Skip to main content
FaStart logo

Current FaStart legal documents — conditional services and transaction templates become binding only when the relevant feature is activated, seller-specific facts are completed, and any required electronic acceptance is recorded.

All legal documents

Subprocessor Register

Last updated: 11.08.2026Effective date: 11.08.2026

Current pre-release register — activation remains provider-specific

This register separates provider capability found in source code from an active production appointment. A provider is not a current subprocessor merely because a client, adapter, SDK, environment variable or test fixture exists in the repository.

1. How to read this register

  • The register is for FaStart services that process merchant-controlled data. Corporate-site-only services are labelled separately and do not automatically form part of the merchant product stack.
  • Purpose, data category, activation status, country, hosting region, transfer mechanism, retention and contractual role must be confirmed for the exact production deployment before a provider is used.
  • FaStart will update this page when a verified production subprocessor is added, removed or materially changed, subject to the notice and objection terms of the applicable merchant agreement.
  • No bank-account, statement or signature records are included in this public register.

2. Source-level provider inventory

Provider or categoryPotential purposePotential dataEvidence statusLocation / transfer status
FaStart hosting, database and runtime operatorsRun APIs, databases, queues, caches, logs and public application surfacesAll categories required by the activated service, including account, store, shopper, order, support and technical dataRequired category, but the production operator and contract are not identified in the reviewed repositoryNot verified; document region, subprocessors and safeguards before activation
IyzicoPayment authentication, payment status, refunds, card storage and reconciliationConditional buyer identity/contact/address/IP, basket and amount data; provider-bound card details; protected provider tokens and last-four metadata in FaStart's payment schemaBackend capability present; payment runtime and HTTP/messaging surfaces default to disabled; base URL is sandboxProvider location, transfer mechanism, retention and executed DPA not verified
NavlungoAddress-book, carrier, shipment, tracking and return-shipment operationsConditional sender/recipient name, phone, email, address, country, city, district, postal code, reference, package and price dataBackend client and DTO capability present; configured URL is a QA endpoint; production activation not verifiedProvider location, transfer mechanism, retention and executed DPA not verified
Cloudflare R2 / Cloudflare StreamConditional image, video, document and return-evidence storage or processingUploaded media, file name/type/size/checksum, owner and tenant references, metadata and evidence referencesAdapters and media lifecycle exist; media, R2, Stream and cleanup jobs default to disabledAccount, bucket/region, transfer mechanism and retention not verified
Google identity providerOptional Google sign-in or account linkingProvider identity claims and account-linking identifiers received during an enabled flowID-token verification/linking capability and client configuration exist; live activation not verifiedProvider location, transfer mechanism, retention and executed DPA not verified
Corporate-site services: Resend, Plausible, PostHog, Sentry, Vercel/Cloudflare and rate-limiting infrastructurefastart.tech contact delivery, consent-gated analytics, error monitoring, hosting/edge delivery and abuse protectionCorporate-site form, cookie, telemetry, error and request metadata, only where configured and consentedSeparate fastart.tech code/configuration surface; not a verified Backend merchant-product subprocessor listActual provider, region, transfer safeguard, retention and contract must be rechecked before relying on the corporate-site notice

3. Providers not verified

No active generative-AI/LLM provider, advertising network, live payment production account, or production shipping account was verified in the reviewed Backend source and default configuration. Product plans, test fixtures, frontend mocks and environment-variable placeholders are not evidence of an appointment.

4. International transfers and safeguards

Before an international transfer, FaStart must identify the destination and onward recipients, choose an applicable lawful transfer mechanism, assess supplementary measures where needed, and reflect the result in the activated service notice and agreement. The repository does not establish these provider-specific facts.

5. Changes and objections

The production merchant agreement must define the notice period, objection route, replacement process and consequences of an unresolved objection. This register does not invent a fixed notice period or promise that every objection will suspend processing.

6. Contact

Send provider, privacy or transfer questions to privacy@fastart.co or legal@fastart.co. This pre-release register must be refreshed from the actual deployment manifest and executed provider contracts before any provider is activated for production data.