Application hosting, edge delivery (CloudFront), transactional email (Amazon SES), DNS (Route 53), object storage (S3). | Australia (ap-southeast-2) | GDPR Center | June 2026 |
| Supabase | Database & auth | Postgres database, authentication, file storage. Runs on AWS infrastructure. | Australia (ap-southeast-2, on AWS) | DPA | June 2026 |
| Anthropic | AI services | Powers the AI Builder, product inference, and support assistant. Prompts are not used to train models per our DPA. | USA | DPA | June 2026 |
| Unsplash | Stock imagery | Stock placeholder images suggested by the AI Builder during onboarding. No personal data shared. | Canada / USA | Privacy policy | June 2026 |
International transfers
Zillo's production infrastructure runs in Australia (ap-southeast-2). Several sub-processors above operate in the USA or EEA. Where personal data is transferred internationally we rely on Standard Contractual Clauses (SCCs) and the adequacy decisions applicable to the relevant transfer corridors.
Customer support
Our support team is based in Australia. When you contact support, the conversation content is held in our own database (no third-party ticketing system) and processed by the staff member handling your case.
How we add or change sub-processors
Before onboarding a new sub-processor we review their certifications (SOC 2, ISO 27001, PCI DSS where relevant), their published security posture, and where they operate. A signed Data Processing Agreement is in place with every sub-processor on this list.
Questions
Email privacy@zillo.app for DPA copies, SCC addendums, or to be added to the change-notice list.