Skip to content
vendor
Trust

Sub-processors.

Every third-party vendor that handles customer data on our behalf — what they process, where they're located, and the safeguards in place.

Last updated:

Vendor relies on the third parties listed below to operate the platform. Each is bound by a Data Processing Agreement with confidentiality, security, and breach-notification obligations equivalent to or stricter than ours. We notify customers at least 30 days before adding a new sub-processor.

Sub-processorPurposeData processedRegion
Amazon Web Services (AWS)Cloud infrastructure — compute, database, object storage, transactional email (SES), message queues, authentication (Cognito), search (OpenSearch), hosting (Amplify)All platform dataEU (Frankfurt) + US (N. Virginia, failover)
CloudflareCDN, DNS, DDoS protectionRequest metadata, IP addresses, page cachesGlobal edge
StripePayment processingCardholder data, billing addresses, transaction historyUS, EU
PayPalPayment processing (alternative)PayPal account email, transaction historyUS, EU
Casys (CPay)Card payment processingCardholder data, billing details, transaction referencesNorth Macedonia
Halkbank (NestPay)Card payment processingCardholder data, transaction detailsNorth Macedonia
NLB / BankartCard payment processingCardholder data, transaction detailsSlovenia (EU)
PayrexxPayment processing (hosted gateway)Customer billing details, transaction dataSwitzerland
IuteBuy Now, Pay Later payment processingCustomer billing details, order and transaction dataEU
GoogleMaps & geocoding, web fonts, reCAPTCHA bot protectionLocation data, IP addresses, bot-detection signalsGlobal (US, EU)
MapboxMaps & geocodingLocation data, IP addressesUS, EU
flagcdn.comCountry flag image deliveryRequest IP addresses only — static images, no account dataGlobal edge
MicroticaDeployment & CI/CD platformBuild artifacts, deployment configuration — no customer dataEU
GitLabSource-code management & private package registrySource code only — no customer dataUS (GitLab.com)
Contact trust team