Subprocessor List

Current as of the Privacy Policy version date. We notify users of material changes at least 14 days in advance.

Each processor is bound by a Data Processing Agreement and, where applicable, the EU–US Data Privacy Framework (DPF) or Standard Contractual Clauses (SCCs).

SubprocessorPurposeData ProcessedLocationTransfer Mechanism
SupabaseDatabase, auth, storage, edge functionsAccount data, brand assets, usage dataUS (or EU region if configured)DPF (verify) + SCCs
VercelHosting, CDN, serverless runtime, cronRequest logs, IP (ephemeral)USDPF + SCCs
SentryError trackingAnonymised stack traces, user IDUSDPF + SCCs
MixpanelProduct analytics — funnels, cohorts (opt-in only). Optional Session Replay (separate, granular opt-in) for UX debugging.Usage events, $device_id, user_id, tenant_id, role, email, name. Session Replay (when enabled): masked DOM events of in-app interactions; payment, integration, admin, and brand-KB routes are excluded entirely.EU (Frankfurt)EU residency for primary storage; SCCs for any incidental US support access
Google (Analytics 4)Audience and acquisition analytics (opt-in only)Pseudonymous client_id, page URL, referrer, user_id once authenticatedUS (with EU regional collection per GA4 default)DPF + SCCs
ResendTransactional emailEmail address, name, message bodyUSDPF + SCCs
OpenAIAI content generationPrompts + brand contextUSDPF
AnthropicAI content generationPrompts + brand contextUSSCCs
Google (Gemini)AI fact-checkingPrompts + brand contextUS / EUDPF
Ideogram / Flux (BFL)AI image generationImage promptsUS / EUSCCs
Customer-connected integrations (WordPress, Buffer, WooCommerce, Google Ads, Meta Ads, Brevo)Publishing + analyticsAPI keys, publishing payloads, analyticsVaries per vendorCustomer-configured

To subscribe to change notifications or ask questions about this list, email kobi@leanspothub.com.

Subprocessors | Coolest.Agency