Legal
Sub-processors
Last updated: 8 June 2026
Every vendor with access to Tradeflo customer data is listed below. We update this page within 30 days of any addition. Each vendor has its own Data Processing Agreement with us, listed by link below — they're each independently bound by GDPR. We never sell data to any of them, and they never sell data downstream.
| Vendor | What they do | Data | Region | DPA |
|---|---|---|---|---|
| Vercel | Website + API hosting, edge functions | Visitor IPs (transit only), HTTP request logs (30-day rotation) | US-headquartered, EU edge (Frankfurt) | View → |
| Supabase | Postgres database, authentication, file storage, edge functions | Client account data, lead records, audit submissions, audit results | EU — Frankfurt | View → |
| PostHog | Site analytics, session replays (only after cookie consent) | Pseudonymised visitor events, page views, click paths. No PII. | EU-hosted | View → |
| Stripe | Payment processing, subscription billing, KYC for paid clients | Cardholder data (held by Stripe, not us), billing email, billing address | Ireland (Stripe Payments Europe Ltd, Dublin) | View → |
| Resend | Transactional email delivery (audit confirmations, lead alerts) | Recipient email, message content | US-headquartered, EU/US sending infrastructure | View → |
| Twilio | SMS + WhatsApp message delivery on behalf of clients | Recipient phone number, message content | Twilio Ireland Ltd (Dublin) | View → |
| Anthropic (Claude API) | AI analysis for the free-audit scan and the AI Automation Suite | Business name, website URL, public-website scrape results. No customer PII beyond what is needed for the scan. | US-headquartered, EU API endpoint available | View → |
| Browserless | Headless browser rendering for audit PDF generation | Public web pages being audited (no personal data unless user submits a PII-laden URL) | EU/US infrastructure | View → |
| Upstash | Redis for API rate limiting (per-IP + per-domain caps) | Hashed IP addresses, request counters. 24-hour rolling window. | EU region (Frankfurt) for Tradeflo workloads | View → |
| Loops / ConvertKit | Nurture email sequences — only for people who explicitly opt in | Email, name, marketing engagement events | US | View → |
Changes to this list
Active clients are notified by email when we add a new sub-processor. You have a right to object — see the Data Processing Addendum for the formal mechanism. Site visitors who haven't signed up don't need to be notified — refer to this page any time.