Subprocessors
Effective 2026-08-09
We built VendorStacks because subprocessor disclosure is useful and under-published. It would be absurd not to publish our own. These are the vendors that process data on our behalf, what they do, and what they see.
| Subprocessor | Purpose | Data processed | Region |
|---|---|---|---|
| Vercel | Website and dashboard hosting, CDN | Request metadata, IP addresses | US |
| Railway | API and worker hosting | Request metadata, API logs | US |
| Supabase | Primary database | Account, usage, billing records, indexed disclosures | US |
| Clerk | Authentication and session management | Email, authentication identifiers | US |
| Stripe | Payment processing | Billing contact, payment records | US |
| Resend | Transactional and support email | Email address, message contents | US |
| PostHog | Product analytics | Pageviews, in-app events, IP address | US |
| Cloudflare | DNS and edge protection | Request metadata, IP addresses | Global |
| Firecrawl | Page rendering for public disclosure pages | Public URLs only — no customer data | US |
| Serper | Search index lookups for disclosure discovery | Public search queries — no customer data | US |
| Anthropic | Generating internal discovery queries | No customer data and no personal data | US |
| sent.dm | Operational SMS alerts to our own team | Order amount, our own phone number | US |
Notice of changes
This page is updated when a subprocessor is added or removed. If you want advance notice by email before a new subprocessor starts processing your data, ask us through support and we will add you to the notification list.