Subprocessors
Infrastructure should be visible, not implied.
Metrico uses service providers to operate parts of the application. This page explains the categories we disclose and separates Metrico subprocessors from commerce and advertising platforms a merchant independently chooses to connect.
Last updated: September 30, 2026
Service-provider categories
A production Metrico deployment can use providers for application hosting and content delivery, managed database infrastructure, cache or queue infrastructure, transactional email, observability, and incident response. Only providers actually enabled for the production service should be represented as active subprocessors.
Application hosting
The prepared production deployment uses Amazon Web Services (AWS) for application hosting and Supabase for managed PostgreSQL. These providers process data needed to deliver the service when that deployment is active.
Transactional email
The backend supports Resend for account-verification and password-recovery email. Resend is a subprocessor only for deployments where that integration is configured and used.
Error monitoring
When enabled, Sentry receives application error types and stack locations to help us diagnose failures. Metrico removes raw exception messages, request details, customer identifiers, and provider payloads from these reports. Session recording, performance tracing, and log forwarding are disabled.
Deployment-dependent infrastructure
Database, cache, backend-hosting, and observability providers can differ by environment. Metrico does not publish a provider as an active subprocessor solely because the codebase supports it. Merchants that need the exact production list for contracting or compliance can request it through the contact channel.
Connected commerce and ad platforms
Shopify, Meta, TikTok, and Google are platforms a merchant may independently authorize Metrico to connect to. They are not described as Metrico subprocessors merely because the merchant chooses to exchange data with them; each platform's own terms and privacy roles continue to apply.
Changes
Material changes to the production subprocessor set should be reflected on this page before or when the new provider begins processing merchant data, subject to any contract-specific notice commitments.
Need the exact production list?
Use the contact page and identify the store or account involved. Do not send API keys, provider tokens, passwords, or other secrets.