{"type":"BuyerProtectionServiceProviderRegister","schemaVersion":"1.0.0","registerVersion":"2026-08-15.1","publishedAt":"2026-08-15T00:00:00.000Z","stage":"pre_pilot","environmentClass":"production","scope":"Public factual register of BuyerProtection production service connections, data direction, minimisation and unresolved contractual classification.","summary":{"connections":11,"activeOrBundled":4,"configuredNotIndependentlyProven":3,"notConfiguredNoTransfer":4,"assuranceConfigurationValid":true,"fullyCounselReviewed":false,"allRequiredDpasVerified":false},"connections":[{"id":"railway","name":"Railway","relationship":"external_infrastructure_provider","state":"active_runtime_observed","direction":"BuyerProtection data is processed and persisted in the hosting environment.","purposes":["application hosting","persistent application storage","runtime logs","deployment operation"],"dataCategories":["merchant account and proof records","field-minimised order evidence","sessions","audit and operational logs"],"location":"Observed Railway runtime region: us-east4-eqdc4a","minimisation":"Order-source ingestion excludes raw customer identity, addresses, card data and raw webhooks by contract; other user-supplied support and account fields remain in scope.","legalClassification":"counsel_review_required","assurance":{"contractStatus":"execution_not_verified","dpaStatus":"execution_not_verified","legalReviewStatus":"not_reviewed","publicTermsAvailable":true,"publicDpaAvailable":true,"publicSubprocessorListAvailable":true,"sources":{"terms":"https://railway.com/legal/terms","dpa":"https://railway.com/legal/dpa","subprocessors":"https://trust.railway.com/?itemName=subprocessors&source=click"},"evidenceDigest":"","reviewedAt":""},"boundary":"A public DPA and subprocessor page do not prove BuyerProtection executed, reviewed or accepted the required documents. The current production region is outside Australia."},{"id":"railway_redis","name":"Railway-hosted Redis","relationship":"external_infrastructure_component","state":"active_shared_rate_limit_runtime_observed","direction":"BuyerProtection writes bounded request counters and expiry times to a shared limiter.","purposes":["distributed anonymous-ingress rate limiting"],"dataCategories":["pseudonymous network-derived rate-limit keys","request counts","expiry times"],"location":"Observed Railway runtime region: us-east4-eqdc4a","minimisation":"No order body, email, card data or support content is required for the limiter.","legalClassification":"counsel_review_required","assurance":{"contractStatus":"execution_not_verified","dpaStatus":"execution_not_verified","legalReviewStatus":"not_reviewed","publicTermsAvailable":true,"publicDpaAvailable":true,"publicSubprocessorListAvailable":true,"sources":{"terms":"https://railway.com/legal/terms","dpa":"https://railway.com/legal/dpa","subprocessors":"https://trust.railway.com/?itemName=subprocessors&source=click"},"evidenceDigest":"","reviewedAt":""},"boundary":"This is a separate infrastructure component under the Railway relationship, not a separate vendor contract represented as executed."},{"id":"resend","name":"Resend","relationship":"external_transactional_email_provider","state":"configured_not_delivery_verified","direction":"BuyerProtection sends transactional email instructions to Resend for delivery to the merchant.","purposes":["signup verification","passwordless recovery","account and lifecycle notices"],"dataCategories":["merchant email address","email content","signed or one-time account link","message delivery metadata"],"location":"Provider processing locations require account-level and legal review.","minimisation":"Transactional messages are addressed to one merchant and do not include card numbers or a copied order database.","legalClassification":"counsel_review_required","assurance":{"contractStatus":"execution_not_verified","dpaStatus":"execution_not_verified","legalReviewStatus":"not_reviewed","publicTermsAvailable":true,"publicDpaAvailable":true,"publicSubprocessorListAvailable":true,"sources":{"terms":"https://resend.com/legal/terms-of-service","dpa":"https://resend.com/legal/dpa","subprocessors":"https://resend.com/legal/subprocessors"},"evidenceDigest":"","reviewedAt":""},"boundary":"Configured credentials do not prove recipient delivery, an executed DPA or an approved bank communication channel."},{"id":"zendesk","name":"Zendesk","relationship":"external_support_provider","state":"configured_not_delivery_verified","direction":"BuyerProtection can create a private support ticket from a submitted inquiry.","purposes":["merchant support","security and privacy inquiries","operator triage"],"dataCategories":["submitter contact details","organisation","request detail","submitted reference and affected path"],"location":"Provider processing locations require account-level and legal review.","minimisation":"Ticket copy instructs operators not to request passwords, card details or unrelated customer records.","legalClassification":"counsel_review_required","assurance":{"contractStatus":"execution_not_verified","dpaStatus":"execution_not_verified","legalReviewStatus":"not_reviewed","publicTermsAvailable":true,"publicDpaAvailable":true,"publicSubprocessorListAvailable":true,"sources":{"terms":"https://www.zendesk.com/company/agreements-and-terms/","dpa":"https://www.zendesk.com/company/data-processing-form/","subprocessors":"https://support.zendesk.com/hc/en-us/articles/4408883061530-Sub-processor-Policy"},"evidenceDigest":"","reviewedAt":""},"boundary":"Configuration does not prove ticket acceptance, contract execution, retention selection or institutional approval."