Trust & Compliance
Sub-processors
These are the third-party services FidiPerks uses to deliver the platform, the personal data each one receives, and where it is processed. Merchants using FidiPerks can rely on this list for their own privacy notices. We update it before adding a sub-processor that receives personal data, and record every change below.
Last updated: 6 October 2026Core platform
Used for every merchant and member.
| Provider | Purpose | Personal data | Location |
|---|---|---|---|
| Amazon Web Services | Hosting, database and file storage, transactional email (Amazon SES), SMS sign-in codes (Amazon SNS), AI-assisted campaign copy (Amazon Bedrock) | All application data: merchant accounts, member profiles, loyalty and transaction records | Australia (Sydney) |
| OneSignal | Mobile app push notifications and merchant campaign email delivery | Member email address, device push identifier, notification and email content | United States |
| Browser push services (Google, Apple, Mozilla) | Delivering web push notifications to members who enable them in their browser | Browser push subscription, notification content | Varies by browser vendor |
| Chargebee | Merchant subscription billing | Merchant billing contact and payment details (members' data is never shared) | United States |
| Cloudflare | Bot protection (Turnstile) on website forms | IP address and browser signals of the person submitting the form | Global network |
Marketing Agent
Used only for merchants who turn on the Marketing Agent. These services receive the merchant's business content. No member's personal details are sent to them; at most an aggregate count of members.
| Provider | Purpose | Personal data | Location |
|---|---|---|---|
| Anthropic | Writing social media posts | Merchant business name, brand voice and post briefs; no member data | United States |
| Google (Gemini) | Generating post images | Image descriptions derived from the merchant's business content; no member data | United States |
| Twilio | WhatsApp messages asking the merchant to approve posts | Merchant's WhatsApp number, draft post content | United States |
| Post for Me (default), or Meta or Upload-Post if the merchant chooses | Publishing approved posts to the merchant's social media accounts | Post content and images, access to the merchant's connected social accounts | United States |
Sign-in providers
Members and merchants can choose to sign in with Google or Apple. Those providers confirm the person's identity and share their name and email address with FidiPerks; they act under their own privacy policies rather than as our sub-processors.
Change log
| Date | Change |
|---|---|
| 6 October 2026 | First published list. Added OneSignal, browser push services, Chargebee, Cloudflare and the Marketing Agent providers (Anthropic, Google, Twilio, social publishing). Removed Stripe, which FidiPerks does not use. |
Questions, or a data processing agreement: support@fidiperks.com. See also Security & Data Protection.