Last reviewed: 31 July 2026
Customer generally authorizes the providers below under the Data Processing Addendum. Actual processing depends on the feature used. Provider locations may include onward processing disclosed in their own DPA and subprocessor lists.
Current providers
| Provider | Purpose | Data involved | Main location / safeguard |
|---|---|---|---|
| Stripe | Checkout, payment, refunds and fraud prevention | Business email, billing and transaction data | Ireland/United States and global infrastructure; Stripe DPA, EU-U.S. DPF and SCCs |
| Convex, Inc. | Application database, authentication integration and backend execution | Account, contract, scope, authorization and application records | Configured deployment region; AWS US East or EU West; Convex DPA |
| Vercel Inc. | Web hosting, edge delivery and infrastructure logs | Requests, IP/device metadata and rendered application data | United States/global edge; Vercel DPA and SCCs |
| Cloudflare, Inc. | Private R2 report storage and DNS services | Report files, object metadata and DNS verification requests | Global infrastructure; Cloudflare DPA, DPF/SCC safeguards where applicable |
| Resend, Inc. | Transactional email delivery | Recipient, subject and message content | United States; Resend DPA, EU-U.S. DPF and SCCs |
Provider documents
- Stripe Privacy Center
- Convex DPA and regions
- Vercel DPA
- Cloudflare Data Processing Addendum
- Resend DPA and subprocessor information
Changes and objections
The list is reviewed when infrastructure changes. Material additions are posted before the provider begins processing audit Personal Data where reasonably possible. A Customer with reasonable data-protection concerns may email melvyn@melvynx.com during the notice period.