Sub-processors
This register identifies providers that process personal data for the core service or when an optional feature is used. Material processor changes are published and notified as required by the applicable customer agreement.
Last updated: 2026-08-03
| Vendor | Purpose | Data processed | Region | Applies when | DPA |
|---|---|---|---|---|---|
| Cloudflare | Website delivery, security, and managed application infrastructure. | Request metadata, IP addresses, and service data needed to deliver and protect the website. | Global processing locations under the provider's data-protection terms | Core service | DPA |
| Clerk | Account services for a limited set of existing account paths. | Email, name, identity reference, organization membership, and session metadata. | Provider processing locations under the applicable data-protection terms | Certain existing accounts | DPA |
| Loops | Service and account email delivery. | Recipient email address, message content, and delivery metadata. | Provider processing locations, including the United States | Optional feature used | DPA |
| Microsoft Azure | Customer-requested cloud and AI workloads when an applicable service is used. | Workload inputs, outputs, operational metadata, and configuration required for the requested service. | Service- and contract-specific processing locations | Optional feature used | DPA |
| Plausible Analytics | Cookieless, privacy-first web analytics. | Aggregate page views, referrers, low-cardinality event tags (no PII). | European Union | Optional feature used | DPA |
| Supabase | Customer identity, account data, preferences, and account lifecycle services. | Identity, profile, preferences, customer-created records, usage, and account lifecycle state. | European Union, with support and sub-processors as described in the provider terms | Core service | DPA |
| Stripe | Payment, subscription, and invoice processing when a paid service is used. | Billing contact details and payment or transaction metadata required for the selected service. | Provider processing locations in the EU and United States under the provider terms | Optional feature used | DPA |
Cloudflare
Website delivery, security, and managed application infrastructure.
- Data:
- Request metadata, IP addresses, and service data needed to deliver and protect the website.
- Region:
- Global processing locations under the provider's data-protection terms
- Applies when:
- Core service
Clerk
Account services for a limited set of existing account paths.
- Data:
- Email, name, identity reference, organization membership, and session metadata.
- Region:
- Provider processing locations under the applicable data-protection terms
- Applies when:
- Certain existing accounts
Loops
Service and account email delivery.
- Data:
- Recipient email address, message content, and delivery metadata.
- Region:
- Provider processing locations, including the United States
- Applies when:
- Optional feature used
Microsoft Azure
Customer-requested cloud and AI workloads when an applicable service is used.
- Data:
- Workload inputs, outputs, operational metadata, and configuration required for the requested service.
- Region:
- Service- and contract-specific processing locations
- Applies when:
- Optional feature used
Plausible Analytics
Cookieless, privacy-first web analytics.
- Data:
- Aggregate page views, referrers, low-cardinality event tags (no PII).
- Region:
- European Union
- Applies when:
- Optional feature used
Supabase
Customer identity, account data, preferences, and account lifecycle services.
- Data:
- Identity, profile, preferences, customer-created records, usage, and account lifecycle state.
- Region:
- European Union, with support and sub-processors as described in the provider terms
- Applies when:
- Core service
Stripe
Payment, subscription, and invoice processing when a paid service is used.
- Data:
- Billing contact details and payment or transaction metadata required for the selected service.
- Region:
- Provider processing locations in the EU and United States under the provider terms
- Applies when:
- Optional feature used