Policies
Sub-processors
Frevn uses the following third-party service providers ("sub-processors") to operate the marketplace. Each is bound by a data-processing agreement that limits how they may use personal data. This page is referenced from our Privacy Policy.
Last updated: July 1, 2026
Infrastructure & hosting
| Provider | Purpose | Data shared | Processing region |
|---|---|---|---|
| Cloudflare Workers | Application hosting, edge compute, DDoS protection | Request metadata, IP, headers | Global (edge) |
| Supabase (PostgreSQL, Storage, Auth) | Database, file storage, authentication | Account data, orders, messages, uploads | EU / US (project-configured) |
Payments & payouts
| Provider | Purpose | Data shared | Processing region |
|---|---|---|---|
| Stripe | Card acquiring, disputes, radar | Buyer name, email, billing address, last4, transaction amount | US / EU / UK |
| PayPal | Card & wallet acquiring | Buyer email, transaction amount, order reference | US / EU |
| Payoneer | Cross-border seller payouts | Seller name, tax country, payout amount, bank/card details | US / EU / global |
| Paystack / Flutterwave | Local acquiring in Africa (where enabled) | Buyer contact + amount | NG / KE / ZA / GH |
Identity & compliance
| Provider | Purpose | Data shared | Processing region |
|---|---|---|---|
| KYC provider (identity verification) | Government-ID and selfie verification for sellers | ID document, selfie, date of birth, address | EU / US |
| Sanctions & PEP screening | OFAC / EU / UK / UN sanction list matching | Legal name, date of birth, country | EU / US |
Communications
| Provider | Purpose | Data shared | Processing region |
|---|---|---|---|
| Transactional email (SMTP) | Order updates, receipts, password resets, tax reminders | Recipient email, message body | Provider-dependent |
| Push notification services (APNs / FCM) | Mobile & web push notifications | Device token, notification content | Global |
Analytics & observability
| Provider | Purpose | Data shared | Processing region |
|---|---|---|---|
| Product analytics | Anonymized usage metrics and funnel analysis | Pseudonymous session events, page URL, UA | EU / US |
| Error monitoring | Runtime error and performance tracing | Stack traces, request path, anonymized user ID | EU / US |
Notification of changes
We may add or replace sub-processors as the platform evolves. Material additions will be posted here at least 30 days before they take effect. Customers on enterprise agreements can subscribe to change notifications by contacting the Help Center.