AfterShip Subprocessors List (September 2026): Changes and History
AfterShip names 12 subprocessors on its published list. Read from the vendor's own page and re-checked daily.
AfterShip subprocessors (September 2026)
| # | Subprocessor | Purpose | Location | Data |
|---|---|---|---|---|
| 1 | Alibaba Cloud | To send SMS messages, only in China | Hong Kong | End User information, SMS and webhook messages. (China only) |
| 2 | Amazon AWS | Cloud Services | United States | All categories |
| 3 | Clarity | Website Heatmaps and Session Recordings | United States | End-User Behavioural Data, End-User Browser Information, End-User IP Address. |
| 4 | Cloud Support Technologies | Customer Support | India | All categories |
| 5 | Cloudflare | DNS and CDN provider- Secure, optimize and accelerate websites and services;- Provide https encryption for services | United States | All categories |
| 6 | Crystal Televentures Pvt Ltd. | Customer Support | India | All categories |
| 7 | Intercom R&D Unlimited | Customer Support | United States | All categories |
| 8 | Support Zebra LLC | Customer Support | Philippines, Mexico, Colombia | All categories |
| 9 | Google Analytics | Analytics | United States | End-User Behavioural Data, End-User Browser Information, End-User IP Address, Cookie _ama, Cookie _am_id. |
| 10 | Google Cloud Platform | Cloud Services | United States | All categories |
| 11 | Sendgrid | Email Notification | United States | Shipping Information, Order Information, End-User Information, Tracking Information. |
| 12 | Twilio | SMS Notification | United States | Shipping Information, Order Information, End-User Information, Tracking Information. |
Get an email when AfterShip changes its subprocessors
ClauseTrail re-checks this list every day and tells you exactly who was added or removed — including when a vendor starts sending data to an AI provider. The first vendors are free.
Key DPA terms at AfterShip
What AfterShip's data processing agreement commits to, with the sentence each answer comes from. SCCs or the Data Privacy Framework: what's the difference?
- Breach notification
-
Within 72 hours
“notify the Data Controller of any Personal Data breach within seventy-two (72) hours of becoming aware of it”
DPA, www.aftership.com ↗ - Notice of a new subprocessor
-
15 days ahead
“Any changes to Authorized Subprocessors will be notified to Data Controller, who may object within fifteen (15) days by contacting”
DPA, www.aftership.com ↗ - Transfers outside the EU
-
Standard contractual clauses and adequacy decisions
“Module 2 of the EU SCCs applies between User as "data exporter" and AfterShip as "data importer"”
“the European Economic Area ("EEA") and any other territory which the European Commission has determined ensures an adequate level of protection for Personal Data pursuant to Article 45 of the GDPR”
DPA, www.aftership.com ↗ - Customer data after the contract ends
-
Deleted or returned when the contract ends
“upon termination of the agreement or the provision of services, and at the choice of the Data Controller, either delete or return all Personal Data, unless applicable law requires otherwise”
DPA, www.aftership.com ↗ - Audit rights
-
Through certifications and audit reports only
“Controller agrees that the Audit Report satisfies any audit right granted by Applicable Data Protection Laws.”
DPA, www.aftership.com ↗
Certifications at AfterShip
What AfterShip's trust page lists, with the text each one comes from.
- ISO 27001
-
Active
“ISO 27001-based ISMS”
Trust page, www.aftership.com ↗
Documents we track for AfterShip
- DPA
- checked September 28, 2026 www.aftership.com ↗
- Privacy policy
- checked September 28, 2026 www.aftership.com ↗
- Subprocessor list
- checked September 28, 2026 www.aftership.com ↗
- Terms of service
- checked September 28, 2026 www.aftership.com ↗
- Trust page
- checked September 28, 2026 www.aftership.com ↗
Change history
Tracking since September 28, 2026. No change has been published since; additions, removals and document changes will appear here as they're published.
AfterShip subprocessors FAQ
- How many subprocessors does AfterShip use?
- AfterShip lists 12 subprocessors on its published list, including Alibaba Cloud, Amazon AWS, Clarity, Cloud Support Technologies, and Cloudflare and 7 more.
- Where does AfterShip process customer data?
- The subprocessors named by AfterShip are located in United States, India, Colombia, Hong Kong, Mexico, and Philippines, as stated on its list.
- How quickly does AfterShip report a personal data breach to customers?
- According to its DPA, AfterShip reports a personal data breach to customers within 72 hours: “notify the Data Controller of any Personal Data breach within seventy-two (72) hours of becoming aware of it”
- How much notice does AfterShip give before adding a subprocessor?
- AfterShip's DPA gives 15 days' notice of a new subprocessor, the time customers have to object: “Any changes to Authorized Subprocessors will be notified to Data Controller, who may object within fifteen (15) days by contacting”
- How does AfterShip transfer personal data outside the EU?
- AfterShip's DPA relies on standard contractual clauses and adequacy decisions: “Module 2 of the EU SCCs applies between User as "data exporter" and AfterShip as "data importer"”
- Which security certifications does AfterShip list?
- AfterShip's trust page lists ISO 27001.
- When was AfterShip's subprocessor list last checked?
- ClauseTrail last checked AfterShip's subprocessor list on September 28, 2026. Lists are re-checked daily.
- How do I find out when AfterShip adds or removes a subprocessor?
- ClauseTrail monitors AfterShip's subprocessor list, DPA, privacy policy and terms and emails you the exact change — who was added or removed and what the page said before and after. The first vendors are free.