Current pre-release register — activation remains provider-specific
This register separates provider capability found in source code from an active production appointment. A provider is not a current subprocessor merely because a client, adapter, SDK, environment variable or test fixture exists in the repository.
1. How to read this register
- The register is for FaStart services that process merchant-controlled data. Corporate-site-only services are labelled separately and do not automatically form part of the merchant product stack.
- Purpose, data category, activation status, country, hosting region, transfer mechanism, retention and contractual role must be confirmed for the exact production deployment before a provider is used.
- FaStart will update this page when a verified production subprocessor is added, removed or materially changed, subject to the notice and objection terms of the applicable merchant agreement.
- No bank-account, statement or signature records are included in this public register.
2. Source-level provider inventory
| Provider or category | Potential purpose | Potential data | Evidence status | Location / transfer status |
|---|---|---|---|---|
| FaStart hosting, database and runtime operators | Run APIs, databases, queues, caches, logs and public application surfaces | All categories required by the activated service, including account, store, shopper, order, support and technical data | Required category, but the production operator and contract are not identified in the reviewed repository | Not verified; document region, subprocessors and safeguards before activation |
| Iyzico | Payment authentication, payment status, refunds, card storage and reconciliation | Conditional buyer identity/contact/address/IP, basket and amount data; provider-bound card details; protected provider tokens and last-four metadata in FaStart's payment schema | Backend capability present; payment runtime and HTTP/messaging surfaces default to disabled; base URL is sandbox | Provider location, transfer mechanism, retention and executed DPA not verified |
| Navlungo | Address-book, carrier, shipment, tracking and return-shipment operations | Conditional sender/recipient name, phone, email, address, country, city, district, postal code, reference, package and price data | Backend client and DTO capability present; configured URL is a QA endpoint; production activation not verified | Provider location, transfer mechanism, retention and executed DPA not verified |
| Cloudflare R2 / Cloudflare Stream | Conditional image, video, document and return-evidence storage or processing | Uploaded media, file name/type/size/checksum, owner and tenant references, metadata and evidence references | Adapters and media lifecycle exist; media, R2, Stream and cleanup jobs default to disabled | Account, bucket/region, transfer mechanism and retention not verified |
| Google identity provider | Optional Google sign-in or account linking | Provider identity claims and account-linking identifiers received during an enabled flow | ID-token verification/linking capability and client configuration exist; live activation not verified | Provider location, transfer mechanism, retention and executed DPA not verified |
| Corporate-site services: Resend, Plausible, PostHog, Sentry, Vercel/Cloudflare and rate-limiting infrastructure | fastart.tech contact delivery, consent-gated analytics, error monitoring, hosting/edge delivery and abuse protection | Corporate-site form, cookie, telemetry, error and request metadata, only where configured and consented | Separate fastart.tech code/configuration surface; not a verified Backend merchant-product subprocessor list | Actual provider, region, transfer safeguard, retention and contract must be rechecked before relying on the corporate-site notice |
3. Providers not verified
No active generative-AI/LLM provider, advertising network, live payment production account, or production shipping account was verified in the reviewed Backend source and default configuration. Product plans, test fixtures, frontend mocks and environment-variable placeholders are not evidence of an appointment.
4. International transfers and safeguards
Before an international transfer, FaStart must identify the destination and onward recipients, choose an applicable lawful transfer mechanism, assess supplementary measures where needed, and reflect the result in the activated service notice and agreement. The repository does not establish these provider-specific facts.
5. Changes and objections
The production merchant agreement must define the notice period, objection route, replacement process and consequences of an unresolved objection. This register does not invent a fixed notice period or promise that every objection will suspend processing.
6. Contact
Send provider, privacy or transfer questions to privacy@fastart.co or legal@fastart.co. This pre-release register must be refreshed from the actual deployment manifest and executed provider contracts before any provider is activated for production data.