Skip to content

Subprocessors

Last reviewed: 31 July 2026

Customer generally authorizes the providers below under the Data Processing Addendum. Actual processing depends on the feature used. Provider locations may include onward processing disclosed in their own DPA and subprocessor lists.

Current providers

ProviderPurposeData involvedMain location / safeguard
StripeCheckout, payment, refunds and fraud preventionBusiness email, billing and transaction dataIreland/United States and global infrastructure; Stripe DPA, EU-U.S. DPF and SCCs
Convex, Inc.Application database, authentication integration and backend executionAccount, contract, scope, authorization and application recordsConfigured deployment region; AWS US East or EU West; Convex DPA
Vercel Inc.Web hosting, edge delivery and infrastructure logsRequests, IP/device metadata and rendered application dataUnited States/global edge; Vercel DPA and SCCs
Cloudflare, Inc.Private R2 report storage and DNS servicesReport files, object metadata and DNS verification requestsGlobal infrastructure; Cloudflare DPA, DPF/SCC safeguards where applicable
Resend, Inc.Transactional email deliveryRecipient, subject and message contentUnited States; Resend DPA, EU-U.S. DPF and SCCs

Provider documents

Changes and objections

The list is reviewed when infrastructure changes. Material additions are posted before the provider begins processing audit Personal Data where reasonably possible. A Customer with reasonable data-protection concerns may email melvyn@melvynx.com during the notice period.