},{"id":"shopify","name":"Shopify","relationship":"merchant_authorised_upstream_commerce_source","state":"active_read_only_connection_observed","direction":"The merchant authorises Shopify to supply read-only, field-minimised commerce evidence to BuyerProtection.","purposes":["order-state evidence","fulfilment linkage","refund evidence","42-day source reconciliation"],"dataCategories":["order reference","amount and currency","order/fulfilment/refund state","source timestamps and integrity metadata"],"location":"The merchant's Shopify relationship and Shopify processing footprint require partner-specific review.","minimisation":"BuyerProtection requests read_orders and read_fulfillments only; it does not retain raw customer identity, address, card data or raw webhook bodies in the source-event ledger.","legalClassification":"upstream_source_role_counsel_review_required","assurance":{"contractStatus":"execution_not_verified","dpaStatus":"execution_not_verified","legalReviewStatus":"not_reviewed","publicTermsAvailable":true,"publicDpaAvailable":true,"publicSubprocessorListAvailable":true,"sources":{"terms":"https://www.shopify.com/legal/api-terms","dpa":"https://www.shopify.com/legal/dpa","subprocessors":"https://help.shopify.com/en/manual/privacy-and-security/privacy/subprocessors"},"evidenceDigest":"","reviewedAt":""},"boundary":"Shopify is not labelled a BuyerProtection subprocessor by default. 1 active read-only connection(s) are observed; distribution remains controlled_merchant_org."},{"id":"stripe","name":"Stripe","relationship":"prospective_payment_processor","state":"not_configured_no_transfer","direction":"No BuyerProtection payment data flow is active.","purposes":["prospective merchant subscription checkout and billing management"],"dataCategories":[],"location":"No active BuyerProtection transfer; provider account and product review remain required.","minimisation":"Full card details remain on provider-hosted payment surfaces; provider tokens cannot be reused with another processor.","legalClassification":"counsel_review_required","assurance":{"contractStatus":"execution_not_verified","dpaStatus":"execution_not_verified","legalReviewStatus":"not_reviewed","publicTermsAvailable":true,"publicDpaAvailable":true,"publicSubprocessorListAvailable":true,"sources":{"terms":"https://stripe.com/au/legal/ssa","dpa":"https://stripe.com/legal/dpa","subprocessors":"https://stripe.com/legal/service-providers"},"evidenceDigest":"","reviewedAt":""},"boundary":"Adapter code and a provider dashboard do not prove account activation, live checkout, KYC acceptance, payment or reconciliation."},{"id":"square","name":"Square","relationship":"policy_gated_prospective_payment_processor","state":"not_configured_no_transfer","direction":"No BuyerProtection payment data flow is active.","purposes":["prospective merchant subscription checkout"],"dataCategories":[],"location":"No active BuyerProtection transfer; written provider approval and release remain required.","minimisation":"A payment method or subscription never moves silently between Stripe and Square.","legalClassification":"counsel_review_required","assurance":{"contractStatus":"execution_not_verified","dpaStatus":"execution_not_verified","legalReviewStatus":"not_reviewed","publicTermsAvailable":true,"publicDpaAvailable":false,"publicSubprocessorListAvailable":false,"sources":{"terms":"https://squareup.com/au/en/legal/general/ua","dpa":"","subprocessors":""},"evidenceDigest":"","reviewedAt":""},"boundary":"Square remains unreleased and fail-closed until written approval and dedicated BuyerProtection configuration exist."},{"id":"slack","name":"Slack","relationship":"optional_operator_notification_provider","state":"not_configured_no_transfer","direction":"No BuyerProtection Slack data flow is active.","purposes":["optional operator notification"],"dataCategories":[],"location":"No active transfer in the current runtime.","minimisation":"Slack is not required for merchant decisions and receives no data when the webhook is absent.","legalClassification":"counsel_review_required","assurance":{"contractStatus":"execution_not_verified","dpaStatus":"execution_not_verified","legalReviewStatus":"not_reviewed","publicTermsAvailable":true,"publicDpaAvailable":true,"publicSubprocessorListAvailable":true,"sources":{"terms":"https://slack.com/intl/en-au/terms-of-service","dpa":"https://slack.com/intl/en-au/terms-of-service/data-processing","subprocessors":"https://www.salesforce.com/company/privacy/full-subprocessor-list/"},"evidenceDigest":"","reviewedAt":""},"boundary":"Optional notification is not the decision record, audit store or merchant system of record."