Subprocessors

Riptide relies on the third-party services below to operate the platform. Each one processes a specific slice of data for a specific purpose, nothing more. This list changes as Riptide evolves; we will update the page and the effective date when we add, remove, or materially change a subprocessor.

Effective
September 5, 2026
Services
7
Hosted in
United States for 6 of 7; Shopify runs in its own regions
Questions
privacy@riptidequeue.com

Seven services with one job and one slice of data each: hosting, database, identity, billing, orders, Discord delivery, optional analytics.

ServiceWhat it does for RiptideData that reaches it
Fly.ioHosting · United States (primary region iad, Ashburn, Virginia)Primary application hosting: the web app, API, Shopify/Stripe webhook handlers, realtime (SSE) endpoints, and the on-stream overlay run on Fly Machines. Fly also terminates TLS and stores application secrets.All request traffic to the app, application secrets (database URL, integration keys, encryption key), and server logs/metrics.
NeonDatabase · United StatesManaged Postgres database: the system of record for workspaces, shops, installations, live sessions, orders, queue entries, queue events, and webhook receipts.All workspace, order, queue, and webhook-receipt data, encrypted at rest. Shopify tokens and Discord webhook URLs are additionally encrypted by Riptide before storage.
ClerkIdentity · United StatesSeller identity, workspaces (organizations), and role management.Email address, display name, hashed password (if used), sign-in session metadata, and organization membership.
StripeBilling · United StatesSubscription billing: checkout, the customer billing portal, and webhook-driven subscription status. The card is tokenized and held by Stripe. Riptide never sees or stores your card number.Billing email, country, and subscription/payment status. Riptide stores only Stripe identifiers and subscription status; the payment method stays with Stripe.
ShopifyOrders · Shopify-operated regionsMerchant integration authorized by the seller at install time. Source of truth for orders and line items.Orders and line items the seller has authorized Riptide to receive via OAuth scopes and webhook subscriptions.
DiscordDelivery · United StatesOutbound delivery target for queue events, stalled-queue alerts, and wrap-up summaries when the seller configures a Discord webhook.Embed payloads the seller has opted to send (queue state, buyer handles, session metadata). The webhook URL is stored encrypted by Riptide.
PostHogAnalytics · United States (PostHog US Cloud, Riptide project)Optional acquisition and seller product analytics, enabled by browser consent and a separate owner/admin workspace preference for completed operations. Autocapture and session replay are disabled.Allowlisted event and normalized page names, pseudonymous seller/workspace identifiers, live/manual/sandbox/test source labels and bounded task durations/error categories. No customer contact details, order contents, payment details, signed URLs, tracking numbers or unrestricted form text.

Paid workspace owners get email before a material new subprocessor. The effective date above is the source of truth.

Workspace owners on a paid plan will receive email notice before we add a new subprocessor that materially changes how your data is processed. For day-to-day changes, check back on this page. The effective date at the top is the source of truth.

Questions about this list go to the privacy mailbox.

Questions about this list should go to privacy@riptidequeue.com. The contact page explains which mailbox reads what.