In terms of which SAQ a merchant is eligible for, that needs to be determined by the customer’s acquirer (merchant bank) or payment brand. Spreedly can not advise on specific applicability given it’s based on multiple factors.
Merchants are responsible for confirming that they meet all of the eligibility criteria for a specific SAQ type before using that SAQ to document their compliance efforts. The SAQ eligibility criteria can be found in the Self-Assessment Questionnaire Instructions and Guidelines on the PCI Security Standards Council website.