},{"id":"peptidelab_item_check","name":"PeptideLab private Item Check bridge","relationship":"separate_cross_brand_service_connection","state":"configured_private_bridge_not_acceptance_verified","direction":"A user-entered item code, email address and pseudonymous request key are sent to the private PeptideLab verification endpoint; BuyerProtection receives only success or failure.","purposes":["private item ownership check"],"dataCategories":["user-entered email","item check code","pseudonymous request key"],"location":"Separate service boundary; infrastructure and legal review are not inherited from BuyerProtection.","minimisation":"No PeptideLab customer record or match detail is returned to BuyerProtection.","legalClassification":"cross_brand_controller_processor_roles_counsel_review_required","assurance":{"contractStatus":"execution_not_verified","dpaStatus":"execution_not_verified","legalReviewStatus":"not_reviewed","publicTermsAvailable":false,"publicDpaAvailable":false,"publicSubprocessorListAvailable":false,"sources":{"terms":"","dpa":"","subprocessors":""},"evidenceDigest":"","reviewedAt":""},"boundary":"This is not a general BuyerProtection merchant integration and does not permit customer-record browsing."},{"id":"offsite_backup","name":"Off-site immutable backup provider","relationship":"required_external_recovery_provider_not_selected","state":"not_configured_no_transfer","direction":"No external backup destination is configured.","purposes":["off-site encrypted recovery copy","clean-room restore"],"dataCategories":[],"location":"Provider and region not selected in the current runtime.","minimisation":"The remote object is encrypted before transfer and plaintext backup material is removed locally.","legalClassification":"counsel_review_required","assurance":{"contractStatus":"execution_not_verified","dpaStatus":"execution_not_verified","legalReviewStatus":"not_reviewed","publicTermsAvailable":false,"publicDpaAvailable":false,"publicSubprocessorListAvailable":false,"sources":{"terms":"","dpa":"","subprocessors":""},"evidenceDigest":"","reviewedAt":""},"boundary":"A local encrypted archive is not an off-site backup. Provider authentication, immutable retention, remote read-back and clean restore must all pass."},{"id":"trustedsite","name":"TrustedSite","relationship":"bundled_internal_product_component","state":"bundled_same_runtime","direction":"BuyerProtection reads the bundled TrustedSite merchant and domain proof engine inside the same application runtime.","purposes":["merchant identity","official domain proof","merchant account and session authority"],"dataCategories":["merchant account","business proof","official domain","session and permission state"],"location":"Observed Railway runtime region: us-east4-eqdc4a","minimisation":"TrustedSite Verified remains a public proof decision; it does not activate BuyerProtection Guaranteed.","legalClassification":"internal_product_and_contracting_entity_review_required","assurance":{"contractStatus":"execution_not_verified","dpaStatus":"execution_not_verified","legalReviewStatus":"not_reviewed","publicTermsAvailable":false,"publicDpaAvailable":false,"publicSubprocessorListAvailable":false,"sources":{"terms":"","dpa":"","subprocessors":""},"evidenceDigest":"","reviewedAt":""},"boundary":"Connected does not mean legally merged. Contracting entity, brand roles and intra-group/data-sharing terms still require accountable legal review."}],"openProcurementActions":["Confirm the accountable BuyerProtection contracting entity and controller/processor roles with Australian counsel.","Execute or evidence the applicable provider terms and DPAs; a public document link is not execution proof.","Review the observed United States hosting region, APP 8 cross-border disclosure and partner-specific transfer safeguards.","Set provider-specific retention, deletion, access, incident-notification and subprocessor-change duties.","Select and independently prove an off-site immutable backup provider and clean restore.","Reissue the register whenever a provider, purpose, field set, region, contract state or source role changes."],"boundaries":["This register is a technical and operational fact surface, not legal advice or a signed DPA.","Configured does not mean provider acceptance, recipient delivery, executed contract, counsel approval or bank approval.","An upstream merchant-authorised platform is not automatically classified as a BuyerProtection subprocessor.","No configured payment processor means BuyerProtection cannot accept a merchant subscription payment today.","No configured off-site destination means a local backup remains a single-provider recovery dependency."],"links":{"dataProcessing":"https://buyerprotection.com.au/data-processing","procurement":"https://buyerprotection.com.au/procurement","evidenceIndex":"https://buyerprotection.com.au/.well-known/buyerprotection/trust-centre.json","dataLifecycle":"https://buyerprotection.com.au/.well-known/buyerprotection/data-lifecycle.json","schema":"https://buyerprotection.com.au/schemas/service-provider-register/v1","contact":"https://buyerprotection.com.au/contact?intent=privacy"},"registerId":"bpspr_4f19196bae728c97bae4737f","digestAlgorithm":"sha256_recursive_key_sort_json_v1","registerDigest":"sha256:4f19196bae728c97bae4737fbc53d4c317671538406cc31c7c498d86357dc566"}