Legal

Sub-processors.

The third parties that process data on our behalf, and what each one does.

Confirmed

  • Stripe โ€” payment processing. Plans are built by your partner and reconciled through Stripe in the background. It handles card data; we do not store it.

This website uses none

Separate from the product, the site you are reading right now sends nothing to a third party as it loads. That is a deliberate choice and it is verifiable from the page source:

  • Typefaces are served from this domain, not from Google Fonts โ€” so your IP address is not disclosed to anyone when the page renders
  • No analytics provider is loaded, and none has been chosen
  • No tag manager, no advertising pixel, no session recorder
  • No CAPTCHA script โ€” a provider has not been configured, and adding one carelessly would leak every visitor's IP on page load
  • No cookies at all โ€” not analytics, not advertising, and not a consent cookie either, because there is nothing to consent to

What the published list will carry

For each sub-processor, the four things a reviewer actually checks:

  • The vendor's legal name, and the service it provides
  • The categories of personal data it can access
  • Where it processes โ€” country or region
  • The transfer safeguard relied on, where processing leaves your region

It will also carry a change-notice commitment โ€” how far in advance a new sub-processor is announced, and how you object. That period has not been agreed.

If you are reviewing us

A GDPR-exposed buyer asks for this list and the data processing addendum by name, usually in the same email. Both are open. Ask, and you will get the current state rather than a document written to survive the question.