As of August 19, 2026. This page lists service providers used to operate, secure, host, store, bill, and support B2B Marshal.
Processing role
B2B Marshal processes Shopify B2B company, location, order, draft-order, payment-term, transaction-timing, refund, app-subscription, product/variant checkout identity, quantity/price checkout input, and store data on the merchant's behalf to provide exposure, policy, reconciliation, checkout control, tiered discounts, financial profile, and audit workflows.
The app stores account and financial state needed for those workflows but minimizes customer identity: it does not store customer contact profiles, addresses, product line-item descriptions, full Shopify payloads, or payment card data. Authorized Shopify admin identity and merchant-entered policy/audit/support content are stored as described in the Privacy Policy.
Financial ledger and merchant/system audit records are retained while the shop remains installed because they preserve provenance and history that current state cannot always reconstruct. Routine operational records use bounded retention, and Shopify's authenticated shop-redaction lifecycle deletes per-shop application records as described in the Privacy Policy.
Providers
| Provider | Purpose | Data involved |
|---|---|---|
| Shopify | App distribution, OAuth, Admin and Partner APIs, Shopify App Pricing, webhooks, app-owned metafields, checkout resources, and Shopify Functions runtime | Merchant store/app data, authorized admin session identity, company/location data, order/draft/refund/payment-term data, subscription state, and transient checkout inputs/operations including cart subtotal, product/variant identifiers, quantities, and current/compare-at unit amounts |
| Railway | Production web application and private reconciliation-worker hosting | Authenticated app requests, application processing, redacted operational logs, environment configuration, and transient data needed to serve requests/jobs |
| Turso | Production libSQL database and recovery services | Encrypted session/token records, shop/company/location/order/draft financial state, derived metrics, account policy including tier ladders and markdown choices, settings, audit events, job/projection state, caches, and limited webhook/privacy metadata |
| GitHub | Source control, dependency/security alerts, build/release workflows, and scheduled billing-reconciliation workflow | Source code, repository metadata, build/release metadata, and redacted operational status; production merchant datasets and credentials are not committed to the repository |
| Zoho Mail | Support, privacy, and security email | Sender/contact information, shop/account context, message content, and attachments provided by the sender |
| Cloudflare | Hosting, DNS, TLS, edge security, bot protection, and optional privacy-oriented analytics for fiveacrecode.com public pages | Public website requests, IP/network metadata, security events, DNS/TLS records, and form-protection signals |
Shopify and merchants can have separate controller or processor roles under applicable law. Merchants are responsible for determining their instructions, notices, lawful basis, and any data-processing terms required for their use of B2B Marshal.
Changes and requests
Five Acre Code updates this list when a provider is added or replaced in a way that materially changes B2B Marshal data processing. Questions about provider locations, transfer safeguards, or available contractual terms can be sent to support@fiveacrecode.com.