Data processing and subprocessors
Roles
The shop is the controller. Bespiq is the processor. Shopify, Etsy, Amazon and Meta are the platforms the shop connects.
Instructions
Bespiq processes data only because of something the shop connected or did: an order, a message, a button.
Requests and deletion
Erasure of a customer and deletion of a whole workspace are built in. Backups age out within seven days, and their contents are unreadable once the keys are gone.
Subprocessors
This list is made from what the code uses. A service is used only when its setting is configured.
Run by Bespiq
| Service | What it processes | Switched on by |
|---|---|---|
| Hosting provider | Servers, database and backups. The provider is being chosen (Hetzner or Google Cloud). | not chosen yet |
| Google Cloud Storage | Files: proofs, artwork and photos. | GCS_BUCKET |
| Resend | E-mails to customers and staff: the address and the message. | RESEND_API_KEY |
| Postmark | The same e-mails, when configured instead of Resend. | POSTMARK_SERVER_TOKEN |
| Clerk | Sign-up and sign-in for shop staff: their e-mail address, name, sign-in methods and security factors. Not used for customers. | CLERK_SECRET_KEY |
| Anthropic | AI suggestions: text with identifiers replaced by placeholders. | ANTHROPIC_API_KEY |
| Google Gemini | AI suggestions when the first provider is unavailable, with the same redaction. | GEMINI_API_KEY |
| Paddle | Subscription billing for shops that do not pay through Shopify. | PADDLE_WEBHOOK_SECRET |
| Twilio | Text messages and calls the shop switches on. | TWILIO_ACCOUNT_SID |
Connected by the shop
These are the shop's own accounts. Data goes to them only when the shop connects them.
| Service | What it processes | Switched on by |
|---|---|---|
| Shopify | Orders, products and customers of a Shopify shop. | SHOPIFY_API_KEY |
| Etsy | Orders and messages of an Etsy shop. | ETSY_API_KEYSTRING |
| Amazon | Orders of an Amazon seller account. | AMAZON_LWA_CLIENT_ID |
| Meta | WhatsApp, Instagram and Messenger conversations. | META_APP_SECRET |
| WooCommerce | Orders of the shop's own WooCommerce site. | connected from the shop's own site |
| Customily | Personalisation entered on the shop's product pages. | CUSTOMILY_API_TOKEN |
| Zakeke | Personalisation entered on the shop's product pages. | ZAKEKE_API_TOKEN |
| Kickflip | Personalisation entered on the shop's product pages. | KICKFLIP_API_TOKEN |
| Printful | Print-on-demand orders sent for production. | PRINTFUL_API_TOKEN |
| Printify | Print-on-demand orders sent for production. | PRINTIFY_API_TOKEN |
| Gelato | Print-on-demand orders sent for production. | GELATO_API_KEY |
| AfterShip | Shipment tracking numbers and delivery status. | AFTERSHIP_API_KEY |
| ShipStation | Shipping labels and tracking. | SHIPSTATION_API_KEY |
Run on Bespiq's own servers, so nothing leaves: the AI gateway, the virus scanner, the workflow engine, the database and the WhatsApp gateway for a shop's own number.