Subprocessor list
Current version: 2026-07-13
This page lists every third-party subprocessor mira (VS Studios AB) uses to provide the loyalty platform. Merchants running programmes on mira grant general authorisation for these processors under §7 of the Data Processing Agreement. Material changes are announced by email to each Merchant's account owner at least 14 days before they take effect.
Changelog
- 2026-07-13 — Initial published list.
Processors
| Processor | Purpose | Data categories | Location | | --- | --- | --- | --- | | Supabase (via Lovable Cloud) | Managed Postgres database, authentication, object storage, edge functions | All Merchant and Data Subject data described in the DPA §4 | EU (Frankfurt) | | Cloudflare, Inc. | Application hosting, CDN, DDoS protection | HTTP request metadata, IP address (transient) | Global edge, EU-preferred routing | | Paddle.com Market Ltd. | Merchant subscription billing and Merchant of Record payment processing | Merchant billing contact, subscription events. No end-customer data. | UK / EU | | Mailgun Technologies (via Lovable Emails) | Transactional email delivery (reward links, welcome, verification, data-export notices) | Recipient email, message content | US (SOC 2 Type II, EU SCCs in place) | | Twilio Inc. | SMS delivery for merchant OTP where configured | Merchant staff phone number, one-time code | US (EU SCCs) | | Google LLC (Google Wallet, Google Cloud Vision) | Wallet pass issuance for loyalty cards; QR image processing for merchant setup | Loyalty-card public code, wallet-class metadata; uploaded QR image | EU / US (EU SCCs) | | Apple Inc. (Apple Wallet PassKit) | Wallet pass issuance for loyalty cards on iOS | Loyalty-card public code, pass metadata | US (EU SCCs) | | Google Ireland Ltd. (Google AI Gateway) | Aggregate merchant insights generation (never end-customer PII) | Aggregated scan counts and derived metrics | EU |
How to object
Write to privacy@miraloyalty.com within 14 days of a notified change.
If we cannot accommodate the objection, either party may terminate the
affected part of the Service under DPA §7.