StoresOmni

Websites, commerce, and operations in one workspace.

Build the public site, run the work behind it, and keep merchant control explicit.

Product

  • Features
  • Pricing
  • Theme showcase
  • Store manager

Support

  • Contact
  • Merchant login
  • Create an account

Legal & privacy

  • Privacy policy
  • Terms of service
  • Data processing addendum
  • Subprocessor list
  • Cookie policy

© 2026 StoresOmni. All rights reserved.

StoresOmni
FeaturesPricingShowcaseContact Us
Log InStart Free Trial

Subprocessors and Service Providers

Providers that support StoresOmni, including conditional integrations and independent payment or tax processing.

Last updated
October 3, 2026
Effective date
October 3, 2026

On this page

1. Roles and conditional use2. Infrastructure service providers and subprocessors3. Conditional AI services4. Conditional email delivery and routing5. Merchant-authorized payment integrations and independent roles6. Merchant-authorized tax services7. Other integrations, locations, and safeguards8. Changes and objectionsContact StoresOmni
Contact StoresOmni

1. Roles and conditional use

StoresOmni LLC uses providers to deliver its Services. A provider may act as our service provider, a subprocessor for Merchant Customer Data, a Merchant-authorized integration, or an independent controller for particular activities. Classification follows the function and applicable agreement, not just the provider's name. This list covers supported functions and does not say every provider is enabled or receives every user's information. Conditional providers may receive applicable data when the corresponding feature or integration is enabled.

The Privacy Policy describes StoresOmni's independent platform processing and Merchant-directed processing. Our DPA governs subprocessors of Merchant Customer Data and their notice/objection requirements. Independent providers' own terms and notices apply to their independent processing.

2. Infrastructure service providers and subprocessors

Vercel — application hosting, deployment, request handling, content delivery, and related infrastructure/security. Applicable data includes requests, IP/network and device information, transmitted account/customer content, and request or operational records. Data received depends on the hosted route and function. Vercel privacy information.

Google / Google Cloud / Firebase — authentication, database, file/media storage, backend and security infrastructure, and scheduled operational jobs where Google Cloud Scheduler is configured. Applicable data includes identity/authentication information, store-specific customer and commerce data, files and media, service/security records, and job request metadata. Google Cloud Scheduler is part of Google Cloud infrastructure, not a separate unrelated provider. Google sign-in may additionally involve Google's independent identity-provider role under its own terms. Google Cloud privacy information and Firebase privacy information.

3. Conditional AI services

OpenAI — AI assistance, conversational/authorized workspace operations, site and product/content proposals, and generated or reference-image functions when configured and invoked. Applicable data includes prompts, relevant limited context and tool results, needed attachments/reference images, generated output, and operational metadata. OpenAI acts as a service provider/subprocessor for applicable supplied content, with provider safety and other processing governed by its terms. Our Responses requests disable application-state storage; abuse-monitoring or endpoint-specific retention can still apply. This is not a zero-retention or region-specific guarantee. See the AI privacy disclosure and OpenAI API data controls.

4. Conditional email delivery and routing

Resend — transactional and operational email delivery when selected/configured. Applicable data includes recipient addresses, relevant message content, verification/account and order messages, and delivery metadata. Resend privacy information.

Postmark — an alternative configured delivery provider for transactional or operational email, with applicable addresses, message content, and delivery/status information. Selecting one delivery provider does not mean both receive every message. Postmark privacy information.

ImprovMX — routing or forwarding for StoresOmni-managed email addresses where that routing is configured. Applicable data may include sender/recipient addresses, headers, subjects, message content, and delivery information. It is email infrastructure, not an assumption that every storefront email is routed through it. ImprovMX privacy information.

5. Merchant-authorized payment integrations and independent roles

PayPal — merchant-managed checkout, partner/platform connections where enabled, payment creation/capture, refunds, billing where configured, and applicable webhook/reconciliation information. Data may include Merchant/provider account identifiers, payer details, checkout/transaction references and amounts, refund/dispute and fraud/security information, and applicable platform-fee records. PayPal determines its own purposes for payment, regulatory, fraud, and account operations and may act as an independent controller. It is not treated as a subprocessor for all those activities merely because StoresOmni integrates with it. PayPal privacy information.

Stripe / Stripe Connect — connected Merchant payment processing, onboarding and account permissions, payment/refund/dispute events, application fees, and reconciliation where enabled. Data may include business/account and customer/payment information, transaction identifiers/amounts, provider tokens, and fraud/compliance records. Stripe may act independently for regulated payment, fraud and legal functions, and as a processor for other contracted functions. Classification follows the relevant use and agreement. Stripe privacy information.

6. Merchant-authorized tax services

Stripe Tax — calculation, transaction recording, refund reversals, registration/configuration and related reporting where enabled, including independently of the chosen payment provider. Data may include seller and customer tax location, product categories, line amounts, shipping/currency, registration or supplied tax-ID evidence, and tax transaction references. Stripe's role follows its contracted tax functions and any independent legal/compliance obligations. Stripe privacy information.

Quaderno — connected tax calculation, transaction/refund recording and related tax/compliance functionality where enabled. Data may include Merchant account/registration information, customer tax location, order/product and amount/currency details, and transaction/reversal records. It is a Merchant-authorized tax integration and may have processor and independent roles depending on its terms and purposes. Quaderno privacy information.

Manual tax configuration is StoresOmni functionality rather than a separate external subprocessor. It does not imply automatic registration, filing, remittance, or a tax advisory service. Providers' own fees and obligations are separate from StoresOmni platform charges.

7. Other integrations, locations, and safeguards

Frankfurter — server-side reference exchange-rate information when currency conversion is configured. Requests contain the base currency and ordinary server request/network metadata, rather than customer profiles or orders. It is an exchange-rate data source, not a subprocessor of customer commerce records merely because rates inform pricing. Frankfurter service information.

Merchant-authorized services receive data only within the applicable authorization and available functionality. A Merchant connecting its own provider is responsible for reviewing that provider's terms and disclosures. If StoresOmni engages an additional subprocessor for Customer Data, we apply the DPA's contractual safeguards and notice process rather than implying a generic future provider is already active.

Processing may occur in the United States and other jurisdictions where the applicable provider operates. Specific locations depend on the service and configuration; no universal region or residency commitment is made here. Provider headquarters or a public privacy notice does not establish a contractual processing location. Restricted transfers require applicable lawful safeguards as explained in the Privacy Policy and DPA. This page does not itself execute transfer instruments or claim StoresOmni certifications.

8. Changes and objections

We update this page when relevant providers or functions change. For new or replacement subprocessors processing Customer Data, Merchants receive notice and may object on the grounds and within the periods stated in the DPA, including its limited emergency provisions. Changes in an independent Merchant-selected integration are also subject to that provider's terms. Contact privacy@storesomni.com for questions about applicable processing, providers or safeguards, and security@storesomni.com for security concerns.

Contact StoresOmni

StoresOmni LLC, a New Mexico limited liability company. Legal and notices address: 1209 Mountain Road Pl, STE N, Albuquerque, NM 87110, United States.

storesomni.com

Support: support@storesomni.com · Privacy: privacy@storesomni.com · Security: security@storesomni.com · Legal: legal@storesomni.com · Copyright: copyright@storesomni.com

Terms of Service · Privacy Policy · Cookie Policy · Data Processing Addendum · Subprocessors and Service Providers