This page lists every third party that may receive personal data through seeonwall.com. Merchants need it to complete their own record of processing activities; shoppers may simply want to know where their photo goes.
We act as an independent controller, not as a merchant's processor. A merchant sends us no shopper personal data — a shopper's own browser reaches us as a result of the shopper's own action — and nothing identifying a shopper is returned to the merchant, because the statistics we provide are aggregate counts only. We determine on our own what is collected, how long it is kept, where it is stored and when it is erased, and we accept no instructions on those points. Article 28 GDPR therefore does not govern the relationship, and the vendors below are our own processors; we list them in the form merchants expect to receive.
Each party is responsible for its own compliance. We provide the Article 13 information to shoppers, inside the widget before any upload and in our Privacy Policy, and we handle every data subject request relating to our processing — including requests a merchant forwards to us. Merchants disclose in their own privacy notice that their product pages embed our widget and that loading it transmits visitors' IP addresses to us.
Should a supervisory authority or court instead characterise the loading of the widget on a merchant's storefront as joint controllership under Article 26 GDPR, the split described above applies as the arrangement that Article requires, and this page is where its essence is made available. That is agreed for procedural certainty and is not an admission that joint controllership arises.
This applies only to shoppers who choose to preview a poster on a photo of their own wall. Shoppers who pick a room-scene template instead never upload anything, and no wall photo exists for them at all.
| Sub-processor | Purpose | Data involved | Processing location |
|---|---|---|---|
| Google Cloud — Vertex AI | Detects the wall's corners in the photo so the poster can be placed at true scale without manual calibration. | The wall photo itself, sent for analysis and not retained by the vendor. | EU |
| Cloudflare R2 | Temporary object storage for the uploaded wall photo during the preview session. | The wall photo file. | EU |
| Cloudflare Turnstile | Abuse and bot protection on photo upload and session creation. | IP address, browser and device signals. | Global edge |
These vendors only ever see the shop owner's own account and billing details. No shopper data reaches them.
| Sub-processor | Purpose | Data involved | Processing location |
|---|---|---|---|
| Polar | Subscription billing and invoicing, for every plan including the free one. | Shop owner name, email address, billing and tax details. | EU / US (SCC) |
| Resend | Transactional email — address verification, usage-limit alerts, digests. | Shop owner email address and message content. | EU / US (SCC) |
| Shopify | App installation, authentication and billing for shops installed from the Shopify App Store. | Store owner account details provided by Shopify. | EU / US (SCC) |
These vendors run the servers behind everything above. They do not use the data for their own purposes; they hold or carry it because the service runs on their infrastructure.
| Sub-processor | Purpose | Data involved | Processing location |
|---|---|---|---|
| Neon | Managed PostgreSQL hosting for the production database. | Everything the application stores: shop owner account and billing records, preview-session metadata such as calibration and placement, and support messages. The wall photo files themselves are not stored here. | EU |
| OVHcloud | Virtual server hosting for the API, the preview renderer, the cache and the application logs. | All traffic in transit, including the wall photo on its way to storage; IP addresses in the abuse rate-limit counters. | EU |
| Cloudflare (CDN, Workers) | Serving our web apps and proxying API traffic to the origin server (CDN, DNS and TLS). | IP address and request metadata for every request, including the wall photo in transit. | Global edge |
These run on seeonwall.com itself and are never loaded inside the preview widget on your storefront. Nothing here touches your shoppers.
| Sub-processor | Purpose | Data involved | Processing location |
|---|---|---|---|
| Google Analytics 4 | Aggregate traffic statistics for the marketing site and the shop-owner dashboard. Loaded only after consent. | IP address, device and browser identifiers. | EU |
| Termly | Cookie consent banner and consent record-keeping on the marketing site and the shop-owner dashboard. | IP address, consent choices. | EU / US (SCC) |
| Healthchecks.io | Monitors that our scheduled maintenance jobs actually ran. | None. Only anonymous job ping identifiers are sent. | EU / US (SCC) |
Wall photos are stored in an EU Cloudflare R2 bucket and analysed through Google's EU Data Boundary endpoint for Vertex AI, pinned to europe-west1. Both the file and its analysis therefore stay inside the EU for their whole lifetime. Vendors marked 'EU / US' are US-headquartered and are covered by Standard Contractual Clauses; they receive account and billing data only, never wall photos. For infrastructure vendors the location given is where their systems run: the production database is in Frankfurt (eu-central-1) and the application servers are in the EU. Where such a vendor is US-headquartered, Standard Contractual Clauses cover the access its support staff could have.
A preview session, including any uploaded wall photo, expires after 7 days and is then deleted automatically. Shoppers have no account, and photos are never used to train any model, never sold, and never shared with anyone outside the table above.
We update this page before adding or replacing a vendor, so merchants have notice of the change rather than discovering it afterwards.
Questions about this list, or a data protection request, go to privacy@seeonwall.com. Privacy Policy