Sub-processors
Service: SalesCentral (sales-central.org) Provider: SalesCentral, Republic of Armenia Last updated: 30 June 2026
SalesCentral engages the sub-processors below to help deliver the service. Each is bound by contractual data-protection obligations and processes personal data only as needed to perform its function. This page is incorporated into our DPA; we provide notice of changes as described there so customers can object on reasonable grounds.
Current sub-processors
| Sub-processor | Function | Personal data processed | Primary location |
|---|---|---|---|
| Apple Inc. | App Store Server API and App Store Server Notifications V2 (in-app purchase verification); Apple Push Notification service (APNs) for delivering push notifications. Apple is also the merchant of record that sells and charges for in-app purchases. | Apple transaction identifiers, app/bundle identifiers, push device tokens. | United States (global infrastructure) |
| Cloudflare, Inc. | Edge network / CDN, TLS termination, reverse proxy, DDoS protection, and IP-based country resolution. | IP addresses and request metadata of End Users and Operators; derived approximate location (country). | United States (global edge network) |
| OpenAI | AI text generation (model gpt-4o-mini, via API) for App Store keyword suggestions and push-notification translation. | Operator-provided content only: App Store metadata (titles, subtitles, keywords) and notification copy. No End-User identifiers, device data, or purchase records are sent. | United States |
| Self-managed infrastructure (SalesCentral) | Hosting of the application servers and the self-managed MongoDB database; all service data is stored at rest here. | All service data described in the Privacy Policy, including End-User and Operator personal data. | Republic of Armenia |
Notes
- Apple is intrinsic to the service: in-app purchase data originates from Apple, Apple processes the actual payments, and push delivery requires APNs.
- OpenAI receives only Developer/Operator content for the two AI features and does not receive End-User personal data, and these features are optional. Data sent via the OpenAI API is processed under OpenAI's API terms and is not used to train its models.
- GeoIP database (optional): if you resolve approximate location with a local GeoIP database (e.g. MaxMind) instead of the edge header, add that provider here.
- Hosting: the application and the MongoDB database run on SalesCentral's own self-managed infrastructure. If you move to a third-party managed host, or add a backup or email provider, list it here as a sub-processor.
Changes
When we add or replace a sub-processor we will update this page and provide notice in line with the DPA. To request notifications of changes, contact [email protected].