Transparency register
Service providers and subprocessors
A role-aware list of external services used by Meridian, including providers that are independent controllers rather than subprocessors.
Current provider register
| Provider | Purpose | Location | Data | Role |
|---|---|---|---|---|
| OpenAI Sites | Application hosting, managed identity, edge delivery, server execution, and platform persistence | Provider-managed global infrastructure; production region to be confirmed by contract | Account signals, request/technical metadata, application records and synthetic product data | Processor/service provider for Meridian |
| Resend | Transactional email delivery and signed delivery events | United States / provider infrastructure | Recipient address, message content, delivery metadata | Processor/service provider |
| Private Email (Namecheap) | Business mailbox and inbound support/legal communication | Provider infrastructure; location governed by account terms | Sender address, message content, attachments and delivery metadata | Processor/service provider for mailbox operation |
| Paddle | Checkout, subscription billing, tax, invoicing, fraud handling, customer portal, and merchant-of-record functions | United States, United Kingdom, EEA and provider/subprocessor locations | Buyer identity/contact, billing and transaction data, tax location, fraud and device signals | Primarily independent controller / merchant of record; processor only for specific contracted services |
| Payoneer | Receipt of Meridian seller revenue paid out by Paddle | Provider-managed global financial infrastructure | Meridian account-holder, compliance and payout data; normally no Meridian end-user product data | Independent financial-services controller; not a Meridian subprocessor for the product |
| Payoneer Mass Payouts (planned) | Participant registration, verification and EUR/USD reward payouts after separate program approval | Provider-managed global financial infrastructure and approved payout corridors | Participant identity, contact, country, verification, sanctions, tax and payout status data; Meridian stores only an opaque payee reference and operational status | Independent financial-services controller; production processing not active |
Why roles are distinguished
A subprocessor processes personal data on Meridian's documented instructions. An independent controller decides parts of its own processing under law. Paddle acts as merchant of record and determines transaction, tax, fraud, and legal record processing. The ordinary Payoneer account receives Meridian seller revenue. A separately approved Payoneer Mass Payouts program would handle participant compensation; the two money flows never share application records or ledger references.
Not yet active
The Payoneer adapter, durable queue, signed webhook gateway and compliance workflow currently operate only in safe sandbox mode. No production participant transfer, production KYC/KYB provider, external data connector, advertising network, or behavioral analytics provider is active. Live participant payouts require Payoneer approval, the account-specific API contract, credentials and an explicit production transfer gate. Material activation details will be published before processing begins.
Changes and objections
Material subprocessor changes will be posted here and, for contracted customers, notified under the DPA. Contracted customers may object within 14 days on reasonable data-protection grounds. Questions or notification requests: office@meridiandataexchange.com.
