Radiant Size Chart
Subprocessors
1. Operator
DAWSEN SA, trading as Ash Spark, operates Radiant Size Chart from Juan María Pérez 2965, CP 11300, Montevideo, Uruguay. This page identifies providers that can process merchant, limited order-linked, or Shopify App Store listing and installation data to deliver, measure, and promote the service.
The Data Processing Addendum describes provider use for Merchant-controlled personal data. DAWSEN-controlled Shopify App Store listing measurement and advertising is described in the Privacy Policy and the provider entries below.
Each entry identifies its role and DPA scope. Only processing expressly labeled DPA subprocessor is covered by the Merchant's general authorization under the DPA. A DAWSEN controller provider is listed for transparency but is outside that authorization.
Effective July 20, 2026. Last updated July 31, 2026.
2. Shopify
Role and DPA scope: platform provider with a direct relationship to each Merchant. To the extent DAWSEN instructs Shopify to transmit or process Merchant-controlled personal data for Radiant, Shopify is also a DPA subprocessor. Shopify's independent platform processing is outside the DPA.
Purpose: commerce platform, app installation and authentication, Admin and storefront APIs, hosted app pricing and billing, consent signals, order and return references, privacy request delivery, and delivery of configured Shopify App Store listing and installation events to measurement providers.
Processing location: Shopify and its providers operate globally under Shopify's published privacy, security, and transfer terms. Shopify also has a direct relationship with each Merchant.
3. Vercel, Inc.
Role and DPA scope: DPA subprocessor when hosting or transmitting Merchant-controlled personal data for Radiant; processor for DAWSEN-controlled account, website, and service-administration data.
Purpose: application hosting, serverless runtime, content delivery, request processing, security controls, deployment, and operational logging.
Processing location: primarily United States and the global locations used by Vercel and its providers. Vercel publishes a data-processing addendum, transfer safeguards, subprocessor list, and encryption controls for data at rest and in transit.
4. Supabase Pte. Ltd.
Role and DPA scope: DPA subprocessor when storing Merchant-controlled personal data for Radiant; processor for DAWSEN-controlled account and service-administration data.
Purpose: managed PostgreSQL database, connection pooling, database security, monitoring, and provider-managed backups.
Processing location: Radiant's production database is hosted in the United States, East region. Supabase publishes a data-processing addendum, transfer safeguards, subprocessor list, and encryption controls for data and backups.
5. Google Cloud Platform (Pub/Sub)
Role and DPA scope: DPA subprocessor for the authenticated transport of Merchant-controlled privacy and lifecycle payloads.
Purpose: authenticated delivery, queueing, and retry of Shopify app-lifecycle, access-scope, and mandatory privacy webhooks to Radiant, including customer data-access and deletion requests and shop-deletion events. The optional support chat uses the separate Google Cloud support entry below.
Processing location and retention: Radiant's production Cloud Billing payments profile is an organization in Mexico. Google's published contracting-entity table identifies Google Cloud México, S. de R.L. de C.V. for Mexico, unless otherwise agreed with Google. The production topics do not set an explicit Pub/Sub message-storage policy, so storage is not pinned to a specific region at the topic level; Google's default location behavior and its data-processing and transfer terms apply. The production source topic retains published messages for up to 7 days, including messages already acknowledged by its subscription. The dead-letter topic retains published dead-letter messages for up to 31 days. The source and dead-letter monitoring subscriptions use those same respective windows and do not add separate acknowledged-message retention.
6. Google Cloud (managed generative model and support corpus)
Role and DPA scope: Google Cloud and Vercel are DPA subprocessors only when a Merchant chooses to include shopper or other Merchant-controlled personal data in a support request. For ordinary merchant-account support, they process data on behalf of DAWSEN as controller.
Purpose: generate merchant-support responses with Google Cloud's managed generative model service and retrieve approved Radiant help materials through a DAWSEN-controlled support service hosted by Vercel and backed by Google Cloud BigQuery and Cloud Storage.
Data and scope: the current support message, up to eight recent entries from that support conversation, locale and in-app context, and the relevant retrieved help materials can be sent to prepare the active response. This flow is not configured to copy support messages into storefront Analytics or Radiant's application database, and the support query is not written into the approved help corpus through this flow.
Processing location and retention: the managed model endpoint uses a global service location. The approved production help corpus is stored in Google Cloud BigQuery and Cloud Storage in the United States. Support content remains in request memory until the reply completes or fails and is not written to the application database or approved help corpus. DAWSEN does not deliberately log that content. Vercel Pro runtime logs remain available for up to one day and can contain request metadata and application status or error messages. Google can cache Gemini inputs, outputs, and derived data in isolated memory for up to 24 hours; a prompt flagged for suspected abuse can be retained for up to 90 days. Request-response logging, grounding with Google Search or Maps, and resumable model sessions are not enabled for this support flow.
7. Google (Google Analytics and Google Ads)
Role and DPA scope: DAWSEN controller provider for Shopify App Store listing data, outside the Merchant DPA. Google acts as a processor for configured measurement services and can act as an independent controller for advertising functions under the applicable Google account and product terms.
Purpose: optional measurement of Shopify App Store listing views, Install interactions, ad-attributed listing visits, and completed installations through Google Analytics 4 and Measurement Protocol; optional campaign attribution, audience measurement, remarketing, and advertising optimization through Google Ads.
Data and scope: listing events can include the app identifier or handle, listing surface, locale, value and currency, and, for a completed installation, the Shopify shop identifier, shop name, and shop domain. This integration does not receive shopper body answers, calculated measurements, size recommendations, or merchant support messages.
Processing location and retention: Google operates globally, including in the United States, under its applicable business, data-protection, transfer, and product terms. Retention is configured to two months for Google Analytics 4 event and user-level data. Google Ads conversion attribution uses a 30-day post-click window. If DAWSEN later creates a remarketing audience, its membership duration will be configured and disclosed before use. The contracting Google entity is the entity identified in the applicable account and product terms.
8. Meta (Meta Pixel and Conversions API)
Role and DPA scope: DAWSEN controller provider for Shopify App Store listing data, outside the Merchant DPA. Under Meta's Business Tools Terms, Meta acts as processor for configured matching, measurement, and analytics services and can act as joint or independent controller for specified advertising uses. Meta Platforms, Inc. applies to non-GDPR processing; Meta Platforms Ireland Limited applies where the GDPR governs the relevant processing.
Purpose: optional measurement of Shopify App Store listing views, Install interactions, and completed installations; campaign attribution, audience measurement, remarketing, and advertising optimization.
Data and scope: listing events can include the app or content identifier and name, value and currency, and, for a completed installation, the Shopify shop name and shop domain. This integration does not receive shopper body answers, calculated measurements, size recommendations, or merchant support messages.
Processing location and retention: Meta operates globally, including in the United States, under its applicable business, data-protection, transfer, and product terms. Retention is limited by those terms to a maximum of two years for event data. Audiences created from that data remain until DAWSEN deletes them using the Meta account tools.
9. Changes and objections
We update this page when a provider begins materially different processing. Merchants may object on reasonable data-protection grounds by emailing info@ashspark.com. Include the Shopify store domain and the provider concerned, but do not include credentials, payment data, or shopper body details.
Providers used for optional features or DAWSEN-controlled listing measurement and advertising are added here, and the Privacy Policy is updated, before the processing begins in production.