Sub-processors
Effective: 2026-04-19
The following sub-processors may process personal data on our behalf. Each operates under a written data-processing agreement (or equivalent terms incorporating GDPR Art. 28 requirements). We notify customers of additions or material changes through this page; for B2B (StackPatch Pro / Team) customers we additionally email data-protection@ contacts.
| Vendor | Purpose | Data | Region | Transfer mechanism |
|---|---|---|---|---|
| Netlify Inc. | Web hosting + edge functions | Identifiers, usage | US (multi-region) | EU SCCs |
| Supabase Inc. | Postgres database + auth | Identifiers, commercial | US-East | EU SCCs |
| Stripe Inc. | Payment processing | Payment, identifiers | US, EU | EU SCCs (independent controller) |
| Resend Inc. | Transactional + marketing email | Identifiers | US | EU SCCs |
| Forward Email LLC | Inbound email routing for shared mailboxes | Identifiers | US | EU SCCs |
| Cloudflare Inc. | CDN + DNS + DDoS protection | IP, request metadata | Global anycast | EU SCCs |
| Hostinger International Ltd. | VPS hosting (StackPatch + site backend) | Request metadata | EU (LT) | Adequacy decision (EU/EEA) |
| Anthropic PBC | LLM inference (Claude family) | Prompt content (zero-retention via API) | US | EU SCCs |
| OpenAI OpCo LLC | LLM inference (GPT family, fallback) | Prompt content (zero-retention via API) | US | EU SCCs |
| Google LLC (Gemini API + AdSense + Analytics) | Optional LLM inference + ads + analytics | Prompt + ad/analytics IDs | US | EU SCCs |
| Groq Inc. | Optional LLM inference (low-latency fallback) | Prompt content | US | EU SCCs |
| Discord Inc. | Community channel (opt-in) | Identifiers, content | US | EU SCCs |
| GitHub Inc. (Microsoft) | Source-code hosting | Issue / commit metadata | US | EU SCCs |
Independent controllers (e.g., Stripe for fraud-prevention purposes, payment networks) process certain data under their own terms. We do not direct that processing.
Object to a New Sub-processor
B2B customers may object to a new sub-processor for legitimate data-protection reasons by emailing privacy@mindsparkstack.com within 30 days of notification. We will work in good faith to provide an alternative or, if none is feasible, allow you to terminate the affected service for a prorated refund.