Subprocessor List
Last updated: August 1, 2026
This page identifies third parties that may process Customer Data for Mantaro Partners LLC, doing business as ASINRx, in providing the ASINRx Services. It is incorporated into the ASINRx Data Processing Addendum.
Amazon is a data source and independent platform, not ASINRx's subprocessor. A customer-selected AI assistant, spreadsheet connector, or MCP client is also not ASINRx's subprocessor when the customer independently selects and directs the recipient; the customer is responsible for that recipient.
Current subprocessors
| Provider | Service and processing | Data categories | Location |
|---|---|---|---|
| OVH US LLC (OVHcloud) | Application and worker hosting | Account data, Customer Data, logs, encrypted credentials | United States |
| Supabase, Inc. | Managed PostgreSQL database infrastructure | Account data, Customer Data, audit and integration records | United States |
| Amazon Web Services, Inc. | Object storage, query, and dashboard infrastructure (S3, Athena, QuickSight) | Customer reports, derived analytics, exports | United States (us-east-1) |
| Stripe, Inc. | Checkout, subscription, invoicing, and payment administration | Billing contact, plan, amount, transaction and customer identifiers (ASINRx does not receive full card numbers) | United States and Stripe processing locations |
| Sinch Mailgun (Mailgun Technologies, Inc.) | Transactional email delivery | Recipient email, name where included, message content and delivery metadata | United States |
| Anthropic, PBC | Optional listing-content analysis and generation through the commercial API, when the customer uses AI features | Submitted listing text, ASIN, optional PDF/image, prompt, generated output | United States |
Conditions for every subprocessor
Before a provider may process Amazon Information or other Customer Data, ASINRx must:
- document necessity, data categories, systems, locations, and retention;
- perform security and privacy due diligence;
- execute written confidentiality, data-protection, breach-notice, deletion, audit/cooperation, and purpose-limitation obligations;
- impose protections at least as strict as ASINRx's applicable Amazon and customer obligations;
- prohibit sale, cross-customer aggregation, advertising, and unauthorized secondary use;
- prohibit AI/model training and improvement using Amazon Information;
- grant least-privilege access only to approved personnel;
- record all locations and copies of Amazon Information;
- require prompt incident notice that lets ASINRx meet its notification deadlines; and
- verify deletion at termination or the end of the approved retention period.
Change notice
ASINRx will post an intended new subprocessor at least 30 days before it begins processing Customer Data and notify subscribed customer contacts. Customers may submit a reasonable, documented data-protection objection during that period. The parties will work in good faith on a commercially reasonable solution. If none is available, either party may terminate only the affected Service, with a prorated refund of prepaid unused fees.
Subscribe to change notices or submit an objection: legal@asinrx.com