Core service providers and platforms
| Provider | Purpose | Relevant data |
|---|---|---|
| Shopify | Commerce platform, app installation and authentication, billing, APIs, app proxy, files, and privacy workflows. | Merchant, store, catalog, theme, order, customer, billing, and authorized writeback data. |
| Render | Application, API, worker, and managed service infrastructure for the BRDG deployment. | Service records, encrypted submission data, account and store data, logs, and technical metadata. |
| Cloudflare | Object storage and content delivery for versioned storefront tool bundles and static artifacts. | Tool code and bundle metadata; request and delivery logs. |
| Resend | Transactional and merchant-configured email delivery. | Recipient address, sender and routing fields, message content, and delivery metadata. |
| Managed text embeddings and the optional onboarding starter-taxonomy proposal. | Minimized catalog text and a bounded catalog sample; not raw shopper contact data through Agent API/MCP. |
Optional BRDG providers
These providers process service data only when BRDG is configured to use the corresponding capability. Availability can depend on plan and deployment configuration.
| Provider | Purpose | Relevant data |
|---|---|---|
| OpenAI | Optional text-embedding infrastructure when explicitly configured instead of the default provider. | Minimized catalog or brand text selected for indexing; no raw shopper contact data. |
Merchant-directed integrations
When a merchant enables an integration, BRDG sends the information selected by that merchant under the merchant's instructions. The provider may act as the merchant's processor, independent controller, or platform under its own terms. These services are not active for every BRDG customer.
| Integration | Purpose | Relevant data |
|---|---|---|
| Klaviyo | Consented profile and messaging workflows. | Permitted contact and profile fields, consent state, segment membership, and campaign metadata. |
| Meta | Conversions API and consented audience workflows selected by the merchant. | Pseudonymous event data and permitted hashed audience identifiers. |
| Merchant-selected agent provider | External authoring and operations through scoped MCP or Agent API credentials. | Governed resources, proposals, manifests, validation evidence, and privacy-filtered operational context. |
International processing
These providers may process data in more than one country. BRDG uses contractual restrictions and recognized transfer safeguards where required. A merchant's direct relationship with an optional integration may include separate location and transfer terms.
Changes and objections
We update this page when the provider set or purpose materially changes. Where a contract or applicable law requires advance notice, we will provide it through the service or the merchant contact on file. A merchant may object on reasonable data-protection grounds by emailing hello@getbrdg.ai and identifying the affected service and concern.