Sub-processors
Last updated: August 14, 2026
To run Styla we rely on a small number of third-party providers that process personal data on our behalf. This page lists them. It is referenced by Section 7.3 of our Privacy Policy and by Section 25 of our Terms of Use.
Each provider is bound by a data processing agreement, may process personal data only on our instructions, and is subject to obligations equivalent to our own. All are established in the United States; where they process personal data from the UK or EEA, we rely on the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.
Current sub-processors
| Provider | What we use it for | Personal data involved |
|---|---|---|
| Vercel | Application hosting, serverless functions, edge network, and storage for uploaded images | Request metadata, IP addresses, uploaded photos and videos |
| Neon | Managed PostgreSQL — our primary database | Account and profile data, content, closets, messages, orders, commission and payout records |
| Stripe | Payment processing, payouts to brands and curators, and tax calculation | Payment card data (held by Stripe), name, billing and delivery address, order amounts, payout and tax details |
| Twilio | SMS delivery and phone number verification | Mobile phone numbers, verification codes, message content |
| Resend | Transactional email delivery | Email addresses, message content, delivery metadata |
| Expo | Delivering push notifications to the Styla mobile apps, via Apple and Google's push services | Your device's push token and the content of the notification |
| Pusher | Realtime transport for direct messages and live notifications | Message content, user identifiers, connection metadata |
| Upstash | Rate limiting and short-lived operational state | IP addresses, request identifiers (short retention) |
| Sentry | Error and performance monitoring | Error and stack-trace context. We do not send IP addresses or user identifiers, and credentials, cookies, tokens, and sensitive URL parameters are stripped before an error leaves our systems |
| “Sign in with Google” authentication, if you choose it | Your name, email address, and Google account identifier | |
| Apple | “Sign in with Apple” authentication, if you choose it | Your name, your email address or Apple private-relay address, and Apple account identifier |
| Anthropic | AI assistance across the Platform: interpreting search queries, identifying and classifying items in photos, moderating uploaded images against our content policies, suggesting captions, powering the styling helper chat, and extracting commercial terms from brand contracts uploaded by brands | Search queries, messages you send the styling helper, outfit and item images with any caption or post text, and contract documents (which may contain signatory names and business contact details) |
| SerpAPI | Visual product matching for reverse image search (Find Items) | The outfit or item images you submit to Find Items |
| Voyage AI | Text embeddings that power outfit search and discovery | Search queries and outfit text |
| Microsoft | Screening uploaded images — including images attached to direct messages — against fingerprints of known child sexual abuse material, using Microsoft's PhotoDNA service. Confirmed matches are reported to the National Center for Missing & Exploited Children, as US law requires | A small, non-reversible fingerprint (hash) of each uploaded image, computed on our own servers. The image itself never leaves our systems, no account identifier is sent, and the fingerprint cannot be turned back into the picture |
Not sub-processors
Shopify is a merchant's own store platform, not our sub-processor. Where a brand connects its store, we receive order data from Shopify on that brand's instruction; the brand's own agreement with Shopify governs Shopify's processing. See Section 10 of the Privacy Policy.
Meta / Instagram works the same way. Where a brand connects its Instagram account, we receive that brand's own profile and media through Instagram's official API with the brand's explicit consent. Meta's own terms govern its processing, and we purge the connection on disconnect and on Meta's data-deletion signal. It is not a sign-in provider.
Brands and retailers that sell through Styla are independent controllers of the order data they receive as seller of record, and payment networks and card issuers are independent controllers within the payment chain.
Changes to this list
We update this page when we add or remove a provider that processes personal data. Merchants who have connected a store and wish to be notified in advance of a change can ask us to add them to the notification list.
Questions, or a request for a provider's data processing agreement, can be sent to privacy@shopstyla.com.