Trust
Sub-processors
Every third party that processes customer data on our behalf.
Current as at 5 September 2026
A sub-processor is a third party that processes personal data on our behalf. This is all of them. It is short because the backend was deliberately built with few dependencies, and it is specific because a list that says “cloud providers” and “analytics partners” tells a reader nothing they could check.
The list
| Sub-processor | What it does for us | What it receives | Where, and on what basis |
|---|---|---|---|
| OTP Mobil Kft. (SimplePay) | Card payments: subscriptions, plan changes and advertising top-ups. | Name and email supplied at checkout, amount, currency, transaction reference and status. Card details are entered on SimplePay's own page and never reach us. | Hungary (EU) |
| Teya | Hosted checkout used by the earlier advertising top-up route, retained while historical orders are settled. | Amount, currency, order reference and payment status. | European Economic Area |
| Resend | Transactional and inbound email: sign-in links, order and account mail, and the inbox behind the support agent. | Recipient address, message content and delivery metadata. | United States — Standard Contractual Clauses |
| Cloudflare | Network delivery in front of our origin: DNS, TLS termination, and protection against hostile traffic. | Connection metadata and request content in transit; IP address and user agent. | United States, with EU points of presence — Standard Contractual Clauses |
| OpenAI | Model inference. The agents that research products, write store copy and draft campaign material run against this provider's models. | The prompt and context sent for a given generation, which can include product, store and campaign content you created. | United States — Standard Contractual Clauses |
Both payment providers also act as independent controllers for their own regulatory purposes — fraud prevention, anti-money-laundering, and the records a payment institution is required to keep. That part of their processing is governed by their own terms rather than by ours.
Vendors that are not sub-processors
We use other services that never receive personal data, and we leave them off the list above rather than padding it. Hosting is one: the origin runs on hardware we operate ourselves in the European Union, so there is no hosting provider holding your data. Public data sources are another — domain availability and pricing are read from public registry and registrar interfaces, and market listings are read from public pages, in both cases without sending anything about you.
Categories we maintain rather than fix
Two categories exist where the specific vendor can change: the model provider behind the agent, and the payment route for a given currency or market. Where either changes, the table above is the current record and the notice below is how you hear about it before it happens. We would rather revise a published list than publish a vague one.
Notice of changes
We give at least 30 days’ notice before adding or replacing a sub-processor, under clause 5 of the data processing addendum. To receive that notice by email, write to [email protected] with “sub-processor notice” in the subject. Business customers may object on reasonable data protection grounds within the notice period, and that clause says what happens next.
What each of them has agreed to
Every party above is bound by a written data processing agreement meeting Article 28 GDPR, with the obligations published in full at sub-processor terms — including that they process only on our instructions, do not use the data for their own purposes, do not use it to train models, and report a breach to us within 48 hours. We remain fully liable to you for what they do.
For what we hold ourselves and for how long, see data handling and retention; for the rights you hold over it, clause 8 of the privacy policy.